Menu

Category Archives: Security

Articles about security

Microsoft continues cyber security spending spree with Miburo buy
Kaiser Permanente Exposes Nearly 70K Medical Records in Data Breach
Linux Malware Deemed ‘Nearly Impossible’ to Detect
DragonForce Gang Unleash Hacks Against Govt. of India
Travel-related Cybercrime Takes Off as Industry Rebounds
In Cybersecurity, What You Can’t See Can Hurt You
Save time and money with Red Hat Insights Compliance reporting
The Three Best Tools You Need to Scan Your Linux System for Malware

An update that fixes 28 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

DDoS-for-hire service which bombarded websites with attacks earns man two years in prison
Kubernetes users struggle with security, Red Hat survey says

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Malaysia-linked DragonForce hacktivists attack Indian targets
Unpatched Exchange server, stolen RDP logins… How miscreants get BlackCat ransomware on your network
Microsoft fixes under-attack Windows zero-day Follina
Former US state agency CIO, IT exec plead guilty to bribery and extortion scheme
Cloudflare says it thwarted record-breaking HTTPS DDoS flood
Man gets two years in prison for selling 200,000 DDoS hits
Azure issues not adequately fixed for months, complain bug hunters

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

Open Source Security: Key Benefits & Drawbacks You Should Know
New Ultra-Stealthy Linux Backdoor Isnt Your Everyday Malware Discovery

An update that solves 7 vulnerabilities and has 14 fixes is now available.

An update that fixes one vulnerability is now available.

UK health privacy watchdog still in talks over who is accessing country’s COVID data store
Detect cloud native security threats with Tracee
Inside the RSAC expo: Buzzword bingo and the bear in the room
Chinese-sponsored gang Gallium upgrades to sneaky PingPull RAT
New Syslogk Linux Rootkit Uses Magic Packets to Trigger Backdoor

security update

security update

security update

The transition to a digital-first world enables us to connect, work and live in a realm where information is available at our fingertips. The children of today will be working in an environment of tomorrow that is shaped by hyperconnectivity. Operating in this environment means our present and future generations need to understand the importance […]

HelloXD ransomware bulked up with better encryption, nastier payload
A Getting-Started Guide to Improving Security with Open-Source Static & Dynamic Security Scanners

Several security issues were fixed in liblouis.

Bluetooth Signals Can Be Used to Track Smartphones, Say Researchers

Firefox could be made to crash or run programs as your login if it opened a malicious website.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Industroyer: A cyber‑weapon that brought down a power grid

Five years ago, ESET researchers released their analysis of the first ever malware that was designed specifically to attack power grids The post Industroyer: A cyber‑weapon that brought down a power grid appeared first on WeLiveSecurity

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Two vulnerabilities were discovered that the containerd container runtime, which could result in denial of service or incomplete restriction of capabilities.

– lockState: do not print `error:` when exit code is unaffected (#2090926) —- – fix potential DoS from unprivileged users via the state file (CVE-2022-1348)

security update

Several vulnerabilities were discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of these flaws for local root privilege escalation.

Multiple vulnerabilities were discovered in the VLC media player, which could result in the execution of arbitrary code or denial of service if a malformed media file is opened.

3 takeaways from RSA Conference 2022 – Week in security with Tony Anscombe

Here are three themes that stood out at the world’s largest gathering of cybersecurity professionals The post 3 takeaways from RSA Conference 2022 – Week in security with Tony Anscombe appeared first on WeLiveSecurity

RSA – APIs, your organization’s dedicated backdoors

API-based data transfer is so rapid, there’s but little time to stop very bad things happening quickly The post RSA – APIs, your organization’s dedicated backdoors appeared first on WeLiveSecurity

U.S. Water Utilities Prime Cyberattack Target, Experts
Potent Emotet Variant Spreads Via Stolen Email Credentials
Feds Forced Travel Firms to Share Surveillance Data on Hacker
Kubernetes Operators: good security practices

An update that fixes one vulnerability is now available.

OMIGOD: Cloud providers still using secret middleware

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The container suse-sles-15-sp3-chost-byos-v20220609-x86_64-gen2 was updated. The following patches have been included in this update:

bump to v1.23.4, security fix for CVE-2022-21698 —- Add missing container networking dependencies (#2081834)

World Economic Forum wants a global map of online crime

security update

Threat and risk specialists signal post-COVID conference season is back on
RSA – Digital healthcare meets security, but does it really want to?

Technology is understandably viewed as a nuisance to be managed in pursuit of the health organizations’ primary mission The post RSA – Digital healthcare meets security, but does it really want to? appeared first on WeLiveSecurity

Symbiote Linux malware spotted, and infections are ‘very hard to detect’
You can be tracked via your Bluetooth signal, researchers claim
DogWalk zero-day Windows bug receives patch – but not from Microsoft

An update that solves 6 vulnerabilities and has three fixes is now available.

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that solves 6 vulnerabilities and has two fixes is now available.

An update that solves 7 vulnerabilities and has three fixes is now available.

“Legacy” cryptography in Fedora 36 and Red Hat Enterprise Linux 9

An update that solves 6 vulnerabilities and has three fixes is now available.

Apple M1 chip contains hardware vulnerability that bypasses memory defense
Emotet malware gang re-emerges with Chrome-based credit card heistware
Chinese ‘Aoqin Dragon’ gang runs undetected ten-year espionage spree
Hardware flaws give Bluetooth chipsets unique fingerprints that can be tracked
Russia, China, warn US its cyber support of Ukraine has consequences
What keeps Mandiant Intelligence EVP Sandra Joyce up at night? The coming storm
Cloud services proving handy for cybercriminals, SANS Institute warns
Google has more reasons why it doesn’t like antitrust law that affects Google
Smashing Security podcast #278: Tim Hortons, avoiding sanctions, and good faith security research
Facebook phishing campaign nets millions in IDs and cash
RSA – Creepy real‑world edition

Digital fiddling somehow got mixed up in a real war The post RSA – Creepy real‑world edition appeared first on WeLiveSecurity

Microsoft disrupts Bohrium spear-phishing ring by seizing 41 domains
Symantec: More malware operators moving in to exploit Follina

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Containers vulnerability risk assessment

An update that fixes 6 vulnerabilities is now available.

Several vulnerabilities were discovered in Mailman, a web-based mailing list manager. An attacker could impersonate more privileged accounts through different vectors.

Several security issues were fixed in FFmpeg.