Menu

Category Archives: Security

Articles about security

Global Cyberattacks from Nation-State Actors Posing Greater Threats
The 5 Most-Wanted Threatpost Stories of 2021

Several security vulnerabilities were found in Apache Log4j2, a Logging Framework for Java, which could lead to a denial of service or information disclosure.

Invalid read for malformed DVI files was fixed in GNU libextractor, a library that extracts meta-data from files of arbitrary type. For Debian 9 stretch, this problem has been fixed in version

What app developers need to do now to fight Log4j exploits

Update log4j to 2.17.0 for CVE-2021-45105 Denial of Service attack

Backport fix for CVE-2021-45078

Update log4j to 2.17.0 for CVE-2021-45105 Denial of Service attack

Backport fix for CVE-2021-45078

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The 5.15.11 stable kernel update contains a number of important fixes across the tree.

Updat eto 4.6.5 to fix CVE-2021-43818.

Update to 2.53.10.1 Backport fixes to improve compatibility of some sites

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container ses/7/ceph/ceph was updated. The following patches have been included in this update:

The container ses/7/ceph/grafana was updated. The following patches have been included in this update:

The container ses/7/cephcsi/cephcsi was updated. The following patches have been included in this update:

security update

security update

https://lib.openmpt.org/libopenmpt/2021/12/23/security- update-0.5.15-releases-0.4.27-0.3.36/

The following vulnerabilities have been discovered in the wpewebkit web engine: CVE-2021-30887

The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2021-30887

OpenPGP signature status doesn’t consider additional message content. (CVE-2021-4126) Matrix chat library libolm bundled with Thunderbird vulnerable to a buffer overflow. (CVE-2021-44538)

Four years: that’s how long Azure’s App Service had a source code leak bug

security update

security update

Security fix for CVE-2021-44224, CVE-2021-44790

Rebuild 3.8.5 using golang-1.16.12

Rebuild 3.8.5 using golang-1.16.12

4-Year-Old Microsoft Azure Zero-Day Exposes Web App Source Code
This holiday season, give your children the gift of cybersecurity awareness

Don’t leave your kids to their own devices – give them a head start with staying safe online instead The post This holiday season, give your children the gift of cybersecurity awareness appeared first on WeLiveSecurity

Telegram Abused to Steal Crypto-Wallet Credentials
‘Spider-Man: No Way Home’ Download Installs Cryptominer
Time to Ditch Big-Brother Accounts for Network Scanning

An update that fixes four vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Fisher Price’s Bluetooth reboot of pre-school play phone has adult privacy flaw
Alibaba Cloud slapped by Chinese ministry for mishandling Log4j

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

security update

PYSA Emerges as Top Ransomware Actor in November
All in One SEO Plugin Bug Threatens 3M Websites with Takeovers
Critical Apache HTTPD Server Bugs Could Lead to RCE, DoS
Four Bugs in Microsoft Teams Left Platform Vulnerable Since March

An update that fixes 33 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

It was discovered that missing SAML signature validation in the SOGo groupware could result in impersonation attacks. For the oldstable distribution (buster), this problem has been fixed

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Of course a Bluetooth-using home COVID test was cracked to fake results
Java Code Repository Riddled with Hidden Log4j Bugs; Here’s Where to Look
How to tackle hybrid cloud security and DevSecOps
Half-Billion Compromised Credentials Lurking on Open Cloud Server
Why SBOM management is no longer optional
Don’t forget to unplug your devices before you leave for the holidays!

As you down tools for the holiday season, be sure to also switch off the standby lights – it’s both cost effective and better for the environment The post Don’t forget to unplug your devices before you leave for the holidays! appeared first on WeLiveSecurity

Two Active Directory Bugs Lead to Easy Windows Domain Takeover
FBI: Another Zoho ManageEngine Zero-Day Under Active Attack
Belgian defence ministry admits attackers accessed its computer network by exploiting Log4j vulnerability

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the postgresql:13 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for openssl is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

UK National Crime Agency finds 225 million previously unexposed passwords
US bags Russian accused of stealing millions after stealing pre-release financial filings
Conti Ransomware Gang Has Full Log4Shell Attack Chain

security update

Robocalls More Than Doubled in 2021, Cost Victims $30B
Third Log4J Bug Can Trigger DoS; Apache Issues Patch
Police National Computer not pwned by Clop ransomware crims, insists Home Office

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update for log4j is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.6 Advanced Update Support, Red

How to keep on top of cloud security best practices
VMware 2FA flaw can divulge that vital second credential to malicious actors
Bad things come in threes: Apache reveals another Log4J bug

security update

security update

An update that fixes one vulnerability is now available.

Updated olm packages fix security vulnerability: The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is

Updated privoxy packages fix security vulnerabilities: A security issue has been found in Privoxy before version 3.0.33. get_url_spec_param() did not free memory of compiled pattern spec before bailing (CVE-2021-44540).

Updated watchdog packages fixes an issue with a memory leak when verbose mode is on. References: – https://bugs.mageia.org/show_bug.cgi?id=29576

Log4j: Everything You Need to Know>

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

Updated mediawiki packages fix security vulnerabilities: == Security fixes == * (T292763. CVE-2021-44854) REST API incorrectly publicly caches autocomplete search results from private wikis.

In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property (CVE-2021-44225).

security update

US distrust of Huawei linked in part to malicious software update in 2012

An update that fixes one vulnerability is now available.

It was discovered that modsecurity-apache, an Apache module to tighten the Web application security, does not properly handles excessively nested JSON objects, which could result in denial of service. The update introduces a new ‘SecRequestBodyJsonDepthLimit’ option to limit the