Menu

Category Archives: Security

Articles about security

– Update cargo-insta to version 1.11.0. – Update the insta crate to version 1.11.0. – Update the ron crate to version 0.7.0. – Introduce a compat package for ron versions 0.6.x. – Update the similar-asserts crate to version 1.2.0. – Update the similar crate to version 2.1.0.

A security bug has been discovered and fixed in the userhelper program.

It was discovered that missing input sanitising in python-nbxmpp, a Jabber/XMPP Python library, could result in denial of service in clients based on it (such as Gajim).

The update for prosody released as DSA 5047 introduced a memory leak. Updated prosody packages are now available to correct this issue. For the oldstable distribution (buster), this problem has been fixed

Several vulnerabilities have been discovered in libraw that may lead to the execution of arbitrary code, denial of service, or information leaks.

Security fixes for CVE-2022-0351, CVE-2022-0359 —- Security fixes for CVE-2022-0213, CVE-2022-0261

Fix for CVE-2021-32765

Safeguarding consumer data for banks: some guidelines for privacy engineering

The container suse-sles-15-sp3-chost-byos-v20220126-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container sles-15-sp1-chost-byos-v20220127 was updated. The following patches have been included in this update:

The container suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp1-chost-byos-v20220127-gen2 was updated. The following patches have been included in this update:

update to version 2.10 and enable OCV CVE-2022-23303

# New in release OpenJDK 17.0.2 (2022-01-18): Live versions of these release notes can be found at: * https://bitly.com/openjdk1702 * https://builds.shipilev.net/backports-monitor/release-notes-17.0.2.txt ## Security fixes – JDK-8251329: (zipfs) Files.walkFileTree walks infinitely if zip has dir named “.” inside – JDK-8264934, CVE-2022-21248: Enhance cross VM

Lazarus APT Uses Windows Update to Spew Malware
Zerodium Spikes Payout for Zero-Click Outlook Zero-Days
Beyond the tick box: What to consider before agreeing to a privacy policy

The trade-off between using a free service and giving up our personal data becomes much less palatable when we think about the wider ramifications of the collection and use of our personal data The post Beyond the tick box: What to consider before agreeing to a privacy policy appeared first on WeLiveSecurity

Conti, DeadBolt Ransomwares Target Delta, QNAP
Shlayer and Bundlore MacOS Malware Strains – How Uptycs EDR Detection Can Help
Internet Society condemns UK’s Online Safety Bill for demonising encryption using ‘think of the children’ tactic
Real-Time Alerting with Snort>

OpenJDK: Incomplete deserialization class filtering in ObjectInputStream (Serialization, 8264934) (CVE-2022-21248) * OpenJDK: Insufficient URI checks in the XSLT TransformerImpl (JAXP, 8270492) (CVE-2022-21282) * OpenJDK: Unexpected exception thrown in regex Pattern (Libraries, 8268813) (CVE-2022-21283) * OpenJDK: Incomplete checks of StringBuffer and StringBuilder during deserialization (L [More…]

Discover and remediate security vulnerabilities faster with Red Hat Insights

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

DDoS attack on Minecraft Twitch tournament disrupted Andorra’s internet access
Silk could tie up all-but-unbreakable encryption, say South Korean boffins

The container suse/sle15 was updated. The following patches have been included in this update:

The container sles-15-sp3-chost-byos-v20220126 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220126-gen2 was updated. The following patches have been included in this update:

Intel fails to get Spectre, Meltdown chip flaw class-action super-suit tossed out
US DoD staffer with top-secret clearance stole identities from work systems to apply for loans
2FA App Loaded with Banking Trojan Infests 10K Victims via Google Play

security update

Dark Overlord collaborator imprisoned for trading stolen identities
BotenaGo Botnet Code Leaked to GitHub, Impacting Millions of Devices
Every breath you take, every move you make: Do fitness trackers pose privacy risks?

Should you beware of wearables? Here’s what you should know about the potential security and privacy risks of your smartwatch or fitness tracker. The post Every breath you take, every move you make: Do fitness trackers pose privacy risks? appeared first on WeLiveSecurity

Targeted ransomware takes aim at QNAP NAS drives, warns vendor: Get your updates done pronto
Shipment-Delivery Scams Become the Favored Way to Spread Malware
How to Secure Your SaaS Stack with a SaaS Security Posture Management Solution
Court papers indicate text messages from HMRC’s 60886 number could snoop on Brit taxpayers’ locations

Several security issues were fixed in shadow.

