Menu

Latest articles

Shedding light on AceCryptor and its operation

ESET researchers reveal details about a prevalent cryptor, operating as a cryptor-as-a-service used by tens of malware families The post Shedding light on AceCryptor and its operation appeared first on WeLiveSecurity

An issue has been found in sniproxy, a transparent TLS and HTTP layer 4 proxy with SNI support. Due to bad handling of wildcard backend hosts, a crafted HTTP or TLS packet might lead to remote arbitrary code execution.

Improving supply chain resiliency with Red Hat Trusted Software Supply Chain

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux Cloud Native Environment 1.6 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Careless IT security worker exploited ransomware attack against his employer, but failed to cover his tracks
BlackByte ransomware crew lists city of Augusta after cyber ‘incident’
It’s 2023 and Sri Lanka doesn’t have a cyber security authority
Spotted: Suspected Russian malware designed to disrupt Euro, Asia energy grids
S3 Ep136: Navigating a manic malware maelstrom
So the FBI ‘persistently’ abused its snoop powers. What’s to worry about?
Sorry scammer, I’m not cancelling my McAfee Antivirus subscription

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Confidential Containers on Azure with OpenShift: A technical deep dive
Facial recog system used by Met Police shows racial bias at low thresholds
Smashing Security podcast #323: Botched Bitcoin blackmail, iSpoof, and Meta’s billion dollar data bungle
Five Eyes and Microsoft accuse China of attacking US infrastructure again
This legit Android app turned into mic-snooping malware – and Google missed it

security update

Philly Inquirer says Cuba ransomware gang’s data leak claims are fake news
Ransomware tales: The MitM attack that really had a Man in the Middle

An update for sudo is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

An update for devtoolset-12-binutils is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

JSON Schema could be made to crash or run programs if it opened specially crafted input.

USN-6074-2 caused some minor regressions in Firefox.

Several security issues were fixed in GNU binutils.

Several security issues were fixed in xmldom.

Digital security for the self‑employed: Staying safe without an IT team to help

Nobody wants to spend their time dealing with the fallout of a security incident instead of building up their business The post Digital security for the self‑employed: Staying safe without an IT team to help appeared first on WeLiveSecurity

IT security analyst admits hijacking cyber attack to pocket ransom payments
US bans North Korean outsourcer and its feisty freelancers

security update

Apria Healthcare says potentially 2M people caught up in IT security breach
PyPI open-source code repository deals with manic malware maelstrom
Dish confirms 300,000 people’s data was exposed in February’s attack
TikTok to let Oracle view source code, algorithm, and content moderation

Go applications could be made to hang or crash if they received specially crafted input.

USN-6073-4 introduced a regression in os-brick.

USN-6073-3 introduced a regression in Nova.

USN-6073-2 introduced a regression in Glance_store.

USN-6073-1 introduced a regression in Cinder.

Several security issues were fixed in ncurses.

Suzuki motorcycle plant shut down by cyber attack
Android app breaking bad: From legitimate screen recording to file exfiltration within a year

ESET researchers discover AhRat – a new Android RAT based on AhMyth – that exfiltrates files and records audio The post Android app breaking bad: From legitimate screen recording to file exfiltration within a year appeared first on WeLiveSecurity

AppMap: A map to reduce developer toil
Ads for lucrative jobs in Asia fail to mention chance of slavery as crypto-scammer
China hasn’t told Micron why it failed security review, or what its ban means
Uncle Sam strangles criminals’ cashflow by reining in money mules

security update

security update

Phone scamming kingpin gets 13 years for running “iSpoof” service
M&S and Diageo pension schemes exposed in Capita hack
Google settles location tracking lawsuit for only $39.9M

tar could be made to crash or expose sensitive information if it received a specially crafted file.

More UK councils caught by Capita’s open AWS bucket blunder

Two vulnerabilities have been fixed in sqlite (V2) which which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact.

Fighting the five

An update for git is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for git is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for git is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for git is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Diligent developer courageously lied about exec’s NSFW printouts – and survived long enough to quit with dignity

It was discovered that missing input sanitising in cups-filters, when using the Backend Error Handler (beh) backend to create an accessible network printer, may result in the execution of arbitrary commands.

Potential NULL dereference during rekeying with algorithm guessing. (CVE-2023-1667) Authorization bypass in pki_verify_data_signature. (CVE-2023-2283 References:

ReDoS (Regular Expression Denial of Service) (CVE-2023-30608) References: – https://bugs.mageia.org/show_bug.cgi?id=31913 – https://ubuntu.com/security/notices/USN-6064-1

An integer overflow vulnerability was discovered in Freetype in tt_hvadvance_adjust() function in src/truetype/ttgxvar.c. (CVE-2023-2004) References: – https://bugs.mageia.org/show_bug.cgi?id=31887

cmark incorrectly handled certain inputs. Fixes quadratic complexity in handle_close_bracket “![[]()” which may lead to a denial of service (CVE-2023-22486). Noting that this also fixes a quadratic parsing issue with repeated

Dmidecode allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. (CVE-2023-30630) References:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The real cost of a free lunch – Week in security with Tony Anscombe

Don’t download software from non-reputable websites and sketchy links – you might be in for more than you bargained for The post The real cost of a free lunch – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Max Chernoff discovered that improperly secured shell-escape in LuaTeX may result in arbitrary shell command execution, even with shell escape disabled, if specially crafted tex files are processed.

The newest upstream commit Security fix for CVE-2023-2426

security update

Teen in court after ‘$600K swiped from DraftKings gamblers’

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Russian IT guy sent to labor camp for DDoSing Kremlin websites
5 useful search engines for internet‑connected devices and services

A roundup of some of the handiest tools that security professionals can use to search for and monitor devices that are accessible from the internet The post 5 useful search engines for internet‑connected devices and services appeared first on WeLiveSecurity

Take action now to avoid BianLian ransomware attacks, US Government warns organisations
Confidential computing use cases
UK’s GDPR replacement could wipe out oversight of live facial recognition

This kernel-linus update is based on upstream 5.15.110 and fixes atleast the following security issues: A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.

Apple warns of three WebKit vulns under active exploitation, dozens more CVEs across its range

fix clone-in-kitty + security fix rhbz#2196803

Upgrade to 1.2.11

Backport fix for CVE-2023-1729.

– Update yubibomb to version 0.2.12. – Update ybaas to version 0.0.16.

– Update yubibomb to version 0.2.12. – Update ybaas to version 0.0.16.

Apple’s secret is out: 3 zero-days fixed, so be sure to patch now!
Cisco squashes critical bugs in small biz switches

security update

Microsoft decides it will be the one to choose which secure login method you use
Meet “AI”, your new colleague: could it expose your company’s secrets?

Before rushing to embrace the LLM-powered “hire”, make sure your organization has safeguards in place to avoid putting its business and customer data at risk The post Meet “AI”, your new colleague: could it expose your company’s secrets? appeared first on WeLiveSecurity