Menu

Category Archives: Security

Articles about security

Red Hat OpenShift: How to create and integrate a private registry with stronger security capabilities
Bahamut cybermercenary group targets Android users with fake VPN apps

Malicious apps used in this active campaign exfiltrate contacts, SMS messages, recorded phone calls, and even chat messages from apps such as Signal, Viber, and Telegram The post Bahamut cybermercenary group targets Android users with fake VPN apps appeared first on WeLiveSecurity

Operation Elaborate – UK police text 70,000 people thought to have fallen victim to iSpoof bank fraudsters

JBIG-KIT could be made to crash if it opened a specially crafted file.

Meta links US military to fake social media influence campaigns

Exim could be made to crash or run programs if it processed specially crafted regular expressions.

Exim could be made to crash or run programs if it processed specially crafted regular expressions.

Several security issues were fixed in ImageMagick.

Several security issues were fixed in ImageMagick.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

European Parliament Putin things back together after cyber attack

The risk of becoming a victim of identity theft has never been greater We are increasingly living our lives in the digital realm. Whether we’re banking, purchasing or browsing, our daily activities are most likely taking place online. Not only has this sped up our efficiency, but it has also expanded our exposure to a […]

Smashing Security podcast #299: EV charging risks, FTX, and an ancient apocalypse

security update

Still using a discontinued Boa web server? Microsoft warns of supply chain attacks
Hive ransomware has extorted $100 million in 18 months, FBI warns
Security fatigue is real: Here’s how to overcome it

Do your employees take more risks with valuable data because they’ve become desensitized to security guidance? Spot the symptoms before it’s too late. The post Security fatigue is real: Here’s how to overcome it appeared first on WeLiveSecurity

Several security issues were fixed in MariaDB.

Expat could be made to crash or execute arbitrary code.

Expat could be made to crash or execute arbitrary code.

APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.

APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.

Understanding open source software supply chain risks

An update that fixes one vulnerability is now available.

‘Pig butchering’ romance scam domains seized and slaughtered by the Feds
For two years security experts have been secretly decrypting systems for Zeppelin ransomware victims
DraftKings gamblers lose $300,000 to credential stuffing attack
AWS fixes ‘confused deputy’ vulnerability in AppSync
Latest insights on APT activity – Week in security with Tony Anscombe

What have some of the world’s most notorious APT groups been up to lately? A new ESET report released this week has the answers. The post Latest insights on APT activity – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Ouch! Ransomware gang says it won’t attack AirAsia again due to the “chaotic organisation” and sloppy security of hacked airline’s network

Several security issues were fixed in FreeRDP.

Several security issues were fixed in FreeRDP.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 10 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Microsoft’s attempts to harden Kerberos authentication broke it on Windows Servers
World Cup phishing emails spike in Middle Eastern countries
US offshore oil and gas installation at ‘increasing’ risk of cyberattack
Cyber security pros: move to the next level next year
Keeping Your Private Files Private: An Introduction to GNU Privacy Guard

An update that fixes two vulnerabilities is now available.

An update that solves 10 vulnerabilities, contains 10 features and has three fixes is now available.

An update that solves 10 vulnerabilities, contains 10 features and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

Google looking outside the usual channels to fix security skills gap
Serendipitous discovery nets security researcher $70k bounty

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Tor vs. VPN: Which should you choose?

Both Tor and a VPN can greatly help you keep prying eyes away from your online life, but they’re also two very different beasts. Which is better for you? The post Tor vs. VPN: Which should you choose? appeared first on WeLiveSecurity

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

security update

Hive ransomware crooks extort $100m from 1,300 global victims

security update

security update

Police force published sexual assault victims’ names and addresses on its website
Red Hat Enterprise Linux and Microsoft security update of November 2022
Hardware-assisted encryption of data in use gets confidential

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 52 vulnerabilities, contains one feature is now available.

An update that fixes 52 vulnerabilities, contains one feature is now available.

Z-Library operators arrested, charged with criminal copyright infringement
Israel sets robotic target-tracking turrets in the West Bank
Security firms hijack New York trees to monitor private workforce

security update

Open banking: Tell me what you buy, and I’ll tell you who you are

The convenience with which you manage all your financial wants and needs may come at a cost The post Open banking: Tell me what you buy, and I’ll tell you who you are appeared first on WeLiveSecurity

Google wins lawsuit against alleged Russian botnet herders

It was discovered that php-phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v2), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific

It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations.

It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations.

Expat could be made to crash or execute arbitrary code.

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler,

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler,

Notorious Emotet botnet returns after a few months off
Smashing Security podcast #298: Housing market scams, Twitter 2FA, and the fesshole

security update

Iranian cyberspies exploited Log4j to break into a US govt network
Germany says nein to Qatari World Cup spyware, err, apps

security update

security update

security update

WASP malware stings Python developers
Cloud vendors should take some responsibility for stolen compute, says Canalys CEO

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.