Menu

Category Archives: Security

Articles about security

Microsoft Azure Developers Awash in PII-Stealing npm Packages
Just-Released Dark Souls Game, Elden Ring, Includes Killer Bug
HP finance manager went on $5m personal spending spree with company card
HubSpot Data Breach Ripples Through Crytocurrency Industry
Mustang Panda’s Hodur: Old tricks, new Korplug variant

ESET researchers have discovered Hodur, a previously undocumented Korplug variant spread by Mustang Panda, that uses phishing lures referencing current events in Europe, including the invasion of Ukraine The post Mustang Panda’s Hodur: Old tricks, new Korplug variant appeared first on WeLiveSecurity

Chinese APT Combines Fresh Hodur RAT with Complex Anti-Detection
Microsoft Help Files Disguise Vidar Malware
Top 3 Attack Trends in API Security – Podcast
Tax-Season Scammers Spoof Fintechs, Including Stash, Public

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

USN-5321-1 introduced minor regressions in Firefox.

An update for python-twisted is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for openstack-nova is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for numpy is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

UK Ministry of Defence takes recruitment system offline, confirms data leak
IT outage at Scotland’s Heriot-Watt University enters second week
Check Point spreads AI goodness throughout its security portfolio
F-Secure spins out new enterprise security business: WithSecure
Smashing Security podcast #267: Virtual kidnapping, two helipads, and a naughty Apple employee

security update

VMware fixes command injection, file upload flaws in Carbon Black security tool
Simplify your security with Forcepoint ONE
US says Russian ran online marketplace of stolen logins
Nestlé says it leaked its own test data, not Anonymous
AvosLocker ransomware – what you need to know
Cybercriminals made $7bn in pure profit in 2021, says FBI
DeadBolt Ransomware Resurfaces to Hit QNAP Again
Microsoft: Lapsus$ Used Employee Account to Steal Source Code
Lockbit wins ransomware speed test, encrypts 25,000 files per minute

Red Hat OpenShift Container Platform release 4.6.56 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.6.

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 17 vulnerabilities is now available.

An update that solves three vulnerabilities and has one errata is now available.

Fresh concerns about ‘indefinite’ UK government access to doctors’ patient data

An update that fixes 17 vulnerabilities is now available.

Okta now says: Lapsus$ may in fact have accessed customer info
Nvidia’s Morpheus AI security framework to land in April
Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta

security update

Well done patching Log4j. Now, are you ready for the next zero day disaster?
Sandworm: A tale of disruption told anew

As the war rages, the APT group with a long résumé of disruptive cyberattacks enters the spotlight again The post Sandworm: A tale of disruption told anew appeared first on WeLiveSecurity

Russia Lays Groundwork for Cyberattacks on US Infrastructure – White House
FIDO: Here’s Another Knife to Help Murder Passwords
Serpent Backdoor Slithers into Orgs Using Chocolatey Installer

Several security issues were fixed in CKEditor.

Authentication oufit Okta investigating Lapsus$ breach report

An update for rh-mariadb105-mariadb and rh-mariadb105-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for rh-mariadb103-mariadb and rh-mariadb103-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Biden says Russia exploring revenge cyberattacks
Just how do you build a healthy software pipeline and make sure it’s secure?
This is a BlackCat you don’t want crossing your path
Skyhigh Security rises from McAfee-FireEye’s SSE
What does Go-written malware look like? Here’s a sample under the microscope
Browser-in-the-Browser Attack Makes Phishing Nearly Invisible

security update

security update

Microsoft investigates Lapsus$’s boasts of Bing, Cortana code heist
Facestealer Trojan Hidden in Google Play Plunders Facebook Accounts
Conti Ransomware V. 3, Including Decryptor, Leaked
Scottish mental health charity “devastated” by heartless RansomEXX ransomware attack
Western Digital tells EdgeRover users to patch app again
FIDO Alliance says it has finally killed the password
Satellite comms networks on alert after US govt warning
Bridgestone Hit as Ransomware Torches Toyota Supply Chain
AvosLocker group is targeting US critical infrastructure, FBI says
Zoom agrees privacy conditions, gets low-risk rating from Netherlands

Several security issues were fixed in ImageMagick.

Red Hat OpenShift Container Platform release 4.10.5 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

Red Hat OpenShift Container Platform release 4.9.25 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Hackers demand $15 million ransom from TransUnion after cracking “password” password

The container ses/6/rook/ceph was updated. The following patches have been included in this update:

The container ses/6/ceph/ceph was updated. The following patches have been included in this update:

The container ses/6/cephcsi/cephcsi was updated. The following patches have been included in this update:

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

An update that fixes one vulnerability is now available.

The 5.16.15 stable kernel update includes a number of important fixes across the tree. It also includes a temporary revert of the feature that makes QNAP NFS mounts fail. We will carry this revert through the 5.16 series in attempt to give the vendor more time to come out with an update, or upstream to […]

WordPress 5.9.2 Security & Maintenance Release

New upstream release 3.1.4

The security update announced as DLA 2955-1 caused a regression in named due to an incomplete fix for CVE-2021-25220 when the Forwarders option was configured. Updated bind9 packages are now available to correct this issue.

Regulatory compliance at scale with Red Hat Insights
This browser-in-browser attack is perfect for phishing
Agencies Warn on Satellite Hacks & GPS Jamming Affecting Airplanes, Critical Infrastructure

It was found that bind9, an internet domain name server, was vulnerable to cache poisoning. When using forwarders, bogus NS records supplied by, or via, those forwarders may be cached and used by named if it needs to recurse for any reason, causing it to obtain and pass on potentially incorrect answers.

Cyclops Blink malware sets up shop in ASUS routers
DarkHotel APT Targets Wynn, Macao Hotels to Rip Off Guest Data
Sandworm APT Hunts for ASUS Routers with Cyclops Blink Botnet
Exotic Lily is a business-like access broker for ransomware gangs
Google Blows Lid Off Conti, Diavol Ransomware Access-Broker Ops

The container trento/trento-web was updated. The following patches have been included in this update:

The container trento/trento-runner was updated. The following patches have been included in this update:

The container trento/trento-db was updated. The following patches have been included in this update:

CISOs face ‘perfect storm’ of ransomware and state-supported cybercrime