Menu

Latest articles

Several security issues were fixed in Open-iSCSI.

Several security issues were fixed in the Linux kernel.

Weakness risk-patterns: A Red Hat way to identify poor software practices in the secure development lifecycle
Red Hat’s CWE journey

Several security issues were fixed in X.Org X Server.

Several security issues were fixed in LLVM Toolchain.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Crooks pwned your servers? You’ve got four days to tell us, SEC tells public companies
Smashing Security podcast #332: Nudes leak at the plastic surgery, Mali mail mix-up, and WormGPT

security update

Russia throws founder of infosec biz Group-IB in the clink for treason
Following claims by two ransomware groups, Yamaha confirms cyberattack
New Realst Mac malware, disguised as blockchain games, steals cryptocurrency wallets

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

Ambulance patient records system hauled offline for cyber-attack probe
Sneaky Python package security fixes help no one – except miscreants
Ivanti plugs critical bug – but not before it was used against Norwegian government
Zenbleed: How the quest for CPU performance could put your passwords at risk
Apple patches exploited bugs in iPhones plus other holes

Avahi could be made to crash if it received specially crafted DBus traffic.

Django could be made to consume resources if it received specially crafted network traffic.

Unlocking the Secrets of Linux Security: An Expert Analysis

Several security issues were fixed in Graphite-Web.

Sam Wheating discovered that python-git, a Python library to interact with Git repositories, is vulnerable to shell injection due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command.

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

How to write a killer pentest report
TETRA radio comms used by emergency heroes easily cracked, say experts
Apple ships that recent “Rapid Response” spyware patch to everyone, fixes a second zero-day
AMD Zenbleed chip bug leaks secrets fast and easy
Google blocks staff’s internet access to reduce attacks – but will it work?

Update to latest upstream version, see following page for changes: https://www.mozilla.org/en-US/thunderbird/38.1.0/releasenotes/ This update also should fixed problems with thunderbird-lightning-gdata package. Rebase to Thunderbird 38. By this release thunderbird-lightning (calendar) package has become obsolete, because it is a part of Thunderbird 38 package now. For changes see: https://www.mozilla.org/en-US/thunderbird/38.0.1/releasenotes/ [More…]

Update to latest upstream version, see following page for changes: https://www.mozilla.org/en-US/thunderbird/38.1.0/releasenotes/ This update also should fixed problems with thunderbird-lightning-gdata package. Rebase to Thunderbird 38. By this release thunderbird-lightning (calendar) package has become obsolete, because it is a part of Thunderbird 38 package now. For changes see: https://www.mozilla.org/en-US/thunderbird/38.0.1/releasenotes/ [More…]

Hacking police radios: 30-year-old crypto flaws in the spotlight

OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049) * OpenJDK: array indexing integer overflow issue (8304468) (CVE-2023-22045) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Prepare for the next quarterly OpenJDK upstream releas [More…]

OpenJDK: ZIP file parsing infinite loop (8302483) (CVE-2023-22036) * OpenJDK: weakness in AES implementation (8308682) (CVE-2023-22041) * OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049) * harfbuzz: OpenJDK: O(n^2) growth via consecutive marks (CVE-2023-25193) * OpenJDK: HTTP client insufficient file name validation (8302475) (CVE-2023-220 [More…]

A new hope for software security
Google half-patches Cloud Build permissions exploit, the rest is on you

This update provides the upstream 7.0.10 maintenance release that fixes at least the following security vulnerabilities: Vulnerability in the Oracle VM VirtualBox prior to 7.0.10 contains an easily exploitable vulnerability that allows high privileged attacker

security update

Security fix for CVE-2023-38408

The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

fix for CVE-2023-36664 (rhbz#2217805)

What happens if AI is wrong? – Week in security with Tony Anscombe

Responses generated by ChatGPT about individual people could be misleading or harmful or spill their personal information. What are the takeaways for you as a ChatGPT user?

8 common work-from-home scams to avoid

That ‘employer’ you’re speaking to may in reality be after your personal information, your money or your help with their illegal activities

Confidential containers with AMD SEV

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-37450

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

Stolen Microsoft key may have opened up a lot more than US govt email inboxes
VirusTotal: We’re sorry someone fat-fingered and exposed 5,600 users

Updated images that fix several bugs are now available for Red Hat OpenShift Data Foundation 4.10.14 on Red Hat Enterprise Linux 8 from Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact

Lawyer sees almost 1,000 complainants sign up to Capita breach class action

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/php was updated. The following patches have been included in this update:

The container bci/php-fpm was updated. The following patches have been included in this update:

MOVEit body count closes in on 400 orgs, 20M+ individuals
RIP Kevin Mitnick: Former most-wanted hacker dies at 59
Child identity theft: how do I keep my kids’ personal data safe?

Why is kids’ personal information in high demand, how do criminals steal it, and what can parents do to help prevent child identity theft? The post Child identity theft: how do I keep my kids’ personal data safe? appeared first on WeLiveSecurity

Estée Lauder – internal data stolen after being hit by two separate ransomware attacks
S3 Ep144: When threat hunting goes down a rabbit hole

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for OpenJDK. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for java-17-openjdk is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update is now available for OpenJDK. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Under CISA pressure collaboration, Microsoft makes cloud security logs available for free
Tech support scammers trick victims into old-school offline money transfer
Ukraine busts bot farm spreading Russian infowar propaganda and fraud

security update

Smashing Security podcast #331: Boris Johnson’s WhatsApps, and sextorting party girls
Tech support scammers go analog, ask victims to mail bundles of cash
JFrog Curation blocks malicious open source software packages

Several security issues were fixed in curl.

Several security issues were fixed in ConnMan.

It was discovered that there was a potential denial of service attack in Django, the popular Python-based web development framework. EmailValidator and URLValidator were subject to potential regular

Building security certifications into your image builder blueprint
INTERSECT ’23: Network Security Summit unveils cutting-edge strategies to safeguard digital assets

It was discovered that there was a potential denial of service (DoS) in bind9, the popular Domain Name Server (DNS) server. Shoham Danino, Anat Bremler-Barr, Yehuda Afek and Yuval Shavitt

Red Hat OpenShift Container Platform release 4.11.45 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.

VolSync v0.7.3 enhancements and security fixes Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

US adds Euro spyware makers to export naughty list
Google Virus Total leaks list of spooky email addresses

security update

Microsoft hit by Storm season – a tale of two semi-zero days