Menu

Latest articles

Multiple vulnerabilities have been discovered in virglrenderer, the worst of which could result in remote code execution.

Multiple vulnerabilities have been discovered in Wireshark, the worst of which could result in denial of service.

Several security issues were fixed in the Linux kernel.

ESET research into POLONIUM’s arsenal – Week in security with Tony Anscombe

More than a dozen organizations operating in various verticals were attacked by the threat actor The post ESET research into POLONIUM’s arsenal – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Infosec still (mostly) a boys club

Multiple security issues were found in Django, a Python web development framework, which could result in denial of service, SQL injection or cross-site scripting.

‘Baby Al Capone’ to pay $22m to SIM-swap crypto-heist victim

The package linux-zen before version 6.0.1.zen2-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

The package linux-lts before version 5.15.73-3 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

The package linux before version 6.0.1.arch2-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

The package linux-hardened before version 5.19.15.hardened2-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

security update

FYI: Microsoft Office 365 Message Encryption relies on insecure block cipher
Store credit card numbers in a debug log, lose millions of accounts. Cost? $1.9m
Serious Security: Microsoft Office 365 attacked over feeble encryption
Life in pursuit of answers: In the words of Ada Yonath

From a little girl financially helping her family in Jerusalem to a Nobel Prize laureate. That is the exceptional life of Ada Yonath in a nutshell. The post Life in pursuit of answers: In the words of Ada Yonath appeared first on WeLiveSecurity

Several security issues were fixed in gThumb.

An update that solves 8 vulnerabilities and has 12 fixes is now available.

An update that solves 8 vulnerabilities and has 11 fixes is now available.

An update that solves 5 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves 9 vulnerabilities, contains 12 features and has 38 fixes is now available.

Just how critical is data sovereignty?
LockBit 3.0 malware forced NHS tech supplier to shut down hosted sites
India set to extend deadline for absurd infosec reporting requirements
Mormon Church IT ransacked, data stolen by ‘state-sponsored’ cyber-thieves
Banks face their ‘darkest hour’ as malware steps up, maker of antivirus says

security update

How scammers target Zelle users – and how you can stay safe

Fraudsters use various tactics to separate people from their hard-earned cash on Zelle. Here’s how to keep your money safe while using the popular P2P payment service. The post How scammers target Zelle users – and how you can stay safe appeared first on WeLiveSecurity

S3 Ep104: Should hospital ransomware attackers be locked up for life? [Audio + Text]
Insurer Medibank hit by targeted cyberattack

Several security issues were fixed in unzip.

XML Security Library could be made to crash if it opened a specially crafted file.

Heat left by users’ fingertips could help hackers crack passwords, researchers claim

An update that fixes two vulnerabilities is now available.

An update is now available for the Red Hat build of Quarkus Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each

Get ready to defend your data against cyber warfare
Financial watchdogs want to know what traders are talking about on WhatsApp

An update that fixes one vulnerability is now available.

Scanning phones to detect child abuse evidence is harmful, ‘magical’ thinking

Red Hat OpenShift Container Platform release 4.8.51 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.8.

Prison inmate accused of orchestrating $11M fraud using cell cellphone
Smashing Security podcast #293: Massive crypto bungle, and the slave scammers
US election workers slammed with phishing, malware-stuffed emails
Hospital giant’s IT still poorly a week after suspected ransomware infection
Patch Tuesday in brief – one 0-day fixed, but no patches for Exchange!
POLONIUM targets Israel with Creepy malware

ESET researchers analyzed previously undocumented custom backdoors and cyberespionage tools deployed in Israel by the POLONIUM APT group The post POLONIUM targets Israel with Creepy malware appeared first on WeLiveSecurity

Microsoft tries to Ignite interest in DevOps cloud security tweaks
Internet outages hit Ukraine following Russian missile strikes

It was discovered that insufficient validation of “vnd.libreoffice.command” URI schemes could result in the execution of arbitrary macro commands.

