Menu

Category Archives: All

Everything

Give put-upon infosec bods professional recognition to keep them working for you, says chartered institute

Red Hat OpenShift Container Platform release 4.6.46 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

REvil customers complain ransomware gang uses backdoors to filch ransoms

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

How secrets (mis)management is the next big cybersecurity threat – download the 1Password report
How to Prevent Account Takeovers in 2021
Gamers Beware: Malware Hunts Steam, Epic and EA Origin Accounts
ASUS patches ROG Armoury Crate app after researcher spots all-too-common flaw
SAS 2021: FinSpy Surveillance Kit Re-Emerges Stronger Than Ever
Google releases emergency fix to plug zero‑day hole in Chrome

The emergency release comes a mere three days after Google’s previous update that plugged another 19 security loopholes The post Google releases emergency fix to plug zero‑day hole in Chrome appeared first on WeLiveSecurity

Serious Security: Let’s Encrypt gets ready to go it alone (in a good way!)
Latest FinFisher spyware upgrades ‘particularly worrying,’ says Kaspersky
Romance scammers arrested in Texas for defrauding elderly lonely hearts
Assume Nothing: The story of the TalkTalk hack
Working Exploit Is Out for VMware vCenter CVE-2021-22005 Flaw
SolarWinds Attackers Hit Active Directory Servers with FoggyWeb Backdoor
How to secure cloud infrastructure across the development lifecycle
UK umbrella payroll firm GiantPay confirms it was hit by ‘sophisticated’ cyber-attack

USN-5090-1 introduced a regression in Apache HTTP Server.

All You Need To Know About IT Security Audits and Its Importance>

Several security issues were fixed in Vim.

USN-5090-1 introduced a regression in Apache HTTP Server.

Microsoft warns: Active Directory FoggyWeb malware being actively used by Nobelium gang

An update for fwupd, shim, shim-unsigned-aarch64, and shim-unsigned-x64 is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Credential Spear-Phishing Uses Spoofed Zix Encrypted Email

An update that fixes 5 vulnerabilities is now available.

Q2 2022 should see networking sales boom – when payouts to replace Huawei and ZTE kit start to flow
Emails, chat logs, more leaked online from far-right militia linked to US Capitol riot
Blockhead admits to helping North Korea mine crypto-bucks, faces 20 years jail
India, Japan flex cyber-defence muscles as China kicks the Quad
Story of the creds-leaking Exchange Autodiscover flaw – the one Microsoft wouldn’t fix even after 5 years
5 Steps to Securing Your Network Perimeter
Women, Minorities Are Hacked More Than Others
Move faster with continuous security scanning in the cloud
EU: Russia Behind ‘Ghostwriter’ Campaign Targeting Germany
3.8 Billion Users’ Combined Clubhouse, Facebook Data Up for Sale
UK’s National Crime Agency WLTM Deputy Director of Digital Data & Technology

Several security issues were fixed in Apache HTTP Server.

Fake ‘BT’ caller fleeces elderly victim of £30k in APP app scam

Several security issues were fixed in Apache HTTP Server.

Apache Santuario, XML Security for Java, is vulnerable to an issue where the “secureValidation” property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.

Upstream details at : https://access.redhat.com/errata/RHSA-2021:3438

Cyber security in the public cloud

An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

‘Quad’ group seeks to set security standards for global tech industry

An issue has been found in openssl, a Secure Sockets Layer toolkit. Ingo Schwarze reported a buffer overrun flaw when processing ASN.1 strings, which can result in denial of service.

An update that fixes 19 vulnerabilities is now available.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

Update to latest in git.

update for sharpziplib 1.3.3 which contains a security fix

update for sharpziplib 1.3.3 which contains a security fix

Update to v1.41.1 Fix CVE-2021-39163, CVE-2021-39164

Cumulative bug-fix release from upstream.

– fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165)

Rebuild for CVE-2021-3672 in c-ares library

Update to 1.1.1l version

Update to 2.0.1; fix RHBZ#1932066 (unsafe use of strncpy), fix RHBZ#1932066

security update

Frustrated dev drops three zero-day vulns affecting Apple iOS 15 after six-month wait
Exchange/Outlook Autodiscover Bug Spills $100K+ Email Passwords

An update that solves 20 vulnerabilities and has 106 fixes is now available.

An update that fixes 5 vulnerabilities is now available.

Rebase with Security fix for CVE-2021-3781

Update to 1.93, fixes CVE-2020-19752

Fix issue with incorrect obsoletes.

Bug in macOS Finder allows remote code execution

While Apple did issue a patch for the vulnerability, it seems that the fix can be easily circumvented The post Bug in macOS Finder allows remote code execution appeared first on WeLiveSecurity

FamousSparrow: A suspicious hotel guest

Yet another APT group that exploited the ProxyLogon vulnerability in March 2021 The post FamousSparrow: A suspicious hotel guest appeared first on WeLiveSecurity

TangleBot Malware Reaches Deep into Android Device Functions
S3 Ep51: OMIGOD a gaping hole, waybill scams, and Face ID hacked [Podcast]
Critical Cisco Bugs Allow Code Execution on Wireless, SD-WAN
Apple Patches 3 More Zero-Days Under Active Attack
Lithuania warns firms not to use Xiaomi and Huawei smartphones after investigation finds security and censorship concerns
The real value of continuous security scanning for cloud-based workloads
Stop worrying that crims could break the ‘net, say cyber-diplomats – only nations have tried
Apple warns of arbitrary code execution zero-day being actively exploited on Macs
REvil Affiliates Confirm: Leadership Were Cheating Dirtbags
STILL ALIVE! iOS 12 gets 3 zero-day security patches – update now
5 Tips for Achieving Better Cybersecurity Risk Management

Multiple issues have been discovered in mupdf. CVE-2016-10246

100M IoT Devices Exposed By Zero-Day Bug
How Outlook “autodiscover” could leak your passwords – and how to stop it
Plugging the holes: How to prevent corporate data leaks in the cloud

Misconfigurations of cloud resources can lead to various security incidents and ultimately cost your organization dearly. Here’s what you can do to prevent cloud configuration conundrums. The post Plugging the holes: How to prevent corporate data leaks in the cloud appeared first on WeLiveSecurity

Smashing Security podcast #244: Facebook Ray-Bans, VPN spies, and AI camouflage
US Government tells firms not to give in to ransomware demands, as first crypto exchange sanctioned for laundering cyber ransoms
FamousSparrow APT Wings in to Spy on Hotels, Governments

Red Hat Advanced Cluster Management for Kubernetes 2.1.11 General Availability release images, which provide a security fix and update the container images. Red Hat Product Security has rated this update as having a security impact

Google Report Spotlights Uptick in Controversial ‘Geofence Warrants’ by Police
Acronis Offers up to $5,000 to Users Who Spot Bugs in Its Cyber Protection Products
Domain Brand Monitor: The First Brand Protection Layer by WhoisXML API
UK Ministry of Defence apologises – again – after another major email blunder in Afghanistan

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Large-Scale Phishing-as-a-Service Operation Exposed
Researchers finger new APT group, FamousSparrow, for hotel attacks