Menu

Category Archives: Security

Articles about security

Hacktivists say they stole 100,000 emails from Iran’s nuclear energy agency

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

Russia wages disinformation war. Ukraine’s cyber chief calls for global anti-fake news fight

An update that solves 7 vulnerabilities, contains one feature and has one errata is now available.

Security fix for CVE-2022-2476

– Update to 20.10.20. – Mitigates CVE-2022-39253

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

Domestic Kitten campaign spying on Iranian citizens with new FurBall malware

APT-C-50’s Domestic Kitten campaign continues, targeting Iranian citizens with a new version of the FurBall malware masquerading as an Android translation app The post Domestic Kitten campaign spying on Iranian citizens with new FurBall malware appeared first on WeLiveSecurity

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) (CVE-2022-21626) * OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628) * OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-2022-21619) * OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) (CVE-2022-21624 [More…]

This update upgrades Firefox to version 102.4.0 ESR. * Mozilla: Same-origin policy violation could have leaked cross-origin URLs (CVE-2022-42927) * Mozilla: Memory Corruption in JS Engine (CVE-2022-42928) * Mozilla: Denial of Service via window.print (CVE-2022-42929) * Mozilla: Memory safety bugs fixed in Firefox 106 and Firefox ESR 102.4 (CVE-2022-42932) For more details about the securit […]

OpenJDK: improper MultiByte conversion can lead to buffer overflow (JGSS, 8286077) (CVE-2022-21618) * OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) (CVE-2022-21626) * OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628) * OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-202 [More…]

Good news, URSNIF no longer a banking trojan. Bad news, it’s now a backdoor
It’s time to prioritize SaaS security
Oops, web trackers may have leaked 3 million patients’ info

security update

Cloud migration and the cyber skills shortage
Don’t get scammed when buying tickets online

With hot-ticket events firmly back on the agenda, scammers selling fake tickets online have also come out in force The post Don’t get scammed when buying tickets online appeared first on WeLiveSecurity

BlueBleed: Microsoft customer data leak claimed to be ‘one of the largest’ in years

Security fix for CVE-2022-38784

Microsoft “BlueBleed” data breach: customer details and email content exposed

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Red Hat OpenShift security portfolio grows with new Red Hat Insights Vulnerability service

An update for java-17-openjdk is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Biden administration wants standard cyber security labelling for smart devices
Confidentiality in the cloud: the delicate bargain of trust
Health insurer’s infosec incident diagnosis goes from ‘take a chill pill’ to emergency ward
CISA warns of security holes in industrial Advantech, Hitachi kit
Cost of a health insurance security breach? NY watchdogs say it’s $4.5m
Smashing Security podcast #294: The Virgin trains swindler, cyber clowns, and AirTag election debacle
Verizon prepaid accounts hijacked by SIM swap crooks

security update

security update

Millennials, Gen Z actually suck at workplace security
So, the US, China, and Russia walk into an infosec conference
Tear in Microsoft Azure Service Fabric can give attackers full admin privileges
The infinite beauty of the hive mind

libXdmcp could be made to expose sensitive information.

Perl could be made to by pass signature verification.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

This update upgrades Firefox to version 102.3.0 ESR. * expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 firefox-102.3.0-7.el7_9.x86_64.rpm firefox-debuginfo-102.3.0-7.el7_9.x86_64.rpm firefox [More…]

This update upgrades Thunderbird to version 102.3.0. * expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 thunderbird-102.3.0-4.el7_9.x86_64.rpm thunderbird-debuginfo-102.3.0-4.el7_9.x86_64.rpm – [More…]

Germany stands down cyber boss over Russian ties
FBI: Looking for Biden’s student loan forgiveness? Watch out for these scams

security update

Build some flexibility into your cyber learning

security update

‘Fully undetectable’ Windows backdoor gets detected
NSA urges enterprises to watch China, Taiwan tensions
5 steps to protect your school from cyberattacks

What can schools, which all too often make easy prey for cybercriminals, do to bolster their defenses and keep threats at bay? The post 5 steps to protect your school from cyberattacks appeared first on WeLiveSecurity

Putting on the Red Hat

It was found that the Node XML DOM library was vulnerable to prototype pollution. For Debian 10 buster, this problem has been fixed in version

Several security issues were fixed in FRR.

Public package repos expose thousands of API security tokens—and they’re active
Ransom Cartel linked to Colonial Pipeline attacker REvil, says infosec crew

An update that solves 26 vulnerabilities, contains two features and has 89 fixes is now available.

An update for nodejs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the nodejs:14 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Ever considered using Confidential Computing to beef up cloud data protection?
Imagine surviving a wiper attack only for ransomware to scramble your restored files
Japanese giants to offer security-as-a-service for connected cars
Cops swoop after crooks use wireless keyfob hack to steal cars
Ex-WSJ reporter says he was framed in elaborate ‘hack-and-smear’ operation
Interpol busts global ‘Black Axe’ cyber-fraud suspects
Fine for Shein! Fashion site hit with $1.9 million bill after lying about data breach

This update fixes a wide range of vulnerabilities. A significant portion affects character set conversion. CVE-2016-10228

China-linked Budworm burrows hole in US legislature systems
Kolide, endpoint security for teams that want to meet SOC 2 compliance goals without sacrificing privacy
Choosing the Right Remote Access Solution for Your Linux Environment

An update that fixes 6 vulnerabilities is now available.

An update for .NET 6.0 is available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Phishing works so well crims won’t bother with deepfakes, says Sophos chap
Xi Jinping hails ‘improved cyber ecology’, says state to direct strategic tech research

security update

Multiple vulnerabilities have been discovered in Rust, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in Tcpreplay, the worst of which could result in denial of service.

A vulnerability has been found in Deluge which could result in XSS.

Multiple vulnerabilities have been discovered in libvirt, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in virglrenderer, the worst of which could result in remote code execution.

Multiple vulnerabilities have been discovered in Wireshark, the worst of which could result in denial of service.

Several security issues were fixed in the Linux kernel.

ESET research into POLONIUM’s arsenal – Week in security with Tony Anscombe

More than a dozen organizations operating in various verticals were attacked by the threat actor The post ESET research into POLONIUM’s arsenal – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Infosec still (mostly) a boys club