Menu

Category Archives: All

Everything

DSE measures and improves DevOps

An update that fixes one vulnerability is now available.

An update that fixes 15 vulnerabilities is now available.

The 5.14.16 stable kernel update contains a number of important fixes across the tree.

The 5.14.16 stable kernel update contains a number of important fixes across the tree.

The binary got built with Fedora mandatory compiler flags.

Cybercriminals have made headlines by forcing Fortune 500 companies to pay million-dollar ransom payments to retrieve their data and unlock their systems. But despite the headlines, most ransomware targets families as well as small and medium sized businesses. In fact, the average ransom payment is closer to $50,000. And it makes sense – just like […]

Reg reader returns Samsung TV after finding giant ads splattered everywhere
Native Tribal Casinos Taking Millions in Ransomware Losses

An update that fixes 15 vulnerabilities is now available.

“Customer complaint” email scam preys on your fear of getting into trouble at work
BrakTooth Bluetooth Bugs Bite: Exploit Code, PoC Released
Google squashes Android zero‑day bug exploited in targeted attacks

Beyond the vulnerability in the Android kernel, the monthly round of security patches plugs another 38 security loopholes The post Google squashes Android zero‑day bug exploited in targeted attacks appeared first on WeLiveSecurity

Beyond the Basics: Tips for Building Advanced Ransomware Resiliency
No day in court: US Foreign Intelligence Surveillance Court rulings will stay a secret
Google Ads for Faux Cryptowallets Net Scammers At Least $500K
Proofpoint Phish Harvests Microsoft O365, Google Logins
Reward! Uncle Sam promises $10m for info about DarkSide ransomware gang chiefs
Feds Offer $10 Million Bounty for DarkSide Info
Labour Party supplier ransomware attack: Who holds ex-members’ data and on what legal basis?
Technically Speaking series decodes DevSecOps

There were a couple of vulnerabilites found in src:python3.5, the Python interpreter v3.5, and are as follows: CVE-2021-3733

This update upgrades Thunderbird to version 91.3.0. * Mozilla: Use-after-free in HTTP2 Session object * Mozilla: Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3 * Mozilla: iframe sandbox rules did not apply to XSLT stylesheets (CVE-2021-38503) * Mozilla: Use-after-free in file picker dialog (CVE-2021-38504) * Mozilla: Firefox could be coaxed into going […]

Stefan Walter found that udisks2, a service to access and manipulate storage devices, could cause denial of service via system crash if a corrupted or specially crafted ext2/3/4 device or image was mounted, which could happen automatically on certain environments.

Beijing fingers foreign spies for data mischief, with help from consulting firm

The container suse/sles12sp5 was updated. The following patches have been included in this update:

Rust 1.56.1 adds a mitigation for CVE-2021-42574, the “trojan source” attack that obfuscates code with BiDi control characters. The compiler will now error on such characters in code comments and string/char literals. For more details, see the upstream [security advisory](https://blog.rust- lang.org/2021/11/01/cve-2021-42574.html).

When containers become a nightmare
US Blacklists Pegasus Spyware Maker
3 Guideposts for Building a Better Incident-Response Plan
S3 Ep57: Europol v. Ransomware, Shrootless bug, and Linux browser flamewars [Podcast]
“PlugWalkJoe” indicted for $784,000 SIM-swap cryptocurrency theft
Win one for privacy – Swiss providers don’t have to talk

Security and privacy get a leg up in Proton’s legal challenge against data retention and disclosure obligations The post Win one for privacy – Swiss providers don’t have to talk appeared first on WeLiveSecurity

What’s it like to work as a malware researcher? 10 questions answered

Three ESET malware researchers describe what their job involves and what it takes to embark on a successful career in this field The post What’s it like to work as a malware researcher? 10 questions answered appeared first on WeLiveSecurity

Free Discord Nitro Offer Used to Steal Steam Credentials
Critical Linux Kernel Bug Allows Remote Takeover

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Magecart Credit Card Skimmer Avoids VMs to Fly Under the Radar

