Menu

Category Archives: Security

Articles about security

Smashing Security podcast #273: Password blips, and who’s calling the airport?
US Cyber Command shored up nine nations’ defenses last year
China-linked APT Caught Pilfering Treasure Trove of IP
Keeper Connection Manager : Privileged access to remote infrastructure with zero-trust and zero-knowledge security
Communication around Heroku security incident dubbed ‘train wreck’

– New upstream version (100.0) – Fix mozbz#1759137 (ffmpeg crash)

Attackers Use Event Logs to Hide Fileless Malware

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in OpenSSL.

Several security issues were fixed in DPDK.

An update for firefox is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.6.57 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.6.

Unpatched DNS Bug Puts Millions of Routers, IoT Devices at Risk
Putin threatens supply chains with counter-sanction order
Cyber-spies target Microsoft Exchange to steal M&A info

Passwords have become a common way to access and manage our digital lives. Think of all the accounts you have with different providers. Having a password allows you to securely access your information, pay bills or connect with friends and family on various platforms. However, having a password alone is not enough. Your password for […]

security update

SEC nearly doubles cryptocurrency cop roles in special cyber unit
Zero trust is more than just vendors and products – it requires process
Microsoft’s standalone Defender for Business hits GA
Mozilla: Lack of Security Protections in Mental-Health Apps Is ‘Creepy’
Lockbit ransomware attack cripples parts of German library service
Cops ignored call to nearby robbery, preferring to hunt Pokémon

100 Chromium releases! Of course, at the rate they release now, we’ll probably be at 150 before the end of the year. Anyway, here’s the update. Fixes: CVE-2022-1232 CVE-2022-1305 CVE-2022-1306 CVE-2022-1307 CVE-2022-1308 CVE-2022-1309 CVE-2022-1310 CVE-2022-1311 CVE-2022-1312 CVE-2022-1313 CVE-2022-1314 CVE-2022-1364

100 Chromium releases! Of course, at the rate they release now, we’ll probably be at 150 before the end of the year. Anyway, here’s the update. Fixes: CVE-2022-1232 CVE-2022-1305 CVE-2022-1306 CVE-2022-1307 CVE-2022-1308 CVE-2022-1309 CVE-2022-1310 CVE-2022-1311 CVE-2022-1312 CVE-2022-1313 CVE-2022-1314 CVE-2022-1364

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Several issues were discovered in OpenVPN, a Virtual Private Network server and client, that could lead to authentication bypass when using deferred auth plugins.

Critical vulnerabilities found in ‘millions of Aruba and Avaya switches’
What’s behind the record‑high number of zero days?

Organizations need to get better at mitigating threats from unknown vulnerabilities, especially as both state-backed operatives and financially-motivated cybercriminals are increasing their activity The post What’s behind the record‑high number of zero days? appeared first on WeLiveSecurity

Several security issues were fixed in MySQL.

Privacy pathology: It’s time for the users to gather a little data – evidence

An update that fixes three vulnerabilities is now available.

Google starts testing fenced frames to guard its Privacy Sandbox

security update

Security is a pain for American Dental Association: Ransomware infection feared
SSE kicks the ‘A’ out of SASE
Dell brings data recovery tools to Apex and the cloud
Spanish PM, defense minister latest Pegasus spyware victims
WinMagic SecureDoc for Linux: Fortify Your Infosec Architecture & Zero Trust Strategy with Defense-in-Depth & Endpoint Encryption>

Several security issues were fixed in libvirt.

libinput could be made to crash or expose sensitive information.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Bad Actors Are Maximizing Remote Everything

The components for Red Hat OpenShift support for Windows Containers 2.0.5 are now available. This product release includes a moderate security update for the following packages: windows-machine-config-operator and windows-machine-config-operator-bundle.

Updated Red Hat JBoss Web Server 5.6.2 packages are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Deep Dive: Protecting Against Container Threats in the Cloud

New pidgin packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue.

