Menu

Category Archives: Security

Articles about security

Red Hat OpenShift Container Platform release 4.10.25 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the mariadb:10.5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-17-openjdk is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for go-toolset-1.17 and go-toolset-1.17-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

NortonLifeLock and Avast $8.6b deal gets provisional yes from UK regulator
Post-quantum crypto cracked in an hour with one core of an ancient Xeon
Nancy Pelosi ties Chinese cyber-attacks to need for Taiwan visit
VMware patches critical ‘make me admin’ auth bypass bug, plus nine other flaws
How a crypto bridge bug led to a $200m ‘decentralized crowd looting’
Universities Put Email Users at Cyber Risk

security update

Robinhood’s crypto unit hit with $30m fine over security, anti-crime misses
Threat groups embrace messaging apps to spread malware, communicate
Bot army risk as 3,000+ apps found spilling Twitter API keys
Installing SurfShark VPN On Kali Linux: The Authoritative Guide
Best Practices for PHP Security
Linux Mint 21 Vanessa Is Now Available for Download, This Is Whats New
LibreOffice Security Update Fixes Macro Execution Bypass and Potential Password Leaking

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Imran Khan’s Instagram account hacked to promote phoney Elon Musk $100 million crypto giveaway
Miscreants aim to cause Discord discord with malicious npm packages
Start as you mean to go on: the top 10 steps to securing your new computer

Whether you are getting ready for back-to-school season, getting new work laptop or fancying a new gamer’s pc, learn the steps to protect your new PC from cyberthreats. The post Start as you mean to go on: the top 10 steps to securing your new computer appeared first on WeLiveSecurity

Charges filed over $300m ‘textbook pyramid and Ponzi scheme’ crypto startup

security update

Defence against the dark arts of ransomware
Securing Your Move to the Hybrid Cloud

Multiple security vulnerabilities have been discovered in cURL, an URL transfer library. These flaws may allow remote attackers to obtain sensitive information, leak authentication or cookie header data or facilitate a denial of service attack.

Several security issues were fixed in Net-SNMP.

OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) (CVE-2022-34169) * OpenJDK: class compilation issue (Hotspot, 8281859) (CVE-2022-21540) * OpenJDK: improper restriction of MethodHandle.invokeBasic() (Hotspot, 8281866) (CVE-2022-21541) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE [More…]

OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) (CVE-2022-34169) * OpenJDK: class compilation issue (Hotspot, 8281859) (CVE-2022-21540) * OpenJDK: improper restriction of MethodHandle.invokeBasic() (Hotspot, 8281866) (CVE-2022-21541) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE [More…]

squid: DoS when processing gopher server responses (CVE-2021-46784) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 squid-3.5.20-17.el7_9.7.x86_64.rpm squid-debuginfo-3.5.20-17.el7_9.7.x86_64.rpm squid-migration-script-3.5.20-17.el7_9.7.x86_64.rpm squid-sysvinit-3.5 [More…]

An update that fixes one vulnerability is now available.

How Cloudflare emerged to take on AWS, Azure, and GCP
Akamai: We stopped record DDoS attack in Europe
Spyware developer charged by Australian Police after 14,500 sales

security update

Several security vulnerabilities have been found in libpgjava, the official PostgreSQL JDBC Driver. CVE-2020-13692

security update

* Add support for PAC proxy in the WebDriver implementation. * Fix video playback when loaded through custom URIs, this fixes video playback in the Yelp documentation browser. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-32792, CVE-2022-32816

Update to version 4.16.4 to address security fixes for CVE-2022-32742, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746

Update to version 4.16.4 to address security fixes for CVE-2022-32742, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746

Rebase gnutls to version 3.7.7 notes=Security fix for CVE-2022-2509

insufficient TLB flush for x86 PV guests in shadow mode [XSA-408, CVE-2022-33745]

security update

Tim Hortons offer free coffee and donut to settle data privacy invasion claims

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container suse/389-ds was updated. The following patches have been included in this update:

This is what to expect when a managed service provider gets popped

Update to 91.12.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2022-31/

Backport fix for CVE-2022-27337.

Backport fix for CVE-2022-33068.

Feds put $10m bounty on Putin pal accused of bankrolling US election troll farm
Decentralized IPFS networks forming the ‘hotbed of phishing’
Music streaming platform victim of a crypto theft – Week in security with Tony Anscombe

Cybercriminals exploited a vulnerability to steal the equivalent of 18M$ from the NFT music streaming platform Audius, while other cyberthreats related to crypto makes the news. The post Music streaming platform victim of a crypto theft – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Malicious Npm Packages Tapped Again to Target Discord Users
Romance scammers jailed after tricking Irish OAP out of €250k

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Automated dynamic application security testing with RapiDAST and cross-team collaboration
What Is the Impact of AI on Cybersecurity? 3 Interesting Use Cases

An update that solves 5 vulnerabilities and has 5 fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves 5 vulnerabilities and has 6 fixes is now available.

It was discovered that Booth, a cluster ticket manager, didn’t correctly restrict intra-node communication when configuring the “authfile” configuration directive.

It’s past time to figure out cross-cloud security
Staying safe online: How to browse the web securely

Learn to spot some of the threats that you can face while browsing online, and the best tips to stay safe on the web. The post Staying safe online: How to browse the web securely appeared first on WeLiveSecurity

BreachForums booms on the back of billion-record Chinese data leak
Businesses confess: We pass cyberattack costs onto customers
US court system suffered ‘incredibly significant attack’ – sealed files at risk
JPMorgan, UBS among trio accused of shoddy ID theft protection

security update

Suspected radiation alert saboteurs cuffed by cops after sensors disabled
Threat Actors Pivot Around Microsoft’s Macro-Blocking in Office
Cash App fraud: 10 common scams to watch out for

It pays to be careful – here’s how you can stay safe from fake giveaways, money flipping scams and other cons that fraudsters use to trick payment app users out of their hard-earned cash The post Cash App fraud: 10 common scams to watch out for appeared first on WeLiveSecurity

$10 million reward offered for information on North Korean hackers

libtirpc could be made to denial of service if it received a specially crafted input.

The Red Hat build of OpenJDK 8 (java-1.8.0-openjdk) is now available for Windows. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The Red Hat build of OpenJDK 8 (java-1.8.0-openjdk) is now available for portable Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that contains security fixes can now be installed.

An update that fixes 10 vulnerabilities is now available.

Your Linux Firewall Cant Stop These 3 Attacks!

An update that contains security fixes can now be installed.

Google brings Street View back to India following 2016 ban
Smashing Security podcast #285: Uber’s hidden hack, tips for travel, and AI accent fixes
FileWave fixes bugs that left 1,000+ orgs open to ransomware, data theft
We’re likely only seeing ‘the tip of the iceberg’ of Pegasus spyware use against the US

security update

security update

Uber’s former head of security faces fraud charges after allegedly covering up data breach
US puts $10 million bounty on North Korean cyber-crews
Apple network traffic takes mysterious detour through Russia
AWS ups security for Elastic Block Store, Kubernetes service
Messaging Apps Tapped as Platform for Cybercriminal Activity