Menu

Category Archives: Security

Articles about security

The container trento/trento-db was updated. The following patches have been included in this update:

CISOs face ‘perfect storm’ of ransomware and state-supported cybercrime

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

SAP community website leaks member data to savvy users
Has Trickbot gang hijacked your router? This scanner may have an answer
Dev Sabotages Popular NPM Package to Protest Russian Invasion
As tax deadlines approach, Emotet malware disguises itself in an IRS email
US military vs. Silicon Valley – a cultural divide

The US military knows it needs to speed up technology adoption through optimization, something at the heart of Silicon Valley culture The post US military vs. Silicon Valley – a cultural divide appeared first on WeLiveSecurity

Misconfigured Firebase Databases Exposing Data in Mobile Apps
Deepfake President Zelensky calls on Ukraine to surrender, as TV station hacked
Reporting Mandates to Clear Up Feds’ Hazy Look into Threat Landscape – Podcast
How CAPTCHAs can cloak phishing URLs in emails

This is a maintenance release of OpenVPN 2.5 with a security fix when used in server mode ([CVE-2022-0547](https://community.openvpn.net/openvpn/wiki/CVE-2022-0547)). The other changes are available in [Changes.rst](https://github.com/OpenVPN/openvpn/blob/release/2.5/Changes.rst).

Update to 91.7.0

Update to version 1.5.5. This includes a fix for a denial-of-service vulnerability ([RUSTSEC-2022-0013](https://rustsec.org/advisories/RUSTSEC-2022-0013.html) / [CVE-2022-24713](https://cve.mitre.org/cgi- bin/cvename.cgi?name=CVE-2022-24713)).

Fix potential DoS in pesign daemon

Brit data regulator fines five cold-calling fiends £405k

An update that fixes one vulnerability, contains one feature is now available.

An update that fixes one vulnerability, contains one feature is now available.

Devil-may-care Lapsus$ gang is not the aspirational brand infosec needs
Smashing Security podcast #266: Dick pics, secret spies, and Kaspersky
CafePress fined for covering up 2019 customer info leak
LokiLocker ransomware family spotted with built-in wiper

security update

Linux botnet exploits Log4j flaw to pwn Arm, x86 systems
Police arrest scammer on FBI’s “Most Wanted” list in relation to $100 million fraud
‘CryptoRom’ Crypto-Scam is Back via Side-Loaded Apps
Another Destructive Wiper Targets Organizations in Ukraine
Russia-linked attackers breach NGO by exploiting MFA, PrintNightmare vuln

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Update to 3.24: fix CVE-2022-26495, CVE-2022-26496

Update to 3.24: fix CVE-2022-26495, CVE-2022-26496

UK regulator puts NortonLifeLock merger with Avast on ice

An update that contains security fixes and contains one feature can now be installed.

An update that solves 13 vulnerabilities and has three fixes is now available.

An update that contains security fixes and contains one feature can now be installed.

Phony Instagram ‘Support Staff’ Emails Hit Insurance Company
The Windows malware on Ukraine CERT’s radar
OpenSSL patches crash-me bug triggered by rogue certs
Cyberattacks Against Israeli Government Sites: ‘Largest in the Country’s History’
Microsoft Azure DevOps revives TLS 1.0/1.1 with rollback
SentinelOne pays $617m for identity biz Attivo Networks
UK Supreme Court snubs Julian Assange’s anti-extradition bid
A first look at threat intelligence and threat hunting tools

An overview of some of the most popular open-source tools for threat intelligence and threat hunting The post A first look at threat intelligence and threat hunting tools appeared first on WeLiveSecurity

Huge DDoS attack temporarily kicks Israeli government sites offline
Most QNAP NAS Devices Affected by ‘Dirty Pipe’ Linux Flaw
Germany advises citizens to uninstall Kaspersky antivirus
NVIDIA staff shouldn’t have chosen passwords like these…
Russian demand for VPNs skyrockets by 2,692%

OpenSSL could be made to stop responding if it opened a specially crafted certificate.

