Menu

Category Archives: Security

Articles about security

HardBit ransomware tells corporate victims to share their cyber insurance details

* Fix large memory allocation when uploading content. * Fix scrolling after a history navigation with PSON enabled. * Always update the active uri of WebKitFrame. * Fix several crashes and rendering issues. * Security fixes: CVE-2023-23529 —- * Improve GStreamer multimedia playback across the board with improved codec selection logic, better handling of latency, […]

Update to upstream 1.1.6

Update to 2.39.2 (CVE-2023-22490, CVE-2023-23946) Refer to the [upstream release notes](https://github.com/git/git/raw/v2.39.2/Documentation/RelNotes/2.30.8.txt) and the security advisories ([CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-

Rebase to upstream version 3.0.8 Resolves: CVE-2022-4203 Resolves: CVE-2022-4304 Resolves: CVE-2022-4450 Resolves: CVE-2023-0215 Resolves: CVE-2023-0216 Resolves: CVE-2023-0217 Resolves: CVE-2023-0286 Resolves: CVE-2023-0401

CVE-2023-0494: potential use-after-free in DeepCopyPointerClasses

xwayland 22.1.8 – Security fix for CVE-2023-0494

Global threats fuel cyber defence training
Will ChatGPT start writing killer malware?

AI-pocalypse soon? As stunning as ChatGPT’s output can be, should we also expect the chatbot to spit out sophisticated malware? The post Will ChatGPT start writing killer malware? appeared first on WeLiveSecurity

An update for tar is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. An update for redhat-release-virtualization-host,

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for the php:8.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Accidental WhatsApp account takeovers? It’s a thing
Locking down the remote printer
DNA testing biz vows to improve infosec after criminals break into database it forgot it had
As Twitter forces users to remove text message 2FA, it’s in danger of decreasing security

An update for firefox is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for firefox is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Private Internet Access: The Best VPN for Linux
What Mary, Queen of Scots, can teach today’s cybersec royalty
GoDaddy joins the dots and realizes it’s been under attack for three years

security update

security update

If you’re struggling to secure email forwarding, it’s not you, it’s … the protocols

Online dating scams are on the RiseAccording to the FBI, Americans lost $1 billion in 2021 due to online dating scams; 2022 numbers are expected to be higher.   Romance scammers are masters of disguise. They lead people on with talk of love and then attempt to trick them into giving money or personal data. As […]

Update to 102.8.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2023-07/ ; https://www.thunderbird.net/en- US/thunderbird/102.8.0/releasenotes/

– fix HTTP multi-header compression denial of service (CVE-2023-23916) – share HSTS between handles (CVE-2023-23915 CVE-2023-23914)

ClamAV 0.103.8 is a critical patch release with the following fixes: * CVE-2023-20032 : Fixed a possible remote code execution vulnerability in the HFS+ file parser. The issue affects versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier. Thank you to Simon Scannell for reporting this issue. *

It was discovered that in c-ares, an asynchronous name resolver library, the config_sortlist function is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow and thus may cause a denial of service.

security update

security update

security update

An update that fixes 5 vulnerabilities is now available.

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the stable distribution (bullseye), these problems have been fixed in

Search ads abused to spread malware – Week in security with Tony Anscombe

Threat actors used search engine ads to impersonate makers of popular software and direct internet users to malicious websites The post Search ads abused to spread malware – Week in security with Tony Anscombe appeared first on WeLiveSecurity

New kernel packages are available for Slackware 15.0 to fix security issues.

2169641 – Syntax highlight for sh files broken —- The newest upstream commit Security fixes for CVE-2022-47024, CVE-2023-0433

* Fix large memory allocation when uploading content. * Fix scrolling after a history navigation with PSON enabled. * Always update the active uri of WebKitFrame. * Fix several crashes and rendering issues. * Security fixes: CVE-2023-23529

Christian Holler discovered that incorrect handling of PKCS 12 Safe Bag attributes in nss, the Mozilla Network Security Service library, may result in execution of arbitrary code if a specially crafted PKCS 12 certificate bundle is processed.

Intruder alert: FBI tackles ‘isolated’ IT security breach

security update

‘Russian hacktivists’ claim responsibility for DDoSing German airport websites

**phpMyAdmin 5.2.1** This is a bugfix release that also contains a security fix for an XSS vulnerability in the drag-and-drop upload functionality (**PMASA-2023-01**). Changelog: – issue #17522 Fix case where the routes cache file is invalid – issue #17506 Fix error when configuring 2FA without XMLWriter or Imagick – issue Fix blank page when some […]

Security amidst a global frost

No longer relegated to a side-show, tech is embedded into virtually every new piece of gear entering the battlefield The post Security amidst a global frost appeared first on WeLiveSecurity

These aren’t the apps you’re looking for: fake installers targeting Southeast and East Asia

ESET researchers have identified a campaign using trojanized installers to deliver the FatalRAT malware, distributed via malicious websites linked in ads that appear in Google search results The post These aren’t the apps you’re looking for: fake installers targeting Southeast and East Asia appeared first on WeLiveSecurity

Cry Havoc and let slip dogs of war … there’s an upgraded malware server in town
EU lawmakers argue against signing US data pact

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-23529

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

Antivirus apps are there to protect you – Cisco’s ClamAV has a heckuva flaw
Norway finds a way to recover crypto North Korea pinched in Axie heist
Google’s big security cert log overhaul broke Android apps. Now it’s hit undo
VMware, Windows 11 shafted by Windows Server 2022
More victims of fake crypto investor scam speak to The Register
10 signs that scammers have you in their sights

Don’t be their next victim – here’s a handy round-up of some the most common signs that should set your alarm bells ringing The post 10 signs that scammers have you in their sights appeared first on WeLiveSecurity

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

The container bci/python was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

ESXiArgs ransomware fights off Team America’s data recovery script
Smashing Security podcast #309: Synthetic voices, ChatGPT reflections, and social skirmishes
Intel patches up SGX best it can after another load of security holes found

security update

security update

security update

ChatGPT, will you be my Valentine?

Spoiler alert: it turned me down. But that’s far from the only thing I learned while playing around with the bot that the world has fallen in love with so badly. The post ChatGPT, will you be my Valentine? appeared first on WeLiveSecurity

Cybersecurity startup Oligo debuts with new application security tech
Gulp! Pepsi hack sees personal information stolen by data-stealing malware

Red Hat OpenShift Container Platform release 4.11.27 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for the Logging subsystem for Red Hat OpenShift 5.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Storage security toughen-up for compliance and cyberwar in 2023
Hyundai and Kia issue software upgrades to thwart killer TikTok car theft hack

Red Hat OpenShift Container Platform release 4.11.27 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Apple splats zero-day bug, other gremlins in macOS, iOS

New php packages are available for Slackware 15.0 and -current to fix security issues.

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

Security fix for CVE-2022-38725

Russian crook made $90M exploiting stolen info on Tesla, Roku, Avnet, Snap, more
Microsoft delivers 75-count box of patches for Valentine’s Day
Record-breaking number of record-breaking DDoS attacks confirmed
Confident cybersecurity means fewer headaches for SMBs

Small and medium-sized businesses have good reason to be concerned about the loss of data and financial impacts The post Confident cybersecurity means fewer headaches for SMBs appeared first on WeLiveSecurity

Google lets a few Android devices into its Privacy Sandbox
EnterpriseDB adds Transparent Data Encryption to PostgreSQL

An update for grub2 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Ransomware attackers steal over 3 million patients’ medical records

The container suse-sles-15-sp4-chost-byos-v20230210-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230210-x86_64-gen2 was updated. The following patches have been included in this update: