Menu

Category Archives: All

Everything

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

Red Hat OpenShift Virtualization release 4.8.5 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that solves four vulnerabilities and has one errata is now available.

Critical bug allows attacker to remotely control medical robot
Industroyer2: Industroyer reloaded

This ICS-capable malware targets a Ukrainian energy company The post Industroyer2: Industroyer reloaded appeared first on WeLiveSecurity

Singapore to license pentesters and managed infosec operators
Defending the Endpoint with AI
HCL and HP named in unflattering audit of India’s biometric ID system
European officials reportedly targeted by NSO spyware
Microsoft Takes Down Domains Used in Cyberattack Against Ukraine
Attackers exploit Spring4Shell flaw to let loose the Mirai botnet
OpenSSH goes Post-Quantum, switches to qubit-busting crypto by default
There are few guarantees when it comes to ransomware, except that you’re a target
Identity access management has a new price: $6.9 billion

Security fix for CVE-2022-1154 Security fix for CVE-2022-1160 —- The newest upstream commit Security fix for CVE-2022-0943

Update to 1.6.2 (rhbz#2068277). Mitigates CVE-2022-24769 / GHSA-c9cp-9c75-9v8c.

Update to 1.1.4 (rhbz#2068719). Mitigates CVE-2022-24778 (rhbz#2069368, rhbz#2069369).

libarchive could be made to expose sensitive information if it received a specially crafted archive file.

– Update to latest upstream (Firefox 99.0 & nss 3.77).

– Update to latest upstream (Firefox 99.0 & nss 3.77).

“Pen tester” who helped FIN7 gang cause $1 billion damage, sentenced to five years behind bars
Google Play pulls sneaky data-harvesting apps with 46m+ downloads

Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec. CVE-2020-27842

GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment). (CVE-2021-45943)

Stack based buffer overflow. (CVE-2022-25308) Heap-buffer-overflow in fribidi_cap_rtl_to_unicode. (CVE-2022-25309) SEGV in fribidi_remove_bidi_marks. (CVE-2022-25310) References:

BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record’s value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal’s colors. (CVE-2022-28391)

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault […]

A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination. (CVE-2021-3700)

GitHub enhances secret scanning for tighter code security

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Finnish govt websites knocked down as Ukraine President addresses MPs
Microsoft dogs Strontium domains to stop attacks on Ukraine

security update

You are Tracked Online – Why? And How To Avoid Being Tracked Online>

The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-22624

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-22624

Five security issues have been discovered in libxml2: XML C parser and toolkit. CVE-2016-9318

Red Hat OpenShift Container Platform release 4.10.8 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

Zero days are for life, not just for Christmas. Here’s how to deal with them
Google Play Bitten by Sharkbot Info-stealer ‘AV Solution’
Popular Ruby Asciidoc toolkit patched against critical vuln – get the update now!

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The following updated rpms for Oracle Linux Cloud Native Environment 1.1 have been uploaded to the Unbreakable Linux Network:

China accused of cyberattacks on Indian power grid
What’s it like on the cyber frontline? Find out in this online session
FIN7 crime-gang pen tester headed to US prison for five years
Russia (still) trying to weaponize Facebook for spying, Ukraine-war disinfo

security update

Adobe Creative Cloud Experience makes it easier to run malware
Fintech platform flaw could have allowed bank transfers, exposed data
Companies are more prepared to pay ransoms than ever before, reveals new report
Broader investment in cybersecurity beginning to pay dividends
Attackers Spoof WhatsApp Voice-Message Alerts to Steal Info
Authorities Fully Behead Hydra Dark Marketplace
SSRF Flaw in Fintech Platform Allowed for Compromise of Bank Accounts

Several security issues were fixed in fribidi.

MacOS Malware: Myth vs. Truth – Podcast
S3 Ep77: Bugs, busts and old-school PDP-11 hacking [Podcast]

Security fix for CVE-2022-27651

Minor update for CVE-2022-1096. Also fixes dependency issues for chrome-remote- desktop and sizing issues where some libraries/binaries were not being stripped.

oslo.utils could be made to expose sensitive information if it received a specially crafted input.

Security fix for CVE-2022-27651

Minor update for CVE-2022-1096. Also fixes dependency issues for chrome-remote- desktop and sizing issues where some libraries/binaries were not being stripped.

How do China’s cyber-spies snoop on governments, NGOs? Probably like this
When MFA fails, defense in depth is key
Cryptocurrency-mining AWS Lambda-specific malware spotted
Smashing Security podcast #269: Trezor Deep Throat, a CCTV stalker, and Amazon’s list of banned words
Hamas-linked cyber-spies ‘target high-ranking Israelis’
Control IT and SaaS complexity with Axonius
Feds take down Kremlin-backed Cyclops Blink botnet
We’re going on Tor

If better privacy and anonymity sound like music to your ears, you may not need to look much further than Tor Browser. Here’s what it’s like to surf the dark web using the browser. The post We’re going on Tor appeared first on WeLiveSecurity

Serious Security: Darkweb drugs market Hydra taken offline by German police
Block claims ex-employee downloaded customer data after leaving firm

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

An update for python-waitress is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Fake e‑shops on the prowl for banking credentials using Android malware

ESET researchers analyzed three malicious applications targeting customers of eight Malaysian banks The post Fake e‑shops on the prowl for banking credentials using Android malware appeared first on WeLiveSecurity

UK spy agencies sharing bulk personal data with foreign allies was legal, says court

kernel: use-after-free in RDMA listen() (CVE-2021-4028) * kernel: fget: check that the fd still exists after getting a ref to it (CVE-2021-4083) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Adding new kernel entry in grub configuration file […]

Apple patched critical flaws in macOS Monterey but not in Big Sur nor Catalina

An update for python-waitress is now available for Red Hat OpenStack Platform 16.2 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Feds slay dark-web souk Hydra: Servers and $25m in crypto-coins seized
US State Department opens cybersecurity policy bureau
Firefox 99 is out – no major bugs, but update anyway!
GitHub tackles leaks by scanning for secrets in pushed code
Google’s monthly Android updates patch numerous “get root” holes
Cooler heads needed in heated E2EE debate, says think tank

Several security issues were fixed in H2.

No-Joke Borat RAT Propagates Ransomware, DDoS

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

An update for kernel is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,