UK criminal defense lawyer hadn’t patched when ransomware hit
Pandora Ransomware Hits Giant Automotive Supplier Denso

Tavis Ormandy discovered that the BN_mod_sqrt() function of OpenSSL could be tricked into an infinite loop. This could result in denial of service via malformed certificates.

rsh would allow unintended modification of target directory permissions.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

10 Common Security Mistakes Sysadmins Make & How To Avoid These Pitfalls>
Another data-leaking Spectre bug found, smashes Intel, Arm defenses
NASA in ‘serious jeopardy’ due to big black hole in security
Russia’s invasion of Ukraine tears open political rift between cybercriminals
CaddyWiper: New wiper malware discovered in Ukraine

This is the third time in as many weeks that ESET researchers have spotted previously unknown data wiping malware taking aim at Ukrainian organizations The post CaddyWiper: New wiper malware discovered in Ukraine appeared first on WeLiveSecurity

Staff Think Conti Group Is a Legit Employer – Podcast

security update

security update

security update

China thrilled it captured already-leaked NSA cyber-weapon
Valorant aimbot hack lures the unwary into malware infection
Viasat, Rosneft hit by cyberattacks as Ukraine war spills online

Command injection in ruby bundler. (CVE-2021-43809) References: – https://bugs.mageia.org/show_bug.cgi?id=30162 – https://blog.sonarsource.com/securing-developer-tools-package-managers

This kernel-linus update is based on upstream 5.15.28 and fixes at least the following security issues: Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially

This kernel update is based on upstream 5.15.28 and fixes at least the following security issues: Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially

The chromium-browser-stable package has been updated to the 99.0.4844.51 version that fixes multiples security vulnerabilities. References: – https://bugs.mageia.org/show_bug.cgi?id=29988

Cybercrooks’ Political In-Fighting Threatens the West
New US law: Cyberattacks to be reported within 72 hours

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Brit techie shows us life in Ukraine amid Russian invasion
Is low-code safe and secure?
China: Attacks from US IP addresses hit us, moved on to Russia and Ukraine
Russia labels Meta an ‘extremist’ organization, bans Instagram
Taiwan rounds up 60 Chinese tech workers on suspicion of poaching tech and people
Ubisoft changes employee passwords after “cyber security incident”

A flaw was discovered in the way HAProxy, a fast and reliable load balancing reverse proxy, processes HTTP responses containing the “Set-Cookie2” header, which can result in an unbounded loop, causing a denial of service.

The update for expat released as DSA 5085-1 introduced regressions for applications using URI characters (‘:’ in particular) for a namespace separator (while the HTML API docs of function XML_ParserCreateNS have been advising against their use). Updated expat packages are now

Emmet Leahy reported that libphp-adodb, a PHP database abstraction layer library, allows to inject values into a PostgreSQL connection string. Depending on how the library is used this flaw can result in authentication bypass, reveal a server IP address or have other

Improve your hybrid cloud security with these 3 tips

Two vulnerabilities were discovered in the server for the Network Block Device (NBD), which could result in the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed

The container sles-15-sp3-chost-byos-v20220310 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220310-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220310-gen2 was updated. The following patches have been included in this update:

Null pointer dereference in MD_UPDATE. (CVE-2021-4209) References: – https://bugs.mageia.org/show_bug.cgi?id=30112 – https://lists.suse.com/pipermail/sle-security-updates/2022-March/010333.html

Singapore uncovers four critical vulnerabilities in Riverbed software

security update

security update

Multiple security vulnerabilities have been discovered in vim, an enhanced vi editor. Buffer overflows, out-of-bounds reads and Null pointer dereferences may lead to a denial of service (application crash) or other unspecified impact.

Russia Issues Its Own TLS Certs
Dunno about you, but we’re seeing an 800% increase in cyberattacks, says one MSP