Menu

Category Archives: Security

Articles about security

Dear all, What are some common subject lines in phishing emails?

Scammers exploit current ongoing events, account notifications, corporate communication, and a sense of urgency.

Used cars? Try used car accounts: 15,000 up for grabs online at just $2 a pop
How to snoop on passwords with this one weird trick (involving public Wi-Fi signals)
Capita class action: 2,000 folks affected by data theft sign up

Red Hat OpenShift Container Platform release 4.11.49 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.

Ransomware attack hits Sri Lanka government, causing data loss

RedCloth could be made to crash if it received specially crafted input.

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix a security issue.

Rebase to 0.5.2 to fix CVE-2023-22652 and CVE-2023-30079

China caught – again – with its malware in another nation’s power grid

It was discovered that there was a potential Man In the Middle (MITM) vulnerability in e2guardian, a web content filtering engine. Validation of SSL certificates was missing in e2guardian’s own MITM

Grab those updates: Microsoft flings out fixes for already-exploited bugs

security update

.NET could be made to crash if it received a specially crafted request.

OpenSSL 1.1.1 reaches end of life for all but the well-heeled
MGM Resorts shuts down IT systems and slot machines go quiet following “cybersecurity incident”
Google’s Chrome gets caught with its WebP down, offers hasty patch-up

An update that fixes four vulnerabilities is now available.

DISA STIG for Red Hat OpenShift is now available
Learn about Confidential Computing Attestation

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

North Korean hackers targeting vulnerability researchers with zero-day attacks, Google warns
Save the Children hit by ransomware, 7TB stolen

security update

security update

MGM Resorts shuts down website, computer systems after ‘cybersecurity incident’
Huge DDoS attack against US financial institution thwarted
Malice in the mail

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function. (CVE-2020-36023) An issue was discovered in freedesktop poppler version 20.12.1, allows

Extension script @substitutions@ within quoting allow SQL injection. (CVE-2023-39417) MERGE fails to enforce UPDATE or SELECT row security policies. (CVE-2023-39418)

Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix). (CVE-2023-36664) A buffer overflow flaw was found in base/gdevdevn.c:1973 in

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=”.?../../../../../../../../../../etc/passwd” in an xi:include element. (CVE-2023-38633)

Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. (CVE-2023-40477) References: – https://bugs.mageia.org/show_bug.cgi?id=32205

A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition […]

Google warns infoseccers: Beware of North Korean spies sliding into your DMs

security update

Enterprise security challenges for CNI organizations: Security challenges with people and processes

Security fix for CVE-2023-37464

– patchlevel 1872 —- The newest upstream commit Security fixes for CVE-2023-4733, CVE-2023-4752, CVE-2023-4750

Release notes for xrdp v0.9.23 (2023/08/31) General announcements – Running xrdp and xrdp-sesman on separate hosts is still supported by this release, but is now deprecated. This is not secure. A future v1.0 release will replace the TCP socket used between these processes with a Unix Domain Socket, and then cross-host running will not be […]

Security fix for CVE-2023-37464

Release notes for xrdp v0.9.23 (2023/08/31) General announcements – Running xrdp and xrdp-sesman on separate hosts is still supported by this release, but is now deprecated. This is not secure. A future v1.0 release will replace the TCP socket used between these processes with a Unix Domain Socket, and then cross-host running will not be […]

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The container bci/php was updated. The following patches have been included in this update:

The container bci/php-fpm was updated. The following patches have been included in this update:

The container bci/php-apache was updated. The following patches have been included in this update:

Security fix for CVE-2022-45061

New version 4.0.8. Includes fixes for CVE-2023-2906, CVE-2023-4511, CVE-2023-4512, CVE-2023-4513.

Security fix for CVE-2022-45061

security update

Safe delivery

An update is now available for Red Hat OpenShift GitOps 1.9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Apple races to patch the latest zero-day iPhone exploit

Vulnerabilities were found in libssh2, a client-side C library implementing the SSH2 protocol, which could lead to denial of service or remote information disclosure.

Microsoft, recently busted by Beijing, thinks it’s across China’s ever-changing cyber-offensive

It was discovered that there was a potential denial of service vulnerability in Django, a popular Python-based web development framework.

Russian infosec boss gets nine years for $100M insider-trading caper using stolen data

Several security issues were fixed in GRUB2.

It was discovered that there was a potential Denial of Service (DoS) vulnerability in memcached, a high-performance in-memory object caching system.

Update to prevent invalid fragment values from leading to a buffer overrun

US, UK sanction more Russians linked to Trickbot
Lawsuit claims Tesla corp data security is far less advanced than its cars

Cybercrime is on the rise. The number of ransomware attacks has increased by 18%, while the worldwide volume of phishing attacks doubled to 500 million in 2022. Depending on the size of the business, one-third to two-thirds of businesses suffer malware attacks in any given year. And those attacks are costing companies a lot of […]

Thousands of dollars stolen from Texas ATMs using Raspberry Pi

When it comes to keeping sensitive data safe, email encryption is a necessity. But it doesn’t have to be a necessary evil. Too many employees and IT experts have experienced the pain of trying to use a needlessly complicated email encryption solution. There’s the endless steps, the hard-to-navigate portals, and the time-consuming processes that add […]

Pizza Hut Australia leaks one million customers’ details, claims ShinyHunters hacking group

PLIB could be made to execute arbitrary code if it opens a specially crafted TGA file.

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

If you like to play along with the illusion of privacy, smart devices are a dumb idea
UK drops ‘spy clause’ for scanning encrypted messages, admits it’s not ‘feasible’

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-busybox was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-busybox was updated. The following patches have been included in this update:

China reportedly bans iPhones from more government offices
Smashing Security podcast #338: Catfishing services, bad sports, and another cockup
Microsoft: China stole secret key that unlocked US govt email from crash debug dump
Guy who ran Bitcoins4Less tells Feds he had less than zero laundering protections
Coffee Meets Bagel outage caused by cybercriminals deleting data and files
Meatbag mishaps more menacing than malware? CISOs think so

Updated Red Hat OpenShift Distributed Tracing 2.9 container images are now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Red Hat OpenShift Container Platform release 4.10.67 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update:

security update

You patched yet? Years-old Microsoft security holes still hot targets for cyber-crooks

security update

Big Tech has failed to police Russian disinformation, EC study concludes
Freecycle gives users the gift of a data breach notice

Multicluster Engine for Kubernetes 2.1.8 General Availability release images, which fix bugs and update container images. Red Hat Product Security has rated this update as having a security impact

An update is now available for Red Hat Ansible Automation Platform 2.4 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.