Menu

Latest articles

IT security teams, business execs still not on same page
UK arrests five for selling ‘dodgy’ point of sale software

Multiple security vulnerabilities have been found in OpenEXR, command-line tools and a library for the OpenEXR image format. Buffer overflows or out-of-bound reads could lead to a denial of service (application crash) if a malformed image file is processed.

Japan, Australia, to bolster cyber-defenses, maybe offensive capacity too

security update

An update that fixes one vulnerability is now available.

Security fix for CVE-2022-3500 Proper exception handling in tornado_requests

Security fix: CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing

Security fix: CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing

Security fix: CVE-2022-42920 bcel: Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing

An update that fixes one vulnerability is now available.

security update

Diamond industry under attack – Week in security with Tony Anscombe

ESET researchers uncover a new wiper and its execution tool, both attributed to the Iran-aligned Agrius APT group The post Diamond industry under attack – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Xenomorph: What to know about this Android banking trojan

Xenomorph pilfers victims’ login credentials for banking, payment, social media, cryptocurrency and other apps with valuable data The post Xenomorph: What to know about this Android banking trojan appeared first on WeLiveSecurity

Zhang Boyang reported that the grub2 update released as DLA 3190-1 did not correctly apply fixes for CVE-2022-2601 and CVE-2022-3775. Updated packages are now available to address this issue. For reference the original advisory text follows.

Update the capnp crate to version 0.14.11 to address CVE-2022-46149 / RUSTSEC-2022-0068. This update also includes a rebuild of the only affected application (the Sequoia PGP plugin for Thunderbird).

Update the capnp crate to version 0.14.11 to address CVE-2022-46149 / RUSTSEC-2022-0068. This update also includes a rebuild of the only affected application (the Sequoia PGP plugin for Thunderbird).

Update the capnp crate to version 0.14.11 to address CVE-2022-46149 / RUSTSEC-2022-0068. This update also includes a rebuild of the only affected application (the Sequoia PGP plugin for Thunderbird).

Update the capnp crate to version 0.14.11 to address CVE-2022-46149 / RUSTSEC-2022-0068. This update also includes a rebuild of the only affected application (the Sequoia PGP plugin for Thunderbird).

updates to screenshooter,settings, and places-plugin

This ransomware gang is a right Royal pain in the AES for healthcare orgs
Legit Android apps poisoned by sticky ‘Zombinder’ malware
Italy, Japan, UK to jointly launch sixth-gen fighter jet by 2035
S3 Ep112: Data breaches can haunt you more than once! [Audio + Text]
Rackspace customers rage following ransomware attack, as class-action lawsuits filed
Guess which Fortune 500 brands and govt agencies share data with Twitter?
UK lawmakers look to enforce blocking tools for legal but harmful content

The container bci/bci-busybox was updated. The following patches have been included in this update:

Boss installed software from behind the Iron Curtain, techies ended up Putin things back together
North Korea using freelance techies to fund missiles and nukes

Fix a possible double free in `woffEncode()`. – Update License to SPDX – improved summary and description – Add hand-written man pages – Install HTML format description as documentation

Openshift Logging Bug Fix Release (5.3.14) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

REvil-hit Medibank to pull plug on IT, shore up defenses

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Credit card skimming – the long and winding road of supply chain failure
Fantasy – a new Agrius wiper deployed through a supply‑chain attack

ESET researchers analyzed a supply-chain attack abusing an Israeli software developer to deploy Fantasy, Agrius’s new wiper, with victims including the diamond industry The post Fantasy – a new Agrius wiper deployed through a supply‑chain attack appeared first on WeLiveSecurity

Metaparasites: The cybercriminals who rip each other off
North Korean hackers exploit Seoul Halloween tragedy in zero-day attack

Several security issues were fixed in Python.

Five British companies fined for making half a million nuisance calls

Logging Subsystem 5.5.5 – Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Weep for the cybercriminals who fell for online scams and lost $2.5m last year
North Korea hits new low by using Seoul Halloween tragedy to exploit Internet Explorer zero-day

An update for python-oslo-utils is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for python-ujson is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for erlang is now available for Red Hat OpenStack Platform 16.2.4 (Train) on Red Hat Enterprise Linux (RHEL) 8.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for python-django20 is now available for Red Hat OpenStack Platform 16.1.9 (Train) for Red Hat Enterprise Linux (RHEL) 8.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

States label TikTok ‘a malicious and menacing threat’
Egad, did Apple do something right? End-to-end encryption for (most) iCloud services
Smashing Security podcast #301: AI chatbot or the start of Skynet? Eufy privacy, and hot desks

security update

security update

San Francisco terminates explosive killer cop bots
Complexity is the enemy of cloud security

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat AMQ Broker 7.10.2 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in NumPy.

Taiwan bans state-owned devices from running Chinese platform TikTok

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

Microsoft: (Cyber) winter is coming as DDoS attack disrupts Russian bank
Amnesty International Canada claims attack by China-backed forces
South Pacific vacations may be wrecked by ransomware
Rackspace confirms ransomware attack behind days-long email meltdown
SIM swapper sent to prison for 2FA cryptocurrency heist of over $20m
Tractors vs. threat actors: How to hack a farm

Forget pests for a minute. Modern farms also face another – and more insidious – breed of threat. The post Tractors vs. threat actors: How to hack a farm appeared first on WeLiveSecurity

Want to detect Cobalt Strike on the network? Look to process memory
KmsdBot botnet is down after operator sends typo in command

An update for grub2 is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.

An update for usbguard is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for kernel is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dbus is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for pki-core is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Complexity is the enemy of security
How to secure application identities at developmental speed

A distrusted certificate authority has been removed from ca-certificates.

TSA to expand facial recognition across America
Four suspects cuffed, face extradition over tax refund scam plot
Gunfire at electrical grid kills power for 45,000 in North Carolina
Google warns stolen Android keys used to sign info-stealing malware
Russian courts attacked by CryWiper malware that poses as ransomware

security update

security update

security update

Hacking cars remotely with just their VIN
ScarCruft updates its toolset – Week in security with Tony Anscombe

Deployed against carefully selected targets, the new backdoor combs through the drives of compromised systems for files of interest before exfiltrating them to Google Drive The post ScarCruft updates its toolset – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Whoops! Researchers accidentally crash botnet used to launch DDoS and cryptomining campaigns

A distrusted certificate authority has been removed from ca-certificates.

Heres Why You Should Get Started With Open Source Log Analytics & Monitoring Today!

Several security issues were fixed in libxml2.

Securing Application Identities in 2023

Several security issues were fixed in libxml2.

Remuneration coming for TrustCor customers impacted by CA revocation
Rackspace customers rage as email outage continues and migrations create migraines

The 6.0.11 stable kernel update contains a number of important fixes across the tree.

The 6.0.11 stable kernel update contains a number of important fixes across the tree.

The 6.0.11 stable kernel update contains a number of important fixes across the tree.