Patch your iPhone now against mystery Mail crash bug

Several security issues were fixed in AdvanceCOMP.

A command injection vulnerability was found in Rexical, a lexical scanner generator for the Ruby programming language. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user

Multiple vulnerabilities were discovered in Nokogiri, an HTML/XML/SAX/Reader parser for the Ruby programming language, leading to command injection, XML external entity injection (XXE), and denial-of-service (DoS).

Red Hat AMQ Broker 7.10.1 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for expat is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

How Wi-Fi spy drones snooped on financial firm
Crypto exchange Bittrex coughs up $53m to end claims of US sanctions busting
“Stealing the crown jewels” – see me talk at UK Cyber Week
It’s Patch Tuesday and still no fix for ProxyNotShell Microsoft Exchange holes
Steam account stolen? Here’s how to get it back

Has your Steam account been hacked? Here are the signs to look for and what you can do to get your account back. The post Steam account stolen? Here’s how to get it back appeared first on WeLiveSecurity

Move over Patch Tuesday – it’s Ada Lovelace Day!
China could use Digital Yuan to swerve Russia-style sanctions
If you’re wondering why Google blew $5b on Mandiant, this may shed some light

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

The Most Important Things you Can do to Quickly Secure Ubuntu Linux

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Fortinet warns of critical flaw in its security appliance OSes, admin panels
Cloud security is the new battle zone
Kolide gives you real-time fleet visibility across Mac, Windows, and Linux, answering questions MDMs can’t
Can IAM help save on cyber insurance?
Optus data breach prompts pincer movement of twin regulatory probes
Toyota dev left key to customer info on public GitHub page for five years
Mystery iPhone update patches against iOS 16 mail crash-attack
Pro-Putin goons claim responsibility for blowing US airport websites offline
Intel Alder Lake BIOS code leak may contain vital secrets
Red Hat backs CNCF project, spills TEE support over Kubernetes
Endor Labs offers dependency management platform for open source software
Serious Security: OAuth 2 and why Microsoft is finally forcing you into it

Evgeny Vereshchagin discovered multiple vulnerabilities in D-Bus, a simple interprocess messaging system, which may result in denial of service by an authenticated user.

It’s 2022 and netizens are only now getting serious about cybersecurity

Several security vulnerabilities were discovered in WordPress, a popular content management framework. Server Side Request Forgery and cross-site scripting (XSS) attacks may facilitate the bypass of access controls or the injection of client-side scripts.

Singtel confirms digital burglary at Dialog subsidiary
Criminal multitool LilithBot arrives on malware-as-a-service scene
How do you protect your online systems? Cultivate an insider threat

A security issue was fixed in nginx’s lua module.

Mastercard moves to protect ‘risky and frisky’ crypto transactions

Security fix for CVE-2022-38784

That thing to help protect internet traffic from hijacking? It’s broken
When are we gonna stop calling it ransomware? It’s just data kidnapping now

There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the ‘err_msg’ of ‘sqlite3_exec’ is not releasing after use, while libxml2 emphasizes that the caller needs to release it. (CVE-2021-42523)

A syntactically invalid type signature with incorrectly nested parentheses and curly brackets would cause an assertion failure in debug builds. Similar messages could potentially result in a crash or incorrect message processing in a production build, although we are not aware of a practical example. (CVE-2022-42010)

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. (CVE-2022-41322)

libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). (CVE-2020-29260) References: – https://bugs.mageia.org/show_bug.cgi?id=30917

Core Fixed bug GH-9323 (Crash in ZEND_RETURN/GC/zend_call_function) Fixed bug GH-9361 (Segmentation fault on script exit #9379). Fixed bug GH-9407 (LSP error in eval’d code refers to wrong class for static type).

Non-Responsive Delegation Attack. (CVE-2022-3204) Improves performance when under load, by cutting promiscuous queries for nameserver discovery and limiting the number of times a delegation point can look in the cache for missing records.