Menu

Latest articles

Red Hat OpenShift Container Platform release 4.11.21 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

xwayland 22.1.7

LockBit: Sorry about the SickKids ransomware, not sorry about the rest
‘Multiple security breaches’ shut down trucker protest

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Data of over 200 million Deezer users stolen, leaks on hacking forum
Inside a scammers’ lair: Ukraine busts 40 in fake bank call-centre raid
The world’s most common passwords: What to do if yours is on the list

Do you use any of these extremely popular – and eminently hackable – passwords? If so, we have a New Year’s resolution for you. The post The world’s most common passwords: What to do if yours is on the list appeared first on WeLiveSecurity

LostPass: after the LastPass hack, here’s what you need to know
Google gets off easy in Indiana, DC location tracking lawsuits

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

It was discovered that node-xmldom, a standard XML DOM (Level2 CORE) implementation in pure javascript, processed ill-formed XML, which may result in bugs and security holes in downstream applications.

The w3m program is a pager (or text file viewer) that can also be used as a text-mode Web browser. W3m features include the following: when reading an HTML document, you can follow links and view images using an external image viewer; its internet message mode determines the type of document from the header; if […]

OpenImageIO is a library for reading and writing images, and a bunch of related classes, utilities, and applications. Main features include: – Extremely simple but powerful ImageInput and ImageOutput APIs for reading and writing 2D images that is format agnostic. – Format plugins for TIFF, JPEG/JFIF, OpenEXR, PNG, HDR/RGBE, Targa, JPEG-2000,

An update that contains security fixes can now be installed.

An update for bcel is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for bcel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

PyTorch: Machine Learning toolkit pwned from Christmas to New Year

security update

security update

security update

security update

Naked Security 33 1/3 – Cybersecurity predictions for 2023 and beyond
Cybersecurity trends and challenges to look out for in 2023

What are some of the key cybersecurity trends and themes that organizations should have on their radars in 2023? The post Cybersecurity trends and challenges to look out for in 2023 appeared first on WeLiveSecurity

Nexperia calls in the lawyers to save Welsh chip fab deal
Twitter data of “+400 million unique users” up for sale – what to do?
The horror! The horror! NOTEPAD gets tabbed editing (very briefly)
US passes the Quantum Computing Cybersecurity Preparedness Act – and why not?
S3 Ep115: True crime stories – A day in the life of a cybercrime fighter [Audio + Text]

security update

Critical “10-out-of-10” Linux kernel SMB hole – should you worry?
2022 in review: 10 of the year’s biggest cyberattacks

The past year has seen no shortage of disruptive cyberattacks – here’s a round-up of some of the worst hacks and breaches that have impacted a variety of targets around the world in 2022 The post 2022 in review: 10 of the year’s biggest cyberattacks appeared first on WeLiveSecurity

US House boots TikTok from government phones
Stolen info on 400m+ Twitter accounts seemingly up for sale
How Physical Security Blends With Cybersecurity

An update that solves 31 vulnerabilities and has 8 fixes is now available.

An update that solves 17 vulnerabilities and has 37 fixes is now available.

An update that solves 19 vulnerabilities and has 40 fixes is now available.

An update that solves 38 vulnerabilities and has 9 fixes is now available.

An update that solves 43 vulnerabilities and has 16 fixes is now available.

It was discovered that there was a potential remote denial of service vulnerability in node-trim-newlines, a Javascript module to strip newlines from the start and/or end of a string.

Back to work, Linux admins: You have a CVSS 10 kernel bug to address
LastPass finally admits: They did steal your password vaults after all

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

LastPass admits attackers have a copy of customers’ password vaults
Crooks copy source code from Okta’s GitHub repository
FCC calls for mega $300 million fine for massive US robocall campaign

security update

Don’t click too quick! FBI warns of malicious search engine ads
Zerobot malware now shooting for Apache systems
S3 Ep114: Preventing cyberthreats – stop them before they stop you! [Audio + Text]
‘Tis the season for gaming: Keeping children safe (and parents sane)

It’s all fun and games over the holidays, but is your young gamer safe from the darker side of the action? The post ‘Tis the season for gaming: Keeping children safe (and parents sane) appeared first on WeLiveSecurity

It’s time to fill those cloud security gaps
Why zero knowledge matters

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

Fraudulent ‘popunder’ Google Ad campaign generated millions of dollars
Apple accused of censoring apps in Hong Kong and Russia to maintain market access
Godfather malware makes banking apps an offer they can’t refuse
Being one of the 1% sucks if you’re a Rackspace user
Smashing Security podcast #303: Secret Roomba snaps, Christmas cab scams, and the future of AI

security update

Microsoft fixes Hyper-V VM problem caused by Patch Tuesday
“Suspicious login” scammers up their game – take care at Christmas
UK’s Guardian newspaper breaks news of ransomware attack on itself
NASA infosec again falls short of required US government standard
How Steampipe enables KPIs as code
Malicious PyPI package found posing as a SentinelOne SDK
Parental control apps prove easy to beat by kids and crims

Fix buggy patch to CVE-2022-46340

Security fix for CVE-2022-41854

Release notes for xrdp v0.9.21 (2022/12/10) General announcements – Running xrdp and xrdp-sesman on separate hosts is still supported by this release, but is now deprecated. This is not secure. A future v1.0 release will replace the TCP socket used between these processes with a Unix Domain Socket, and then cross-host running will not be […]

Security fixes for CVE-2022-37966, CVE-2022-37967 and CVE-2022-38023

Update to 102.6.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2022-53/ ; https://www.thunderbird.net/en- US/thunderbird/102.6.0/releasenotes/

Security fix for CVE-2022-41854

Cisco’s Talos security bods predict new wave of Excel Hell
Swatting suspects charged with subverting Ring doorbell cams and calling cops
Big Apple locals hire Russians to game New York’s taxi system
Microsoft reports macOS Gatekeeper has an ‘Achilles’ heel
Microsoft dishes the dirt on Apple’s “Achilles heel” shortly after fixing similar Windows bug

An update that fixes 7 vulnerabilities is now available.

The container sles-15-sp4-chost-byos-v20221215-arm64 was updated. The following patches have been included in this update:

The container sles-15-sp4-chost-byos-v20221118-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20221215-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20221215-x86_64-gen2 was updated. The following patches have been included in this update:

The container sles-15-sp3-chost-byos-v20221215-x86-64 was updated. The following patches have been included in this update: