Menu

Latest articles

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

British intelligence recycles old argument for thwarting strong encryption: Think of the children!
Russia, Iran discuss tech manufacturing, infosec and e-governance collaboration

security update

Ex-Coinbase manager charged in first-ever crypto insider trading case
US Cyber Command spots another 20 malware strains targeting Ukraine
Last member of Gozi malware troika arrives in US for criminal trial
ESET Research Podcast: Hot security topics at RSA or mostly hype?

Listen to Cameron Camp, Juraj Jánošík, and Filip Mazán discuss the use of machine learning in cybersecurity, followed by Cameron’s insights into the security of medical devices The post ESET Research Podcast: Hot security topics at RSA or mostly hype? appeared first on WeLiveSecurity

S3 Ep92: Log4Shell4Ever, travel tips, and scamminess [Audio + Text]
Simplifying backup and recovery management

This update fixes many bugs some of which are security relevant.

Security fixes for CVE-2022-2257, CVE-2022-2284, CVE-2022-2285, CVE-2022-2286, CVE-2022-2287, CVE-2022-2288, CVE-2022-2289, CVE-2022-2264, CVE-2022-2304, CVE-2022-2345, CVE-2022-2344, CVE-2022-2343.

Hackers for Hire: Adversaries Employ ‘Cyber Mercenaries’

This update fixes many bugs some of which are security relevant.

Apple patches “0-day” browser bug fixed 2 weeks ago in Chrome, Edge
DataDome looks to CAPTCHA the moment with test of humanity that doesn’t hurt
Complete Guide to Vulnerability Basics

An update that solves 9 vulnerabilities and has four fixes is now available.

Outlook email users alerted to suspicious activity from Microsoft-owned IP address
What does software supply chain pain really feel like? Find out right here

The container bci/nodejs was updated. The following patches have been included in this update:

An update that fixes three vulnerabilities is now available.

Atlassian reveals critical flaws in almost everything it makes and touches
Suspected Gozi malware gang ‘CIO’ extradited to US on fraud, hacking charges
Smashing Security podcast #284: The Most Wanted Missing CryptoQueen
Google: Kremlin-backed goons spread Android malware disguised as pro-Ukraine app
Boffins release tool to decrypt Intel microcode. Have at it, x86 giant says
I see what you did there: A look at the CloudMensis macOS spyware

Previously unknown macOS malware uses cloud storage as its C&C channel and to exfiltrate documents, keystrokes, and screen captures from compromised Macs The post I see what you did there: A look at the CloudMensis macOS spyware appeared first on WeLiveSecurity

More malware-infested apps, downloaded millions of times, found in the Google Play store
DoJ, FBI recover $500,000 in ransomware payments to Maui gang
Clunk flush! Bexplus cryptocurrency exchange closes suddenly, giving its users only 24 hours to withdraw funds

Red Hat OpenStack Platform 16.2 (Train) director operator containers, with several Important security fixes, are available for technology preview. 2. Description: Release osp-director-operator images

Conti’s Reign of Chaos: Costa Rica in the Crosshairs
Magecart Serves Up Card Skimmers on Restaurant-Ordering Systems

Apache XML Security for Java could be made to expose sensitive information.

An update that fixes one vulnerability is now available.

Several security issues were fixed in FreeType.

Several security issues were fixed in Checkmk.

Singapore distances itself from local crypto companies

The container suse-sles-15-sp3-chost-byos-v20220718-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

Amazon sues 10,000 Facebook Group admins for offering fake reviews
Belgium says Chinese cyber gangs attacked its government and military
Security flaws in GPS trackers can be abused to cut off fuel to vehicles, CISA warns
Google pulls malware-infected apps in its Store, over 3 million users at risk
Authentication Risks Discovered in Okta Platform
FBI Warns Fake Crypto Apps are Bilking Investors of Millions
Who on earth would be trying to promote EC-Council University via comment spam on my website?
Hacker hijacks NFT artist DeeKay’s Twitter account, steals $150,000 worth of NFTs from fans

An update that fixes one vulnerability is now available.

A collaborative approach to threat modeling
Hacker’s Corner: Complete Guide to Anti-Debugging in Linux – Part 3
Walmart-controlled flight booking service suffers substantial data leak
How we’ll solve software supply chain security

HarfBuzz could be made to crash if it opened specially crafted data.

The container sles-15-sp2-chost-byos-v20220718-x86-64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp2-chost-byos-v20220718-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp2-chost-byos-v20220718-x86_64-gen2 was updated. The following patches have been included in this update:

Several security issues were fixed in LibTIFF.

Jailed crooks told to cough up $600k for COVID fraud
Bogus cryptocurrency apps steal millions in mere months
Botnet malware disguises itself as password cracker for industrial controllers
8 months on, US says Log4Shell will be around for “a decade or longer”
Albanian government websites go dark after cyberattack
Microsoft’s latest security patch troubles Windows 11 users

HTTP-Daemon could allow HTTP Request Smuggling attacks.

Google Boots Multiple Malware-laced Android Apps from Marketplace
CISA Urges Patch of Exploited Windows 11 Bug by Aug. 2
Securing data at rest and data in motion

An update that solves 11 vulnerabilities and has 44 fixes is now available.

An update that fixes four vulnerabilities is now available.

An update that solves 10 vulnerabilities, contains one feature and has 43 fixes is now available.

An update that solves 9 vulnerabilities and has 9 fixes is now available.

The container sles-15-sp1-chost-byos-v20220715-x86-64 was updated. The following patches have been included in this update:

Bill for US telcos to bin Chinese kit blows out by $3 billion
TikTok’s chief security officer steps aside, thanks to Oracle move
Alibaba execs hauled in to discuss Shanghai Police data leak

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/bci-minimal was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs — This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: – CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode – CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar […]

Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs — This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: – CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode – CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar […]

security update

security update

An update that fixes 5 vulnerabilities is now available.

Think twice before downloading pirated games – Week in security with Tony Anscombe

Why downloading pirated video games may ultimately cost you dearly and how to stay safe while gaming online The post Think twice before downloading pirated games – Week in security with Tony Anscombe appeared first on WeLiveSecurity

North Koreans spotted harassing SMBs with malware

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-micro was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

**Version 2.13.0** Enhancement * 106: Refined types as per laminas/laminas- coding-standard:2.3.x upgrades thanks to @Ocramius * 103: Update to laminas/laminas-coding-standard:2.3.x, improved types and internal API thanks to @gsteel —- **Version 2.12.0** Bug * 99: Merge release 2.11.3 into 2.12.x thanks to @github-actions[bot] * 92: Fix typo in property name in

CISA pulls the fire alarm on Juniper Networks bugs
Thousands of websites run buggy WordPress plugin that allows complete takeover
API security moves mainstream

The heavyweights are now moving into API security, cementing it as “A Thing” The post API security moves mainstream appeared first on WeLiveSecurity

Emerging H0lyGh0st Ransomware Tied to North Korea
7 cybersecurity tips for your summer vacation!