Menu

Category Archives: Security

Articles about security

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

Twilio reveals hackers compromised its systems a month earlier than previously thought
Apple patches actively exploited iPhone, iPad kernel vulns
Singapore hosts ICS/OT cybersecurity training extravaganza
Indian government creates body with power to order social media content takedowns

security update

security update

security update

Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2021-43980

It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For the stable distribution (bullseye), these problems have been fixed in

A security issue was discovered in Chromium, which could result in the execution of arbitrary code. For the stable distribution (bullseye), this problem has been fixed in

It was discovered that libxml2, the GNOME XML library, was vulnerable to integer overflows and memory corruption. CVE-2022-40303

A heap use-after-free vulnerability after overeager destruction of a shared DTD in the XML_ExternalEntityParserCreate function in Expat, an XML parsing C library, may result in denial of service or potentially the execution of arbitrary code.

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

Courts vs. cybercrime – Week in security with Tony Anscombe

A look at a recent string of law enforcement actions directed against (in some cases suspected) perpetrators of various types of cybercrime The post Courts vs. cybercrime – Week in security with Tony Anscombe appeared first on WeLiveSecurity

It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For Debian 10 buster, these problems have been fixed in version

Everything You Need To Know About Open Source Network Monitoring Tools

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

An issue has been found in openvswitch, a software-based, Ethernet virtual switch.

An issue has been found in ncurses, a collection of shared libraries for terminal handling. This issue is about an out-of-bounds read in convert_strings in the

This Windows worm evolved into slinging ransomware. Here’s how to detect it

security update

Federal bans aren’t stopping US states from buying forbidden Chinese kit
Why your phone is slow – and how to speed it up

You probably don’t have to ditch your phone just yet – try these simple tips and tricks to make any Android device or iPhone run faster The post Why your phone is slow – and how to speed it up appeared first on WeLiveSecurity

Multiple vulnerabilities were discovered in Django, a popular Python-based web development framework: * CVE-2020-24583: Fix incorrect permissions on intermediate-level

The top cloud cyber security threats unpacked
Post-quantum cryptography: Hash-based signatures
3 primo cloud gigs in 2023

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Biden now wants to toughen up chemical sector’s cybersecurity

security update

New York Post was hacked from the inside, employee fired after offensive articles posted online
Parcel delivery scams are on the rise: Do you know what to watch out for?

As package delivery scams that spoof DHL, USPS and other delivery companies soar, here’s how to stay safe not just this shopping season The post Parcel delivery scams are on the rise: Do you know what to watch out for? appeared first on WeLiveSecurity

LinkedIn’s new security features fight scammers, deepfakes, and hackers
The point solution IAM evolution under reform

An update that fixes four vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Cryptographic signatures for zip distributions

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Purpleurchin cryptocurrency miners spotted scouring free GitHub, Heroku accounts
Japan to citizens: Get a digital ID or health insurance gets harder
Pro-China crew ramps up disinfo ahead of US midterms. Not that anyone’s falling for it
Feds accuse Ukrainian of renting out PC-raiding Raccoon malware to fiends
Cisco AnyConnect Windows client under active attack
Microsoft realizes it hasn’t updated list of banned dodgy Windows 10 drivers in years

This is the October 2022 release of .NET Core 3.1 This updates .NET Core 3.1 SDK to 3.1.424 and Runtime to 3.1.30. This includes fixes for CVE-2022-41032

added patches to fix CVE-2022-41751

– New version 4.4.3-P1 (rhbz#2132240) – Fix for CVE-2022-2928 (rhbz#2132429) – Fix for CVE-2022-2929 (rhbz#2132430)

Update to 1.12.24 * Fix CVE-2022-42010, CVE-2022-42011, CVE-2022-42012

This is the October 2022 release of .NET Core 3.1 This updates .NET Core 3.1 SDK to 3.1.424 and Runtime to 3.1.30. This includes fixes for CVE-2022-41032

added patches to fix CVE-2022-41751

Service Preview of Red Hat Advanced Cluster Security Cloud Service
New Year, new cyber security career
Ransomware down this year – but there’s a catch
If someone tries ransacking your Windows network, it’s a bit easier now to grok in Microsoft 365 Defender
Health insurer Medibank’s data breach diagnosis keeps getting worse
FTC slaps down Drizly CEO after 2.4m user records stolen from ‘careless’ booze app biz
PayPal ditches passwords, at least on Apple devices
The safety of numbers
Cybersecurity event cancelled after scammers disrupt LinkedIn live chat

An update that fixes four vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

What Should Be on My Resume as a Linux Administrator?

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Why you’re getting cloud security wrong
Gone phishing: UK data watchdog fines construction biz £4.4m for poor infosec hygiene
Seven months after it found out, FamilySearch tells users their personal data has been breached
Uncle Sam says these Chinese nationals are Beijing agents breaking the law on US soil
Payment terminal malware steals $3.3m worth of credit card numbers – so far

security update

Car dealer group Pendragon refuses to pay $60 million to ransomware extortionists
DHL named most-spoofed brand in phishing
CISA, FBI warn healthcare organizations of Daixin ransomware
APT‑C‑50 updates FurBall Android malware – Week in security with Tony Anscombe

ESET Research spots a new version of Android malware known as FurBall that APT-C-50 is using in its wider Domestic Kitten campaign The post APT‑C‑50 updates FurBall Android malware – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Ex-cop abused police tool in Snapshot sextortion plot that stole sexually explicit photos and videos
Google says slap some GUAC on your software supply chain

An incomplete fix was discovered in Pillow.

Several security issues were fixed in MySQL.

An update that fixes four vulnerabilities is now available.

An update for pki-core is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for libksba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Update to maintenance release 3.0.8

Most reported CVEs for Docker Hub images are harmless
5 reasons to keep your software and devices up to date

Next time you’re tempted to hold off on installing software updates, remember why these updates are necessary in the first place The post 5 reasons to keep your software and devices up to date appeared first on WeLiveSecurity

A year of SANS security summits
Linux: Here, there and everywhere
Could you not? BlackByte ransomware slinger twists the knife with data stealer