Menu

Latest articles

Non-Responsive Delegation Attack. (CVE-2022-3204) Improves performance when under load, by cutting promiscuous queries for nameserver discovery and limiting the number of times a delegation point can look in the cache for missing records.

Key takeaways from ESET Threat Report T2 2022 – Week in security with Tony Anscombe

A look back on the key trends and developments that shaped the cyberthreat landscape from May to August of this year The post Key takeaways from ESET Threat Report T2 2022 – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Update to the September 2022 update release of .NET Core 3.1 Release Notes: https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.29/3.1.29.md This includes a fix for CVE-2022-38013

Security fix for CVE-2022-21797

Update to the September 2022 update release of .NET Core 3.1 Release Notes: https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.29/3.1.29.md This includes a fix for CVE-2022-38013

Open source incident response solutions
What is the Confidential Containers project?
Biden’s Privacy Shield 2.0 order may not satisfy Europe
Make your neighbor think their house is haunted by blinking their Ikea smart bulbs

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

security update

security update

Binance robbed of $600 million in crypto-tokens
The need to change cybersecurity for the next generation

Healthy habits that are instilled and nurtured at an early age bring lifelong benefits – the same applies to good cybersecurity habits The post The need to change cybersecurity for the next generation appeared first on WeLiveSecurity

ESET Threat Report T2 2022

A view of the T2 2022 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T2 2022 appeared first on WeLiveSecurity

WhatsApp goes after Chinese password scammers via US court
Utility security is so bad, US DoE offers rate cuts to improve it

Security fix for CVE-2022-38784

Some stability fixes. —- Update to 2.53.14 Note that besides the ordinary builds for the current Fedora and EPEL branches, there is an additional distro- independed build available at https://buc.fedorapeople.org/seamonkey . So if you have friends who use other Linux distro, but that distro does not provide SeaMonkey yet, you can recommend it for them.

Rebase to 2.4.9

**Version 3.4.3** (2022-09-28) * Fix a security issue on filesystem loader (possibility to load a template outside a configured directory)

**Version 2.15.3** (2022-09-28) * Fix a security issue on filesystem loader (possibility to load a template outside a configured directory)

Updated to version 0.10.2 with CVE fix.

Loads of PostgreSQL systems are sitting on the internet without SSL encryption
Hardening data security in the cloud
Top of the Pops: US authorities list the 20 hottest vulns that China’s hackers love to hit
Lloyd’s of London reboots after dodgy network activity detected
Huge nonprofit hospital network suffers IT meltdown after ‘security incident’
NetWalker ransomware affiliate sentenced to 20 years by Florida court
Papa John’s sued for ‘wiretap’ spying on website mouse clicks, keystrokes
Foreign spies hijacking US mid-terms? FBI, CISA are cool as cucumbers about it
S3 Ep103: Scammers in the Slammer (and other stories) [Audio + Text]

expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 expat-2.1.0-15.el7_9.i686.rpm expat-2.1.0-15.el7_9.x86_64.rpm expat-debuginfo-2.1.0-15.el7_9.i686.rpm expat-debuginfo-2.1.0-15.el7_9.x86_ [More…]

squid: buffer-over-read in SSPI and SMB authentication (CVE-2022-41318) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 squid-3.5.20-17.el7_9.8.x86_64.rpm squid-debuginfo-3.5.20-17.el7_9.8.x86_64.rpm squid-migration-script-3.5.20-17.el7_9.8.x86_64.rpm squid-sysvinit [More…]

Australian Federal Police arrest man suspected of exploiting Optus cyberattack

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Smashing Security podcast #292: Trussterflucks and eBay stalking
Learning from real life situations
Former Uber CSO convicted of covering up megabreach back in 2016
Former Uber CSO convicted for covering up massive 2016 data theft
NetWalker ransomware scumbag jailed for 20 years

security update

security update

security update

Cyber-snoops broke into US military contractor, stole data, hid for months

Several security issues were fixed in DHCP.

Several vulnerabilities were discovered in BIND, a DNS server implementation. CVE-2022-2795

Multiple vulnerabilities were discovered in Node.js, a JavaScript runtime environment, which could result in memory corruption, invalid certificate validation, prototype pollution or command injection.

Don’t let your employees become the weakest link
Modified version of Tor Browser spies on Chinese users
Enterprise Encryption for Linux: Improve Manageability & Compliance

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

DoJ ‘very disappointed’ with probation sentence for Capital One hacker Paige Thompson
All your identity needs fulfilled
No Shangri-La for you: Top hotel chain confirms data leak
Uncle Sam orders federal agencies to step up scans for govt IT security holes
How a deepfake Mark Ruffalo scammed half a million dollars from a lonely heart
8 questions to ask yourself before getting a home security camera

As each new smart home device may pose a privacy and security risk, do you know what to look out for before inviting a security camera into your home? The post 8 questions to ask yourself before getting a home security camera appeared first on WeLiveSecurity

Microsoft: Watch out for password spray attacks – especially you, Basic Auth
CISA orders federal agencies to catalog their networks, and scan for bugs
Romance scammer and BEC fraudster sent to prison for 25 years

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Rocky Linux Security Advisories Are Now on LinuxSecurity.com!
Kolide can help you nail audits and compliance goals with endpoint security for your entire fleet
Japanese sushi chain boss resigns amid accusation of improper data access
Giveaways for every security professional
Atlassian, Microsoft bugs on CISA’s must-patch list after exploitation spree
Scammers and rogue callers – can anything ever stop them?
Online romance scamlord who netted $9.5m jailed for 25 years

security update

From today, America and UK follow new rules on how they can demand your data from each other
It’s 2058. A quantum computer is just another decade away. Still, you curse Cloudflare
National Cybersecurity Awareness program 18 years on: Don’t click that
Student data leaked after LA school district says it won’t pay ransom
There’s good and bad news about the Microsoft Exchange server zero-day exploit
FBI: We tracked who was printing secret documents to unmask ex-NSA suspect
Cyber-proofing data in the cloud

Several security issues were fixed in the Linux kernel.

Founder of cybersecurity firm Acronis is afraid of his own vacuum cleaner
Between ransomware and month-long engagements, IR teams need a hug – and a nap

An update that fixes three vulnerabilities is now available.

This update includes the changes in tzdata 2022d for the Perl bindings. For the list of changes, see DLA-3134-1. For Debian 10 buster, this problem has been fixed in version

Moody’s turns up the heat on ‘riskiest’ sectors for cyberattacks

This update includes the changes in tzdata 2022d. Notable changes are: – – Palestine now switches back to standard time on October 29.

An invalid HTTP request (websocket handshake) may cause a NULL pointer dereference in the wstunnel module. For Debian 10 buster, this problem has been fixed in version

Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.