Menu

Latest articles

Fighting the five

An update for git is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for git is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for git is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for git is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Diligent developer courageously lied about exec’s NSFW printouts – and survived long enough to quit with dignity

It was discovered that missing input sanitising in cups-filters, when using the Backend Error Handler (beh) backend to create an accessible network printer, may result in the execution of arbitrary commands.

Potential NULL dereference during rekeying with algorithm guessing. (CVE-2023-1667) Authorization bypass in pki_verify_data_signature. (CVE-2023-2283 References:

ReDoS (Regular Expression Denial of Service) (CVE-2023-30608) References: – https://bugs.mageia.org/show_bug.cgi?id=31913 – https://ubuntu.com/security/notices/USN-6064-1

An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c. (CVE-2023-2004) References: – https://bugs.mageia.org/show_bug.cgi?id=31887

cmark incorrectly handled certain inputs. Fixes quadratic complexity in handle_close_bracket “![[]()” which may lead to a denial of service (CVE-2023-22486). Noting that this also fixes a quadratic parsing issue with repeated

Dmidecode allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. (CVE-2023-30630) References:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The real cost of a free lunch – Week in security with Tony Anscombe

Don’t download software from non-reputable websites and sketchy links – you might be in for more than you bargained for The post The real cost of a free lunch – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Max Chernoff discovered that improperly secured shell-escape in LuaTeX may result in arbitrary shell command execution, even with shell escape disabled, if specially crafted tex files are processed.

The newest upstream commit Security fix for CVE-2023-2426

security update

Teen in court after ‘$600K swiped from DraftKings gamblers’

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Russian IT guy sent to labor camp for DDoSing Kremlin websites
5 useful search engines for internet‑connected devices and services

A roundup of some of the handiest tools that security professionals can use to search for and monitor devices that are accessible from the internet The post 5 useful search engines for internet‑connected devices and services appeared first on WeLiveSecurity

Take action now to avoid BianLian ransomware attacks, US Government warns organisations
Confidential computing use cases
UK’s GDPR replacement could wipe out oversight of live facial recognition

This kernel-linus update is based on upstream 5.15.110 and fixes atleast the following security issues: A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.

Apple warns of three WebKit vulns under active exploitation, dozens more CVEs across its range

fix clone-in-kitty + security fix rhbz#2196803

Upgrade to 1.2.11

Backport fix for CVE-2023-1729.

– Update yubibomb to version 0.2.12. – Update ybaas to version 0.0.16.

– Update yubibomb to version 0.2.12. – Update ybaas to version 0.0.16.

Apple’s secret is out: 3 zero-days fixed, so be sure to patch now!
Cisco squashes critical bugs in small biz switches

security update

Microsoft decides it will be the one to choose which secure login method you use
Meet “AI”, your new colleague: could it expose your company’s secrets?

Before rushing to embrace the LLM-powered “hire”, make sure your organization has safeguards in place to avoid putting its business and customer data at risk The post Meet “AI”, your new colleague: could it expose your company’s secrets? appeared first on WeLiveSecurity

S3 Ep135: Sysadmin by day, extortionist by night

It was discovered that missing input sanitising in the implementation of the OIDCStripCookie option in mod_auth_openidc could result in denial of service.

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Red Hat AMQ Streams 2.4.0 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in Ruby.

minimatch could be made to crash if it opened a specially crafted input file.

Six million patients’ data feared stolen from PharMerica

security update

Smashing Security podcast #322: When you buy a criminal’s phone, and paying for social media scams
‘Strictly limit’ remote desktop – unless you like catching BianLian ransomware
You may not care where you download software from, but malware does

Why do people still download files from sketchy places and get compromised as a result? The post You may not care where you download software from, but malware does appeared first on WeLiveSecurity

US offers $10m bounty for Russian ransomware suspect outed in indictment
Is this the answer to Google Drive spam?
Google is going to delete your data forever, if you haven’t logged into your account for two years
Another security calamity for Capita: An unsecured AWS bucket

EventSource could leak sensitive information if it opened a specially crafted input file.

Don’t panic. Google offering scary .zip and .mov domains is not the end of the world
How to reduce your devops tool sprawl

The container bci/openjdk was updated. The following patches have been included in this update:

Upstart encryption app walks back privacy claims, pulls from stores after probe

An update for openstack-nova is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-nova is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-nova is now available for Red Hat OpenStack Platform 16.2 (Train). Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for openstack-nova is now available for Red Hat OpenStack Platform 17.0 (Wallaby). Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

Ransomware-as-a-service groups rain money on their affiliates
Feds offer $10m reward for info on alleged Russian ransomware crim
Surprise! Elon Musk’s encrypted Twitter DMs feature will cost you dear
US Dept of Transport security breach exposes info on a quarter-million people
Belkin Wemo Smart Plug V2 – the buffer overflow that won’t be patched
Compliance automation to confound cyber criminals
Expel’s UK cybersecurity landscape report sheds light on the challenges facing organisations

An update for libreswan is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libreswan is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for python-mako is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the freeradius:3.0 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for ctags is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Don’t overlook attack surface management
Cops crack gang that used bots to book and resell immigration appointments
FTC sues VoIP provider over ‘billions of illegal robocalls’
Intel says Friday’s mystery ‘security update’ microcode isn’t really a security update
Extra! Extra! Don’t quite read all about it: Cyber attack hits Philadelphia Inquirer

security update

Some potential: How bad software updates could over-volt, brick remote servers
Zut alors! Raclage crapuleux! Clearview AI in 20% more trouble in France
No more macros? No problem, say miscreants, we’ll adapt

Several security issues were fixed in Thunderbird.

Two security issues were found in PostgreSQL, which may result in privilege escalation or incorrect policy enforcement. For Debian 10 buster, these problems have been fixed in version

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

Sigstore: Roots of trust for software artifacts
An important system on project [REDACTED] was all [REDACTED] up
Ransomware corrupts data, so backups can be faster and cheaper than paying up
Arm acknowledges side-channel attack but denies Cortex-M is crocked

Several security issues were fixed in Firefox.

Toyota’s bungling of customer privacy is becoming a pattern

Patch CVE-2023-27783 – CVE-2023-27789 – CVE-2023-27783 – CVE-2023-27784 – CVE-2023-27785 – CVE-2023-27786 – CVE-2023-27787 – CVE-2023-27788 – CVE-2023-27789

Patch CVE-2023-27783 – CVE-2023-27789 – CVE-2023-27783 – CVE-2023-27784 – CVE-2023-27785 – CVE-2023-27786 – CVE-2023-27787 – CVE-2023-27788 – CVE-2023-27789

security update

The 6.2.15 stable kernel update contains a number of important fixes across the tree.

Update to 102.11.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2023-18/ ; https://www.thunderbird.net/en- US/thunderbird/102.11.0/releasenotes/

The 6.2.15 stable kernel update contains a number of important fixes across the tree.

Update to 0.10.5 (CVE-2023-1667 CVE-2023-2283)