Menu

Category Archives: Security

Articles about security

DARPA study challenges assumptions about distributed ledger (and Bitcoin) security
Gamification of Ethical Hacking and Hacking Esports
Discovery of 56 OT Device Flaws Blamed on Lackluster Security Culture
Elusive ToddyCat APT Targets Microsoft Exchange Servers

Squid could be made to crash if it received specially crafted network traffic.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

postgresql: Autovacuum, REINDEX, and others omit “security restricted operation” sandbox (CVE-2022-1552) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 postgresql-debuginfo-9.2.24-8.el7_9.i686.rpm postgresql-debuginfo-9.2.24-8.el7_9.x86_64.rpm postgresql-libs-9.2.24-8. [More…]

Yodel becomes the latest victim of a cyber ‘incident’

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

Okta says Lapsus$ incident was actually a brilliant zero trust demonstration
Israeli military personnel spied on via Strava fitness-tracking app
Info on 1.5m people stolen from US bank in cyberattack
Voicemail-themed phishing attacks target organisations
Crypto mixers: What are they and how are they used?

How crypto mixers, also known as crypto tumblers, are used to obscure the trail of digital money The post Crypto mixers: What are they and how are they used? appeared first on WeLiveSecurity

Don’t react, prevent
1Password’s Insights tool to help admins monitor users’ security practices

Several vulnerabilities were discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of these flaws for local root privilege escalation.

Kazakh Govt. Used Spyware Against Protesters
Office 365 Config Loophole Opens OneDrive, SharePoint Data to Ransomware Attack

Several security issues were fixed in QEMU.

OpenSSL could be made to crash or run programs when the c_rehash script is used.

A great day for non-robots: iOS 16 will bypass CAPTCHAs
Voicemail Scam Steals Microsoft Credentials
Interview with Guardian Digital CEO Dave Wreski: Open Source Utilization in Email Security Solutions & More
Email Security FAQs Answered by Guardian Digital

An update that fixes one vulnerability is now available.

Several security issues were fixed in Apache HTTP Server.

This update includes the latest changes to the leap second list, including an update to its expiry date, which was set for the end of June.

Legacy systems are the new attack vectors for hackers
How refactoring code in Safari’s WebKit resurrected ‘zombie’ security bug
CISA and friends raise alarm on critical flaws in industrial equipment, infrastructure
Voicemail phishing emails steal Microsoft credentials

security update

Five Things You Need To Know about Linux Container Security
Akamai Warns Of “Panchan” Linux Botnet That Leverages Golang Concurrency, Systemd
Capital One: Convicted techie got in via ‘misconfigured’ AWS buckets
How to get Fortune 500 cybersecurity without the hefty price tag
There are 24.6 billion sets of credentials up for sale on the dark web

Brief introduction CVE-2017-13755

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 17 vulnerabilities and has 26 fixes is now available.

Are you ready to automate continuous deployment in CI/CD?
You don’t need another hero…you need an automated incident response process
Indian government issues confidential infosec guidance to staff – who leak it

security update

security update

It was discovered that exo, a support library for the Xfce desktop environment, would allow executing remote .desktop files. In some scenario, an attacker could use this vulnerability to trick an user an execute arbitrary code on the platform with the privileges of that user.

Security fix for CVE-2015-20107

Security fix for CVE-2015-20107

Update to version 2.1.1 CVE-2022-24065

New version 2.8.5 is released. This new version address the security issue CVE-2022-31033 related to header information leak.

Security fix for CVE-2015-20107

How to spot malicious spam – Week in security with Tony Anscombe

As the risk of receiving a malware-laden email increases, take a moment to consider how to spot attacks involving malicious spam The post How to spot malicious spam – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Common Security Advisory Framework (CSAF) beta files now available
DeadBolt ransomware takes another shot at QNAP storage

The 5.18.5 stable kernel update contains mitigation for the processor MMIO stale-data vulnerabilities. These are covered by CVE-2022-21166 CVE-2022-21125 and CVE-2022-21123

Update to 2.36.3: * Support capturing already encoded video streams, which takes advantage of encoding done in hardware by devices which support this feature. * Avoid using experimental GStreamer elements for video demuxing. * Avoid using the legacy GStreamer VA-API decoding plug-ins, which often cause rendering issues and are not much maintained. Their usage can […]

Inverse Finance stung for $1.2 million via flash loan attack

Rebuild for ntfs-3g CVE

US senators seek ban on sale of health location data
International operation takes down Russian RSOCKS botnet
How Emotet is changing tactics in response to Microsoft’s tightening of Office macro security

Emotet malware is back with ferocious vigor, according to ESET telemetry in the first four months of 2022. Will it survive the ever-tightening controls on macro-enabled documents? The post How Emotet is changing tactics in response to Microsoft’s tightening of Office macro security appeared first on WeLiveSecurity

Microsoft Defender goes cross-platform for the masses
QNAP warns of new DeadBolt ransomware attack locking up NAS devices
China-linked APT Flew Under Radar for Decade
Cookie consent crumbles under fresh UK data law proposals
NinjaForms WordPress plugin, actively exploited in wild, receives forced security update

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

An update that solves 30 vulnerabilities and has 14 fixes is now available.

Hardening Virtio for emerging security usecases
Heineken giving away free beer for Father’s Day? It’s a WhatsApp scam
Password recovery from beyond the grave

Red Hat OpenShift Container Platform release 4.6.59 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.6.

The container suse/sles12sp5 was updated. The following patches have been included in this update:

Interpol anti-fraud operation busts call centers behind business email scams
RSAC branded a ‘super spreader event’ as attendees share COVID-19 test results
Interpol arrests thousands of scammers in operation “First Light 2022”

Several security issues were fixed in Exempi.

Want to block two billion known breached passwords from being used at your company? It’s easy with Specops Password Policy tools
State-Sponsored Phishing Attack Targeted Israeli Military Officials
Ransomware Risk in Healthcare Endangers Patients
Post-quantum cryptography, an introduction
Complete Guide to Keylogging in Linux: Part 3

An update that fixes one vulnerability is now available.

Facebook Messenger Scam Duped Millions

Several security issues were fixed in the kernel.

Okta’s Matt Raible: How I became a Java hipster
Elasticsearch server with no password or encryption leaks a million records

Red Hat OpenShift Container Platform release 4.7.53 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

Smashing Security podcast #279: Encrypted notes, and a deadly case of AirTag spying

The 5.17.14 stable kernel update contains a number of important fixes across the tree.

golang-x-sys: Bump to commit bc2c85ada10aa9b6aa9607e9ac9ad0761b95cf1d golang- github-containernetworking-cni: Update to 1.1.1. golang-github-containerd-cni: Update to 1.1.6. Fixes rhbz#2092632. containerd: Update to 1.6.6. Mitigates GHSA-5ffw-gxpp-mxpf / CVE-2022-31030.

Heineken says there’s no free beer, warns of phishing scam