Menu

Latest articles

It’s past time to figure out cross-cloud security
Staying safe online: How to browse the web securely

Learn to spot some of the threats that you can face while browsing online, and the best tips to stay safe on the web. The post Staying safe online: How to browse the web securely appeared first on WeLiveSecurity

BreachForums booms on the back of billion-record Chinese data leak
Businesses confess: We pass cyberattack costs onto customers
US court system suffered ‘incredibly significant attack’ – sealed files at risk
JPMorgan, UBS among trio accused of shoddy ID theft protection

security update

Suspected radiation alert saboteurs cuffed by cops after sensors disabled
Threat Actors Pivot Around Microsoft’s Macro-Blocking in Office
Cash App fraud: 10 common scams to watch out for

It pays to be careful – here’s how you can stay safe from fake giveaways, money flipping scams and other cons that fraudsters use to trick payment app users out of their hard-earned cash The post Cash App fraud: 10 common scams to watch out for appeared first on WeLiveSecurity

$10 million reward offered for information on North Korean hackers

libtirpc could be made to denial of service if it received a specially crafted input.

The Red Hat build of OpenJDK 8 (java-1.8.0-openjdk) is now available for Windows. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The Red Hat build of OpenJDK 8 (java-1.8.0-openjdk) is now available for portable Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that contains security fixes can now be installed.

An update that fixes 10 vulnerabilities is now available.

Your Linux Firewall Cant Stop These 3 Attacks!

An update that contains security fixes can now be installed.

Google brings Street View back to India following 2016 ban
Smashing Security podcast #285: Uber’s hidden hack, tips for travel, and AI accent fixes
FileWave fixes bugs that left 1,000+ orgs open to ransomware, data theft
We’re likely only seeing ‘the tip of the iceberg’ of Pegasus spyware use against the US

security update

security update

Uber’s former head of security faces fraud charges after allegedly covering up data breach
US puts $10 million bounty on North Korean cyber-crews
Apple network traffic takes mysterious detour through Russia
AWS ups security for Elastic Block Store, Kubernetes service
Messaging Apps Tapped as Platform for Cybercriminal Activity
Knotweed Euro cyber mercenaries attacking private sector, says Microsoft
Time from vulnerability disclosures to exploits is shrinking

Red Hat Advanced Cluster Management for Kubernetes 2.5.1 General Availability release images, which fix security issues and bugs. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

An update for java-11-openjdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update is now available for Red Hat build of Quarkus. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For more

An update for kernel is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Weak data protection helped China attack US Federal Reserve, report says
Build SBOMs with Microsoft’s internal tool
IBM puts NIST’s quantum-resistant crypto to work in Z16 mainframe
Vietnamese attacker circumvents Facebook security with ‘DUCKTAIL’ malware
Charter told to pay $7.3b in damages after cable installer murders grandmother
Mild monthly security update from Firefox – but update anyway
Crypto exchange Kraken reportedly hunted by the Feds for alleged sanctions busting
Culture shock: Ransomware gang sacks arts orgs’ email lists
Novel Malware Hijacks Facebook Business Accounts
Luca Stealer malware spreads rapidly after code handily appears on GitHub
With ransomware, the road to recovery starts well before you’re attacked
Ransomware less popular this year, but malware up: SonicWall cyber threat report
CrowdStrike enhances container visibility and threat hunting capabilities
Cyber security training to fit your summer plans
Testing times for AV-Test as Twitter account hijacked by NFT spammers
Phishing Attacks Skyrocket with Microsoft and Facebook as Most Abused Brands

An update for grafana is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which

IoT Botnets Fuels DDoS Attacks – Are You Prepared?

Update to the latest bugfixes (1-5) against 5.4.4. Includes fixes for CVE-2022-28805 and CVE-2022-33099.

Bottle could be made to leak sensitive information if it received a specially crafted request.

Enhancing RHEL Security: Understanding SHA-1 deprecation on RHEL 9
Practical Guide to Using End-to-end Encryption (E2EE) on Linux
7 biggest Kubernetes security mistakes

It was discovered that SPIP, a website engine for publishing, would allow a malicious user to execute arbitrary code or escalate privileges. For the oldstable distribution (buster), this problem has been fixed

LockBit ransomware gang claims it ransacked Italy’s tax agency

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/389-ds was updated. The following patches have been included in this update:

security update

Node.js prototype pollution is bad for your app environment
T-Mobile US to cough up $550m after info stolen on 77m customers

security update

Twitter launches probe after miscreants claims to have swiped 5.4m users’ details

The RSA Conference 2022 – one of the world’s premier IT security conferences – was held June 6th-9th in San Francisco. The first in-person event for RSA since the global pandemic had a slightly lower turnout than in years past (26,000 compared to 36,000 attendees). But attendees and presenters alike made up for it with […]

Simon Josefsson discovered an out-of-bounds memory read in GNU SASL, an implementation of the Simple Authentication and Security Layer framework, which could result in denial of service.

Cyber-mercenaries for hire represent shifting criminal business model
T-Mobile to cough up $500 million over 2021 data breach
DoJ approves Google’s acquisition of Mandiant
Infosec not your job but your responsibility? How to be smarter than the average bear

An update that contains security fixes can now be installed.

Why Physical Security Maintenance Should Never Be an Afterthought
Realizing your software has a vulnerability is bad. Realizing you’ve shipped it to thousands of customers…
NFT: A new‑fangled trend or also a new‑found treasure?

I’ve created an NFT so you don’t have to – here’s the good, the bad and the intangible of the hot-ticket tokens The post NFT: A new‑fangled trend or also a new‑found treasure? appeared first on WeLiveSecurity

PHP could be made to crash or run programs if it processed specially crafted data.

This update provides the upstream 6.1.36 maintenance release that fixes at least the following security vulnerabilities: A vulnerability in the Oracle VM VirtualBox prior to 6.1.36 contains an easily exploitable vulnerability that allows a high privileged attacker

Apply proposed patch for CVE-2022-28506.

An update that solves 8 vulnerabilities and has one errata is now available.

An update that solves 8 vulnerabilities and has one errata is now available.

security update

security update

macOS malware: myth vs. reality – Week in security with Tony Anscombe

ESET research shows yet again that macOS is not immune to malware and why some users can benefit from Apple’s Lockdown Mode The post macOS malware: myth vs. reality – Week in security with Tony Anscombe appeared first on WeLiveSecurity

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Office macro security: on-again-off-again feature now BACK ON AGAIN!
My Big Coin founder is – you guessed it – a $6m crypto-fraudster

**Changelog** “` * Thu Jul 07 2022 Clemens Lang – 1:1.1.1q-1 – Upgrade to 1.1.1q Resolves: CVE-2022-2097 “` —- “` * Thu Jun 30 2022 Clemens Lang – 1:1.1.1p-1 – Upgrade to 1.1.1p Resolves: CVE-2022-2068 Related: rhbz#2099975 “` Security fix for CVE-2022-2068

Microsoft closes off two avenues of attack: Office macros, RDP brute-forcing
Don’t dive head first into that crypto pool, FBI warns

An update that fixes one vulnerability is now available.

At the edge, nobody can hear your IoT devices scream …

An update that solves two vulnerabilities and has one errata is now available.