Menu

Latest articles

T-Mobile US exposes some customer data – but don’t call it a breach
ESET’s cutting-edge threat research at LABScon – Week in security with Tony Anscombe

Two ESET malware researchers took to the LABScon stage this year to deconstruct sophisticated attacks conducted by two well-known APT groups

security update

Accelerated Encryption with 4th Gen Intel® Xeon® Scalable Processors
Apple squashes security bugs after iPhone flaws exploited by Predator spyware
ESA gets the job of building Europe’s secure satcomms network
US govt IT help desk techie ‘leaked top secrets’ to foreign nation

security update

TransUnion reckons big dump of stolen customer data came from someone else
Snatch ransomware – what you need to know
Cisco spends $28B on data cruncher Splunk in cybersecurity push
Donald Trump Jr’s hacked Twitter account announces his father has died
Smashing Security podcast #340: Heated seats, car privacy, and Graham’s porn video
Menacing marketeers fined by ICO for 1.9M cold calls
India’s biggest tech centers named as cyber crime hotspots
Data breach reveals distressing info: People who order pineapple on pizza
Feds raise alarm over Snatch ransomware as extortion crew brags of Veterans Affairs hit
Signal adopts new alphabet jumble to protect chats from quantum computers
International Criminal Court hit in cyber-attack amid Russia war crimes probe
Pot calls the kettle hack as China claims Uncle Sam did digital sneak peek first
Robocall scammers sentenced in US after netting $1.2M via India-based call centers
Sysadmin and spouse admit to part in ‘massive’ pirated Avaya licenses scam
Broaden your cyber security knowhow at CyberThreat 2023
What a mess! Clorox warns of “material impact” to its financial results following cyberattack
The Expel Quarterly Threat Report distills the threats and trends the Expel SOC saw in Q2. Download it now.
Marvell disputes claim Cavium backdoored chips for Uncle Sam

security update

security update

security update

security update

Yikes! My sex video has been uploaded to YouPorn, apparently
Russian allegedly smuggled US weapons electronics to Moscow

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container suse/helm was updated. The following patches have been included in this update:

The Clorox Company admits cyberattack causing ‘widescale disruption’
Australia to build six ‘cyber shields’ to defend its shores
Thousands of Juniper Junos firewalls still open to hijacks, exploit code available to all
Former CIO accuses Penn State of faking cybersecurity compliance
Microsoft worker accidentally exposes 38TB of sensitive data in GitHub blunder
California passes bill to set up one-stop data deletion shop

A buffer overflow in parsing WebP images may result in the execution of arbitrary code. For Debian 10 buster, this problem has been fixed in version

Cryptojackers spread their nets to capture more than just EC2

An update for busybox is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

What ChatGPT doesn’t say about Kubernetes in production

The container sles-15-sp5-chost-byos-v20230915-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp5-chost-byos-v20230915-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

Update matrix-synapse to v1.80.0 to fix CVE-2022-39374, CVE-2023-32323

Update matrix-synapse to v1.80.0 to fix CVE-2022-39374, CVE-2023-32323

security update

A buffer overflow in parsing WebP images may result in the execution of arbitrary code. For Debian 10 buster, this problem has been fixed in version

A vulnerability has been discovered in Requests which could result in the disclosure of plaintext secrets.

Multiple vulnerabilities have been discovered in Binwalk, the worst of which could result in remote code execution.

Multiple vulnerabilities have been discovered in Samba, the worst of which could result in root remote code execution.

An arbitrary file overwrite vulnerability has been discovered in RAR and UnRAR, potentially resulting in arbitrary code execution.

Multiple vulnerabilities have been discovered in GPL Ghostscript, the worst of which could result in remote code execution.

Probe reveals previously secret Israeli spyware that infects targets via ads

A buffer overflow in parsing WebP images may result in the execution of arbitrary code. For Debian 10 buster, this problem has been fixed in version

The container bci/dotnet-aspnet was updated. The following patches have been included in this update:

Backport fix for CVE-2023-4863.

**Redis 7.0.13** Released Wed 06 Sep 2023 15:00:00 IDT Upgrade urgency SECURITY: See security fixes below. Security Fixes * (**CVE-2023-41053**) Redis does not correctly identify keys accessed by SORT_RO and as a result may grant users executing this command access to keys that are not explicitly authorized by the ACL configuration. Bug Fixes * Cluster: […]

Security fix for CVE-2020-22219

– fix HTTP headers eat all memory (CVE-2023-38039)

Scattered Spider traps 100+ victims in its web as it moves into ransomware
Google throws California $93M to make location tracking lawsuit disappear
Ballistic Bobcat’s Sponsor backdoor – Week in security with Tony Anscombe

Ballistic Bobcat is a suspected Iran-aligned cyberespionage group that targets organizations in various industry verticals, as well as human rights activists and journalists, mainly in Israel, the Middle East, and the United States

Car companies are collecting data on your sex life, and apparently you’re fine with that

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

atftp could be made to crash if it received specially crafted network traffic.

An update that fixes one vulnerability is now available.

Greater Manchester Police ransomware attack another classic demo of supply chain challenges

A vulnerability has been identified in c-ares, an asynchronous name resolver library: CVE-2020-22217:

– Updated to latest upstream (117.0.1)

US-Canada water org confirms ‘cybersecurity incident’ after ransomware crew threatens leak

security update

security update

Caesars says cyber-crooks stole customer data as MGM casino outage drags on
Read it right! How to spot scams on Reddit

Do you know what types of scams and other fakery you should look out for when using a platform that once billed itself as “the front page of the Internet”?

BLASTPASS: Government agencies told to secure iPhones against spyware attacks
Greater Manchester Police latest force to suffer serious data breach
Rollbar might be good at tracking bugs, uninvited guests not so much
Automation is key to effective and efficient pentest reporting

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container rancher/seedimage-builder was updated. The following patches have been included in this update:

The container rancher/elemental-operator was updated. The following patches have been included in this update:

Smashing Security podcast #339: Bitcoin boo-boo, deepfakes for good, and time to say goodbye to usernames?
JFrog adds ML model management to devsecops platform