Menu

Category Archives: Security

Articles about security

There were a couple of vulnerabilites found in src:python3.5, the Python interpreter v3.5, and are as follows: CVE-2021-3733

This update upgrades Thunderbird to version 91.3.0. * Mozilla: Use-after-free in HTTP2 Session object * Mozilla: Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3 * Mozilla: iframe sandbox rules did not apply to XSLT stylesheets (CVE-2021-38503) * Mozilla: Use-after-free in file picker dialog (CVE-2021-38504) * Mozilla: Firefox could be coaxed into going […]

Stefan Walter found that udisks2, a service to access and manipulate storage devices, could cause denial of service via system crash if a corrupted or specially crafted ext2/3/4 device or image was mounted, which could happen automatically on certain environments.

Beijing fingers foreign spies for data mischief, with help from consulting firm

The container suse/sles12sp5 was updated. The following patches have been included in this update:

Rust 1.56.1 adds a mitigation for CVE-2021-42574, the “trojan source” attack that obfuscates code with BiDi control characters. The compiler will now error on such characters in code comments and string/char literals. For more details, see the upstream [security advisory](https://blog.rust- lang.org/2021/11/01/cve-2021-42574.html).

When containers become a nightmare
US Blacklists Pegasus Spyware Maker
3 Guideposts for Building a Better Incident-Response Plan
“PlugWalkJoe” indicted for $784,000 SIM-swap cryptocurrency theft
Win one for privacy – Swiss providers don’t have to talk

Security and privacy get a leg up in Proton’s legal challenge against data retention and disclosure obligations The post Win one for privacy – Swiss providers don’t have to talk appeared first on WeLiveSecurity

What’s it like to work as a malware researcher? 10 questions answered

Three ESET malware researchers describe what their job involves and what it takes to embark on a successful career in this field The post What’s it like to work as a malware researcher? 10 questions answered appeared first on WeLiveSecurity

Free Discord Nitro Offer Used to Steal Steam Credentials
Critical Linux Kernel Bug Allows Remote Takeover

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Magecart Credit Card Skimmer Avoids VMs to Fly Under the Radar

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

FYI: Code compiled to WebAssembly may lack standard security defenses
Smashing Security podcast #250: Yes, you heard that correctly. Two hundred and fifty

This update upgrades Firefox to version 91.3.0 ESR. * Mozilla: Use-after-free in HTTP2 Session object * Mozilla: Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3 * Mozilla: iframe sandbox rules did not apply to XSLT stylesheets (CVE-2021-38503) * Mozilla: Use-after-free in file picker dialog (CVE-2021-38504) * Mozilla: Firefox could be coaxed into […]

Beijing lashes USA’s China Telecom ban – but quite gently

The 5.14.15 stable kernel update contains a number of important fixes across the tree.

US Dept of Commerce sanctions NSO Group, Positive Technologies, other makers of snoopware
Mekotio Banking Trojan Resurges with Tweaked Code, Stealthy Campaign
Microsoft rolls out $3-a-user Defender for small biz types
Google warns Android users of zero-day vulnerability being actively attacked
‘Tortilla’ Wraps Exchange Servers in ProxyShell Attacks
Predicting the Next OWASP API Security Top 10
Man charged with hacking major US sports leagues to illegally stream games

On top of illegally streaming sports games for profit, the man is also believed to have attempted to extort MLB for $150,000 The post Man charged with hacking major US sports leagues to illegally stream games appeared first on WeLiveSecurity

Top 6 Vulnerability Scanning Tools>
BlackMatter ransomware gang says it’s disbanding – again – after Ukraine arrests
Locked up: UK’s Labour Party data ‘rendered inaccessible’ on third-party systems after cyber attack

An update that solves two vulnerabilities and has two fixes is now available.

UK data spillers fined, but enforcement slows: £5m in ICO penalties not yet paid
Report: BlackMatter Ransomware Gang Goes Dark, Again

An update is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

BlackMatter ransomware gang to shut down
CyberUp presents four principles to keep security researchers out of jail for good-faith probing

The container sles-15-sp3-chost-byos-v20211101 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20211101-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20211101-gen2 was updated. The following patches have been included in this update:

Keeping an eye on critical infrastructure and industrial systems? So are legions of cyber-criminals
Squid Game Crypto Scammers Rips Off Investors for Millions

security update

security update

Ransomware Gangs Target Corporate Financial Activities
Android Patches Actively Exploited Zero-Day Kernel Bug
Apple macOS Flaw Allows Kernel-Level Compromise

An update that fixes 12 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Red Hat OpenShift Virtualization release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

China says it applied to join digital free trade deal days after proposing law against cross-border data flow

An update that solves two vulnerabilities and has one errata is now available.

