Menu

Category Archives: Security

Articles about security

Hackers hit Vesuvius, UK engineering company shuts down affected systems
Keeping unstructured data safe and sound
The tech leader’s guide to 2023

EditorConfig Core C could be made to crash or run programs if it received specially crafted input.

Trust, not tech, is holding back a safer internet
School laptop auction devolves into extortion allegation
Ransomware scum launch wave of attacks on critical, but old, VMWare ESXi vuln

Several security issues were fixed in Thunderbird.

USN-5825-1 caused some minor regressions in PAM.

USN-5816-1 caused some minor regressions in Firefox.

Have we learnt nothing from SolarWinds supply chain attacks? Not yet it appears

Security fix for CVE-2022-4510

# New in release [OpenJDK 8u362](https://bit.ly/openjdk8u362) (2023-01-17) ## CVEs Fixed – CVE-2023-21830 – CVE-2023-21843 ## Security Fixes – JDK-8285021: Improve CORBA communication – JDK-8286496: Improve Thread labels – JDK-8288516: Enhance font creation – JDK-8289350: Better media supports – JDK-8293554: Enhanced DH Key Exchanges – JDK-8293598: Enhance InetAddress

# New in release [OpenJDK 11.0.18](https://bit.ly/openjdk11018) (2023-01-17) ## CVEs Fixed – CVE-2023-21835 – CVE-2023-21843 ## Security Fixes – JDK-8286070: Improve UTF8 representation – JDK-8286496: Improve Thread labels – JDK-8287411: Enhance DTLS performance – JDK-8288516: Enhance font creation – JDK-8289350: Better media supports – JDK-8293554: Enhanced DH Key Exchanges

# New in release [OpenJDK 17.0.6](https://bit.ly/openjdk1706) (2023-01-17) ## CVEs Fixed – CVE-2023-21835 – CVE-2023-21843 ## Security Fixes – JDK-8286070: Improve UTF8 representation – JDK-8286496: Improve Thread labels – JDK-8287411: Enhance DTLS performance – JDK-8288516: Enhance font creation – JDK-8289350: Better media supports – JDK-8293554: Enhanced DH Key Exchanges

# New in release OpenJDK 19.0.2 (2023-01-17) ## CVEs Fixed * CVE-2023-21835 * CVE-2023-21843 ## Security Fixes – JDK-8286070: Improve UTF8 representation – JDK-8286496: Improve Thread labels – JDK-8287411: Enhance DTLS performance – JDK-8288516: Enhance font creation – JDK-8293554: Enhanced DH Key Exchanges – JDK-8293598: Enhance InetAddress address handling – JDK-8293717: Objective

Rebase to sudo 1.9.12p2 – security fix for CVE-2023-22809

Key takeaways from ESET’s new APT Activity Report – Week in security with Tony Anscombe

As our latest APT Activity Report makes abundantly clear, the threat of cyberespionage and stealthy attacks remains very real The post Key takeaways from ESET’s new APT Activity Report – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Red Hat OpenShift sandboxed containers: Peer-pods technical deep dive
Red Hat OpenShift sandboxed containers: Peer-pods solution overview
Red Hat OpenShift sandboxed containers: Peer-pods hands-on
CSAF VEX documents now generally available

An update that fixes one vulnerability is now available.

Iran crew stole Charlie Hebdo database, says Microsoft

The 6.1.9 stable kernel update contains a number of important fixes across the tree.

Update to version 1.23.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.23.0 Additionally, this update was built with a version of golang that addresses CVE-2022-41717, and it fixes the installation of icon files.

The 6.1.9 stable kernel update contains a number of important fixes across the tree.

Update to version 1.23.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.23.0 Additionally, this update was built with a version of golang that addresses CVE-2022-41717, and it fixes the installation of icon files.

HeadCrab bots pinch 1,000+ Redis servers to mine coins
Fast-evolving Prilex POS malware can block contactless payments
Guy accused of wrecking crypto exchange now hauled into court

Several security issues were fixed in LibTIFF.

