Menu

Latest articles

10 years after Snowden’s first leak, what have we learned?
Cl0p gang tells MOVEit hack victims to contact it before June 14, or else…

Several security issues were fixed in libxml2.

Red Hat OpenShift Container Platform release 4.10.61 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

Red Hat OpenShift Container Platform release 4.10.61 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

An update for python-flask is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in LibreOffice.

security update

Police use of PayPal records under fire after raid on ‘Cop City’ protest fund trio
Malwarebytes may not be allowed to label rival’s app as ‘potentially unwanted’
US govt now bans TikTok from contractors’ work gear
Crypto catastrophe strikes some Atomic Wallet users, over $35M thought stolen
Identity thieves can hunt us for ‘rest of our lives,’ claims suit after university data leak
Chrome zero-day: “This exploit is in the wild”, so check your version now

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

An update for curl is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

Academics, media, and think tanks warned of North Korean hacking campaign
Taking the art of email security to the next level
British Airways, Boots, BBC payroll data stolen in MOVEit supply-chain attack
MOVEit zero-day exploit used by data breach gangs: The how, the why, and what to do…
BBC staffers warned of payroll data breach. Other firms also affected by MOVEit vulnerability
Hate speech is driving advertisers away from Twitter
Qbot malware adapts to live another day … and another …

Perl could be made to install modules from untrusted sources.

Confidential computing: From root of trust to actual trust
Australian cyber-op attacked ISIL with the terrifying power of Rickrolling
Toyota admits to yet another cloud leak
Meet TeamT5, the Taiwanese infosec outfit taking on Beijing and defeating its smears

security update

Two vulnerabilities were fixed in GNU cpio, a program to manage archives of files. CVE-2019-14866

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

Latest MariaDB minor maintenance release 10.3.39 included a fix for the following security vulnerability: CVE-2022-47015

Rebase to upstream version 3.0.9

API security in the spotlight – Week in security with Tony Anscombe

Given the reliance of today’s digital world on APIs and the fact that attacks targeting them continue to rise sharply, API security cannot be an afterthought. The post API security in the spotlight – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Alvaro Mu’±oz from the GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert, a tool and library used to convert notebooks to various other formats via Jinja templates.

Red Hat OpenShift Container Platform release 4.13.1 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.13.

Updated images are now available for Red Hat Advanced Cluster Security for Kubernetes (RHACS). The updated image includes security fixes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.13.1 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.13.

Red Hat OpenShift Container Platform release 4.11.42 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.

Red Hat OpenShift Container Platform release 4.13.1 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.13.

Uncle Sam wants DEF CON hackers to pwn this Moonlighter satellite in space
Malaysia goes its own Huawei, won’t ban Chinese vendor from 5G network
All eyes on APIs: Top 3 API security risks and how to mitigate them

As APIs are a favorite target for threat actors, the challenge of securing the glue that holds various software elements together is taking on increasing urgency The post All eyes on APIs: Top 3 API security risks and how to mitigate them appeared first on WeLiveSecurity

Researchers claim Windows “backdoor” affects hundreds of Gigabyte motherboards

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

This malicious PyPI package mixed source and compiled code to dodge detection
You might have been phished by the gang that stole North Korea’s lousy rocket tech
Millions of Gigabyte PC motherboards backdoored? What’s the actual score?
Deployed publicly accessible MOVEit Transfer? Oh no. Mass exploitation underway
Kremlin claims Apple helped NSA spy on diplomats via iPhone backdoor

security update

Serious Security: That KeePass “master password crack”, and what we can learn from it
5 free OSINT tools for social media

A roundup of some of the handiest tools for the collection and analysis of publicly available data from Twitter, Facebook and other social media platforms The post 5 free OSINT tools for social media appeared first on WeLiveSecurity

Tricks of the trade: How a cybercrime ring operated a multi‑level fraud scheme

A peek under the hood of a cybercrime operation and what you can do to avoid being an easy target for similar ploys The post Tricks of the trade: How a cybercrime ring operated a multi‑level fraud scheme appeared first on WeLiveSecurity

Decade-old critical vulnerability in Jetpack patched on millions of WordPress websites
S3 Ep137: 16th century crypto skullduggery
The downside of frenemies
SAS Airlines hit by $3 million ransom demand following DDoS attacks

CUPS could be made to crash or run programs if it received specially crafted network traffic.

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Amazon Ring, Alexa accused of every nightmare IoT security fail you can imagine
Ukraine war blurs lines between cyber-crims and state-sponsored attackers

Update to version 24.1.

Security fix for CVE-2023-0341: update to 0.12.6 (close RHBZ#2162811)

include latest dbx update (may 9th, black lotus edition). —- drop ASSERT from NestedInterruptTplLib (rhbz#2183336).

Dark Pink cyber-spies add info stealers to their arsenal, notch up more victims

Updated images are now available for Red Hat Advanced Cluster Security (RHACS). The updated image includes security and bug fixes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Feds, you’ll need a warrant for that cellphone border search
Smashing Security podcast #324: .ZIP domains, AI lies, and did social media inflame a riot?
Barracuda Email Security Gateways bitten by data thieves
Hacking forum hacked, user database leaked online
Criminals spent 10 days in US dental insurer’s systems extracting data of 9 million
XFS bug in Linux kernel 6.3.3 coincides with SGI code comeback
When the popular safeguarding tool is anything but

Several security issues were fixed in libvirt.

Linux Container Security Primer
Thinking straight in the SoC: How AI erases cognitive bias
Venezuela pays people to tweet state propaganda and deepfake videos

The container bci/python was updated. The following patches have been included in this update:

The container bci/php-apache was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container suse/registry was updated. The following patches have been included in this update:

Hacked DJ’s Twitter account costs cryptocurrency investors $170,000

security update

1. This crypto-coin is called Jimbo. 2. $8m was stolen from its devs in flash loan attack
90+ orgs tell Slack to stop slacking when it comes to full encryption
Pegasus-pusher NSO gets new owner keen on the commercial spyware biz