Menu

Latest articles

OpenSSH fixes double-free memory bug that’s pokable over the network
Is that survey real or fake? How to spot a survey scam

“Can I tell a legitimate survey apart from a fake one?” is the single most important question you need to answer for yourself before taking any surveys online The post Is that survey real or fake? How to spot a survey scam appeared first on WeLiveSecurity

Another RAC staffer nabbed for storing and sharing road accident data
How multicloud changes devops
LockBit claims responsibility for ION ransomware attack but US/UK hounds are sniffing
Chinese ‘surveillance balloon’ over US causes fearful gasbagging

The newest upstream commit Security fix for CVE-2023-0288

Former Ubiquiti dev pleads guilty in data theft and extortion case

Update to 109.0.5414.119. Fixes the following security issues: CVE-2023-0471 CVE-2023-0472 CVE-2023-0473 CVE-2023-0474

New openssh packages are available for Slackware 15.0 and -current to fix security issues.

security update

security update

security update

security update

Malvertising attacks are distributing .NET malware loaders
S3 Ep120: When dud crypto simply won’t let go [Audio + Text]
Less is more: Conquer your digital clutter before it conquers you

Lose what you don’t use and other easy ways to limit your digital footprint and strengthen your online privacy and security The post Less is more: Conquer your digital clutter before it conquers you appeared first on WeLiveSecurity

Romance fraud losses rose 91% during the pandemic, claims UK’s TSB bank
Super Bock says ‘cyber’ nasty ‘disrupting computer services’

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

Rebuild for CVE-2022-41717 in golang.

Fix CVE-2022-47021

new upstream version

Rebuild for CVE-2022-41717 in golang.

Update to pgadmin4-6.19. —- Backport fix for CVE-2023-22298.

Smashing Security podcast #307: ChatGPT and the Minister for Foreign Affairs
Google boosts bounties for open source flaws found via fuzzing
Take a tour of the Edgescan Cybersecurity Platform
Microsoft sweeps up after breaking .NET with December security updates
Password-stealing “vulnerability” reported in KeePass – bug or feature?

Several security issues were fixed in Vim.

An update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed

ESET APT Activity Report T3 2022

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in T3 2022 The post ESET APT Activity Report T3 2022 appeared first on WeLiveSecurity

Beyond the STIG: What hardening really means

Several security issues were fixed in Slurm.

Attackers abuse Microsoft’s ‘verified publisher’ status to steal data

Update to 2.53.15

Several vulnerabilities have been fixed in the libstb library. CVE-2018-16981

Planet Ice hacked! 240,000 skating fans’ details stolen
Microsoft upgrades Defender to lock down Linux gear for its own good

Brief introduction CVE-2020-21529

New year, new storage challenge
GitHub code-signing certificates stolen (but will be revoked this week)

python-future could be made to crash if it received specially crafted input.

C++ creator Bjarne Stroustrup defends its safety

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

Amid FTX’s burning wreckage, Japan outpost promises asset withdrawals in February
South Korea makes crypto crackdown a national justice priority
Chromebook SH1MMER exploit promises admin jailbreak
The wages of sin aren’t that great if you’re a developer choosing the dark side

security update

security update

Gootloader malware updated with PowerShell, sneaky JavaScript
Serious Security: The Samba logon bug caused by outdated crypto
Latvia says Russian hackers tried to phish its Ministry of Defence
JD Sports admits intruder accessed 10 million customers’ data
If a locked filing cabinet is stolen along with its key, can you still say it’s locked? GoTo thinks you can
Hackers steal 10 million customer details from JD Sports
We are the weakest link
A Complete Guide to Security Automation & Reporting Using Open Source Tools
Data Privacy Day, every day

The components for Red Hat OpenShift support for Windows Container 7.0.0 are now available. This product release includes bug fixes and a moderate security update for the following packages: windows-machine-config-operator and

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Gee, tanks: Russian hackers DDoS Germany for aiding Ukraine

Update to 1.3.2 (CVE-2022-29187, CVE-2022-24765)

* CVE-2022-47318

Update 1.2.6

security update

Several buffer overflow, divide by zero or out of bounds read/write vulnerabilities were discovered in tiff, the Tag Image File Format (TIFF) library and tools, which may cause denial of service when processing a crafted TIFF image.

Two vulnerabilities were found in dojo, a modular JavaScript toolkit, that could result in information disclosure. CVE-2020-4051

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

security update

In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used.

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

Mon Dieu! Suspected French ShinyHunters gang member in the dock
Microsoft to enterprises: Patch your Exchange servers
Uncle Sam slaps $10m bounty on Hive while Russia ban-hammers FBI, CIA

security update

security update

Are you in control of your personal data? – Week in security with Tony Anscombe

Data Privacy Week is a reminder to protect your data – all year round. Here are three privacy-boosting habits you can start today. The post Are you in control of your personal data? – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Hive ransomware servers shut down at last, says FBI
SwiftSlicer: New destructive wiper malware strikes Ukraine

Sandworm continues to conduct attacks against carefully chosen targets in the war-torn country The post SwiftSlicer: New destructive wiper malware strikes Ukraine appeared first on WeLiveSecurity

Why your data is more valuable than you may realize

The data trail you leave behind whenever you’re online is bigger – and more revealing – than you may think The post Why your data is more valuable than you may realize appeared first on WeLiveSecurity

An update that fixes four vulnerabilities is now available.

Update to 1.3.2 (CVE-2022-29187, CVE-2022-24765)

https://www.mediawiki.org/wiki/Release_notes/1.38 https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/message/UEMW64LVEH3BEXCJV43CVS6XPYURKWU3/

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

Savvy cybersecurity pros benefit from host of free resources to step up fight against hackers and cyber threats