Menu

Category Archives: Security

Articles about security

Twitter’s top security staff out after incoming CEO shakes things up

Whether you’re shopping for the latest tech gadgets or checking your work email, your online presence is susceptible to malicious threats. No industry or sector is immune. Even in the early days of 2022, a hospital in Jackson, Florida, experienced a ransomware attack that left medical professionals struggling to access patient records. Attacks like this […]

Linux Servers at Risk of RCE Due to Critical CWP Bugs
MoleRats APT Launches Spy Campaign on Bankers, Politicians, Journalists
Surge in Malicious QR Codes Sparks FBI Alert
Dark Souls 3 Servers Shut Down Due to Critical RCE Bug
Hive View security camera customers left in the dark as some gear goes TITSUP*

The Red Hat Build of OpenJDK 11 (java-11-openjdk) is now available for Windows. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The Red Hat build of OpenJDK 17 (java-17-openjdk) is now available for portable Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The Red Hat Build of OpenJDK 11 (java-11-openjdk) is now available for portable Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The Red Hat build of OpenJDK 17 (java-17-openjdk) is now available for Windows. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for etcd is now available for Red Hat OpenStack Platform 16.2 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libreswan is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Of hacks and patches
Unusual ‘Donald Trump’ Packer Malware Delivers RATs, Infostealers
Myanmar’s military junta seeks ban on VPNs and digital currency
Australian Prime Minister’s WeChat Shanghaied by Chinese patriots

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Update to 2.34.4: * Fix dire [“Safari Leaks”](https://safarileaks.com/) IndexedDB privacy violation. * Make audio tools (like mixers) display the actual name of the application producing sound, instead of a generic one. * Fix several crashes and rendering issues. * Additional security fixes: CVE-2021-30887, CVE-2021-30890, CVE-2021-30934, CVE-2021-30936, CVE-2021-30951,

Fix CVE-2022-23132, CVE-2022-23133, CVE-2022-23134

Fix CVE-2022-23132, CVE-2022-23133, CVE-2022-23134

Several vulnerabilities were discovered in the Go programming language. An attacker could trigger a denial-of-service (DoS) and information leak.

Several vulnerabilities were discovered in the Go programming language. An attacker could trigger a denial-of-service (DoS) and information leak.

Apple preps fix for Safari’s web-history-leaking IndexedDB privacy bug
Rust 1.58.1 fixes dangerous race condition
The Internet’s Most Tempting Targets

The 5.15.16 stable kernel update contains a number of important fixes across the tree.

Security fix for CVE-2021-45931

Merck Awarded $1.4B Insurance Payout over NotPetya Attack

security update

security update

The 5.15.16 stable kernel update contains a number of important fixes across the tree.

An update is now available for OpenShift Logging (5.2.6) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Arm rages against the insecure chip machine with new Morello architecture
20K WordPress Sites Exposed by Insecure Plugin REST-API
McAfee Bug Can Be Exploited to Gain Windows SYSTEM Privileges
How to know if your email has been hacked

Think your email may have been hacked? Here are the signs to look for, how account takeover attacks commonly occur, and how to recover your account and avoid falling victim again The post How to know if your email has been hacked appeared first on WeLiveSecurity

Spyware Blitzes Compromise, Cannibalize ICS Networks

Several security issues were fixed in Thunderbird.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Security fix for CVE-2021-45930

Rebase to version 2.4.3

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Why should I pay for that security option? Hijacking only happens to planes
UK, Australia, to build ‘network of liberty that will deter cyber attacks before they happen’
Japan’s Supreme Court rules cryptojacking scripts are not malware
Russia’s Putin out the idea of a broad cryptocurrency ban

security update

2FA Bypassed in $34.6M Crypto.com Heist
Crypto.com now says someone tried to drain $34m from hundreds of accounts
For those worried about Microsoft’s Pluton TPM chip: Lenovo won’t even switch it on by default in latest ThinkPads
Critical Cisco StarOS Bug Grants Root Access via Debug Mode
Understand Diffie-Hellman key exchange
Microsoft: Attackers Tried to Login to SolarWinds Serv-U Via Log4j Bug
UK mulls making MSPs subject to mandatory security standards where they provide critical infrastructure
Pervasive Apple Safari Bug Exposes Web-Browsing Data, Google IDs
Red Cross Begs Attackers Not to Leak Stolen Data for 515K People
Privacy is for paedophiles, UK government seems to be saying while spending £500k demonising online chat encryption
‘Now’ would be the right time to patch Ubuntu container hosts and ditch 21.04 thanks to heap buffer overflow bug
SEC Filing Reveals Fortune 500 Firm Targeted in Ransomware Attack
Jail for prolific romance fraudster who fleeced besotted lonely hearts

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for Red Hat build of Eclipse Vert.x. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For

Smashing Security podcast #258: Tesla remote hijacks and revolting YouTubers
Fileless Malware on Linux: Anatomy of an Attack>

The container suse/sle15 was updated. The following patches have been included in this update:

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Overcoming vulnerabilities with live kernel patching in Red Hat Enterprise Linux 8.5
NortonLifeLock and Avast tie-up falls under UK competition regulator’s spotlight

AIDE could be made to crash or run programs as an administrator if it opened a specially crafted file.

Red Cross forced to shutter family reunion service following cyberattack and data leak
Being ‘Threat-Led’ is the answer. Your ISO certificate won’t save you from a breach!
McAfee and FireEye rename themselves ‘Trellix’
Singapore gives banks two-week deadline to fix SMS security

The onset of COVID-19 accelerated growth of the digital nomad. No longer just for bloggers and influencers, the global workforce is increasingly becoming more highly connected and widely dispersed. As workforces become more globally linked, businesses large and small need to protect themselves from evolving threats. Employees represent the first line of defense from malicious […]

Need to prioritize security bug patches? Don’t forget to scan Twitter as well as use CVSS scores
Destructive Wiper Targeting Ukraine Aimed at Eroding Trust, Experts Say
Sniff those Ukrainian emails a little more carefully, advises Uncle Sam in wake of Belarusian digital vandalism
Faker NPM package back on track after malicious coding incident
Box 2FA Bypass Opens User Accounts to Attack
Vulnerabilities and censorship tools among hot new features in Beijing’s Olympics app
DoNot Go! Do not respawn!

ESET researchers take a deep look into recent attacks carried out by Donot Team throughout 2020 and 2021, targeting government and military entities in several South Asian countries The post DoNot Go! Do not respawn! appeared first on WeLiveSecurity

Beijing Olympics App Flaws Allow Man-in-the-Middle Attacks
US mergers doubled in 2021 so FTC and DoJ seek new guidelines to stop illegal ones

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Updated Satellite 6.10 packages that fix several bugs are now available for Red Hat Satellite. 2. Relevant releases/architectures: Red Hat Satellite 6.10 – noarch, x86_64

Red Hat OpenShift Container Platform release 4.7.41 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

An update for kernel is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Cloned Dept. of Labor Site Hawks Fake Government Contracts

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Nine-year-old kids are launching DDoS attacks against schools
Will 2022 Be the Year of the Software Bill of Materials?
Crypto.com acknowledges ‘unauthorized activity’ on servers, maintains no funds have been lost
The Log4j Vulnerability Puts Pressure on the Security World
Cybercriminals Actively Target VMware vSphere with Cryptominers
Suse open sources NeuVector container security platform
‘White Rabbit’ Ransomware May Be FIN8’s Latest Tool