Menu

Latest articles

Now you can legally repair your tech – sort of

A new law portends a future where (we hope) it will be easier for us all to repair, fix, upgrade, and just tinker with things we already own The post Now you can legally repair your tech – sort of appeared first on WeLiveSecurity

Researchers warn AI-generated phishing attacks are becoming more convincing
Smashing Security podcast #304: Oxford’s dating disaster, cheap security robots, and faking a suicide

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for sqlite is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the postgresql:10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for systemd is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

VALL-E AI can mimic a person’s voice from a three-second snippet
US think tank says China would probably lose if it tries to invade Taiwan
Post-ransomware attack, The Guardian warns staff their personal data was accessed
Free decryptor for victims of MegaCortex ransomware released
Royal Mail, cops probe ‘cyber incident’ that’s knackered international mail
AI-generated phishing emails just got much more convincing
StrongPity espionage campaign targeting Android users

ESET researchers identified an active StrongPity campaign distributing a trojanized version of the Android Telegram app, presented as the Shagle app – a video-chat service that has no app version The post StrongPity espionage campaign targeting Android users appeared first on WeLiveSecurity

Microsoft fixes Windows database connections it broke in November
German cartel watchdog objects to the way Google processes user data

An update that fixes one vulnerability is now available.

Red Hat Insights malware detection service is now generally available

It was discovered that there were two issues in viewvc, a web-based interface for browsing Subversion and CVS repositories. The attack vectors involved files with unsafe names; names that, when embedded into an HTML stream, could cause the browser to run unwanted code.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

Swiss Army’s Threema messaging app was full of holes – at least seven

A vulnerability has been discovered in protobuf-java which could result in denial of service.

Multiple vulnerabilities have been found in Alpine, the worst of which could result in denial of service.

Health insurer Aflac blames US partner for leak of Japanese cancer policy info
Privacy on the line: Boffins break VoLTE phone security
Microsoft Patch Tuesday: One 0-day; Win 7 and 8.1 get last-ever patches
First Patch Tuesday of the year explodes with in-the-wild exploit fix

security update

security update

Russian meddling in 2016 US presidential election was weak sauce
Popular JWT cloud security library patches “remote” code execution hole
Cracked it! Highlights from KringleCon 5: Golden Rings

Learning meets fun at the 2022 SANS Holiday Hack Challenge – strap yourself in for a crackerjack ride at the North Pole as I foil Grinchum’s foul plan and recover the five golden rings The post Cracked it! Highlights from KringleCon 5: Golden Rings appeared first on WeLiveSecurity

Hybrid work: Turning business platforms into preferred social spaces

Hybrid work and hybrid play now merge into hybrid living, but where is the line between the two? Is there one? The post Hybrid work: Turning business platforms into preferred social spaces appeared first on WeLiveSecurity

California e-ink platemaker exploited to track equipped cars
Wiretap lawsuit accuses Apple of tracking iPhone users who opted out

Red Hat OpenShift Container Platform release 4.10.47 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

The container suse/registry was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

Pakistan’s government to agencies: Dark web is dangerous, please don’t go there
Homeland Security, CISA builds AI-based cybersecurity analytics sandbox
US Supremes deny Pegasus spyware maker’s immunity claim

security update

Does a hybrid model for vulnerability management make sense?
CircleCI – code-building service suffers total credential compromise

Libksba could be made to crash or run programs if it processed specially crafted data.

Admins Receive Automated Linux Patch Management & Improved Security with ManageEngine Endpoint Central

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in HTTP request smuggling, cache poisoning or denial of service.

No more holidays for US telcos, FCC is cracking down
Chinese researchers’ claimed quantum encryption crack looks unlikely

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container bci/bci-busybox was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Here’s how to remotely takeover a Ferrari…account, that is

The container bci/bci-micro was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Freedom for MegaCortex ransomware victims – the fix is out
RSA crypto cracked? Or perhaps not!
How to prioritize effectively with threat modeling
Ransomware target list – Week in security with Tony Anscombe

Why schools, hospitals, local governments and other public sector organizations are in a sweet spot for ransomware attacks The post Ransomware target list – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Dridex malware pops back up and turns its attention to macOS

Red Hat OpenShift Container Platform release 4.9.54 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

JP Morgan must face suit from Ray-Ban maker after crooks drained $272m from accounts

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Rackspace blames ransomware woes on zero-day attack
Twitter data dump: 200m+ account database now free to download

It was discovered that there was a potential cross-site scripting vulnerability in smarty3, a widely-used PHP templating engine. For Debian 10 buster, this problem has been fixed in version

It was discovered that there was a potential null pointer dereference vulnerability in libetpan, an low-level library for handling email. For Debian 10 buster, this problem has been fixed in version

Several security issues were fixed in curl.

S3 Ep116: Last straw for LastPass? Is crypto doomed? [Audio + Text]
The doctor will see you now … virtually: Tips for a safe telehealth visit

Are your virtual doctor visits private and secure? Here’s what to know about, and how to prepare for, connecting with a doctor from the comfort of your home. The post The doctor will see you now … virtually: Tips for a safe telehealth visit appeared first on WeLiveSecurity

LockBit ransomware gang says sorry, gives free decryptor to SickKids hospital
Twitter whistleblower Peiter ‘Mudge’ Zatko lands new gig at Rapid7

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

New vim packages are available for Slackware 15.0 and -current to fix security issues.

Security fix for CVE-2021-4287

Security fix for CVE-2021-4287

Ex-GE engineer gets two years in prison after stealing turbine tech for China

Red Hat OpenShift Container Platform release 4.10.46 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The Guardian ransomware attack hits week two as staff told to work from home

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

An update that solves 13 vulnerabilities and has one errata is now available.

The welcoming of a new year also welcomes the return of one of the most overused sayings in our shared lexicon: “New Year, New Me!” While there are countless overused resolutions like starting a workout regimen, the new year does provide an opportunity for additional self-improvement that most people never consider – bolstering cybersecurity protections. […]

Serious Security: Vital cybersecurity lessons from the holiday season
Gaming: How much is too much for our children?

With many children spending a little too much time playing video games, learn to spot the signs things may be spinning out of control The post Gaming: How much is too much for our children? appeared first on WeLiveSecurity

Google Home smart speaker bug could have allowed hackers to spy on your conversations
Ireland fines Meta $414m for using personal data without asking
PyTorch dependency poisoned with malicious code

Red Hat OpenShift Container Platform release 4.11.21 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenShift Container Platform release 4.11.21 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

xwayland 22.1.7