Mac webcam hijack flaw wins man $100,500 from Apple
Indonesia bars financial institutions from offering crypto services

Red Hat OpenShift Container Platform release 4.6.54 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.6.

An update for httpd24-httpd is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The container caasp/v4/velero-plugin-for-microsoft-azure was updated. The following patches have been included in this update:

The container caasp/v4/velero-plugin-for-gcp was updated. The following patches have been included in this update:

The container caasp/v4/velero-plugin-for-aws was updated. The following patches have been included in this update:

China orders web operators to spring clean its entire internet
Smashing Security podcast #259: Techquilibrium and mediocre linguistic escapades
Update now! Apple pushes out security patches for iPhone and Mac zero-day vulnerabilities
TrickBot Crashes Security Researchers’ Browsers in Latest Upgrade
Apple Fixes 2 Zero-Day Security Bugs, One Exploited in the Wild
Alert: Let’s Encrypt to revoke about 2 million HTTPS certificates in two days
‘Dark Herring’ Billing Malware Swims onto 105M Android Devices

security update

security update

security update

security update

security update

New Year, New Threats: 4 Tips to Activate Your Best Cyber-Defense
Cybercriminals Love Supply-Chain Chaos: Here’s How to Protect Your Inbox
Qualys Research Team Warns of Significant polkit Vulnerability Affecting All Linux Users>
Linux Bug in All Major Distros: ‘An Attacker’s Dream Come True’

Phishing attacks sustain historic highs In their latest report, IDG and the pros behind Carbonite + Webroot spoke with 300 global IT professionals to learn the current state of phishing. We learned that 93% of IT executives are still concerned about phishing – and it’s no wonder, as companies averaged 28 attacks each over the […]

Watering hole deploys new macOS malware, DazzleSpy, in Asia

Hong Kong pro-democracy radio station website compromised to serve a Safari exploit that installed cyberespionage malware on site visitors’ Macs The post Watering hole deploys new macOS malware, DazzleSpy, in Asia appeared first on WeLiveSecurity

Threat Actors Blanket Androids with Flubot, Teabot Campaigns

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the parfait:0.5 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the parfait:0.5 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the parfait:0.5 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the parfait:0.5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Infosec big dogs break out the bubbly over UK government’s latest cyber strategy emission
Infosec chap: I found a way to hijack your web accounts, turn on your webcam from Safari – and Apple gave me $100k
Linux distros haunted by Polkit-geist for 12+ years: Bug grants root access to any user

If you’ve considered using a virtual private network (VPN) at all, it’s likely to establish a secure connection while working remotely or to connect to public networks. But privacy enthusiasts appreciate the benefits of a VPN even from the comfort of their own homes. Depending on your level of comfort with your internet service provider […]

Cyberattacks on Squid Game Minecraft Tourney Take Down Andorra’s Internet
Ozzy Osbourne NFTs Used to Bite Off Chunk of Crypto Coin
Segway Hit by Magecart Attack Hiding in a Favicon

security update

security update

security update

security update

security update

MacOS Malware ‘DazzleSpy’ Used in Watering-Hole Attacks
How I hacked my friend’s PayPal account

Somebody could easily take control of your PayPal account and steal money from you if you’re not careful – here’s how to stay safe from a simple but effective attack The post How I hacked my friend’s PayPal account appeared first on WeLiveSecurity

AdSanity, AccessPress Plugins Open Scads of WordPress Sites to Takeover
Sophos: Log4Shell would have been a catastrophe without the Y2K-esque mobilisation of engineers
BRATA Android Trojan Updated with ‘Kill Switch’ that Wipes Devices

The Qualys Research Labs discovered a local privilege escalation in PolicyKit’s pkexec. Details can be found in the Qualys advisory at

The Qualys Research Labs discovered a local privilege escalation in PolicyKit’s pkexec. Details can be found in the Qualys advisory at

Is Google tracking your location even when you think you’ve turned it off? US states sue over “deception”

Upstream details at : https://access.redhat.com/errata/RHSA-2022:0143

Red Hat OpenShift Container Platform release 3.11.570 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.2 Extended Update Support, and Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact

An update for etcd is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

UK government opens consultation on medic-style register for Brit infosec pros
Yes, your data is special. But do you know how special?