Menu

Category Archives: Security

Articles about security

An update is now available for Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated ovirt-engine packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Updated ovirt-engine packages that fix several bugs and add various enhancements are now available. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Spanish banished: Google Chrome to snub Camerfirma for lax cert management
In wake of Apple privacy controls, Facebook mulls just begging its iOS app users to let it track them over the web
Wind River Security Incident Affects SSNs, Passport Numbers
US court system ditches electronic filing, goes paper-only for sensitive documents following SolarWinds hack
Hezbollah-Linked Lebanese Cedar APT Infiltrates Hundreds of Servers
SolarWinds Hack Prompts Congress to Put NSA in Encryption Hot Seat

security update

Chrome 89 beta: Google presses on with ‘advanced hardware interactions’ that Mozilla, Apple see as harmful
Critical Libgcrypt Crypto Bug Opens Machines to Arbitrary Code
Alleged Gaming Software Supply-Chain Attack Installs Spyware
Ransomware attack takes out UK Research and Innovation’s Brussels networking office
Hacked road sign talks back after driver complains to council

This kernel-linus update is based on upstream 5.10.12 and fixes atleast the following security issue: An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local

An update that fixes three vulnerabilities is now available.

£30m in contracts awarded in Post Office’s £357m ATM overhaul

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

New Red Hat Single Sign-On 7.4.5 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

New Red Hat Single Sign-On 7.4.5 packages are now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

New Red Hat Single Sign-On 7.4.5 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Countless emails wrongly blocked as spam after Cisco’s SpamCop failed to renew domain name at the weekend
Poor password security at the British branch of Mensa?

New upstream version 10.94.00. Introduced new script pamhomography.

Fixes heap use-after-free when parsing malformed file (upstream issue [2989](https://gitlab.com/mbunkus/mkvtoolnix/-/issues/2989)).

New upstream version 2.0.24 with all reported CVE fixes available.

IRQ vector leak on x86 [XSA-360]

This is probably not the update you want. Let me be clear, it does fix the security vulnerabilities in this list: CVE-2020-16044 CVE-2021-21118 CVE-2021-21119 CVE-2021-21120 CVE-2021-21121 CVE-2021-21122 CVE-2021-21123 CVE-2021-21124 CVE-2021-21125 CVE-2021-21126 CVE-2021-21127 CVE-2021-21129 CVE-2021-21130 CVE-2021-21131 CVE-2021-21132 CVE-2021-21133 CVE-2021-21134

An update that fixes 6 vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

Google QUIC-ly left privacy behind in its quest for a speedier internet, boffins find

An update that solves two vulnerabilities and has one errata is now available.

WordPress Pop-Up Builder Plugin Flaw Plagues 200K Sites
Microsoft 365 Becomes Haven for BEC Innovation

Fixes startup crash.

Update to latest upstream version.

Severe bug in Libgcrypt – used by GPG and others – is a whole heap of trouble, prompts patch scramble
Industrial Gear at Risk from Fuji Code-Execution Bugs
European Commission redacts AstraZeneca vaccine contract – but forgets to wipe the bookmarks tab
Emotet botnet disrupted in global operation

The law enforcement action is one of the most significant operations against cybercriminal enterprises ever The post Emotet botnet disrupted in global operation appeared first on WeLiveSecurity

Data Privacy Day: Top tips for safe remote learning

As schools and students continue to contend with the very real cyber-risks of virtual classrooms, we share some advice for protecting children’s data and privacy The post Data Privacy Day: Top tips for safe remote learning appeared first on WeLiveSecurity

Apple iOS 14 Thwarts iMessage Attacks With BlastDoor System
Hackers could live-stream your home through your LifeShield security camera
Lazarus Affiliate ‘ZINC’ Blamed for Campaign Against Security Researcher

The package libgcrypt before version 1.9.1-1 is vulnerable to arbitrary code execution.

The package home-assistant before version 2021.1.4-1 is vulnerable to information disclosure.

The package mutt before version 2.0.5-1 is vulnerable to denial of service.

The package libvirt before version 1:7.0.0-1 is vulnerable to arbitrary code execution.

Considering privacy in a work from home world

An update that fixes 26 vulnerabilities is now available.

BEC scammers take advantage of “Out-of-office” Microsoft 365 users

New Firefox version (85.0) with various Wayland fixes. New NSS version (3.60).

security update

security update

Rocke Group’s Malware Now Has Worm Capabilities
Utah Ponders Making Online ‘Catfishing’ a Crime
LogoKit Simplifies Office 365, SharePoint ‘Login’ Phishing Pages
Mimecast Confirms SolarWinds Hack as List of Security Vendor Victims Snowball
Emotet botnet takedown – what you need to know

An update that fixes one vulnerability is now available.

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

How do most cloud security breaches happen? Orca’s “State of Public Cloud Security” report reveals all
If you want to leg it through China’s Great Firewall, don’t forget to pull on your newly darned Shadowsocks
Smashing Security podcast #212: Dutch leaks, Peeping Toms, and researchers under fire
Apple patches three iOS zero‑days under attack

The company emits emergency updates to fix bugs affecting devices ranging from iPhones to Apple Watches The post Apple patches three iOS zero‑days under attack appeared first on WeLiveSecurity

TeamTNT Cloaks Malware With Open-Source Tool
FTC warns of scam website that promises refund for victims of online scams
NetWalker Ransomware Suspect Charged: Tor Site Seized
Update your iPhone now to protect against vulnerabilities that hackers may have actively exploited

Update to 2.53.6

Update to latest upstream version.

Remote Attackers Can Now Reach Protected Network Devices via NAT Slipstreaming
Knock, knock. Who’s there? NAT. Nat who? A NAT URL-borne killer

security update

North Korean hackers attempt to hack security researchers investigating zero-day vulnerabilities
Stack Overflow 2019 hack was guided by advice from none other than… Stack Overflow
Sudo Bug Gives Root Access to Mass Numbers of Linux Systems
ADT Security Camera Flaws Open Homes to Eavesdropping
Emotet Takedown Disrupts Vast Criminal Infrastructure; NetWalker Site Offline
Command ‘n’ control botnet of notorious Emotet Windows ransomware shut down in multinational police raid
Wormable Android malware spreads via WhatsApp messages

“Download This application and Win Mobile Phone”, reads the message attempting to trick users into downloading a fake Huawei app The post Wormable Android malware spreads via WhatsApp messages appeared first on WeLiveSecurity

Today’s ‘sophisticated cyber attack’ victim is the Woodland Trust: Pre-Xmas breach under investigation

An update that fixes 26 vulnerabilities is now available.

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Apple Patches Three Actively Exploited Zero-Days, Part of iOS Emergency Update

An update for firefox is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Multiple vulnerabilities have been found in phpMyAdmin, allowing remote attackers to conduct XSS.

Multiple vulnerabilities have been found in Telegram, the worst of which could result in information disclosure.

US cyber intelligence officer jailed for kidnapping her kid, trying to hawk top secrets to Russia in Mexico
Nvidia Squashes High-Severity Jetson DoS Flaw
DanaBot Malware Roars Back into Relevancy
Decade-old bug in Linux world’s sudo can be abused by any logged-in user to gain root privileges
Apple emits emergency iOS security updates while warning holes may have been exploited in wild by hackers

security update