Menu

Category Archives: Security

Articles about security

* CVE-2022-47318

Update 1.2.6

security update

Several buffer overflow, divide by zero or out of bounds read/write vulnerabilities were discovered in tiff, the Tag Image File Format (TIFF) library and tools, which may cause denial of service when processing a crafted TIFF image.

Two vulnerabilities were found in dojo, a modular JavaScript toolkit, that could result in information disclosure. CVE-2020-4051

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

security update

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

Mon Dieu! Suspected French ShinyHunters gang member in the dock
Microsoft to enterprises: Patch your Exchange servers
Uncle Sam slaps $10m bounty on Hive while Russia ban-hammers FBI, CIA

security update

security update

Are you in control of your personal data? – Week in security with Tony Anscombe

Data Privacy Week is a reminder to protect your data – all year round. Here are three privacy-boosting habits you can start today. The post Are you in control of your personal data? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

SwiftSlicer: New destructive wiper malware strikes Ukraine

Sandworm continues to conduct attacks against carefully chosen targets in the war-torn country The post SwiftSlicer: New destructive wiper malware strikes Ukraine appeared first on WeLiveSecurity

Why your data is more valuable than you may realize

The data trail you leave behind whenever you’re online is bigger – and more revealing – than you may think The post Why your data is more valuable than you may realize appeared first on WeLiveSecurity

An update that fixes four vulnerabilities is now available.

Update to 1.3.2 (CVE-2022-29187, CVE-2022-24765)

https://www.mediawiki.org/wiki/Release_notes/1.38 https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/message/UEMW64LVEH3BEXCJV43CVS6XPYURKWU3/

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

Savvy cybersecurity pros benefit from host of free resources to step up fight against hackers and cyber threats

**Redis 6.2.10** Released Mon Jan 17 12:00:00 IST 2023 Upgrade urgency: MODERATE, a quick followup fix for a recently released 6.2.9. Bug Fixes * Revert the change to KEYS in the recent client output buffer limit fix (#11676) —- **Redis 6.2.9** Released Mon Jan 16 12:00:00 IDT 2023 Upgrade urgency: SECURITY, contains fixes to security […]

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

UK Cyber Security Centre’s scary new story: One phish, two phish, Russia phish, Iran phish
Google slays thousands of fake news vids posted by pro-China group Dragonbridge

security update

security update

security update

FBI smokes ransomware Hive after secretly buzzing around gang’s network for months
Mastodon vs. Twitter: Know the differences

Looking for an alternative to Twitter and thinking about joining the folks flocking to Mastodon? Here’s how the two platforms compare to each other. The post Mastodon vs. Twitter: Know the differences appeared first on WeLiveSecurity

Hive ransomware leak site and decryption keys seized in police sting
ShinyHunters suspect extradited to United States from Morocco, could face 116 years in jail if convicted
Canonical security subscriptions for Ubuntu Linux now available
Bloke allegedly stole, sold private info belonging to ‘tens of millions’ globally
Months after NSA disclosed Microsoft cert bug, datacenters remain unpatched

libXpm 3.5.15, fixes CVE-2022-46285, CVE-2022-44617, CVE-2022-4883

**Redis 7.0.8** Released Mon Jan 16 12:00:00 IDT 2023 Security Fixes: * (**CVE-2022-35977**) Integer overflow in the Redis SETRANGE and SORT/SORT_RO commands can drive Redis to OOM panic * (**CVE-2023-22458**) Integer overflow in the Redis HRANDFIELD and ZRANDMEMBER commands can lead to denial-of- service Bug Fixes * Avoid possible hang when client issues long KEYS,

Several security issues were fixed in the Linux kernel.

Smashing Security podcast #306: No Fly lists, cell phones, and the end of ransomware riches?

An update is now available for Red Hat OpenShift GitOps 1.6.4 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat OpenShift GitOps 1.5.9 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat OpenShift GitOps 1.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Microsoft closes another door to attackers by blocking Excel XLL files from the internet
5 valuable skills your children can learn by playing video games

Gaming can help your children build and sharpen a range of life skills that will stand them in good stead in the future The post 5 valuable skills your children can learn by playing video games appeared first on WeLiveSecurity

Strengthening the human element

PAM would allow unintended access to the machine over network.

An update for go-toolset-1.18 and go-toolset-1.18-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Cybersecurity professionals upskill in Brazil and Mexico
Go to security school, GoTo – theft of encryption keys shows you need it

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Logfile management is no fun. Now it’s a nightmare thanks to critical-rated VMware flaws

Update to 42.6

Apple emits emergency patch for older iPhones after snoops pounce on WebKit hole

security update

Fujitsu: Quantum computers no threat to encryption just yet
Hybrid play: Leveling the playing field in online video gaming and beyond

Does VALORANT’s approach to cheating signal a turning point in how we deal with the continued hacks afflicting our hybrid world of work and play? The post Hybrid play: Leveling the playing field in online video gaming and beyond appeared first on WeLiveSecurity

How to use Red Hat Insights malware detection service

Red Hat OpenShift Container Platform release 4.10.50 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for pcs is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for sssd is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

After data breach put their lives at risk, US releases 3000 immigrants seeking asylum
FanDuel gamblers warned of phishing threat after data breach at Mailchimp
Microsoft took its macros and went home, so miscreants turned to Windows LNK files
Kolide – Endpoint security for people, not paper clips
How to Check if Your Linux System is Infected with a Virus

Setuptools could be made to crash if it received specially crafted input.

Multiple vulnerabilities were found in trafficserver, a caching proxy server. CVE-2021-37150

An update for sudo is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for sudo is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for sudo is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for sudo is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

US authorities release asylum seekers after leaking their data online
India floats plan to make big tech pay for news, walks back government censorship
Taking patch management to the next level with automation

– Update to 109.0

This updates .NET 6 to the January 2023 security release. The updated versions are SDK 6.0.113 and Runtime 6.0.13 This include a fix for CVE-2023-21538

Patches for CVE-2023-23456 and CVE-2023-23457

Rebase to sudo-1.9.12p2 – security fix for CVE-2023-22809

libXpm 3.5.15, fixes CVE-2022-46285, CVE-2022-44617, CVE-2022-4883

This updates .NET 6 to the January 2023 security release. The updated versions are SDK 6.0.113 and Runtime 6.0.13 This include a fix for CVE-2023-21538

Ransomware payments down 40% in 2022 – Week in security with Tony Anscombe

Ransomware revenue plunges to $456 million in 2022 as more victims refuse to pay up. Here’s what to make of the trend. The post Ransomware payments down 40% in 2022 – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update: