Menu

Category Archives: Security

Articles about security

North Korea ready to cash out more than $40 million in Bitcoin after summer of hacks, warns FBI
Pulling the strings

Han Zheng discovered an out-of-bounds write in w3m, a text based web browser and pager. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service (DoS) or possibly have unspecified other impact.

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Two teens were among those behind the Lapsus$ cyber-crime spree, jury finds
Smashing Security podcast #336: Pizza pests, and securing your wearables
Tornado Cash ‘laundered over $1B’ in criminal crypto-coins
North Korea may be itching to sell $40m of purloined Bitcoin
Nearly a third of young people preyed on by “text pest” delivery drivers
BlackCat ransomware gang claims credit for Seiko data breach
Criminals go full Viking on CloudNordic, wipe all servers and customer data

Secondary Scheduler Operator for Red Hat OpenShift 1.1.2 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An auto-block can occur for an untrusted X-Forwarded-For header in MediaWiki, a website engine for collaborative work. X-Forwarded-For is not necessarily trustworthy and can specify multiple IP

Several vulnerabilities have been found in qt4-x11, a graphical windowing toolkit. CVE-2021-3481

‘Millions’ of spammy emails with no opt-out? That’ll cost you $650K, Experian

An update for subscription-manager is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for subscription-manager is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for subscription-manager is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

SEC fines fintech crypto fund that promised 2,700% returns

Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially allowing to crash the server, information disclosure or Cross-Site-Scripting attacks.

The devil in the detail
Apple’s defense against apps vandalizing other apps still broken, developer claims

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

Red Hat OpenStack Platform (RHOSP) 16.2.z (Train) director Operator containers are now available. 2. Description: Release of Red Hat OpenStack Platform (RHOSP) 16.2.z (Train) provides these

An update is now available for Red Hat Ansible Automation Platform 2.4 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

CVE-2023-20197 ClamAV File Scanning Infinite Loop Denial of Service Vulnerability

Ivanti Sentry exploited in the wild, patches emitted
Uncle Sam: Rest of the world would love to steal our space blueprints – don’t let ’em

security update

Leak of 75k employee records was insiders’ fault, claims Tesla

ClamAV could be made to crash if it opened a specially crafted file.

High severity vuln in WinRAR could allow code to run when files are opened

An update that fixes 21 vulnerabilities is now available.

Last rites for the UK’s Online Safety Bill, an idea too stupid to notice it’s dead

Several security issues were fixed in Vim.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/nginx was updated. The following patches have been included in this update:

Microsoft DNS boo-boo breaks Hotmail for users around the globe

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Better securing the frontlines: Leveraging Ansible Automation Platform and AIDE for DoD file integrity
Interpol arrests 14 who allegedly scammed $40m from victims in ‘cyber surge’

The container bci/golang was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

security update

The container suse/sles12sp5 was updated. The following patches have been included in this update:

respin of security cpu due to uninstallable sources subpkg —- updatet to july security update 382.b05

respin of security cpu due to uninstallable sources subpkg —- updatet to july security update 382.b05

update to 115.0.5790.170. Fixes several security issues

update to 2.9.8

FYI: There’s another BlackCat ransomware variant on the prowl

security update

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

Centralized cloud security is now a must-have

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/389-ds was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update:

Add ‘writing malware’ to the list of things generative AI is not very good at doing
Don’t just patch your Citrix gear, check for intrusion: Two bugs exploited in wild

security update

LinkedIn under attack, hackers seize accounts

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

FBI warns cryptocurrency app beta-testers of malware menace
Smashing Security podcast #335: AI chat wars, and hacker passwords exposed
Man arrested in Northern Ireland police data leak as more incidents come to light
Japan’s digital minister surrenders salary to say sorry for data leaks
Vietnam admits it has just ten percent of the infosec pros it needs
Discord.io pulls the cord after crooks steal 760K users’ info

Red Hat OpenShift Virtualization release 4.13.3 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

OpenStack Heat could be made to expose sensitive information.

Ceph could be made to run programs as an administrator.

LockBit’s dirty little secret: ransomware gang is failing to publish victims’ data

GStreamer could be made to denial of service if it received a specially crafted datetime string.

Two vunerabilities were discovered in openssl, a Secure Sockets Layer toolkit: CVE-2023-3446, CVE-2023-3817

Clorox cleans up IT security breach that soaked its biz ops

security update

Cumbria Police accidentally publish officers’ names and salaries online
Ensure data security at the edge
You’re not seeing double – yet another UK copshop is confessing to a data leak
Tech CEO admits role in tricking Qualcomm into $150M takeover
Florida Man and associates indicted for conspiracy to steal data, software

An update for rust-toolset-1.66-rust is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Chinese media teases imminent exposé of seismic US spying scheme