Menu

Category Archives: All

Everything

Several security issues were fixed in DHCP.

Several vulnerabilities were discovered in BIND, a DNS server implementation. CVE-2022-2795

Multiple vulnerabilities were discovered in Node.js, a JavaScript runtime environment, which could result in memory corruption, invalid certificate validation, prototype pollution or command injection.

Don’t let your employees become the weakest link
Modified version of Tor Browser spies on Chinese users
Enterprise Encryption for Linux: Improve Manageability & Compliance

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

DoJ ‘very disappointed’ with probation sentence for Capital One hacker Paige Thompson
All your identity needs fulfilled
No Shangri-La for you: Top hotel chain confirms data leak
Uncle Sam orders federal agencies to step up scans for govt IT security holes
How a deepfake Mark Ruffalo scammed half a million dollars from a lonely heart
8 questions to ask yourself before getting a home security camera

As each new smart home device may pose a privacy and security risk, do you know what to look out for before inviting a security camera into your home? The post 8 questions to ask yourself before getting a home security camera appeared first on WeLiveSecurity

Microsoft: Watch out for password spray attacks – especially you, Basic Auth
CISA orders federal agencies to catalog their networks, and scan for bugs
Romance scammer and BEC fraudster sent to prison for 25 years

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Rocky Linux Security Advisories Are Now on LinuxSecurity.com!
Kolide can help you nail audits and compliance goals with endpoint security for your entire fleet
Japanese sushi chain boss resigns amid accusation of improper data access
Giveaways for every security professional
Atlassian, Microsoft bugs on CISA’s must-patch list after exploitation spree
Scammers and rogue callers – can anything ever stop them?
Online romance scamlord who netted $9.5m jailed for 25 years

security update

From today, America and UK follow new rules on how they can demand your data from each other
It’s 2058. A quantum computer is just another decade away. Still, you curse Cloudflare
National Cybersecurity Awareness program 18 years on: Don’t click that
Student data leaked after LA school district says it won’t pay ransom
There’s good and bad news about the Microsoft Exchange server zero-day exploit
FBI: We tracked who was printing secret documents to unmask ex-NSA suspect
Cyber-proofing data in the cloud

Several security issues were fixed in the Linux kernel.

Founder of cybersecurity firm Acronis is afraid of his own vacuum cleaner
Between ransomware and month-long engagements, IR teams need a hug – and a nap

An update that fixes three vulnerabilities is now available.

This update includes the changes in tzdata 2022d for the Perl bindings. For the list of changes, see DLA-3134-1. For Debian 10 buster, this problem has been fixed in version

Moody’s turns up the heat on ‘riskiest’ sectors for cyberattacks

This update includes the changes in tzdata 2022d. Notable changes are: – – Palestine now switches back to standard time on October 29.

An invalid HTTP request (websocket handshake) may cause a NULL pointer dereference in the wstunnel module. For Debian 10 buster, this problem has been fixed in version

Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Steganography alert: Backdoor spyware stashed in Microsoft logo
BlackCat malware lashes out at US defense IT contractor

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

ESET Research into new attacks by Lazarus – Week in security with Tony Anscombe

The attack involved the first recorded abuse of a security vulnerability in a Dell driver that was patched in May 2021 The post ESET Research into new attacks by Lazarus – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Amazon‑themed campaigns of Lazarus in the Netherlands and Belgium

ESET researchers have discovered Lazarus attacks against targets in the Netherlands and Belgium that use spearphishing emails connected to fake job offers The post Amazon‑themed campaigns of Lazarus in the Netherlands and Belgium appeared first on WeLiveSecurity

S3 Ep102.5: “ProxyNotShell” Exchange bugs – an expert speaks [Audio + Text]

An update that fixes two vulnerabilities is now available.

Gone in a day: Ethical hackers say it would take mere hours to empty your network

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Two issues were found in GDAL, a geospatial library, that could lead to denial of service via application crash or possibly the execution of arbitrary code if maliciously crafted data was parsed.

thenify is a Promisify a callback-based function using any-promise. Affected versions of this package are vulnerable to Arbitrary Code Execution. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval

Update to 102.3.1 * https://www.mozilla.org/en- US/security/advisories/mfsa2022-43/ * https://www.thunderbird.net/en- US/thunderbird/102.3.1/releasenotes/

security update

An issue has been found in tinyxml, a C++ XML parsing library. Crafted XML messages could lead to an infinite loop in TiXmlParsingData::Stamp(), which results in a denial of service.

Protecting teens from sextortion: What parents should know

Online predators increasingly trick or coerce youth into sharing explicit videos and photos of themselves before threatening to post the content online The post Protecting teens from sextortion: What parents should know appeared first on WeLiveSecurity

Prison for ex-eBay staff who aggressively cyberstalked company’s critics with Craigslist sex party ads and funeral wreaths
Enterprises embrace devsecops practices against supply chain attacks
Watchfinder warns customers that hackers stole their data
URGENT! Microsoft Exchange double zero-day – “like ProxyShell, only different”

An issue has been found in libhttp-daemon-perl, a simple http server class. Due to insufficient Content-Length: handling in HTTP-header an attacker

Connecting to the RHEL web console, part 2: Running the Cockpit web server

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

This update upgrades Thunderbird to version 102.3.0. * Mozilla: Leaking of sensitive information when composing a response to an HTML email with a META refresh tag (CVE-2022-3033) * Mozilla: Bypassing FeaturePolicy restrictions on transient pages (CVE-2022-40959) * Mozilla: Data-race when parsing non-UTF-8 URLs in threads (CVE-2022-40960) * Mozilla: Memory safety bugs fixed in Firefox 105 […]

This update upgrades Firefox to version 102.3.0 ESR. * Mozilla: Bypassing FeaturePolicy restrictions on transient pages (CVE-2022-40959) * Mozilla: Data-race when parsing non-UTF-8 URLs in threads (CVE-2022-40960) * Mozilla: Memory safety bugs fixed in Firefox 105 and Firefox ESR 102.3 (CVE-2022-40962) * Mozilla: Bypassing Secure Context restriction for cookies with __Host and __Secure pref [More…]

Microsoft warns of North Korean crew posing as LinkedIn recruiters
Stop us if you’ve heard this one before: Exchange Server zero-day being actively exploited
Ex-eBay execs jailed for cyberstalking web critics
How CIA betrayed informants with shoddy front websites built for covert comms
Pentagon is far too tight with its security bug bounties

security update

security update

IT admin admits sabotaging ex-employer’s network in bid for higher salary
S3 Ep102: Cutting through cybersecurity news hype [Audio + Transcript]
Covert malware targets VMware shops for hypervisor-level espionage

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Red Hat Shares ― Edge computing: Security
Why developers hold the key to cloud security
Microsoft to kill off old access rules in Exchange Online
Smashing Security podcast #291: Deepfake dangers, AI image opt out, and controlling your urges
Matrix chat encryption sunk by five now-patched holes