Menu

Latest articles

Pentagon: We’ll pay you if you can find a way to hack us
Cyberattacks: A very real existential threat to organizations

One in five organizations have teetered on the brink of insolvency after a cyberattack. Can your company keep hackers at bay? The post Cyberattacks: A very real existential threat to organizations appeared first on WeLiveSecurity

Calls for bans on Chinese CCTV makers Hikvision, Dahua expand
Google patches “in-the-wild” Chrome zero-day – update now!
How to spot your biggest security threat? Just look out for the humans
Latest Cyberattack Against Iran Part of Ongoing Campaign
Germany unveils plan to tackle cyberattacks on satellites
Google Patches Actively Exploited Chrome Bug

GnuPG could allow forged signatures.

OpenSSL could be made to expose sensitive information over the network.

An update that fixes four vulnerabilities is now available.

Which Browser is Best for Online Security?
Deprecated Linux Commands You Should Not Use Anymore (And Their Alternatives)
Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware
Alibaba’s finance arm open sources its privacy software and a ‘Secure Processing Unit’
Dutch University retrieves Bitcoin ransomware payment and makes a profit

The container suse/sle15 was updated. The following patches have been included in this update:

Billion-record stolen Chinese database for sale on breach forum

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

Google updates Chrome to squash actively exploited WebRTC Zero Day

security update

security update

How To Hide Your IP And Keep From Being Tracked
Canadian cybercriminal pleads guilty to “NetWalker” attacks in US

An update that solves three vulnerabilities and has three fixes is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Several security issues were fixed in PHP.

Official British Army Twitter and YouTube accounts hijacked by NFT scammers
Identity, trust, and their role in modern applications

An update for rh-php73-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

British Army Twitter and YouTube feeds hijacked by crypto-promos

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

What to do about inherent security flaws in critical infrastructure?

An update that fixes 5 vulnerabilities is now available.

Watch out for survey scams – Week in security with Tony Anscombe

As scammers continue to ask people to take fake surveys, can you recognize some common telltale signs you’re dealing with a scam? The post Watch out for survey scams – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Phishing scam poses as Canadian tax agency before Canada Day

The lead-up to the Canada Day festivities has brought a tax scam with it The post Phishing scam poses as Canadian tax agency before Canada Day appeared first on WeLiveSecurity

How is Red Hat addressing the demand to develop offerings more securely?
Obsolescence of ATO Pathways
Google location tracking to forget you were ever at that medical clinic

The container suse/sles12sp5 was updated. The following patches have been included in this update:

The container suse/sles12sp4 was updated. The following patches have been included in this update:

The container suse/sles12sp3 was updated. The following patches have been included in this update:

Cyberattack shuts down unemployment, labor websites across the US

An update that fixes four vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

Facebook 2FA phish arrives just 28 minutes after scam domain created
Crypto sleuths pin $100 million Harmony theft on Lazarus Group
“Missing Cryptoqueen” hits the FBI’s Ten Most Wanted list
FTC warns LGBTQ+ community of extortion scams targeting them on dating apps
AMD held to ransom by gang that claims 450GB of data has been stolen

This update upgrades Thunderbird to version 91.11. * Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI (CVE-2022-34468) * Mozilla: Use-after-free in nsSHistory (CVE-2022-34470) * Mozilla: A popup window could be resized in a way to overlay the address bar with web content (CVE-2022-34479) * Mozilla: Memory safety bugs fixed in […]

Several security vulnerabilities have been discovered in isync, an IMAP and MailDir mailbox synchronizer. An malicious attacker who can control an IMAP server may exploit these flaws for remote code execution.

This update upgrades Firefox to version 91.11 ESR. * Mozilla: CSP sandbox header without `allow-scripts` can be bypassed via retargeted javascript: URI (CVE-2022-34468) * Mozilla: Use-after-free in nsSHistory (CVE-2022-34470) * Mozilla: A popup window could be resized in a way to overlay the address bar with web content (CVE-2022-34479) * Mozilla: Memory safety bugs fixed […]

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The Migration Toolkit for Containers (MTC) 1.7.2 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Microsoft gives its partners power to change AD privileges on customer systems – without permission

An update for vim is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

OpenSea phishing threat after rogue insider leaks customer email addresses

security update

Jenkins warns of security holes in these 25 plugins
California state’s gun control websites expose personal data
ZuoRAT Can Take Over Widely Used SOHO Routers
Google battles bots, puts Workspace admins on alert
Black Basta ransomware – what you need to know
How to Spend Less Time on Web and API Security

Several security issues were fixed in Vim.

S3 Ep89: Sextortion, blockchain blunder, and an OpenSSL bugfix [Podcast + Transcript]

A heap use-after-free vulnerability was found in systemd, a system and service manager, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate

A Guide to Surviving a Ransomware Attack

Several security issues were fixed in Libjpeg6b.

Costco 40th anniversary scam targets WhatsApp users

If the promise of a cash prize in return for answering a few questions sounds like a deal that is too good to be true, that’s because it is The post Costco 40th anniversary scam targets WhatsApp users appeared first on WeLiveSecurity

Israel plans ‘Cyber-Dome’ to defeat digital attacks from Iran and others

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Start using Modern Auth now for Exchange Online

– Update to new upstream (102.0)

Leaky Access Tokens Exposed Amazon Photos of Users
Sysdig Secure update adds ability to stop container attacks at runtime
‘Prolific’ NetWalker extortionist pleads guilty to ransomware charges
Firefox 102 fixes address bar spoofing security hole (and helps with Follina!)

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or spoofing.

Patchable and Preventable Security Issues Lead Causes of Q1 Attacks
Scanning container image vulnerabilities with Clair

An update that fixes 9 vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 9 vulnerabilities is now available.

Do back offices mean backdoors?

War in Europe, a reminder for shared service centers and shoring operations to re-examine IT security posture The post Do back offices mean backdoors? appeared first on WeLiveSecurity

An update that fixes three vulnerabilities is now available.

Microsoft postpones shift to New Commerce Experience subscriptions
FBI warning: Crooks are using deepfake videos in interviews for remote gigs
Trio accused of selling $88m of pirated Avaya licenses
Walmart accused of turning blind eye to transfer fraud totaling millions of dollars

security update

security update

Guide to Web Application Penetration Testing