Menu

Category Archives: Security

Articles about security

Russia, Iran, Saudi Arabia are top sources of online misinformation
Yale finance director stole $40m in computers to resell on the sly
Zlib crash-an-app bug finally squashed, 17 years later
Smashing Security podcast #268: LinkedIn deepfakes, doxxing Russian spies, and a false alarm
Shutterfly, hit by Conti ransomware group, warns staff their data has been stolen
Ubiquiti sues Krebs on Security for defamation
RCE Bug in Spring Cloud Could Be the Next Log4Shell, Researchers Warn
Cyberattackers Target UPS Backup Power Devices in Mission-Critical Environments
Forcepoint ONE helps firms simplify their security
Viasat spills on the Russian attack, warns of continued risks
Lapsus$ ‘Back from Vacation’
Google Chrome Bug Actively Exploited as Zero-Day
VMware Horizon platform pummeled by Log4j-fueled attacks

zlib could be made to crash or run programs if it received specially crafted input.

MSHTML Flaw Exploited to Attack Russian Dissidents

zlib could be made to crash or run programs if it received specially crafted input.

An update that solves 12 vulnerabilities and has 25 fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves 12 vulnerabilities and has 25 fixes is now available.

Electric Vehicle DC charging tripped by a wireless hack

An update that solves 22 vulnerabilities and has 22 fixes is now available.

Women in tech: Unique insights from a lifelong pursuit of innovation

Leading Slovak computer scientist Mária Bieliková shares her experience working as a woman driving technological innovation and reflects on how to inspire the next generation of talent in tech The post Women in tech: Unique insights from a lifelong pursuit of innovation appeared first on WeLiveSecurity

UK Cyber Security Centre advises review of risk posed by Russian tech
Lapsus$ back? Researchers claim extortion gang attacked software consultancy Globant
Detailed: Critical hijacking bugs that took months to patch in Microsoft Azure Defender for IoT
Mutating Verblecon malware in illicit cryptomining … so far
Log4JShell Used to Swarm VMware Servers with Miners, Backdoors
Ransomware driving you to distraction? Here’s how to recover
Mnuchin’s private equity firm buys security startup Zimperium for $525m
Ukraine security agency shutters Russian disinformation bot farms
Exchange Servers Speared in IcedID Phishing Campaign

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

This kernel-linus update is based on upstream 5.15.32 and fixes at least the following security issues: An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts

This kernel update is based on upstream 5.15.32 and fixes at least the following security issues: An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts

5 security considerations for edge implementations

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Cybercrooks target students with fake job opportunities
Mozilla unveils vision for web evolution
Europe’s quest for energy independence – and how cyber‑risks come into play

Soaring energy prices and increased geopolitical tensions amid the Russian invasion of Ukraine bring a sharp focus on European energy security The post Europe’s quest for energy independence – and how cyber‑risks come into play appeared first on WeLiveSecurity

5.5 years in a US prison for Estonian man linked to $53 million ransomware attacks
US charges Russian agents over cyber attacks on oil refineries and nuclear power plants
IcedID malware, in the hijacked email thread, with the insecure Exchange servers

security update

Sophos fixes critical hijack flaw in firewall offering
Google Chrome, Microsoft Edge patched in race against exploitation
Okta Says It Goofed in Handling the Lapsus$ Attack
Critical Sophos Security Bug Allows RCE on Firewalls
China APT group using Russia invasion, COVID-19 in phishing attacks
Triton malware still a threat to energy sector, FBI warns

openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssl-1.0.2k-25.el7_9.x86_64.rpm openssl-debuginfo-1.0.2k-25.el7_9.i686.rpm openssl-debuginfo-1.0.2k-25.el7_9.x86_64.rpm ope [More…]

expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235) * expat: Namespace-separator characters in “xmlns[:prefix]” attribute values can lead to arbitrary code execution (CVE-2022-25236) * expat: Integer overflow in storeRawNames() (CVE-2022-25315) * expat: Large number of prefixed XML attributes on a single tag can crash libexpat (CVE-2021-4596 [More…]

Red Hat OpenShift Container Platform release 4.10.6 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

An update for openssl is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for openssl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for expat is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The first step to data privacy is admitting you have a problem, Google
Under the hood of Wslink’s multilayered virtual machine

