Menu

Latest articles

Several security issues were fixed in ImageMagick.

Several security issues were fixed in ImageMagick.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

European Parliament Putin things back together after cyber attack

The risk of becoming a victim of identity theft has never been greater We are increasingly living our lives in the digital realm. Whether we’re banking, purchasing or browsing, our daily activities are most likely taking place online. Not only has this sped up our efficiency, but it has also expanded our exposure to a […]

Smashing Security podcast #299: EV charging risks, FTX, and an ancient apocalypse

security update

Still using a discontinued Boa web server? Microsoft warns of supply chain attacks
Hive ransomware has extorted $100 million in 18 months, FBI warns
CryptoRom “pig butchering” scam sites seized, suspects arrested in US
Security fatigue is real: Here’s how to overcome it

Do your employees take more risks with valuable data because they’ve become desensitized to security guidance? Spot the symptoms before it’s too late. The post Security fatigue is real: Here’s how to overcome it appeared first on WeLiveSecurity

Several security issues were fixed in MariaDB.

Expat could be made to crash or execute arbitrary code.

Expat could be made to crash or execute arbitrary code.

APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.

APR-util could be made to crash or leak sensitive information if it opened a specially crafted SDBM file.

Understanding open source software supply chain risks

An update that fixes one vulnerability is now available.

‘Pig butchering’ romance scam domains seized and slaughtered by the Feds
For two years security experts have been secretly decrypting systems for Zeppelin ransomware victims
DraftKings gamblers lose $300,000 to credential stuffing attack
AWS fixes ‘confused deputy’ vulnerability in AppSync
How to hack an unpatched Exchange server with rogue PowerShell code
Latest insights on APT activity – Week in security with Tony Anscombe

What have some of the world’s most notorious APT groups been up to lately? A new ESET report released this week has the answers. The post Latest insights on APT activity – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Ouch! Ransomware gang says it won’t attack AirAsia again due to the “chaotic organisation” and sloppy security of hacked airline’s network

Several security issues were fixed in FreeRDP.

Several security issues were fixed in FreeRDP.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 10 vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

Microsoft’s attempts to harden Kerberos authentication broke it on Windows Servers
World Cup phishing emails spike in Middle Eastern countries
How social media scammers buy time to steal your 2FA codes
US offshore oil and gas installation at ‘increasing’ risk of cyberattack
Cyber security pros: move to the next level next year
Keeping Your Private Files Private: An Introduction to GNU Privacy Guard

An update that fixes two vulnerabilities is now available.

An update that solves 10 vulnerabilities, contains 10 features and has three fixes is now available.

An update that solves 10 vulnerabilities, contains 10 features and has three fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

Google looking outside the usual channels to fix security skills gap
Serendipitous discovery nets security researcher $70k bounty

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

Tor vs. VPN: Which should you choose?

Both Tor and a VPN can greatly help you keep prying eyes away from your online life, but they’re also two very different beasts. Which is better for you? The post Tor vs. VPN: Which should you choose? appeared first on WeLiveSecurity

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting

Greg Hudson discovered integer overflow flaws in the PAC parsing in krb5, the MIT implementation of Kerberos, which may result in remote code execution (in a KDC, kadmin, or GSS or Kerberos application server process), information exposure (to a cross-realm KDC acting

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

security update

Hive ransomware crooks extort $100m from 1,300 global victims

security update

security update

Police force published sexual assault victims’ names and addresses on its website
Red Hat Enterprise Linux and Microsoft security update of November 2022
Hardware-assisted encryption of data in use gets confidential

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 18 vulnerabilities, contains one feature is now available.

An update that fixes 52 vulnerabilities, contains one feature is now available.

An update that fixes 52 vulnerabilities, contains one feature is now available.

Z-Library operators arrested, charged with criminal copyright infringement
Israel sets robotic target-tracking turrets in the West Bank
Security firms hijack New York trees to monitor private workforce

security update

S3 Ep109: How one leaked email password could drain your business
Open banking: Tell me what you buy, and I’ll tell you who you are

The convenience with which you manage all your financial wants and needs may come at a cost The post Open banking: Tell me what you buy, and I’ll tell you who you are appeared first on WeLiveSecurity

Google wins lawsuit against alleged Russian botnet herders

It was discovered that php-phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v2), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific

It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations.

It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations.

Black Friday and retail season – watch out for PayPal “money request” scams

Expat could be made to crash or execute arbitrary code.

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler,

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a heap-based buffer over-read. This can be triggered by arbitrary local users with access to Sudo by entering a password of seven characters or fewer. The impact could vary depending on the system libraries, compiler,

Notorious Emotet botnet returns after a few months off
Smashing Security podcast #298: Housing market scams, Twitter 2FA, and the fesshole

security update

Iranian cyberspies exploited Log4j to break into a US govt network
Germany says nein to Qatari World Cup spyware, err, apps

security update

security update

security update

WASP malware stings Python developers
Firefox fixes fullscreen fakery flaw – get the update now!
Cloud vendors should take some responsibility for stolen compute, says Canalys CEO

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550) * xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 xorg-x11-server-Xephyr-1.20.4-19.el7_9.x86_64.rpm xorg- [More…]