Menu

Latest articles

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

An update that fixes one vulnerability is now available.

Centralized cloud security is now a must-have

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/389-ds was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update:

Add ‘writing malware’ to the list of things generative AI is not very good at doing
Don’t just patch your Citrix gear, check for intrusion: Two bugs exploited in wild

security update

LinkedIn under attack, hackers seize accounts
S3 Ep148: Remembering crypto heroes

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

FBI warns cryptocurrency app beta-testers of malware menace
Smashing Security podcast #335: AI chat wars, and hacker passwords exposed
Man arrested in Northern Ireland police data leak as more incidents come to light
Japan’s digital minister surrenders salary to say sorry for data leaks
Vietnam admits it has just ten percent of the infosec pros it needs
Discord.io pulls the cord after crooks steal 760K users’ info
FBI warns about scams that lure you in as a mobile beta-tester

Red Hat OpenShift Virtualization release 4.13.3 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

OpenStack Heat could be made to expose sensitive information.

Ceph could be made to run programs as an administrator.

LockBit’s dirty little secret: ransomware gang is failing to publish victims’ data

GStreamer could be made to denial of service if it received a specially crafted datetime string.

Two vunerabilities were discovered in openssl, a Secure Sockets Layer toolkit: CVE-2023-3446, CVE-2023-3817

Clorox cleans up IT security breach that soaked its biz ops

security update

Cumbria Police accidentally publish officers’ names and salaries online
Ensure data security at the edge
You’re not seeing double – yet another UK copshop is confessing to a data leak
Tech CEO admits role in tricking Qualcomm into $150M takeover
Florida Man and associates indicted for conspiracy to steal data, software

An update for rust-toolset-1.66-rust is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Chinese media teases imminent exposé of seismic US spying scheme
Sextortion suspects on trial after teen victim dies from a self-inflicted gunshot wound
“Grab hold and give it a wiggle” – ATM card skimming is still a thing
Beware cool-looking beta crypto-apps. They may be money-stealing fakes
Ford SYNC 3 infotainment vulnerable to drive-by Wi-Fi hijacking

An update for the rust-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for .NET 7.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Multicluster Engine for Kubernetes 2.2.7 General Availability release images, which provide security updates and fix bugs. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score,

Preventing Linux DDoS Attacks with Minimal Cybersecurity Knowledge
Crimeware server used by NetWalker ransomware seized and shut down
How to hack casino card-shuffling machines

Two vulnerabilities have been fixed in poppler, a PDF rendering library. CVE-2020-36023

Pygments could be made to hang if it opened a specially crafted file.

Cumbrian cops accidentally publish all of its officers’ details online

Several security issues were patched in the Go yaml package.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Hacktivists attack Japanese government over Fukushima wastewater release
US government to investigate China’s Microsoft email breach

PyPDF2 could be made to crash if it opened a specially crafted file.

security update

Persistent volume support with peer-pods: Solution overview

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

security update

Multiple vulnerabilities were discovered in the RealMedia demuxers for the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Google Chrome to shield encryption keys from promised quantum computers

The container trento/trento-web was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

FTX crypto-clown Sam Bankman-Fried couldn’t even do house arrest. Now he’s in jail
Microsoft: Codesys PLC bugs could be exploited to ‘shut down power plants’
Maker of Chrome extension with 300,000+ users tells of constant pressure to sell out
Electoral Commission had internet-facing server with unpatched vuln
Magento shopping cart attack targets critical vulnerability revealed in early 2022

Ubuntu security team noted after extensive testing that DLA-3495-1 was incomplete as one PoC for CVE-2022-2400 (particularly the chroot escape) was still working on the patched version of the package.

CVE-2022-40982 Daniel Moghimi discovered Gather Data Sampling (GDS), a hardware vulnerability for Intel CPUs which allows unprivileged speculative

This update ships updated CPU microcode for some types of Intel CPUs and provides mitigations for security vulnerabilities. CVE-2022-40982

Privacy-invading LetMeSpy stalkerware announces it is shutting down after hack

The container bci/php-fpm was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

US Cyber Command boss says China’s spooky cyber skills still behind
There’s a good chance your VPN is vulnerable to privacy-menacing TunnelCrack attack
10,000 N Ireland police officers and staff have their details exposed after spreadsheet screw-up
S3 Ep147: What if you type in your password during a meeting?

An update is now available for Red Hat Ansible Automation Platform 2.3 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Rhysida ransomware – what you need to know
The State of Edge Security Report
Hardening SSH connections to managed hosts with Red Hat Ansible Automation Platform

Velocity Engine could be made to run arbitrary code if it opened a specially crafted file.