Menu

Category Archives: Security

Articles about security

New kernel packages are available for Slackware 15.0 to fix security issues.

2169641 – Syntax highlight for sh files broken —- The newest upstream commit Security fixes for CVE-2022-47024, CVE-2023-0433

* Fix large memory allocation when uploading content. * Fix scrolling after a history navigation with PSON enabled. * Always update the active uri of WebKitFrame. * Fix several crashes and rendering issues. * Security fixes: CVE-2023-23529

Christian Holler discovered that incorrect handling of PKCS 12 Safe Bag attributes in nss, the Mozilla Network Security Service library, may result in execution of arbitrary code if a specially crafted PKCS 12 certificate bundle is processed.

Intruder alert: FBI tackles ‘isolated’ IT security breach

security update

‘Russian hacktivists’ claim responsibility for DDoSing German airport websites

**phpMyAdmin 5.2.1** This is a bugfix release that also contains a security fix for an XSS vulnerability in the drag-and-drop upload functionality (**PMASA-2023-01**). Changelog: – issue #17522 Fix case where the routes cache file is invalid – issue #17506 Fix error when configuring 2FA without XMLWriter or Imagick – issue Fix blank page when some […]

Security amidst a global frost

No longer relegated to a side-show, tech is embedded into virtually every new piece of gear entering the battlefield The post Security amidst a global frost appeared first on WeLiveSecurity

These aren’t the apps you’re looking for: fake installers targeting Southeast and East Asia

ESET researchers have identified a campaign using trojanized installers to deliver the FatalRAT malware, distributed via malicious websites linked in ads that appear in Google search results The post These aren’t the apps you’re looking for: fake installers targeting Southeast and East Asia appeared first on WeLiveSecurity

Cry Havoc and let slip dogs of war … there’s an upgraded malware server in town
EU lawmakers argue against signing US data pact

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-23529

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

Antivirus apps are there to protect you – Cisco’s ClamAV has a heckuva flaw
Norway finds a way to recover crypto North Korea pinched in Axie heist
Google’s big security cert log overhaul broke Android apps. Now it’s hit undo
VMware, Windows 11 shafted by Windows Server 2022
More victims of fake crypto investor scam speak to The Register
10 signs that scammers have you in their sights

Don’t be their next victim – here’s a handy round-up of some the most common signs that should set your alarm bells ringing The post 10 signs that scammers have you in their sights appeared first on WeLiveSecurity

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

The container bci/python was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

ESXiArgs ransomware fights off Team America’s data recovery script
Smashing Security podcast #309: Synthetic voices, ChatGPT reflections, and social skirmishes
Intel patches up SGX best it can after another load of security holes found

security update

security update

security update

ChatGPT, will you be my Valentine?

Spoiler alert: it turned me down. But that’s far from the only thing I learned while playing around with the bot that the world has fallen in love with so badly. The post ChatGPT, will you be my Valentine? appeared first on WeLiveSecurity

Cybersecurity startup Oligo debuts with new application security tech
Gulp! Pepsi hack sees personal information stolen by data-stealing malware

Red Hat OpenShift Container Platform release 4.11.27 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for the Logging subsystem for Red Hat OpenShift 5.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Storage security toughen-up for compliance and cyberwar in 2023
Hyundai and Kia issue software upgrades to thwart killer TikTok car theft hack

Red Hat OpenShift Container Platform release 4.11.27 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Apple splats zero-day bug, other gremlins in macOS, iOS

New php packages are available for Slackware 15.0 and -current to fix security issues.

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

Security fix for CVE-2022-38725

Russian crook made $90M exploiting stolen info on Tesla, Roku, Avnet, Snap, more
Microsoft delivers 75-count box of patches for Valentine’s Day
Record-breaking number of record-breaking DDoS attacks confirmed
Confident cybersecurity means fewer headaches for SMBs

Small and medium-sized businesses have good reason to be concerned about the loss of data and financial impacts The post Confident cybersecurity means fewer headaches for SMBs appeared first on WeLiveSecurity

Google lets a few Android devices into its Privacy Sandbox
EnterpriseDB adds Transparent Data Encryption to PostgreSQL

An update for grub2 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Ransomware attackers steal over 3 million patients’ medical records

The container suse-sles-15-sp4-chost-byos-v20230210-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230210-x86_64-gen2 was updated. The following patches have been included in this update:

Romance scam targets security researcher, hilarity ensues
Pepsi Bottling Ventures says info-stealing malware swiped sensitive data

An update that fixes 10 vulnerabilities is now available.

Bryan Gonzalez discovered that the PNG support in Imagemagick could be tricked into embedding the content of an arbitrary file when converting an image file.

An updated version of Red Hat Update Infrastructure (RHUI) is now available. RHUI 4.3 fixes a security bug, introduces multiple new features, and upgrades underlying Pulp to a Long Term Support (LTS) version. 2. Relevant releases/architectures:

Namecheap admits ‘unauthorized emails’ pwning its customers
LockBit’s Royal Mail ransom deadline flies by. No data released

Several security issues were fixed in Nova.

ZeroLock: How to Defend Against Ransomware on Linux
Learn the art of malicious compliance: doing exactly what you were asked, even when it’s wrong

The container sles-15-sp4-chost-byos-v20230210-arm64 was updated. The following patches have been included in this update:

Red Hat OpenShift Container Platform release 4.9.55 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

China’s spy balloon barrage earns six of its companies a spot on US entity list

Update to 110.0.5481.77. Fixes the following security issues: CVE-2023-0696 CVE-2023-0697 CVE-2023-0698 CVE-2023-0699 CVE-2023-0700 CVE-2023-0701 CVE-2023-0702 CVE-2023-0703 CVE-2023-0704 CVE-2023-0705 CVE-2023-25193

The newest upstream commit Security fixes for CVE-2023-0433, CVE-2022-47024

Fix a possible DOS involving the Qt SQL ODBC driver plugin.

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

xwayland 22.1.8 – Security fix for CVE-2023-0494

security update

Key findings from the latest ESET Threat Report – Week in security with Tony Anscombe

What is behind the drop in ransomware and what should still be done for containing the ransomware scourge? The post Key findings from the latest ESET Threat Report – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

Ransomware crooks steal 3m+ patients’ medical records, personal info
Alexa, who else is listening?

Your smart speaker is designed to listen, but could it be eavesdropping too? The post Alexa, who else is listening? appeared first on WeLiveSecurity

Dallas Central Appraisal District paid $170,000 to ransomware attackers
Hard drugs actively sold on Twitter in plain sight. Twitter says it doesn’t breach its safety policies
Urgent OpenSSL Security Advisory: High-Severity Address Type Confusion Vuln Fixed
Securing open source development: A supply chain perspective
3 reasons not to repatriate cloud-based apps and data sets
US, UK slap sanctions on Russians linked to Conti, Ryuk, Trickbot malware
US teases more China tech sanctions, this time to deflate balloon-makers

This update fixes multiple file format validation vulnerabilities that could result in memory access violations such as buffer overflows and floating point exceptions. It also fixes a regression in hcom parsing introduced when fixing CVE-2017-11358.

Australian government gives made-in-China CCTV cams the boot
Romance scammers’ favorite lies cost victims $1.3B last year
Reddit reveals security incident that looks more SNAFU than TIFU

Add upstream fix for CVE-2022-47021

Add upstream fix for CVE-2022-47021