Menu

Latest articles

Details not available at this time. (CVE-2022-48503) Memory corruption issue may lead to arbitrary code execution (CVE-2023-32435) Type confusion issue may lead to arbitrary code execution (CVE-2023-32439)

Denial of service due to integer overflow (CVE-2022-28041) References: – https://bugs.mageia.org/show_bug.cgi?id=32055 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SEQGDVH43YW7AG7TRU2CTU5TMIYP27WP/

Nickelodeon probes claims of massive data leak as SpongeBob fans rejoice
Microsoft puts out Outlook fire, says everything’s fine with Teams malware flaw

security update

security update

S3 Ep142: Putting the X in X-Ops
Free Akira ransomware decryptor released for victims who wish to recover their data without paying extortionists
What’s up with Emotet?

A brief summary of what happened with Emotet since its comeback in November 2021 The post What’s up with Emotet? appeared first on WeLiveSecurity

The rising risk of eavesdropping

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

Red Hat OpenShift Container Platform release 4.11.44 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.

Red Hat OpenShift Container Platform release 4.11.44 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.

Red Hat OpenShift Container Platform release 4.10.63 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

LockBit louts unload ransomware at Japan’s most prolific cargo port
North Korean satellite had no military utility for spying, says South Korea
Former boss who stole $10M from Amazon using fake vendor invoices is jailed for 16 years
Smashing Security podcast #329: Pornhub, Barbie dolls, and can you trust a free TV?
RAM-ramming Rowhammer is back – to uniquely fingerprint devices
Suspected bank-infecting OPERA1ER crime boss cuffed
Firefox 115 is out, says farewell to older Windows and Mac users

Django could be made to consume resources if it received specially crafted network traffic.

Several security issues were fixed in containerd.

Several security issues were fixed in Firefox.

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Singapore tells crypto operators: act like grown up financial institutions

security update

Ghostscript bug could allow rogue documents to run system commands
How Open Source Can Help Protect Your Organization Against Email Threats

Several security issues were fixed in ImageMagick.

Deepfaking it: What to know about deepfake‑driven sextortion schemes

Criminals increasingly create deepfake nudes from people’s benign public photos in order to extort money from them, the FBI warns The post Deepfaking it: What to know about deepfake‑driven sextortion schemes appeared first on WeLiveSecurity

Undiplomatic Chinese threat actor attacks embassies and foreign affairs departments

Update to 114.0.5735.198. Fixes the following security issues: CVE-2023-3420 CVE-2023-3421 CVE-2023-3422 CVE-2023-36191

Update to 2.40.3: * Make memory pressure monitor honor memory.memsw.usage_in_bytes if exists. * Include key modifiers in wheel events. * Apply cookie blocking policy to WebSocket handshakes. * Fix several crashes and rendering issues. * Security fixes: CVE-2023-32439

croc 9.6.4

croc 9.6.4

**Changelog** “` * Sun Jun 25 2023 Didik Supriadi – 2.5.1-3 – Build with ivy instead of maven “`

You’ve patched right? ‘340K+ Fortinet firewalls’ wide open to critical security bug
TSA wants to expand facial recognition to hundreds of airports within next decade
Dublin Airport staff pay details stolen by hackers after MOVEit attack at third-party provider Aon
WordPress plugin lets users become admins – Patch early, patch often!
Dublin Airport staff pay data ‘compromised’ by criminals

GNU Screen could be made to crash applications if it received specially crafted input.

OpenLDAP could be made to crash if it received specially crafted input.

ReportLab could be made to crash or run programs as your login if it opened a specially crafted file.

Verizon 2023 DBIR: What’s new this year and top takeaways for SMBs

Here are some of the key insights on the evolving data breach landscape as revealed by Verizon’s analysis of more than 16,000 incidents The post Verizon 2023 DBIR: What’s new this year and top takeaways for SMBs appeared first on WeLiveSecurity

The container suse-sles-15-sp4-chost-byos-v20230606-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

US authorities warn on China’s new counter-espionage law

Several security issues were fixed in Vim.

Japan rebukes Fujitsu for cloud security fails

Update to 114.0.5735.198. Fixes the following security issues: CVE-2023-3420 CVE-2023-3421 CVE-2023-3422 CVE-2023-36191

A memory leak has been found in yajl, a JSON parser / small validating JSON generator written in ANSI C, which might allow an attacker to cause an out of memory situation and potentially causing a crash.

