Menu

Latest articles

3CX teases security-focused client update, plus password hashing
US cyber chiefs warn AI will help crooks, China develop nastier cyberattacks faster

Important: httpd and mod_http2 security update

Another zero-click Apple spyware maker just popped up on the radar again
April Patch Tuesday: Ransomware gangs already exploiting this Windows bug

security update

Attention gamers! Motherboard maker MSI admits to breach, issues “rogue firmware” alert

An update that contains security fixes can now be installed.

An update that fixes 12 vulnerabilities is now available.

Azure admins warned to disable shared key access as backdoor attack detailed

The container sles-15-sp4-chost-byos-v20230410-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230410-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230410-x86_64-gen2 was updated. The following patches have been included in this update:

Beyond Firewalls: What Else Is Required to Secure a Linux System?
GitGuardian’s honeytokens in codebase to fish out DevOps intrusion

Red Hat OpenShift Container Platform release 4.12.11 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

40% of IT security pros say they’ve been told not to report a data leak
3 overlooked cloud security attack vectors
How much to infect Android phones via Google Play store? How about $20k
Inside FTX: Jokes about misplaced funds, diabolical IT, poor oversight, and worse
Apple squashes iOS, macOS zero-day bugs already exploited by snoops
Apple zero-day spyware patches extended to cover older Macs, iPhones and iPads
Google to kill Dropcam, Nest Secure hardware next year
Microsoft, Fortra are this fed up with cyber-gangs abusing Cobalt Strike
When it comes to technology, securing your future means securing your present

Irssi could be made to crash in specific scenarios.

A regression was reported that the fix for CVE-2021-3802 broken mounting allow-listed mount option/value pairs, for example errors=remount-ro. For Debian 10 buster, this problem has been fixed in version

Multiple security vulnerabilities have been discovered in OpenImageIO, a library for reading and writing images. Buffer overflows and out-of-bounds read and write programming errors may lead to a denial of service (application crash) or the execution of arbitrary code if a malformed image

update to 112.0.5615.49. Fixes the following security issues: CVE-2023-1528 CVE-2023-1529 CVE-2023-1530 CVE-2023-1531 CVE-2023-1532 CVE-2023-1533 CVE-2023-1534

https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/message/6UQBHI5FWLATD7QO7DI4YS54U7XSSLAN/

Update to 2.53.16 Langpacks are now provided in the modern form of web extensions. This may take a bit longer at startup if all languages are enabled at the same time. To avoid this, just disable unneeded languages by Add-ons Manager. (Note, langpacks are related to the language of the application menus etc., and are […]

– fix SSH connection too eager reuse still (CVE-2023-27538) – fix GSS delegation too eager connection re-use (CVE-2023-27536) – fix FTP too eager connection reuse (CVE-2023-27535) – fix SFTP path ~ resolving discrepancy (CVE-2023-27534) – fix TELNET option IAC injection (CVE-2023-27533)

Popular server-side JavaScript security sandbox “vm2” patches remote execution hole

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

An update for httpd and mod_http2 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for tigervnc is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

The 6.2.9 stable kernel update contains a number of important fixes across the tree.

Apple issues emergency patches for spyware-style 0-day exploits – update now!
MSI hit in cyberattack, warns against installing knock-off firmware

Stefan Walter found that udisks2, a service to access and manipulate storage devices, could cause denial of service via system crash if a corrupted or specially crafted ext2/3/4 device or image was mounted, which could happen automatically on certain environments.

Welcome to open source, Elon. Your Twitter code just got a CVE for shadow ban bug
It’s this easy to seize control of someone’s Nexx ‘smart’ home plugs, garage doors
With ICMP magic, you can snoop on vulnerable HiSilicon, Qualcomm-powered Wi-Fi

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal. (CVE-2023-28371) References: – https://bugs.mageia.org/show_bug.cgi?id=31742

Buffer overrun in util.c (CVE-2022-4899) References: – https://bugs.mageia.org/show_bug.cgi?id=31740 – https://lists.suse.com/pipermail/sle-security-updates/2023-March/014246.html

security update

security update

security update

Ukrainian hackers spend $25,000 of pro-Russian blogger’s money on sex toys
A fireside chat with four CISOs about how they secure their cybersecurity firms from attack
Own a Nexx “smart” alarm or garage door opener? Get rid of it, or regret it
S3 Ep129: When spyware arrives from someone you trust
Steer clear of tax scams – Week in security with Tony Anscombe

In a rush to file your taxes? Watch out for cybercriminals preying on stressed taxpayers as Tax Day looms large on the horizon. The post Steer clear of tax scams – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Russia has a stash of scary malware? We’re shocked

It was discovered that there was a potential path-traversal vulnerability in GruntJS, a multipurpose task runner and build system tool. This could have been exploited via malicious symlinks.

Red Hat OpenShift sandboxed containers for debugging with elevated privileges
Eight Distros Release Important Advisories for Actively Exploited Linux Kernel Use After Free Vuln

Red Hat OpenShift Container Platform release 4.9.59 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

CAN do attitude: How thieves steal cars using network bus
Cleaning up your social media and passwords: What to trash and what to treasure

Give your social media presence a good spring scrubbing, audit your passwords and other easy ways to bring order to your digital chaos The post Cleaning up your social media and passwords: What to trash and what to treasure appeared first on WeLiveSecurity

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

Criminal records office yanks web portal offline amid ‘cyber security incident’
Cops cuff teenage ‘Robin Hood hacker’ suspected of peddling stolen info
Smashing Security podcast #316: Of Musk and Afroman
Cops put the squeeze on Genesis crime souk denizens, not just the admins this time
US government warning! What if anyone could open your garage door?

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

A security issue was fixed in trim-newlines.

Microsoft tells admins to autoreview your Autopatch alerts or autolose the service
Why you should spring clean your home network and audit your backups

Do you know how many devices are connected to your home network? You don’t? This is precisely why it’s time for a network audit. The post Why you should spring clean your home network and audit your backups appeared first on WeLiveSecurity

Notorious stolen credential warehouse Genesis Market seized by FBI
Feds seize $112m in cryptocurrency linked to ‘pig-butchering’ finance scams
Can ChatGPT bash together some data-stealing code? With the right prompts, sure
Snyk bolsters developer security with fresh devsecop, cloud capabilities
Einstein tilings – the amazing “Hat” shape that never repeats!
UK data regulator issues warning over generative AI data protection concerns
UK data watchdog fines TikTok £12.7M for failing to protect kids
Best Browsers with a Built-in VPN
Spring into action and tidy up your digital life like a pro

Spring is in the air and as the leaves start growing again, why not breathe some new life into the devices you depend on so badly? The post Spring into action and tidy up your digital life like a pro appeared first on WeLiveSecurity

Bank rewrote ads for infosec jobs to stop scaring away women
Hey Siri, use this ultrasound attack to disarm a smart-home system
Uber driver info stolen yet again: This time from law firm
April brings tulips, taxes … and phisherfolk scammers
Researchers claim they can bypass Wi-Fi encryption (briefly, at least)
Keeping secrets safe
Western Digital confirms digital burglary, calls the cops
3CX thought supply chain attack was a false positive

Several security issues were fixed in amanda.

Vietnam threatens to cut off two million mobile subscribers