The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/bci-minimal was updated. The following patches have been included in this update:
The container bci/bci-micro was updated. The following patches have been included in this update:
The container suse/helm was updated. The following patches have been included in this update:
A buffer overflow in parsing WebP images may result in the execution of arbitrary code. For Debian 10 buster, this problem has been fixed in version
An update for busybox is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
The container sles-15-sp5-chost-byos-v20230915-arm64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp5-chost-byos-v20230915-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
Update matrix-synapse to v1.80.0 to fix CVE-2022-39374, CVE-2023-32323
Update matrix-synapse to v1.80.0 to fix CVE-2022-39374, CVE-2023-32323
security update
A buffer overflow in parsing WebP images may result in the execution of arbitrary code. For Debian 10 buster, this problem has been fixed in version
A vulnerability has been discovered in Requests which could result in the disclosure of plaintext secrets.
Multiple vulnerabilities have been discovered in Binwalk, the worst of which could result in remote code execution.
Multiple vulnerabilities have been discovered in Samba, the worst of which could result in root remote code execution.
An arbitrary file overwrite vulnerability has been discovered in RAR and UnRAR, potentially resulting in arbitrary code execution.
Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which could result in remote code execution.
A buffer overflow in parsing WebP images may result in the execution of arbitrary code. For Debian 10 buster, this problem has been fixed in version
The container bci/dotnet-aspnet was updated. The following patches have been included in this update:
Backport fix for CVE-2023-4863.
**Redis 7.0.13** Released Wed 06 Sep 2023 15:00:00 IDT Upgrade urgency SECURITY: See security fixes below. Security Fixes * (**CVE-2023-41053**) Redis does not correctly identify keys accessed by SORT_RO and as a result may grant users executing this command access to keys that are not explicitly authorized by the ACL configuration. Bug Fixes * Cluster: […]
Security fix for CVE-2020-22219
– fix HTTP headers eat all memory (CVE-2023-38039)
Ballistic Bobcat is a suspected Iran-aligned cyberespionage group that targets organizations in various industry verticals, as well as human rights activists and journalists, mainly in Israel, the Middle East, and the United States
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
atftp could be made to crash if it received specially crafted network traffic.
An update that fixes one vulnerability is now available.
A vulnerability has been identified in c-ares, an asynchronous name resolver library: CVE-2020-22217:
– Updated to latest upstream (117.0.1)
security update
security update
Do you know what types of scams and other fakery you should look out for when using a platform that once billed itself as “the front page of the Internet”?
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:
The container rancher/seedimage-builder was updated. The following patches have been included in this update:
The container rancher/elemental-operator was updated. The following patches have been included in this update:
The update to X’s privacy policy has sparked some questions among privacy and security folks, including how long X will retain users’ biometric information and how the data will be stored and secured
Closing intrusion vectors force cybercriminals to revisit old attack avenues, but also to look for new ways to attack their victims
New reports from Europol and the UK’s National Crime Agency (NCA) shed a light on how the battle against cybercrime is being fought
ESET Research uncovers the Sponsoring Access campaign, which utilizes an undocumented Ballistic Bobcat backdoor we have named Sponsor
ESET research uncovers active campaigns targeting Android users and spreading espionage code through the Google Play store, Samsung Galaxy Store and dedicated websites
Phishing emails are a weapon of choice for criminals intent on stealing people’s personal data and planting malware on their devices. The healing process does not end with antivirus scanning.
Listen as ESET’s Director of Threat Research Jean-Ian Boutin unravels the tactics, techniques and procedures of MoustachedBouncer, an APT group taking aim at foreign embassies in Belarus
ESET researchers uncover a Telegram bot that enables even less tech-savvy scammers to defraud people out of their money
ESET researchers have discovered active campaigns linked to the China-aligned APT group known as GREF, distributing espionage code that has previously targeted Uyghurs
If you want to try to enter the world of VPNs with a small dip, then iCloud Private Relay is your friend — but is it a true VPN service? The devil is in the details.
The campaign started with a trojanized version of unsupported financial software
Analysis of Spacecolon, a toolset used to deploy Scarab ransomware on vulnerable servers, and its operators, CosmicBeetle
DEF CON, the annual hacker convention in Las Vegas, was interrupted on Saturday evening when authorities evacuated the event’s venue due to a bomb threat
The limits of current AI need to be tested before we can rely on their output
When it comes to privacy, it remains complicated and near impossible for a consumer to make an informed decision.
Unsurprisingly, artificial intelligence took the center stage at this year’s edition of Black Hat, one of the world’s largest gatherings of cybersecurity professionals
Search engines, AI, and monetization in the new era
Hiding behind a black box and hoping no one will hack it has been routinely proven to be unwise and less secure.
The AI race is on! It’s easy to lose track of the latest developments and possibilities, and yet everyone wants to see firsthand what the hype is about. Heydays for cybercriminals!
Current LLMs are just not mature enough for high-level tasks
Black Hat is big on AI this year, and for a good reason
What happens to cyberweapons after a cyberwar?
ESET researchers have observed a new phishing campaign targeting users of the Zimbra Collaboration email server.
Analysis of Telegram bot that helps cybercriminals scam people on online marketplaces
When you invest in a company, do you check its cybersecurity? The U.S. Securities and Exchange Commission has adopted new cybersecurity rules.
Long-term espionage against diplomats, leveraging email-based C&C protocols, C++ modular backdoors, and adversary-in-the-middle (AitM) attacks… Sounds like the infamous Turla? Think again!
Gamers and cybersecurity professionals have something in common – the ever-terrible presence of hacking, scams, and data theft – but how and why would anyone want to target gamers?
Bills granting access to end-to-end encrypted systems, opportunity for cybercriminals, abuse by authority, human rights, and tech companies leaving the UK?
With powerful AI, it doesn’t take much to fake a person virtually, and while there are some limitations, voice-cloning can have some dangerous consequences.
Browser fingerprinting is supposedly a more privacy-conscious tracking method, replacing personal information with more general data. But is it a valid promise?
Current cryptographic security methods watch out – quantum computing is coming for your lunch.
Mitigate the risk of data leaks with a careful review of the product and the proper settings.
