Menu

Category Archives: Security

Articles about security

Russian snoops just love invading unpatched Cisco gear, America and UK warn
Microsoft opens up Defender threat intel library with file hash, URL search
Payments firm accused of aiding ‘contact Microsoft about a virus’ scammers must cough $650k
Army helicopter crash blamed on skipped software patch
Brit cops rapped over app that recorded 200k phone calls

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Wrong time to weaken encryption, UK IT chartered institute tells government
Several Distros Release Important Advisories for Actively Exploited Linux Kernel Use After Free Vuln
Capita IT breach gets worse as Black Basta claims it’s now selling off stolen data
US alleges China created troll army that tried to have dissidents booted from Zoom
Military helicopter crash blamed on failure to apply software patch
LockBit crew cooks up half-baked Mac ransomware

security update

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code. For the stable distribution (bullseye), this problem has been fixed in

Two ruby-rack issues have been addressed: CVE-2023-27530

Marketing biz sent 107 million spam emails… to just 437k people

LibreOffice could be made to run arbitrary code if an empty entry to the java class path is configured.

Several security issues were fixed in ImageMagick.

Deploying confidential containers on the public cloud
Firmware is on shaky ground – let’s see what it’s made of
Student requested access to research data. And waited. And waited. And then hacked to get root

config file permission change to increase security of polkitd

Update now: Google emits emergency fix for zero-day Chrome vulnerability

Update to ldb 2.5.3 and samba 4.16.10 Security fixes for CVE-2023-0922, CVE-2023-0614

Update to ldb 2.5.3 and samba 4.16.10 Security fixes for CVE-2023-0922, CVE-2023-0614

security update

Fullscreen notification obscured. (CVE-2023-29533) Double-free in libwebp. (MFSA-TMP-2023-0001) Potential Memory Corruption following Garbage Collector compaction. (CVE-2023-29535) Invalid free from JavaScript code. (CVE-2023-29536)

Updated firefox and libwebp packages fix security vulnerabilities: Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash (CVE-2023-1945).

DOS due to incorrect HTTP and MIME header parsing (CVE-2023-24534) DOS due to incorrect Multipart form parsing (CVE-2023-24536) Calling any of the Parse functions on Go source code which contains //line directives with very large line numbers can cause an infinite loop due to integer overflow. (CVE-2023-24537)

Vulnerability in the strided image data parsing code in the emscripten wrapper for libheif. An attacker could exploit this through a crafted image file to cause a buffer overflow in linear memory during a memcpy call. (CVE-2023-0996)

Hunting down BlackLotus – Week in security with Tony Anscombe

Microsoft releases guidance on how organizations can check their systems for the presence of BlackLotus, a powerful threat first analyzed by ESET researchers The post Hunting down BlackLotus – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Safety first: 5 cybersecurity tips for freelance bloggers

The much-dreaded writer’s block isn’t the only threat that may derail your progress. Are you doing enough to keep your blog (and your livelihood) safe from online dangers? The post Safety first: 5 cybersecurity tips for freelance bloggers appeared first on WeLiveSecurity

Learn about Confidential Containers

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Russia-pushed UN Cybercrime Treaty may rewrite global law. It’s … not great
US extradites Nigerian charged in $6m email fraud scam

security update

security update

Compatibility mess breaks not one but two Windows password tools
As Tax Day approaches, Microsoft warns accounting firms of targeted attacks

Several security issues were fixed in the Linux kernel.

While Twitter wants to sell its verification, Microsoft will do it for free on LinkedIn

The container suse/sles/15.5/cdi-importer was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

Linux kernel logic allowed Spectre attack on ‘major cloud provider’
To improve security, consider how the aviation world stopped blaming pilots
Pentagon leak suspect Jack Teixeira arrested at gunpoint

security update

security update

Pentagon super-leak suspect cuffed: 21-year-old Air National Guardsman
What are the cybersecurity concerns of SMBs by sector?

Some sectors have high confidence in their in-house cybersecurity expertise, while others prefer to enlist the support of an external provider to keep their systems and data secured The post What are the cybersecurity concerns of SMBs by sector? appeared first on WeLiveSecurity

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Demystifying risk using CVEs and CVSS
DISA releases the first Ansible STIG

An update for openvswitch3.1 is now available in Fast Datapath for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openvswitch2.17 is now available in Fast Datapath for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openvswitch2.17 is now available in Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openvswitch3.1 is now available in Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

How insecure is America’s FirstNet emergency response system? No one’s sure
Smashing Security podcast #317: Another Uber SNAFU, an AI chatbot quiz, and is juice-jacking genuine?
FBI: How fake Xi cops prey on Chinese nationals in the US
Remotely Exploitable Chromium DoS, Info Disclosure Vulns Fixed
Google launches dependency API and curated package repository with security metadata
10 things to look out for when buying a password manager

Here’s how to choose the right password vault for you and what exactly to consider when weighing your options The post 10 things to look out for when buying a password manager appeared first on WeLiveSecurity

Plenty of juice-jacking scare stories, but precious little juice-jacking

Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially allowing User Enumeration, Cross-Site-Scripting or Cross-Site Request Forgery.

OpenAI starts bug bounty program with cash rewards up to $20,000
Mission possible

Several security issues were fixed in Json-smart.

Several security issues were fixed in Firefox.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

3CX teases security-focused client update, plus password hashing
US cyber chiefs warn AI will help crooks, China develop nastier cyberattacks faster

Important: httpd and mod_http2 security update

Another zero-click Apple spyware maker just popped up on the radar again
April Patch Tuesday: Ransomware gangs already exploiting this Windows bug

security update

An update that contains security fixes can now be installed.

An update that fixes 12 vulnerabilities is now available.

Azure admins warned to disable shared key access as backdoor attack detailed

The container sles-15-sp4-chost-byos-v20230410-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230410-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230410-x86_64-gen2 was updated. The following patches have been included in this update:

Beyond Firewalls: What Else Is Required to Secure a Linux System?
GitGuardian’s honeytokens in codebase to fish out DevOps intrusion