Menu

Latest articles

security update

Google, Apple squash exploitable browser bugs

security update

security update

security update

security update

Software developer cracks Hyundai car security with Google search
After 7 years, long-term threat DarkTortilla crypter is still evolving

The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-32792

How to stop the evil lurking in the shadows
TikTok wants your trust around US midterm elections data
APT Lazarus Targets Engineers with macOS Malware
Chrome browser gets 11 security fixes with 1 zero-day – update now!

USN-5526-1 introduced a regression in PyJWT.

Kubescape boosts Kubernetes scanning capabilities

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-32792

Mozilla finds 18 of 25 popular reproductive health apps leak data
Russian military uses Chinese drones and bots in combat, over manufacturers’ protests

The container suse/sles12sp4 was updated. The following patches have been included in this update:

RubyGems now requires multi-factor auth for top package maintainers
SEC says brokerage accounts hijacked for $1.3m pump-and-dump scam

Update to yara-4.2.3 —- Update to 4.2.0 —- Update to 4.2.2

Update to yara-4.2.3 —- Update to 4.2.0 —- Update to 4.2.2

security update

US offers reward “up to $10 million” for information about the Conti gang
Do you know what’s happening on your users’ devices?
U.K. Water Supplier Hit with Clop Ransomware Attack
Microsoft’s macOS Tamper Protection hits general availability
1,900 Signal users exposed: Twilio attacker ‘explicitly’ looked for certain numbers
DEF CON – “don’t worry, the elections are safe” edition

Don’t worry, elections are safe. Our Security Researcher Cameron Camp provide us highlights from the DEF CON 30 conference. The post DEF CON – “don’t worry, the elections are safe” edition appeared first on WeLiveSecurity

Xiaomi Phone Bug Allowed Payment Forgery

An update that solves one vulnerability, contains one feature and has 7 fixes is now available.

An update that fixes 22 vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Reckon Russian spies are lurking in your inbox? Check for these IOCs, Microsoft says
How a spoofed email passed the SPF check and landed in my inbox

The Sender Policy Framework can’t help prevent spam and phishing if you allow billions of IP addresses to send as your domain The post How a spoofed email passed the SPF check and landed in my inbox appeared first on WeLiveSecurity

Digital Ocean dumps Mailchimp after attack leaked customer email addresses
It’s 2022 and there are still thousands of public systems using password-less VNC
Oh Deere: Farm hardware jailbroken to run Doom
CIA accused of illegally spying on Americans visiting Assange in embassy
Dutch authorities arrest 29-year-old dev with suspected ties to Tornado Cash
Zoom for Mac patches get-root bug – update now!
Black Hat and DEF CON Roundup
Open Source OSINT Tools and Techniques

An update that fixes three vulnerabilities is now available.

Black Hat USA 2022: Burnout, a significant issue

The digital skills gap, especially in cybersecurity, is not a new phenomenon. This problematic is now exacerbate by the prevalence of burnout, which was presented at Black Hat USA 2022 The post Black Hat USA 2022: Burnout, a significant issue appeared first on WeLiveSecurity

Black Hat – Windows isn’t the only mass casualty platform anymore

Windows used to be the big talking point when it came to exploits resulting in mass casualties. Nowadays, talks turned to other massive attack platforms like #cloud and cars The post Black Hat – Windows isn’t the only mass casualty platform anymore appeared first on WeLiveSecurity

Several security issues were fixed in WebKitGTK.

An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for collectd-libpod-stats is now available for Red Hat OpenStack Platform 16.2 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for collectd-libpod-stats is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Indian military ready to put long-range quantum key distribution on the line
Black Hat and DEF CON visitors differ on physical risk management
Elon Musk wrote article for China’s internet regulator, hinted at aged care robots

Multiple vulnerabilities have been discovered in libarchive, the worst of which could result in arbitrary code execution.

Multiple vulnerabilities have been discovered in QEMU, the worst of which could result in remote code execution (guest sandbox escape).

Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution.

Multiple vulnerabilities have been discovered in the GNU C Library, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in Xen, the worst of which could result in remote code execution (guest sandbox escape).

The 5.18.17 stable kernel update contains a number of important fixes across the tree.

security update

The potential consequences of data breach, and romance scams – Week in security with Tony Anscombe

The NHS was victim of a potential cyberattack, which raises the question of the impact of those data breach for the public. The post The potential consequences of data breach, and romance scams – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Black Hat 2022‑ Cyberdefense in a global threats era

Our Security evangelist’s take on this first day of Black Hat 2022, where cyberdefense was on every mind. The post Black Hat 2022‑ Cyberdefense in a global threats era appeared first on WeLiveSecurity

Safety first: how to tweak the settings on your dating apps

Tinder, Bumble or Grindr – popular dating apps depend heavily on your location, personal data, and loose privacy settings. Find out how to put yourself out there safely by following our suggested settings tweaks. The post Safety first: how to tweak the settings on your dating apps appeared first on WeLiveSecurity

Ukraine’s cyber chief comes to Black Hat in surprise visit

The container bci/bci-micro was updated. The following patches have been included in this update:

A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit (CVE-2022-34526) References: – https://bugs.mageia.org/show_bug.cgi?id=30716

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service. (CVE-2022-32189) References:

A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. (CVE-2022-27337) References:

An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected. (CVE-2022-34265)

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. (CVE-2022-29970) References: – https://bugs.mageia.org/show_bug.cgi?id=30542

Let there be ambient light sensing, without fear of data theft
Palo Alto bug used for DDoS attacks and there’s no fix yet
Starlink satellite dish cracked on stage at Black Hat

security update

US reveals ‘Target’ pic of Conti man with $10m reward offer
Feds: Zeppelin Ransomware Resurfaces with New Compromise, Encryption Tactics
Microsoft trumps Google for 2021-22 bug bounty payouts
An eighties classic – Zero Trust

A deep-dive in Zero-trust, to help you navigate in a zero-trust world and further secure your organization. The post An eighties classic – Zero Trust appeared first on WeLiveSecurity

Intel ups protection against physical chip attacks in Alder Lake
Facebook’s In-app Browser on iOS Tracks ‘Anything You Do on Any Website’
Emergency services call-handling provider: Ransomware forced it to pull servers offline

An update that fixes one vulnerability is now available.

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in HTTP request smuggling, cache poisoning or information disclosure.

Ransomware attack blamed for closure of all 7-Eleven stores in Denmark
Chinese criminals scam kids desperate to play games for more than three hours a week

The container bci/rust was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

FAANGs failing on keeping user data safe from bug hunters
Higher risks and premiums are creating critical gap in cyber insurance
Security needs to learn from the aviation biz to avoid crashing
Russian invasion has dangerously destabilized cyber security norms
AWS and Splunk partner for faster cyberattack response
Ex-CIA security boss predicts coming crackdown on spyware