The newest upstream commit Security fixes for CVE-2022-1381, CVE-2022-1420

Fix CVE-2022-29536

zgrep applied to a crafted file name with two or more newlines can no longer overwrite an arbitrary, attacker-selected file. reproducer: $ touch foo.gz $ echo foo | gzip > “$(printf ‘|n;e touch pwnedn#.gz’)” $ zgrep foo *.gz (the unfixed version of zgrep creates the file called pwned)

An issue has been found in tinyxml, a C++ XML parsing library. Crafted XML messages could lead to an infinite loop in

Three issues have been found in libarchive, a multi-format archive and compression library.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

TA410 under the microscope – Week in security with Tony Anscombe

Here’s what you should know about FlowingFrog, LookingFrog and JollyFrog – the three teams making up the TA410 espionage umbrella group The post TA410 under the microscope – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Call for Contributors with Knowledge of Linux Firewalls!>
Facebook’s Meta, tracking code, and the student financial aid website

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Data-wiper malware strains surge as Ukraine battles ongoing invasion

This vulnerability could potentially be exploited by a local user to execute arbitrary code with root privileges.

SDL (Simple DirectMedia Layer) could be made to crash or run programs if it opened a specially crafted file.

Microsoft Edge’s ‘Secure Network’ sounds a lot like a built-in VPN
Ransomware costs show prevention is better than the cure
Don’t expect to get your data back from the Onyx ransomware group
Security Turbulence in the Cloud: Survey Says…
Interpol: We can’t arrest our way out of cybercrime
Cyberespionage APT Now Identified as Three Separate Actors
India gives local techies 60 days to hit 6-hour deadline for infosec incident reporting
Elon Musk says Twitter DMs should be end-to-end encrypted
Sina Weibo, China’s Twitter analog, reveals users’ locations and IP addresses
Bumblebee malware loader emerges as Conti’s BazarLoader fades

Security fixes for CVE-2022-1227, CVE-2022-21698, CVE-2022-27191, CVE-2022-27649

Security fix for CVE-2021-28021, CVE-2021-42715, CVE-2021-42716, and CVE-2022-28041

Security fix for CVE-2021-25220

Security fix for CVE-2018-25032

security update

A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity

ESET researchers reveal a detailed profile of TA410: we believe this cyberespionage umbrella group consists of three different teams using different toolsets, including a new version of the FlowCloud espionage backdoor discovered by ESET. The post A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity appeared first on WeLiveSecurity

Cloudflare stomps huge DDoS attack on crypto platform

This kernel-linus update is based on upstream 5.15.35 and fixes at least the following security issues: A denial of service (DOS) issue was found in the Linux kernel smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet

This kernel update is based on upstream 5.15.35 and fixes at least the following security issues: A denial of service (DOS) issue was found in the Linux kernel smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet

Attacker Breach ‘Dozens’ of GitHub Repos Using Stolen OAuth Tokens

Several security issues were fixed in networkd-dispatcher.

Cyberattacks Rage in Ukraine, Support Military Operations

An update for zlib is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that solves one vulnerability, contains one feature and has one errata is now available.

An update that fixes one vulnerability is now available.

Compliance as Code: Extending compliance automation for process improvement
Smashing Security podcast #272: Going ape over the Kardashians, and the face of romance scams
US offers $10 million reward for information about Russian military hackers implicated in NotPetya attack
Money or your business: Ensure your ransomware defense strategy beats off disruptions, extortions
Five Eyes nations reveal 2021’s fifteen most-exploited flaws
Microsoft points at Linux and shouts: Look, look! Privilege-escalation flaws here, too!
Looking for the latest insight to ensure cyber security in the long term? It’s right here
Emotet is Back From ‘Spring Break’ With New Nasty Tricks
Feds offer big rewards for info on suspected Russian Sandworm intel officers
China turns cyber-espionage eyes to Russia as Ukraine invasion grinds on