Menu

Latest articles

Red Hat Government Symposium 2022: Unleashing innovation, powering missions
Simplifying digital sovereignty in a multi-cloud world
Eurozone plans to formalize passenger data, improve security
McGraw Hill’s S3 buckets exposed 100,000 students’ grades and personal info
Patch Tuesday update is causing some Windows 10 systems to blue screen
Google adds stronger encryption for some Gmail users, in beta
OneCoin scammer Sebastian Greenwood pleads guilty, “Cryptoqueen” still missing
Lynis: A Linux Security Audit Tool You Should Know About
How to set up parental controls on your child’s new smartphone

Give yourself peace of mind and help create a safe online space for your child using Android or iOS parental controls The post How to set up parental controls on your child’s new smartphone appeared first on WeLiveSecurity

Multiple vulnerabilities have been discovered in NSS, the worst of which could result in arbitrary code execution.

A vulnerability has been discovered in LibreOffice which could result in arbitrary script execution via crafted links.

Multiple vulnerabilities have been discovered in Unbound, the worst of which could result in denial of service.

Multiple vulnerabilities have been found in curl, the worst of which could result in arbitrary code execution.

Update to version 4.17.4

xwayland 22.1.6 Fixes CVE-2022-46340, CVE-2022-46341, CVE-2022-46342, CVE-2022-46343, CVE-2022-46344, CVE-2022-4283

Automate like an expert with Ansible validated content

An update that fixes 7 vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

advancecomp has been updated to fix a number of bugs and security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=31234 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/KQHLMLFHPV5C7PTBZML6U72QT6VNEOEF/

Update to 102.6.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2022-53/ ; https://www.thunderbird.net/en- US/thunderbird/102.6.0/releasenotes/

security update

security update

MirrorFace aims for high‑value targets in Japan – Week in security with Tony Anscombe

The group’s proprietary backdoor LODEINFO delivers additional malware, exfiltrates credentials, and steals documents and emails The post MirrorFace aims for high‑value targets in Japan – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Email hijackers scam food out of businesses, not just money

An update that fixes 6 vulnerabilities is now available.

An update that fixes 7 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

New version 4.0.2

New version 3.6.10

Let’s spend $22m supporting survivors of tech-enabled abuse, lawmakers suggest
Twitter staffer turned Saudi spy jailed for 3.5 years
Traveling for the holidays? Stay cyber‑safe with these tips

Holiday travel is back with a vengeance this year. Set yourself up for a cyber-safe and hassle-free trip with our checklist. The post Traveling for the holidays? Stay cyber‑safe with these tips appeared first on WeLiveSecurity

Data breach at Social Blade confirmed. Hacker offers to sell database on underground website
Backup saves the day after crime author loses laptop in blizzard
Help! My kid has asked Santa for a smartphone

The time has come for your child to receive their first smartphone. Before handing it over, however, make sure to help them use their new gadget safely and responsibly. The post Help! My kid has asked Santa for a smartphone appeared first on WeLiveSecurity

Microsoft Teams: A vector for child sexual abuse material with a two-day processing time for complaints
US adds 36 Chinese entities to naughty list, drops 25 after checking it twice
NIST says you better dump weak SHA-1 … by 2030

– New upstream release (108.0)

CVE fixes for: CVE-2022-4283, CVE-2022-46340, CVE-2022-46341, CVE-2022-46342, CVE-2022-46343, CVE-2022-46344

Update to 2.9.0 (CVE-2022-39316, CVE-2022-39317, CVE-2022-39318, CVE-2022-39319, CVE-2022-39320, CVE-2022-41877 and CVE-2022-39347).

Update to upstream release 3.0.26.

Update to 2.9.0 (CVE-2022-39316, CVE-2022-39317, CVE-2022-39318, CVE-2022-39319, CVE-2022-39320, CVE-2022-41877 and CVE-2022-39347). —- Update to 2.8.1 (CVE-2022-39282, CVE-2022-39283).

An update that fixes 5 vulnerabilities is now available.

Large-Scale Phishing Campaign Floods Open-Source Repositories with 144,000 Packages
Sting op takes down 50 DDoS-for-hire domains, seven people collared

security update

Microsoft approved and digitally-signed malicious drivers used in ransomware attacks
S3 Ep113: Pwning the Windows kernel – the crooks who hoodwinked Microsoft [Audio + Text]
Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities

ESET researchers discovered a spearphishing campaign targeting Japanese political entities a few weeks before the House of Councillors elections, and in the process uncovered a previously undescribed MirrorFace credential stealer The post Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities appeared first on WeLiveSecurity

Microsoft to Europe: We’re setting an EU ‘data boundary’ from 2023
Operation Power Off: 50 DDoS-services taken offline in international crackdown
Smashing Security podcast #302: Lensa AI, and a dog called Bob
Using system tags to enable extended security hardening recommendations
Beyond the STIG: The wider world of cybersecurity
Iran-linked Charming Kitten espionage gang bares claws to pollies, power orgs
On the 12th day of the Rackspace email disaster, it did not give to me …
Malicious Microsoft-signed Windows drivers wielded in cyberattacks
Seven smuggled US military tech for Moscow, say Feds
AWS strains to make Simple Storage Service not so simple to screw up
TikTok could be banned from America, thanks to proposed bipartisan bill
Patch Tuesday updates spark errors when creating Hyper-V VMs
Top tips for security‑ and privacy‑enhancing holiday gifts

Think outside the (gift) box. Here are a few ideas for security and privacy gifts to get for your relatives – or even for yourself. Some don’t cost a penny! The post Top tips for security‑ and privacy‑enhancing holiday gifts appeared first on WeLiveSecurity

EU takes another step towards US data-sharing agreement

The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

Several security issues were fixed in X.Org X Server.

Citrix patches critical ADC flaw the NSA says is already under attack from China
Apple patches everything, finally reveals mystery of iOS 16.1.2
Patch Tuesday: 0-days, RCE bugs, and a curious tale of signed malware
Microsoft ain’t the only one squashing exploited-in-the-wild bugs this month
LockBit threatens to leak confidential info stolen from California’s beancounters
Uber staff info leaks after supplier Teqtivity gets pwned

security update

COVID-bit: the wireless spyware trick with an unfortunate name
Cybersecurity Trends 2023: Securing our hybrid lives

ESET experts offer their reflections on what the continued blurring of boundaries between different spheres of life means for our human and social experience – and especially our cybersecurity and privacy The post Cybersecurity Trends 2023: Securing our hybrid lives appeared first on WeLiveSecurity

Apple should pay €6m to French data watchdog for tracking users without consent, says official

An update that contains security fixes can now be installed.

An update that solves 12 vulnerabilities, contains one feature and has two fixes is now available.

An update that solves 12 vulnerabilities, contains one feature and has two fixes is now available.

An update that contains security fixes can now be installed.

An update that fixes 12 vulnerabilities, contains one feature is now available.

Several security issues were fixed in containerd.

Researchers smell a cryptomining Chaos RAT targeting Linux systems
Pwn2Own contest concludes with nearly $1m paid out to ethical hackers

Timothee Desurmont discovered an information leak vulnerability in node-eventsource, a W3C compliant EventSource client for Node.js: the module was not honoring the same-origin-policy and upon following a redirect would leak cookies to the the target URL.

Pwn2Own Toronto: 54 hacks, 63 new bugs, $1 million in bounties
Hive ransomware gang claims responsibility for attack on Intersport that left cash registers disabled
Using threat modeling to get your priorities right
Deception Technology for Linux: How to Trick Cyber Criminals into Focusing on a Decoy
Open source security fought back in 2022

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.