Menu

Category Archives: Security

Articles about security

Charming Kitten targets critical infrastructure in US and elsewhere with BellaCiao malware

The container bci/python was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

Smashing Security podcast #319: The CEO who also ran IT, Strava strife, and TikTok tall tales
Microsoft probes complaints of Edge leaking URLs to Bing
DoJ, Treasury accuses 3 men of laundering crypto for North Korea
Pro-Russia hackers attack European air traffic control website, but don’t panic! Flights continue as normal

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.11.7 on Red Hat Enterprise Linux 8 from Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact

Logging Subsystem 5.6.5 – Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Evasive Panda APT group delivers malware via updates for popular Chinese software

ESET Research uncovers a campaign by the APT group known as Evasive Panda targeting an international NGO in China with malware delivered through updates of popular Chinese software The post Evasive Panda APT group delivers malware via updates for popular Chinese software appeared first on WeLiveSecurity

The good, the bad and the generative AI

The container suse/pcp was updated. The following patches have been included in this update:

Red Hat OpenShift Container Platform release 4.10.58 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

USN-6010-2 caused some minor regressions in Firefox.

update to 112.0.5615.165. Fixes the following security issues: CVE-2023-2004 CVE-2023-2133 CVE-2023-2134 CVE-2023-2135 CVE-2023-2136 CVE-2023-2137 CVE-2023-2033 CVE-2023-2136

Apache Superset: A story of insecure default keys, thousands of vulnerable systems, few paying attention
Menaced by miscreants, critical infrastructure needs a good ETHOS. Ah, here’s one
How fiends abuse an out-of-date Microsoft Windows driver to infect victims

Several security issues were fixed in the Linux kernel.

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for OpenJDK. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for OpenJDK. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for pcs is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

How To Secure Against WordPress Vulnerabilities with Predictive Analysis Detection & Automated Remediation

An update that fixes 5 vulnerabilities is now available.

If you haven’t patched Microsoft Process Explorer, prepare to be pwned

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

An update for emacs is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for emacs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Multiple security issues were discovered in 389-ds-base: an open source LDAP server for Linux. CVE-2019-3883

That 3CX supply chain attack keeps getting worse: More victims found
Chinese scientists calculate the Milky Way’s mass as 805 billion times that of our Sun

Authenticated users can use the HINCRBYFLOAT command to create an invalid hash field that will crash Redis on access. (CVE-2023-28856) References: – https://bugs.mageia.org/show_bug.cgi?id=31809

security update

security update

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Backport fix for CVE-2023-1972.

ceph 16.2.12 GA Security fix for CVE-2022-3650

Disable stringop-overflow warnings. Patch “bfd-CVE-2023-1972” fixes a security issue in bfd library.

Update to 4.10 for CVE-2023-23009

Did you mistakenly sell your network access? – Week in security with Tony Anscombe

Many routers that are offered for resale contain sensitive corporate information and allow third-party connections to corporate networks The post Did you mistakenly sell your network access? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Linux malware strengthens links between Lazarus and the 3CX supply‑chain attack

Similarities with newly discovered Linux malware used in Operation DreamJob corroborate the theory that the infamous North Korea-aligned group is behind the 3CX supply-chain attack The post Linux malware strengthens links between Lazarus and the 3CX supply‑chain attack appeared first on WeLiveSecurity

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.12.2 on Red Hat Enterprise Linux 8 from Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact

European air traffic control confirms website ‘under attack’ by pro-Russia hackers

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

The container rancher/elemental-operator/5.3 was updated. The following patches have been included in this update:

The container rancher/elemental-teal/5.3 was updated. The following patches have been included in this update:

Microsoft pushes for more women in cybersecurity

security update

US Facebook users can now claim their share of $725 million Cambridge Analytica settlement
MacStealer – newly-discovered malware steals passwords and exfiltrates data from infected Macs
International cops urge Meta not to implement secure encryption for all
Healthcare organisations urged to improve system security

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The container suse/postgres was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container suse/registry was updated. The following patches have been included in this update:

Thanks for fixing the computer lab. Now tell us why we shouldn’t expel you?

update to 112.0.5615.121. Fixes the following security issues: CVE-2023-2004 CVE-2023-2133 CVE-2023-2134 CVE-2023-2135 CVE-2023-2136 CVE-2023-2137 CVE-2023-2033

Update to 4b3d078 (dr_wav 0.13.8): fix a possible null-pointer dereference and a crash when loading files with badly-formed metadata.

The EU’s Cyber Solidarity Act: Security Operations Centers to the rescue!

The legislation aims to bolster the Union’s cyber-resilience and enhance its capabilities to prepare for, detect and respond to incidents The post The EU’s Cyber Solidarity Act: Security Operations Centers to the rescue! appeared first on WeLiveSecurity

PC running slow? 10 ways you can speed it up

Before you rush to buy new hardware, try these simple tricks to get your machine up to speed again – and keep it that way. The post PC running slow? 10 ways you can speed it up appeared first on WeLiveSecurity

US charges three men with six million dollar business email compromise plot
LockBit ransomware for Mac – coming soon?

Dnsmasq could cause transmission reliability issues when sending large DNS messages.

Capita has ‘evidence’ customer data was stolen in digital burglary
An earlier supply chain attack led to the 3CX supply chain attack, Mandiant says
Ex-CEO of hacked therapy clinic sentenced for failing to protect patients’ session notes
FTC accuses payments firm of knowingly assisting tech support scammers

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

Designing user management for machine-to-machine interactions
AI defenders ready to foil AI-armed attackers
Protect the Industrial Control Systems (ICS)
Medusa ransomware crew brags about spreading Bing, Cortana source code
Smashing Security podcast #318: Tesla workers spy on drivers, and Operation Fox Hunt scams
Appeals court spares Google from $20m patent payout over Chrome
Spyware slinger QuaDream’s reported demise may be the canary in the coal mine
Discarded, not destroyed: Old routers reveal corporate secrets

When decommissioning their old hardware, many companies ‘throw the baby out with the bathwater’ The post Discarded, not destroyed: Old routers reveal corporate secrets appeared first on WeLiveSecurity

GitHub debuts pedigree check for npm packages via Actions

Several security issues were fixed in Vim.

The State of Kubernetes Security in 2023
Prioritize what matters most

The container bci/nodejs was updated. The following patches have been included in this update:

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Avoid possible self-DoS attack Resolves: CVE-2023-25136

Update to the latest 1.0.16: * Lots of updates, enhancements and fixes from 1.0.4 * CVEs: CVE-2020-27827, CVE-2021-43612

US citizens charged with pushing pro-Kremlin disinfo, election interference