ESET researchers describe the structure of the virtual machine used in samples of Wslink and suggest a possible approach to see through its obfuscation techniques The post Under the hood of Wslink’s multilayered virtual machine appeared first on WeLiveSecurity

Will Chinese giants defy US sanctions on Russia? We asked a ZTE whistleblower
Okta acknowledges ‘mistake’ in handling of Lapsus$ attack
Kaspersky, China Telecom, China Mobile named ‘threats to US national security’

security update

The container bci/rust was updated. The following patches have been included in this update:

Prepare Your Business for the Future of Cyberwar: A Review of The Art of Cyberwarfare>

This is the March 2022 update for .NET Core 3.1: SDK 3.1.417 and Runtime 3.1.23 Release notes: https://github.com/dotnet/core/blob/main/release- notes/3.1/3.1.23/3.1.23.md This includes fixes for CVE-2022-24464, CVE-2022-24512 and CVE-2020-8927

CVE-2022-24302: Creation of new private key files using `~paramiko.pkey.PKey` subclasses was subject to a race condition between file creation and mode modification, which could be exploited by an attacker with knowledge of where the Paramiko-using code would write out such files; this has been patched by using `os.open` and `os.fdopen` to ensure new files are […]

This is the March 2022 update for .NET Core 3.1: SDK 3.1.417 and Runtime 3.1.23 Release notes: https://github.com/dotnet/core/blob/main/release- notes/3.1/3.1.23/3.1.23.md This includes fixes for CVE-2022-24464, CVE-2022-24512 and CVE-2020-8927

CVE-2022-24302: Creation of new private key files using `~paramiko.pkey.PKey` subclasses was subject to a race condition between file creation and mode modification, which could be exploited by an attacker with knowledge of where the Paramiko-using code would write out such files; this has been patched by using `os.open` and `os.fdopen` to ensure new files are […]

Fix for CVE-2022-0860

The container bci/ruby was updated. The following patches have been included in this update:

The container suse/rmt-nginx was updated. The following patches have been included in this update:

The container suse/rmt-mariadb was updated. The following patches have been included in this update:

The container suse/rmt-mariadb-client was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

‘Precursor malware’ infection may be sign you’re about to get ransomware, says startup
DOJ Indicts Russian Gov’t Employees Over Targeting Power Sector

security update

Unit 42: Ransomware demands we’re aware of averaged $2.2m last year

Think of all the important files sitting on your computer right now. If your computer crashed tomorrow, would you be able to retrieve your important files? Would your business suffer as a result? As more and more of our daily activities incorporate digital and online files, it’s important for businesses and consumers to back up […]

Optimistic father of LAPSUS$ hacking suspect says he’s going to try to stop him using computers
Is a nation‑state digital deterrent scenario so far‑fetched?

Why has the conflict in Ukraine not caused the much anticipated global cyber-meltdown? The post Is a nation‑state digital deterrent scenario so far‑fetched? appeared first on WeLiveSecurity

Crypto malware in patched wallets targeting Android and iOS devices

ESET Research uncovers a sophisticated scheme that distributes trojanized Android and iOS apps posing as popular cryptocurrency wallets The post Crypto malware in patched wallets targeting Android and iOS devices appeared first on WeLiveSecurity

Atlassian flags Bitbucket and Confluence Data Center flaws
Hackers remotely start, unlock Honda Civics with $300 tech
Google Chrome Zero-Day Bugs Exploited Weeks Ahead of Patch
How AI can fend off supply-chain attacks
US DoJ reveals Russian supply chain attack targeting energy sector

The container suse/sles12sp3 was updated. The following patches have been included in this update:

The container ses/7/prometheus-webhook-snmp was updated. The following patches have been included in this update:

The container ses/7/ceph/prometheus-server was updated. The following patches have been included in this update:

The container ses/7/ceph/prometheus-node-exporter was updated. The following patches have been included in this update:

The container ses/7/ceph/prometheus-alertmanager was updated. The following patches have been included in this update:

Distributor dumps Kaspersky to show solidarity with Ukraine
We blocked North Korea’s Chrome exploit, says Google
Microsoft Azure developers targeted by 200-plus data-stealing npm packages
British cops arrest seven in Lapsus$ crime gang probe

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

UK Cops Collar 7 Suspected Lapsus$ Gang Members