Red Hat OpenShift Virtualization release 4.9.0 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Office 365 Phishing Campaign Uses Kaspersky’s Amazon SES Token
Pirate Sports Streamer Gets Busted, Pivots to MLB Extortion
Your data is wider and deeper than ever – and so are the threats

An update for flatpak is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in WebKitGTK.

An update for flatpak is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Trojan Source attack: Code that says one thing to humans tells your compiler something very different, warn academics
‘Trojan Source’ Hides Invisible Bugs in Source Code
Android has its head in the sand with AbstractEmu malware rooting phones
Prevent identity fraud and disupt attackers with Recorded Future Identity Intelligence
Data transfers between the EU and the US: Still unclear on what you’re supposed to do? Here’s an explainer
Alleged Trickbot malware gang member extradited to United States, and appears in court

The package bind before version 9.16.22-1 is vulnerable to denial of service.

The package freerdp before version 2:2.4.1-1 is vulnerable to arbitrary code execution.

The package wpewebkit before version 2.34.1-1 is vulnerable to multiple issues including arbitrary code execution and sandbox escape.

The package webkit2gtk before version 2.34.1-1 is vulnerable to multiple issues including arbitrary code execution and sandbox escape.

The package opera before version 80.0.4170.63-1 is vulnerable to multiple issues including arbitrary code execution and sandbox escape.

The package chromium before version 95.0.4638.69-1 is vulnerable to multiple issues including arbitrary code execution and insufficient validation.

security update

security update

Several security vulnerabilities have been discovered in OpenCV, the Open Computer Vision Library. Buffer overflows, NULL pointer dereferences and out-of-bounds write errors may lead to a denial-of-service or other unspecified impact.

An update that fixes 16 vulnerabilities is now available.

security update

An issue has been found in cups, the Common UNIX Printing System. Due to an input validation issue a malicious application might be allowed to read restricted memory.

Update to 2.34.1: * Update user agent browser versions. * Fix a crash with GTK >= 3.24.30. * Fix a crash when loading videos on reddit. * Fix file type detection when application calls g_desktop_app_info_set_as_default_for_extension() passing html. * Security fixes: CVE-2021-42762

Fix for CVE-2021-41990 and CVE-2021-41991

# New in release OpenJDK 11.0.13 (2021-10-19): Live versions of these release notes can be found at: * https://bitly.com/openjdk11013 * https://builds.shipilev.net/backports-monitor/release-notes-11.0.13.txt ## Security fixes – JDK-8163326, CVE-2021-35550: Update the default enabled cipher suites preference – JDK-8254967, CVE-2021-35565:

Shrootless: Microsoft found a way to evade Apple’s SIP macOS filesystem protection
5 tips for parents for a cybersecure Halloween

What are some of the key dangers faced by children online and how can you help protect them from the ghosts, ghouls and goblins creeping on the internet? The post 5 tips for parents for a cybersecure Halloween appeared first on WeLiveSecurity

Dark HunTOR: 150 arrested, $31 million seized in major dark web bust

The police sting spanned three continents and involved crackdowns in nine countries The post Dark HunTOR: 150 arrested, $31 million seized in major dark web bust appeared first on WeLiveSecurity

Wslink: Unique and undocumented malicious loader that runs as a server

There are no code, functionality or operational similarities to suggest that this is a tool from a known threat actor The post Wslink: Unique and undocumented malicious loader that runs as a server appeared first on WeLiveSecurity

Could “Unbreakable” Oracle Linux be the Logical Enterprise-Ready CentOS Replacement?>
Google Chrome is Abused to Deliver Malware as ‘Legit’ Win 10 App
Data-breached Guntrader website calls in liquidators, is reborn as Guntrader 2 Ltd
UK data watchdog calls for end-to-end encryption across video chat apps by default
Teenager made Bitcoin fortune after promoting scam website with Google ad

This update includes the changes in tzdata 2021e for the Perl bindings. For the list of changes, see DLA-2797-1. For Debian 9 stretch, this problem has been fixed in version

This update includes the changes in tzdata 2021e. Notable changes are: – – Fiji suspends DST for the 2021/2022 season.

A security vulnerability was discovered in gpsd, the Global Positioning System daemon. A stack-based buffer overflow may allow remote attackers to execute arbitrary code via traffic on port 2947/TCP or crafted JSON inputs.

Feds cuff Russian said to be developer of ‘Trickbot’ ransomware

The container suse/sle15 was updated. The following patches have been included in this update:

India’s Supreme Court starts probe into use of Pegasus spyware