Menu

Latest articles

An update for rh-mysql80-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for samba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Love scam or espionage? Transparent Tribe lures Indian and Pakistani officials

ESET researchers analyze a cyberespionage campaign that distributes CapraRAT backdoors through trojanized and supposedly secure Android messaging apps – but also exfiltrates sensitive information The post Love scam or espionage? Transparent Tribe lures Indian and Pakistani officials appeared first on WeLiveSecurity

Pro-Putin scammers trick politicians and celebrities into low-tech hoax video calls
EPA orders US states to check cyber security of public water supplies
DoppelPaymer ransomware suspects cuffed, alleged ringleaders escape

security update

DoppelPaymer ransomware supsects arrested in Germany and Ukraine

An update for pesign is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for libjpeg-turbo is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for Jenkins and Jenkins-2-plugins is now available for OpenShift Developer Tools and Services for OCP 4.12. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

An update for pesign is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for pesign is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Study reveals companies are wasting millions on unused Kubernetes resources
Where are the women in cyber security? On the dark side, study suggests

Build of libtpms 0.9.6 with fixes for CVE-2023-1017 & CVE-2023-1018

Recently two problems have been found in the glibc suite, which could beused to trick setuid applications to run arbitrary code.

Multiple issues were found in libde265, an open source implementation of the h.265 video codec, which may result in denial of service, possibly code execution due to a heap-based buffer overflow or have unspecified other impact.

Open Source Vulnerability Assessment Tools & Scanners

Security fixes for CVE-2022-24580 and CVE-2023-41323

Security fixes for CVE-2022-24580 and CVE-2023-41323

add sub-package with xen build (resolves: rhbz#2170730) —- update openssl (CVE-2023-0286, CVE-2023-0215, CVE-2022-4450, CVE-2022-4304). —- cherry-pick aarch64 bugfixes, set firmware build release date, add ext4 sub-package

security update

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

What does $5,000 buy you on a hacking forum? – Week in security with Tony Anscombe

A bootkit that ESET researchers have discovered in the wild is the BlackLotus UEFI bootkit that is being peddled on hacking forums The post What does $5,000 buy you on a hacking forum? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Security fix for CVE-2023-27320

The newest upstream patchlevel 1367 Security fix for CVE-2023-1127

Secret Service, ICE break the law over and over with fake cell tower spying
Snap CISO: I rate software supply chain risk 9.9 out of 10

It was discovered that the fix for CVE-2023-27372 broke (de)activation of plugins with dependencies. For Debian 10 buster, this problem has been fixed in version

FTC: BetterHelp pushed users to share mental health info then gave it to Facebook

It was discovered that the libreswan IPsec implementation could be forced into a crash/restart via malformed IKEv2 packets after peer authentication, resulting in denial of service.

Frankenstein malware stitched together from code of others disguised as PyPI package
Feds warn about right Royal ransomware rampage that runs the gamut of TTPs
MQsTTang: Mustang Panda’s latest backdoor treads new ground with Qt and MQTT

ESET researchers tease apart MQsTTang, a new backdoor used by Mustang Panda, which communicates via the MQTT protocol The post MQsTTang: Mustang Panda’s latest backdoor treads new ground with Qt and MQTT appeared first on WeLiveSecurity

BlackLotus UEFI bootkit: Myth confirmed

The first in-the-wild UEFI bootkit bypassing UEFI Secure Boot on fully updated UEFI systems is now a reality The post BlackLotus UEFI bootkit: Myth confirmed appeared first on WeLiveSecurity

Beyond the STIG: What does “security leadership” really mean?
Warning on SolarWinds-like supply-chain attacks: ‘They’re just getting bigger’

node-css-what was vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable. The exploitation of this vulnerability could be triggered

German Digital Affairs Committee hearing heaps scorn on Chat Control
Smart security

The system could be made to crash or run programs as an administrator.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Insecure software pushers in Biden’s crosshairs
CI/CD: Necessary for modern software development, yet it carries a lot of risk

security update

Vice Society publishes data stolen during Vesuvius ransomware attack
Trezor crypto wallets under attack in SMS phishing campaign
S3 Ep124: When so-called security apps go rogue [Audio + Text]
WH Smith investigates hacking attack after employee data stolen
Indigo Books & Music refuses to pay ransom after hackers stole employee information
Intruder alert: UK retailer WH Smith hit by another cyber attack

Several security issues were fixed in SoX.

Forget ChatGPT, the most overhyped security tool is technology itself, Wiz warns

It was discovered that SPIP, a website engine for publishing, would allow a malicious user to execute arbitrary code. For the stable distribution (bullseye), this problem has been fixed in

New upstream version, including fix for CVE-2023-26081

Important: kernel-rt security and bug fix update

A new image is available for Red Hat Single Sign-On 7.6.2, running on Red Hat OpenShift Container Platform from the release of 3.11 up to the release of 4.12.0. Red Hat Product Security has rated this update as having a security impact

A security update is now available for Red Hat Single Sign-On 7.6 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Smashing Security podcast #311: TikTok, wiretapping, and your deepfake voice is your password

security update

It’s official: BlackLotus malware can bypass Secure Boot on Windows machines

security update

ESET Research Podcast: Ransomware trashed data, Android threats soared in T3 2022

And that’s just the tip of the iceberg when it comes to the trends that defined the cyberthreat landscape in the final four months of 2022. The post ESET Research Podcast: Ransomware trashed data, Android threats soared in T3 2022 appeared first on WeLiveSecurity

Top 10 open source software risks for 2023

Red Hat OpenShift Container Platform release 4.10.53 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

The Qualys Research Labs reported an authorization bypass (CVE-2022-41974) and a symlink attack (CVE-2022-41973) in multipath-tools, a set of tools to drive the Device Mapper multipathing driver, which may result in local privilege escalation.

USN-5880-1 caused some minor regressions in Firefox.

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

The container ses/7.1/rook/ceph was updated. The following patches have been included in this update:

PlugX RAT masquerades as legit Windows debugger to slip past security
Google: You get crypto, you get crypto, almost everyone gets email crypto!
US government sets a 30-day deadline for wiping TikTok from feds’ phones
US cybersecurity chief: Software makers shouldn’t lawyer their way out of security responsibilities
Dish: Someone snatched our data, if you’re wondering why our IT systems went down

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat OpenShift Container Platform release 4.11.29 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for vim is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for httpd is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for git is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kubeflow, dashboard, deployer is now available for Red Hat OpenShift Data Science 1.22. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

News Corp outfoxed by IT intruders for years
Russian hacktivists DDoS hospitals, with pathetic results
US Marshals Service leaks ‘law enforcement sensitive information’ in ransomware incident
LastPass: Keylogger on home PC led to cracked corporate password vault
Feeling VEXed by software supply chain security? You’re not alone
Dish multi-day outage rolls on as ransomware fears grow

security update

security update

security update

security update

Beware rogue 2FA apps in App Store and Google Play – don’t get hacked!