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

FYI: Code compiled to WebAssembly may lack standard security defenses
Smashing Security podcast #250: Yes, you heard that correctly. Two hundred and fifty

This update upgrades Firefox to version 91.3.0 ESR. * Mozilla: Use-after-free in HTTP2 Session object * Mozilla: Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3 * Mozilla: iframe sandbox rules did not apply to XSLT stylesheets (CVE-2021-38503) * Mozilla: Use-after-free in file picker dialog (CVE-2021-38504) * Mozilla: Firefox could be coaxed into […]

Beijing lashes USA’s China Telecom ban – but quite gently

The 5.14.15 stable kernel update contains a number of important fixes across the tree.

US Dept of Commerce sanctions NSO Group, Positive Technologies, other makers of snoopware
Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign
Microsoft rolls out $3-a-user Defender for small biz types
Google warns Android users of zero-day vulnerability being actively attacked
‘Tortilla’ Wraps Exchange Servers in ProxyShell Attacks
Facebook to throw out face recognition, delete all template data
Predicting the Next OWASP API Security Top 10
Man charged with hacking major US sports leagues to illegally stream games

On top of illegally streaming sports games for profit, the man is also believed to have attempted to extort MLB for $150,000 The post Man charged with hacking major US sports leagues to illegally stream games appeared first on WeLiveSecurity

Top 6 Vulnerability Scanning Tools>
BlackMatter ransomware gang says it’s disbanding – again – after Ukraine arrests
Locked up: UK’s Labour Party data ‘rendered inaccessible’ on third-party systems after cyber attack

An update that solves two vulnerabilities and has two fixes is now available.

UK data spillers fined, but enforcement slows: £5m in ICO penalties not yet paid
Report: BlackMatter Ransomware Gang Goes Dark, Again

An update is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

BlackMatter ransomware gang to shut down
CyberUp presents four principles to keep security researchers out of jail for good-faith probing

The container sles-15-sp3-chost-byos-v20211101 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20211101-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20211101-gen2 was updated. The following patches have been included in this update:

Keeping an eye on critical infrastructure and industrial systems? So are legions of cyber-criminals
Squid Game Crypto Scammers Rips Off Investors for Millions

security update

security update

Ransomware Gangs Target Corporate Financial Activities
Android Patches Actively Exploited Zero-Day Kernel Bug
Apple macOS Flaw Allows Kernel-Level Compromise

An update that fixes 12 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Red Hat OpenShift Virtualization release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

China says it applied to join digital free trade deal days after proposing law against cross-border data flow

An update that solves two vulnerabilities and has one errata is now available.

Red Hat OpenShift Virtualization release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Office 365 Phishing Campaign Uses Kaspersky’s Amazon SES Token
Pirate Sports Streamer Gets Busted, Pivots to MLB Extortion
Your data is wider and deeper than ever – and so are the threats

An update for flatpak is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in WebKitGTK.

An update for flatpak is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Trojan Source attack: Code that says one thing to humans tells your compiler something very different, warn academics
‘Trojan Source’ Hides Invisible Bugs in Source Code
Android has its head in the sand with AbstractEmu malware rooting phones
Prevent identity fraud and disupt attackers with Recorded Future Identity Intelligence
Data transfers between the EU and the US: Still unclear on what you’re supposed to do? Here’s an explainer
Alleged Trickbot malware gang member extradited to United States, and appears in court

The package bind before version 9.16.22-1 is vulnerable to denial of service.

The package freerdp before version 2:2.4.1-1 is vulnerable to arbitrary code execution.

The package wpewebkit before version 2.34.1-1 is vulnerable to multiple issues including arbitrary code execution and sandbox escape.

The package webkit2gtk before version 2.34.1-1 is vulnerable to multiple issues including arbitrary code execution and sandbox escape.

The package opera before version 80.0.4170.63-1 is vulnerable to multiple issues including arbitrary code execution and sandbox escape.

The package chromium before version 95.0.4638.69-1 is vulnerable to multiple issues including arbitrary code execution and insufficient validation.

security update