Menu

Latest articles

Bringing security to account: why identity must be unified
Florida man insists he didn’t violate the law by keeping Top Secret docs

security update

Patch Tuesday fixes 4 critical RCE bugs, and a bunch of Office holes
June Patch Tuesday: VMware vuln under attack by Chinese spies, Microsoft kinda meh
Last of the Gozi 3 sentenced over Windows info-stealing malware ops
Gozi banking malware “IT chief” finally jailed after more than 10 years
The commonality of criminal intrusion
These Microsoft Office security signatures are ‘practically worthless’
As MOVEit hackers’ deadline approaches, Ofcom reveals it is amongst victims
Malicious hackers are weaponizing generative AI
Russia-Ukraine war sending shockwaves into cyber-ecosystem

The container bci/bci-init was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

US charges two men with Mt. Gox heist, the world’s largest cryptocurrency hack
UK telco watchdog Ofcom, Minnesota Dept of Ed named as latest MOVEit victims
China’s cyber now aimed at infrastructure, warns CISA boss
India probes medical info ‘leak’ to Telegram
Unsealed: Charges against Russians blamed for Mt Gox crypto-exchange collapse
Fortinet squashes hijack-my-VPN bug in FortiOS gear

security update

Posing as journalists, Pink Drainer pilfers $3.3M in crypto
Surprise! Staff don’t like receiving phishing tests from their firms that pose as salary increases
Microsoft stole our stolen dark web data, says security outfit
History revisited: US DOJ unseals Mt. Gox cybercrime charges

SSSD could allow unintended access to network services.

Requests could be made to expose sensitive information over the network.

Lantum S3 bucket leak is prescription for chaos for thousands of UK doctors

Several security issues were fixed in Vim.

Hold it – more vulnerabilities found in MOVEit file transfer software

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

The container sles-15-sp4-chost-byos-v20230606-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230606-x86_64-gen2 was updated. The following patches have been included in this update:

Introduction to confidential virtual machines
Confidential containers on Azure with OpenShift: setup guide

update to 114.0.5735.106. Fixes the following security issue: CVE-2023-3709

Update to 102.12.0 ; https://www.thunderbird.net/en- US/thunderbird/102.12.0/releasenotes/ ; https://www.thunderbird.net/en- US/thunderbird/102.11.2/releasenotes/ ; https://www.thunderbird.net/en- US/thunderbird/102.11.1/releasenotes/ ; https://www.thunderbird.net/en- US/thunderbird/102.11.0/releasenotes/

Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72

Update to 1.14.8

Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72

Security fix for CVE-2022-39335

An update that fixes 14 vulnerabilities is now available.

python: urllib.parse url blocklisting bypass (CVE-2023-24329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 python3-3.6.8-19.el7_9.x86_64.rpm python3-debuginfo-3.6.8-19.el7_9.i686.rpm python3-debuginfo-3.6.8-19.el7_9.x86_64.rpm python3-libs-3.6.8-19.el7_9.i686.rpm [More…]

python: urllib.parse url blocklisting bypass (CVE-2023-24329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 python-2.7.5-93.el7_9.x86_64.rpm python-debuginfo-2.7.5-93.el7_9.i686.rpm python-debuginfo-2.7.5-93.el7_9.x86_64.rpm python-libs-2.7.5-93.el7_9.i686.rpm [More…]

Mixing cybercrime and cyberespionage – Week in security with Tony Anscombe

A crimeware group that usually targets individuals and SMBs in North America and Europe adds cyberespionage to its activities The post Mixing cybercrime and cyberespionage – Week in security with Tony Anscombe appeared first on WeLiveSecurity

**MariaDB 10.5.20** Release notes: https://mariadb.com/kb/en/mariadb-10-5-20-release-notes/

An update for openshift-gitops-kam is now available for Red Hat OpenShift GitOps 1.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Online muggers make serious moves on unpatched Microsoft bugs
More MOVEit mitigations: new patches published for further protection

Sebastian Krause discovered that manipulated inline images can force PyPDF2, a pure Python PDF library, into an infinite loop, if a maliciously crafted PDF file is processed.

FBI: FISA Section 702 ‘absolutely critical’ to spy on, err, protect Americans

New packages of am-utils are available for all Red Hat Linux platforms. This version includes an important security fix for a buffer overrun problem which is being actively exploited on the Internet.

Ransomware scum hit Japanese pharma giant Eisai Group
Thoughts on scheduled password changes (don’t call them rotations!)
Asylum Ambuscade: crimeware or cyberespionage?

A curious case of a threat actor at the border between crimeware and cyberespionage The post Asylum Ambuscade: crimeware or cyberespionage? appeared first on WeLiveSecurity

Seven steps for using zero trust to protect your multicloud estate
Barracuda: Immediately rip out and replace our security hardware

An update for python is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for python3 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Brit data watchdog fines sleazy sales ops £250K for ‘bombarding’ folk with calls

A couple of security issues were discovered in ruby2.5, the Ruby interpreter, and are as follows – CVE-2021-33621

It was discovered that jupyter-core, the core common functionality for Jupyter projects, could execute arbitrary code in the current working directory while loading configuration files.

The container bci/python was updated. The following patches have been included in this update:

Darkweb credit card marts in decline across Asia, researchers claim
Google changes email authentication after spoof shows a bad delivery for UPS
Robot can rip the data out of RAM chips with chilling technology

security update

North Korea’s Lazarus Group linked to Atomic Wallet heist
Barracuda tells its ESG owners to ‘immediately’ junk buggy kit

security update

security update

Firefox 114 is out: No 0-days, but one fascinating “teachable moment” bug
Hear no evil: Ultrasound attacks on voice assistants

How  your voice assistant could do the bidding of a hacker – without you ever hearing a thing The post Hear no evil: Ultrasound attacks on voice assistants appeared first on WeLiveSecurity

S3 Ep138: I like to MOVEit, MOVEit
Malware menaces Minecraft mods
Google puts $1M behind its promise to detect cryptomining malware
New York City latest to sue Hyundai and Kia claiming their cars are too easy to steal

An update for python is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

On the frontline of cyber threats
Securing D-Bus based connections with mTLS and double proxy

Several security issues were fixed in Netatalk.

Microsoft says share the wealth with cyber-info for business
Helping Windows 11 fight the hackers
7 key features for Kubernetes and container security
UK government to set deadline for removal of Chinese surveillance cams

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Update to 1.14.8

– fix more POST-after-PUT confusion (CVE-2023-28322) – fix IDN wildcard match (CVE-2023-28321)

Security fix for CVE-2023-24329

Deepfakes being used in ‘sextortion’ scams, FBI warns
Clop ransomware crew sets June extortion deadline for MOVEit victims
Microsoft cops $20M slap on the wrist for mishandling kids’ Xbox data
7 tips for spotting a fake mobile app

Plus, 7 ways to tell that you downloaded a sketchy app and 7 tips for staying safe from mobile security threats in the future The post 7 tips for spotting a fake mobile app appeared first on WeLiveSecurity

emacs: command injection vulnerability in htmlfontify.el (CVE-2022-48339) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 emacs-24.3-23.el7_9.1.x86_64.rpm emacs-common-24.3-23.el7_9.1.x86_64.rpm emacs-debuginfo-24.3-23.el7_9.1.x86_64.rpm emacs-nox-24.3-23.el7_9.1.x8 [More…]

10 years after Snowden’s first leak, what have we learned?
Cl0p gang tells MOVEit hack victims to contact it before June 14, or else…