Menu

Latest articles

Smashing Security podcast #327: Mark’s metaverse for minors, and getting down to business
Apple squashes kernel bug used by TriangleDB spyware
FTC accuses DNA testing company of lying about dumping samples
Beware bad passwords as attackers co-opt Linux servers into cybercrime
Passwords out, passkeys in: are you ready to make the switch?

With passkeys poised for prime time, passwords seem passé. What are the main benefits of ditching one in favor of the other? The post Passwords out, passkeys in: are you ready to make the switch? appeared first on WeLiveSecurity

Oreo maker Mondelez staff hit by data breach at third-party law firm

A heap-based buffer overflow vulnerability was found in the HTTP chunk parsing code of minidlna, a lightweight DLNA/UPnP-AV server, which may result in denial of service or the execution of arbitrary code.

Training in Spanish for cyber security pros
“The Ransomware Documentary” – brand new video series from Sophos starting now!

An update for kpatch-patch is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in pngcheck.

Several security issues were fixed in Ruby.

Ensure the security and reliability of your applications at every stage, from development to production, with Uptycs

Gregory James Duck reported that missing input validation in various functions provided by libx11, the X11 client-side library, may result in denial of service.

USN-6143-2 caused some minor regressions in Firefox.

Oreo cookie maker says crooks gobbled up staff info
Reddit confirms BlackCat gang pinched some data
100,000 hacked ChatGPT accounts up for sale on the dark web
ASUS warns router customers: Patch now, or block all inbound requests

An update for c-ares is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

Jettison could be made to crash if it opened a specially crafted file.

libxpm is a library handling X PixMap image format (so called xpm files). xpm files are an extension of the monochrome X BitMap format specified in the X protocol, and is commonly used in traditional X applications.

Over 100,000 compromised ChatGPT accounts found for sale on dark web
Data leak at major law firm sets Australia’s government and elites scrambling

Niels Dossche and Tim D’¼sterhus discovered that PHP’s implementation of the SOAP HTTP Digest authentication did not check for failures, which may result in a stack information leak. Furthermore, the code used an insufficient number of random bytes.

Update to 114.0.5735.133. Fixes the following security issues: CVE-2023-3214, CVE-2023-3215, CVE-2023-3215, CVE-2023-3217,

security update

Megaupload duo will go to prison at last, but Kim Dotcom fights on…
Guess what happened to this US agency using outdated software?

Several security issues were fixed in Jettison.

libcap could be made to crash or possibly execute arbitrary code if it received a specially crafted input.

An update for c-ares is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for texlive is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, Red Hat Enterprise Linux 8.2 Update

An update for c-ares is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

Release of Bug Advisories for the OpenShift Jenkins image and Jenkins agent base image. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Service on AWS (ROSA) IRAP Assessment kicks off
Confidential computing platform-specific details
Outsource to infill on cyber security
With dead-time dump, Microsoft revealed DDoS as cause of recent cloud outages

libX11 1.8.6 (CVE-2023-3138)

Bump to 5.8.6

Bump to 5.8.6

Security fix for CVE-2023-33461

Bump to 5.8.6

Bump to 5.8.6

security update

security update

Is a RAT stealing your files? – Week in security with Tony Anscombe

Could your Android phone be home to a remote access tool (RAT) that steals WhatsApp backups or performs other shenanigans? The post Is a RAT stealing your files? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Stop Cyberbullying Day: Prevention is everyone’s responsibility

Strategies for stopping and responding to cyberbullying require a concerted, community-wide effort involving parents, educators and children themselves The post Stop Cyberbullying Day: Prevention is everyone’s responsibility appeared first on WeLiveSecurity

GitLab Dedicated offers single-tenant, SaaS-based devsecops
Best practices for patch management

The container bci/golang was updated. The following patches have been included in this update:

update to 114.0.5735.106. Fixes the following security issue: CVE-2023-3709

Update to v1.85.2 —- Update to v1.85.1 —- Update to v1.85.0 Fixes CVE-2023-32682, CVE-2023-32683 —- Update to v1.84.1

Third MOVEit bug fixed a day after PoC exploit made public

Several security vulnerabilities have been discovered in golang-go.crypto, the supplementary Go cryptography libraries. CVE-2019-11840

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

security update

security update

LockBit suspect’s arrest sheds more light on ‘trustworthy’ gang
Android GravityRAT goes after WhatsApp backups

ESET researchers analyzed an updated version of Android GravityRAT spyware that steals WhatsApp backup files and can receive commands to delete files The post Android GravityRAT goes after WhatsApp backups appeared first on WeLiveSecurity

USN-6156-1 introduced a regression in SSSD.

An update that fixes four vulnerabilities is now available.

Capita faces first legal Letter of Claim over mega breach

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of sandbox restrictions.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

Microsoft: Russia sent its B team to wipe Ukrainian hard drives
EU boss Breton: There’s no Huawei that Chinese comms kit is safe to use in Europe
US government hit by Russia’s Clop in MOVEit mass attack
MOVEit mayhem 3: “Disable HTTP and HTTPS traffic immediately”
Chinese spies blamed for data-harvesting raids on Barracuda email gateways
S3 Ep139: Are password rules like running through rain?

The Migration Toolkit for Containers (MTC) 1.7.10 is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

New packages for Red Hat Ceph Storage 6.1 are now available on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for jenkins and jenkins-2-plugins is now available for OpenShift Developer Tools and Services for OCP 4.13. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat compliance certifications and attestations achieved

Requests could be made to expose sensitive information over the network.

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-28204

Click-jacking certificate exceptions through rendering lag (CVE-2023-34414) Memory safety bugs fixed in Thunderbird 102.12 (CVE-2023-34416) References: – https://bugs.mageia.org/show_bug.cgi?id=31996

North Korea created very phishy evil twin of Naver, South Korea’s top portal

security update

Decision to hold women-in-cyber events in abortion-banning states sparks outcry
Smashing Security podcast #326: Right Royal security threats and MOVEit mayhem

security update

security update

LockBit victims in the US alone paid over $90m in ransoms since 2020
Cyber insurance: What is it and does my company need it?

While not a ‘get out of jail free card’ for your business, cyber insurance can help insulate it from the financial impact of a cyber-incident The post Cyber insurance: What is it and does my company need it? appeared first on WeLiveSecurity

Lethal weather
Talking cybersecurity on “Learning Curve”
Capita wins £50M fraud reporting contract with City of London cops

An update for .NET 7.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for python3.11 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for nodejs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

An update for .NET 7.0 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for firefox is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.