Menu

Category Archives: Security

Articles about security

Being hit with a cyber-attack is bad. Not having a recovery plan is worse
Typo-squatting NPM software supply chain attack uncovered
Marriott Hotels admits to third data breach in 4 years
Comprehensive risk-based API protection with AppTrana

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Human Error Blamed for Leak of 1 Billion Records of Chinese Citizens
Multi-cloud doesn’t have to mean multi problems for data protection
Near-undetectable malware linked to Russia’s Cozy Bear
AstraLocker ransomware reportedly closes doors to pursue cryptojacking
Actual quantum computers don’t exist yet. The cryptography to defeat them may already be here

security update

security update

Pentagon: We’ll pay you if you can find a way to hack us
Cyberattacks: A very real existential threat to organizations

One in five organizations have teetered on the brink of insolvency after a cyberattack. Can your company keep hackers at bay? The post Cyberattacks: A very real existential threat to organizations appeared first on WeLiveSecurity

Calls for bans on Chinese CCTV makers Hikvision, Dahua expand
How to spot your biggest security threat? Just look out for the humans
Latest Cyberattack Against Iran Part of Ongoing Campaign
Germany unveils plan to tackle cyberattacks on satellites
Google Patches Actively Exploited Chrome Bug

GnuPG could allow forged signatures.

OpenSSL could be made to expose sensitive information over the network.

An update that fixes four vulnerabilities is now available.

Which Browser is Best for Online Security?
Deprecated Linux Commands You Should Not Use Anymore (And Their Alternatives)
Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware
Alibaba’s finance arm open sources its privacy software and a ‘Secure Processing Unit’
Dutch University retrieves Bitcoin ransomware payment and makes a profit

The container suse/sle15 was updated. The following patches have been included in this update:

Billion-record stolen Chinese database for sale on breach forum

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

Google updates Chrome to squash actively exploited WebRTC Zero Day

security update

security update

How To Hide Your IP And Keep From Being Tracked

An update that solves three vulnerabilities and has three fixes is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in PHP.

Official British Army Twitter and YouTube accounts hijacked by NFT scammers
Identity, trust, and their role in modern applications

An update for rh-php73-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

British Army Twitter and YouTube feeds hijacked by crypto-promos

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

What to do about inherent security flaws in critical infrastructure?

An update that fixes 5 vulnerabilities is now available.

Watch out for survey scams – Week in security with Tony Anscombe

As scammers continue to ask people to take fake surveys, can you recognize some common telltale signs you’re dealing with a scam? The post Watch out for survey scams – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Phishing scam poses as Canadian tax agency before Canada Day

The lead-up to the Canada Day festivities has brought a tax scam with it The post Phishing scam poses as Canadian tax agency before Canada Day appeared first on WeLiveSecurity

How is Red Hat addressing the demand to develop offerings more securely?
Obsolescence of ATO Pathways
Google location tracking to forget you were ever at that medical clinic

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

The container suse/sles12sp3 was updated. The following patches have been included in this update:

Cyberattack shuts down unemployment, labor websites across the US

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

Crypto sleuths pin $100 million Harmony theft on Lazarus Group
FTC warns LGBTQ+ community of extortion scams targeting them on dating apps
AMD held to ransom by gang that claims 450GB of data has been stolen

This update upgrades Thunderbird to version 91.11. * Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI (CVE-2022-34468) * Mozilla: Use-after-free in nsSHistory (CVE-2022-34470) * Mozilla: A popup window could be resized in a way to overlay the address bar with web content (CVE-2022-34479) * Mozilla: Memory safety bugs fixed in […]

Several security vulnerabilities have been discovered in isync, an IMAP and MailDir mailbox synchronizer. An malicious attacker who can control an IMAP server may exploit these flaws for remote code execution.

This update upgrades Firefox to version 91.11 ESR. * Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI (CVE-2022-34468) * Mozilla: Use-after-free in nsSHistory (CVE-2022-34470) * Mozilla: A popup window could be resized in a way to overlay the address bar with web content (CVE-2022-34479) * Mozilla: Memory safety bugs fixed […]

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The Migration Toolkit for Containers (MTC) 1.7.2 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Microsoft gives its partners power to change AD privileges on customer systems – without permission

An update for vim is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

OpenSea phishing threat after rogue insider leaks customer email addresses

security update

Jenkins warns of security holes in these 25 plugins
California state’s gun control websites expose personal data
ZuoRAT Can Take Over Widely Used SOHO Routers
Google battles bots, puts Workspace admins on alert
Black Basta ransomware – what you need to know
How to Spend Less Time on Web and API Security

Several security issues were fixed in Vim.

A heap use-after-free vulnerability was found in systemd, a system and service manager, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate

A Guide to Surviving a Ransomware Attack

Several security issues were fixed in Libjpeg6b.

Costco 40th anniversary scam targets WhatsApp users

If the promise of a cash prize in return for answering a few questions sounds like a deal that is too good to be true, that’s because it is The post Costco 40th anniversary scam targets WhatsApp users appeared first on WeLiveSecurity

Israel plans ‘Cyber-Dome’ to defeat digital attacks from Iran and others

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Start using Modern Auth now for Exchange Online

– Update to new upstream (102.0)

Leaky Access Tokens Exposed Amazon Photos of Users
Sysdig Secure update adds ability to stop container attacks at runtime
‘Prolific’ NetWalker extortionist pleads guilty to ransomware charges

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or spoofing.

Patchable and Preventable Security Issues Lead Causes of Q1 Attacks
Scanning container image vulnerabilities with Clair

An update that fixes 9 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.