Menu

Category Archives: Security

Articles about security

SSRF Flaw in Fintech Platform Allowed for Compromise of Bank Accounts

Several security issues were fixed in fribidi.

MacOS Malware: Myth vs. Truth – Podcast

Security fix for CVE-2022-27651

Minor update for CVE-2022-1096. Also fixes dependency issues for chrome-remote- desktop and sizing issues where some libraries/binaries were not being stripped.

oslo.utils could be made to expose sensitive information if it received a specially crafted input.

Security fix for CVE-2022-27651

Minor update for CVE-2022-1096. Also fixes dependency issues for chrome-remote- desktop and sizing issues where some libraries/binaries were not being stripped.

How do China’s cyber-spies snoop on governments, NGOs? Probably like this
When MFA fails, defense in depth is key
Cryptocurrency-mining AWS Lambda-specific malware spotted
Smashing Security podcast #269: Trezor Deep Throat, a CCTV stalker, and Amazon’s list of banned words
Hamas-linked cyber-spies ‘target high-ranking Israelis’
Control IT and SaaS complexity with Axonius
Feds take down Kremlin-backed Cyclops Blink botnet
We’re going on Tor

If better privacy and anonymity sound like music to your ears, you may not need to look much further than Tor Browser. Here’s what it’s like to surf the dark web using the browser. The post We’re going on Tor appeared first on WeLiveSecurity

Block claims ex-employee downloaded customer data after leaving firm

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

An update for python-waitress is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Fake e‑shops on the prowl for banking credentials using Android malware

ESET researchers analyzed three malicious applications targeting customers of eight Malaysian banks The post Fake e‑shops on the prowl for banking credentials using Android malware appeared first on WeLiveSecurity

UK spy agencies sharing bulk personal data with foreign allies was legal, says court

kernel: use-after-free in RDMA listen() (CVE-2021-4028) * kernel: fget: check that the fd still exists after getting a ref to it (CVE-2021-4083) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Adding new kernel entry in grub configuration file […]

Apple patched critical flaws in macOS Monterey but not in Big Sur nor Catalina

An update for python-waitress is now available for Red Hat OpenStack Platform 16.2 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Feds slay dark-web souk Hydra: Servers and $25m in crypto-coins seized
US State Department opens cybersecurity policy bureau
GitHub tackles leaks by scanning for secrets in pushed code
Cooler heads needed in heated E2EE debate, says think tank

Several security issues were fixed in H2.

No-Joke Borat RAT Propagates Ransomware, DDoS

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

An update for kernel is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The Works hit by hackers, UK retailer shuts some stores after problems with payment tills

Fix CVE-2021-45942.

Testing, testing, testing: Why Red Teaming is a must for every CISO
Bank had no firewall license, intrusion or phishing protection – guess the rest
Mailchimp: Crook stole cryptocurrency clients’ mailing-list subscriber info

security update

Mandiant shareholder sues to block $5.4b Google deal

Cyber threats are becoming increasingly difficult to detect. Cybercriminals are also becoming experts in deception. What does this mean for your business? How can you keep your family members safe online and reassure your customers you are protecting their data? Our threat research analysts have complied the latest threat intelligence data to bring you the […]

Welcome to the Age of Zero Trust
Borat RAT: Multiple threat of ransomware, DDoS and spyware

Red Hat Ceph Storage 5.1 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Several issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, information disclosure or the the execution of arbitrary code.

An update that fixes one vulnerability, contains one feature is now available.

An update that fixes one vulnerability is now available.

Emma Sleep Company admits checkout cyber attack

An update for httpd is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The container bci/openjdk-devel was updated. The following patches have been included in this update:

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Trezor wallets hacked? Don’t be duped by phishing attack email

Multiple security issues were discovered in asterisk, an Open Source Private Branch Exchange (PBX). CVE-2019-13161

The container ses/7/rook/ceph was updated. The following patches have been included in this update:

The container ses/7/prometheus-webhook-snmp was updated. The following patches have been included in this update:

The container ses/7/ceph/prometheus-server was updated. The following patches have been included in this update:

The container ses/7/ceph/prometheus-node-exporter was updated. The following patches have been included in this update:

Crooks use fake emergency data requests to get personal info out of Big Tech – report
5G edge and security deployment evolution, trends and insights

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

GitLab issues critical update after hard-coding passwords into accounts
Two teenagers charged in relation to LAPSUS$ hacking group investigation
More charged in UK Lapsus$ investigation
Apple Rushes Out Patches for 0-Days in MacOS, iOS

Bump version to 2.0.15

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

Danilo Ramos discovered that incorrect memory handling in zlib’s deflate handling could result in denial of service or potentially the execution of arbitrary code if specially crafted input is processed.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Google: Russian credential thieves target NATO, Eastern European military
LAPSUS$ hacks Globant. 70GB of data leaked from IT firm
Modem-wiping malware caused Viasat satellite broadband outage in Europe
National Security Agency employee indicted for ‘leaking top secret info’

security update

Apple emits macOS, iOS, iPadOS patches for ‘exploited’ security bugs
FBI adds LAPSUS$ data extortion gang to its “Most Wanted” list
Belarusian ‘Ghostwriter’ Actor Picks Up BitB for Ukraine-Related Attacks
Patch now: RCE Spring4shell hits Java Spring framework
Automaker Cybersecurity Lagging Behind Tech Adoption, Experts Warn
Nvidia DGX systems prone to side channel, covert attacks
QNAP Customers Adrift, Waiting on Fix for OpenSSL Bug
A Blockchain Primer and a Bored Ape Headscratcher – Podcast

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Expect ‘long tail of cyber retaliation’ from Russia for sanctions, says ExtraHop CEO
Cryptomining groups fight fiercely for cloud resources
UK spy boss warns China hopes Russia will help it take over tech standards