Menu

Category Archives: Security

Articles about security

Updated web-admin-build packages are now available for Red Hat Gluster Storage 3.5 Web Administration on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Millions of Java Apps Remain Vulnerable to Log4Shell

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Block over two billion known breached passwords from your AD with Specops Password Policy tools
Chinese drone-maker DJI suspends ops in Russia, Ukraine
Should security teams be giving service with a smile?
Study: How Amazon uses Echo smart speaker conversations to target ads
Who is exploiting VMware right now? Probably Iran’s Rocket Kitten, to name one

security update

Coca-Cola probes pro-Kremlin gang’s claims of 161GB data theft
USA’s plan to decouple its tech with China lacks a strategy – report
DDoS attacks at an all-time-high in Q1 2022, says Kaspersky

Updated virtualbox packages fix security vulnerabilities: Vulnerability in the Oracle VM VirtualBox prior to 6.1.34 contains an easily exploitable vulnerability that allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to

Firms Push for CVE-Like Cloud Bug System

An update for maven-shared-utils is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for xmlrpc-c is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for xmlrpc-c is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

UNS-5376-1 was missing patches to properly fix the addressed issues.

Nation-state Hackers Target Journalists with Goldbackdoor Malware
Microsoft fixes Point of Sale bug that delayed Windows 11 startup for 40 minutes

An update that fixes 9 vulnerabilities is now available.

The trouble with BEC: How to stop the costliest internet scam

BEC fraud generated more losses for victims than any other type of cybercrime in 2021. It’s long past time that organizations got a handle on these scams. The post The trouble with BEC: How to stop the costliest internet scam appeared first on WeLiveSecurity

Ransomware attack attempted to destabilise Costa Rica, says outgoing president
India inks tech pact with EU – only the US has the same deal
Crooks steal NFTs worth ‘$3m’ in Bored Ape Yacht Club heist
Intuit sued over alleged cryptocurrency thefts via Mailchimp intrusion
Homeland Security bug bounty program uncovers 122 holes in its systems
Flaw could have granted criminals control over Ever Surf crypto wallets
Ukraine’s postal service prints stamp mocking sunken Russian ship, and gets hit by DDoS attack

Git could be made to run arbitrary commands in platforms with multiple users support.

Lapsus$ Hackers Target T-Mobile

Several security issues were fixed in barbican.

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Webcam hacking: How to know if someone may be spying on you through your webcam

Camfecting doesn’t ‘just’ invade your privacy – it could seriously impact your mental health and wellbeing. Here’s how to keep an eye on your laptop camera. The post Webcam hacking: How to know if someone may be spying on you through your webcam appeared first on WeLiveSecurity

FBI: BlackCat ransomware scratched 60-plus orgs

The newest upstream commit Security fixes for CVE-2022-1381, CVE-2022-1420

Security fix for [CVE-2022-1227]

A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document. (CVE-2021-45341) A buffer overflow vulnerability in CDataList of the jwwlib component of

A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2021-21898)

An update that fixes two vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Now Mandiant says 2021 was a record year for exploited zero-day security bugs

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

US DOJ probes Google’s $5.4b Mandiant acquisition

verify upstream GPG signature

Backport fix for possible DOS by regex assigned as CVE-2022-24836.

Update for CVE-2022-27191

Hive ransomware affiliate zeros in on Exchange servers
Cybersecurity threats to critical infrastructure – Week in security with Tony Anscombe

As the Five Eyes nations warn of attacks against critical infrastructure, we look at the potentially cascading effects of such attacks and how essential systems and services can ramp up their defense The post Cybersecurity threats to critical infrastructure – Week in security with Tony Anscombe appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

Zero-Trust For All: A Practical Guide
Skeletons in the Closet: Security 101 Takes a Backseat to 0-days
The new Elastic CEO puts cloud front and center

An update that fixes 9 vulnerabilities is now available.

REvil resurrected? Ransomware crew appears to be back. Keyword: Appears

Red Hat OpenShift Container Platform release 4.10.10 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

Is your Lenovo laptop vulnerable to cyberattack?

Here’s what to know about vulnerabilities in more than 100 Lenovo consumer laptop models and what you can do right away to stay safe – all in under three minutes The post Is your Lenovo laptop vulnerable to cyberattack? appeared first on WeLiveSecurity

YouTube terminates account for Hong Kong’s presumed next head of government
REvil reborn? Notorious gang’s dark web site redirects to new ransomware operation

Logging Subsystem 5.4 – Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Free Yanlouwang decryptor released, after flaw found in ransomware code
Smashing Security podcast #271: Crypto break-in, Google blurring, and mics not muting
Emotet reestablishes itself at the top of the malware world
Critical infrastructure: Under cyberattack for longer than you might think

Lessons from history and recent attacks on critical infrastructure throw into sharp relief the need to better safeguard our essential systems and services The post Critical infrastructure: Under cyberattack for longer than you might think appeared first on WeLiveSecurity

Red Hat OpenShift Container Platform release 4.9.29 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.9.

Red Hat Advanced Cluster Management for Kubernetes 2.4.3 General Availability release images. This update provides security fixes, bug fixes, and updates the container images. Red Hat Product Security has rated this update as having a security impact

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

The container suse/sles12sp3 was updated. The following patches have been included in this update:

Five Eyes nations fear wave of Russian attacks against critical infrastructure
AWS’s Log4j patches blew holes in its own security
Oracle already wins ‘crypto bug of the year’ with Java digital signature bypass
Most Email Security Approaches Fail to Block Common Threats
Russian-linked Shuckworm crew ramps up Ukraine attacks
Protect Your Executives’ Cybersecurity Amidst Global Cyberwar
Apple iCloud account attack results in man losing $650,000 from his cryptocurrency wallet
How can we support young people in harnessing technology for progress?

Young people are not passive victims of technology or helpless addicts. They are technology creators and agents with diverse backgrounds and interests. The post How can we support young people in harnessing technology for progress? appeared first on WeLiveSecurity

New Red Hat Single Sign-On 7.5.2 packages are now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat Single Sign-On 7.5 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Criminals adopting new methods to bypass improved defenses, says Zscaler
Google: 2021 was a Banner Year for Exploited 0-Day Bugs
US warns North Korean Lazarus gang rises against cryptocurrency outfits
Google tracked record 58 exploited-in-the-wild zero-day security holes in 2021

security update