Several security issues were fixed in Long Range ZIP.

Several security issues were fixed in Apache HTTP Server.

Is that survey real or fake? How to spot a survey scam

“Can I tell a legitimate survey apart from a fake one?” is the single most important question you need to answer for yourself before taking any surveys online The post Is that survey real or fake? How to spot a survey scam appeared first on WeLiveSecurity

Another RAC staffer nabbed for storing and sharing road accident data
How multicloud changes devops
LockBit claims responsibility for ION ransomware attack but US/UK hounds are sniffing
Chinese ‘surveillance balloon’ over US causes fearful gasbagging

The newest upstream commit Security fix for CVE-2023-0288

Former Ubiquiti dev pleads guilty in data theft and extortion case

Update to 109.0.5414.119. Fixes the following security issues: CVE-2023-0471 CVE-2023-0472 CVE-2023-0473 CVE-2023-0474

New openssh packages are available for Slackware 15.0 and -current to fix security issues.

security update

security update

security update

security update

Malvertising attacks are distributing .NET malware loaders
Less is more: Conquer your digital clutter before it conquers you

Lose what you don’t use and other easy ways to limit your digital footprint and strengthen your online privacy and security The post Less is more: Conquer your digital clutter before it conquers you appeared first on WeLiveSecurity

Romance fraud losses rose 91% during the pandemic, claims UK’s TSB bank
Super Bock says ‘cyber’ nasty ‘disrupting computer services’

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

Rebuild for CVE-2022-41717 in golang.

Fix CVE-2022-47021

new upstream version

Rebuild for CVE-2022-41717 in golang.

Update to pgadmin4-6.19. —- Backport fix for CVE-2023-22298.

Smashing Security podcast #307: ChatGPT and the Minister for Foreign Affairs
Google boosts bounties for open source flaws found via fuzzing
Take a tour of the Edgescan Cybersecurity Platform
Microsoft sweeps up after breaking .NET with December security updates

Several security issues were fixed in Vim.

An update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed

ESET APT Activity Report T3 2022

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in T3 2022 The post ESET APT Activity Report T3 2022 appeared first on WeLiveSecurity

Beyond the STIG: What hardening really means

Several security issues were fixed in Slurm.

Attackers abuse Microsoft’s ‘verified publisher’ status to steal data

Update to 2.53.15

Several vulnerabilities have been fixed in the libstb library. CVE-2018-16981

Planet Ice hacked! 240,000 skating fans’ details stolen
Microsoft upgrades Defender to lock down Linux gear for its own good

Brief introduction CVE-2020-21529

New year, new storage challenge

python-future could be made to crash if it received specially crafted input.

C++ creator Bjarne Stroustrup defends its safety

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

Amid FTX’s burning wreckage, Japan outpost promises asset withdrawals in February
South Korea makes crypto crackdown a national justice priority
Chromebook SH1MMER exploit promises admin jailbreak
The wages of sin aren’t that great if you’re a developer choosing the dark side

security update

security update

Gootloader malware updated with PowerShell, sneaky JavaScript
Latvia says Russian hackers tried to phish its Ministry of Defence
JD Sports admits intruder accessed 10 million customers’ data
If a locked filing cabinet is stolen along with its key, can you still say it’s locked? GoTo thinks you can
Hackers steal 10 million customer details from JD Sports
We are the weakest link
A Complete Guide to Security Automation & Reporting Using Open Source Tools
Data Privacy Day, every day

The components for Red Hat OpenShift support for Windows Container 7.0.0 are now available. This product release includes bug fixes and a moderate security update for the following packages: windows-machine-config-operator and

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Gee, tanks: Russian hackers DDoS Germany for aiding Ukraine

Update to 1.3.2 (CVE-2022-29187, CVE-2022-24765)

* CVE-2022-47318