Multiple multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

security update

security update

security update

An issue has been found in cups, the Common UNIX Printing System(tm). Due to a use-after-free bug an attacker could cause a denial-of-service. In case of having access to the log files, an attacker could also

The good, the bad and the ugly of AI – Week in security with Tony Anscombe

The growing use of synthetic media and difficulties in distinguishing between real and fake content raises a slew of legal and ethical questions The post The good, the bad and the ugly of AI – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Update to 2.40.3: * Make memory pressure monitor honor memory.memsw.usage_in_bytes if exists. * Include key modifiers in wheel events. * Apply cookie blocking policy to WebSocket handshakes. * Fix several crashes and rendering issues. * Security fixes: CVE-2023-32439

– Rebased to the latest upstream sources (see CHANGELOG.md) – Updated pcs-web-ui – Removed dependency fedora-logos – favicon is now correctly provided by pcs- web-ui – Resolves: rhbz#2109852 rhbz#2170648

Patch update to Kubernetes 1.25 for Fedora 37. Primarily a security fix for CVE-2023-2431: Bypass of seccomp profile enforcement.

– Rebased to the latest upstream sources (see CHANGELOG.md) – Updated pcs-web-ui – Removed dependency fedora-logos – favicon is now correctly provided by pcs- web-ui – Resolves: rhbz#2109852 rhbz#2170648

Us, hacked by LockBit? No, says TSMC, that would be our IT supplier

Several vulnerabilities were fixed in the Python3 interpreter. CVE-2015-20107

security update

Cops told: Er, no, you need a wiretap order if you want real-time Facebook snooping

Al Viro found a buffer overflow in Window Maker 0.80.0 and earlier which may allow remote attackers to execute arbitrary code via a certain image file that is not properly handled when Window Maker uses width and height information to allocate a buffer.

Updated mICQ packages are available for Red Hat Linux versions 7.2 and 7.3 that fix a remote crash.

Updated zlib packages are now available which fix a buffer overflow vulnerability.

Versions of man before 1.51 have a bug where a malformed man file can cause a program named “unsafe” to be run.

Employee monitoring: is ‘bossware’ right for your company?

While employee monitoring software may boost productivity, it may also be a potential privacy minefield and it can affect your relationship with your employees The post Employee monitoring: is ‘bossware’ right for your company? appeared first on WeLiveSecurity

Over 1500 gas stations disrupted in Canada, after energy giant hacked

open-vm-tools: authentication bypass vulnerability in the vgauth module (CVE-2023-20867) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * [ESXi] [SL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file ‘quiesce_manifest.xml’ * [ESX [More…]

An update that fixes one vulnerability is now available.

Life long cyber security learning
Quirky QWERTY killed a password in Paris
Fujitsu admits it fluffed the fix for Japan’s flaky ID card scheme
Crook who stole $23m+ in YouTube song royalties gets five years behind bars

security update

It’s 2023 and memory overwrite bugs are not just a thing, they’re still number one
Avoid juice jacking and recharge your batteries safely this summer

Cybercriminals can use USB charging stations in airports, hotels, malls or other public spaces as conduits for malware The post Avoid juice jacking and recharge your batteries safely this summer appeared first on WeLiveSecurity

School’s out for summer, but it’s not time to let your cyber guard down

The beginning of the summer break is the perfect time for parents to remind their children about the importance of safe online habits The post School’s out for summer, but it’s not time to let your cyber guard down appeared first on WeLiveSecurity

Chinese balloon that US shot down was ‘crammed’ with American hardware
S3 Ep141: What was Steve Jobs’s first job?

A flaw was found in the ‘/v2/_catalog’ endpoint in ‘distribution/distribution’, which accepts a parameter to control the maximum number of records returned (query string: ‘n’). This vulnerability allows a malicious user to

An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for go-toolset-1.19 and go-toolset-1.19-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

Now Apple takes a bite out of encryption-bypassing ‘spy clause’ in UK internet law
Smashing Security podcast #328: UPS smishing, ChatGPT 101, and storing secret files
Network security guy in extradition tug of war between US and Russia

security update

Interested in $10,000,000? Ready to turn in the Clop ransomware crew?