Menu

Latest articles

Number Nine! Chrome fixes another 2022 zero-day, Edge not patched yet

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Understanding the Confidential Containers Attestation Flow

Security fix for CVE-2022-45866

Security fix for CVE-2022-45866

New version 4.0.1, Fix for bug #2148308, fix for CVE-2022-3725

Security fix for CVE-2022-45866

Rackspace rocked by ‘security incident’ that has taken out some hosted Exchange services

pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is larger than 2k. This

g810-led, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive data.

Mitsurugi Heishiro found out that in VLC, multimedia player and streamer, a potential buffer overflow in the vnc module could trigger remote code execution if a malicious vnc URL is deliberately played.

US Air Force reveals B-21 Raider stealth bomber that’ll fly the unfriendly skies

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.

Update capnproto to version 0.9.2 to address CVE-2022-46149. Dependent packages were rebuilt for both the fix for the security issue and the capnproto SONAME bump.

Medibank prognosis gets worse after more stolen data leaked
Apple pushes out iOS security update that’s more tight-lipped than ever
FBI warns about Cuba, no, not that one — the ransomware gang

security update

Top tips to save energy used by your electronic devices

With the rapidly rising energy prices putting a strain on many households, what are some quick wins to help reduce the power consumption of your gadgets? The post Top tips to save energy used by your electronic devices appeared first on WeLiveSecurity

Cloud computing gets back to basics
What is DevSecOps? Securing devops pipelines
Domain aging gang CashRewindo picks vintage sites to push malvertising

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

Mozilla, Microsoft drop TrustCor as root certificate authority
Two signs in the comms cabinet said ‘Do not unplug’. Guess what happened
LastPass admits to customer data breach caused by previous breach
Nvidia patches 29 GPU driver bugs that could lead to code execution, device takeover
Google warns about commercial Heliconia spyware hitting Chrome, Firefox and Microsoft Defender
S3 Ep111: The business risk of a sleazy “nudity unfilter” [Audio + Text]
The CHRISTMA EXEC network worm – 35 years and counting!
Intruders gain access to user data in LastPass incident

Several security issues were fixed in the Linux kernel.

Twenty years on, command-line virus scanner ClamAV puts out version 1

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

snapd could be made to run programs as an administrator.

snapd could be made to run programs as an administrator.

Keeping customers happy means the big IAM just got bigger
Almost 300 predatory loan apps found in Google and Apple stores

An update that fixes one vulnerability is now available.

Smashing Security podcast #300: Interplanetary file systems, iSpoof, and don’t delete Twitter
Sirius XM flaw unlocks so-called smart cars thanks to code flaw
San Francisco lawmakers approve lethal robots, but they can’t carry guns
AWS’ Inspector offers vulnerability management for Lambda serverless functions
Serious Security: MD5 considered harmful – to the tune of $600,000
Twitter isn’t going to stop people posting COVID-19 misinformation anymore
TikTok NSFW if you work for the South Dakota government
Who’s swimming in South Korean waters? Meet ScarCruft’s Dolphin

ESET researchers uncover Dolphin, a sophisticated backdoor extending the arsenal of the ScarCruft APT group The post Who’s swimming in South Korean waters? Meet ScarCruft’s Dolphin appeared first on WeLiveSecurity

Flaw allowed man to access private information of other Brinks Home Security customers

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

The container trento/trento-web was updated. The following patches have been included in this update:

The container trento/trento-web was updated. The following patches have been included in this update:

The container trento/trento-runner was updated. The following patches have been included in this update:

The container trento/trento-runner was updated. The following patches have been included in this update:

Cloudflare finds a way through China’s network defences

security update

Criminals use trending TikTok challenge to make data-stealing malware invisible
TikTok “Invisible Challenge” porn malware puts us all at risk
Lockheed Martin’s Army cyber training platform goes civilian

The end of year holidays mark the busiest time of the year for online shoppers. We’re all rushing around trying to find the right gift that doesn’t break the budget. Throw in family time and stress can get out of hand. Sadly, this time also marks one of the busiest times of year for online […]

RansomBoggs: New ransomware targeting Ukraine

ESET researchers spot a new ransomware campaign that goes after Ukrainian organizations and has Sandworm’s fingerprints all over it The post RansomBoggs: New ransomware targeting Ukraine appeared first on WeLiveSecurity

The five cyber attack techniques of the apocalypse

USN-5745-1 introduced a regression in shadow.

Sysstat could be made to crash or run programs if it processed specially crafted data.

Sysstat could be made to crash or run programs if it processed specially crafted data.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Sandworm gang launches Monster ransomware attacks on Ukraine
International cops arrest hundreds of fraudsters, money launderers and cocaine kingpins
Blockchain couldn’t stop TXT spam in India, regulator now trying AI

security update

AWS releases Wickr, its encrypted messaging service for enterprises
Windows Server domain controllers may stop, restart after recent updates
Want to boost your cyber security skills by playing games this Christmas?
An Enterprises Guide To Strengthening Linux Cloud Security

It was discovered that twisted, a framework for internet applications written in Python, was prone to an HTML injection when displaying the HTTP Host header in an error page.

It was discovered that twisted, a framework for internet applications written in Python, was prone to an HTML injection when displaying the HTTP Host header in an error page.

An update that fixes 8 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Chrome fixes 8th zero-day of 2022 – check your version now

security update

US bans Chinese telecoms imports – won’t even consider authorizing them
Spyware posing as VPN apps – Week in security with Tony Anscombe

The Bahamut APT group distributes at least eight malicious apps that pilfer victims’ data and monitor their messages and conversations The post Spyware posing as VPN apps – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

security update