Menu

Latest articles

Now Windows Follina zero-day exploited to infect PCs with Qbot

security update

SSNDOB Market domains seized, identity theft “brokerage” shut down
Feds raid dark web market selling data on 24 million Americans
Taming the Digital Asset Tsunami
Intel offers ‘server on a card’ reference design for network security
Paying Ransomware Paints Bigger Bullseye on Target’s Back
Getting a list of fixes for a Red Hat product between two dates is easy with daysofrisk.pl
Joomla Security in 2022 – Best Practices To Secure Your Website
Black Basta Ransomware Teams Up with Malware Stalwart Qbot

An update that solves one vulnerability and has four fixes is now available.

MongoDB: From jokes to juggernaut

python-twisted: possible http request smuggling (CVE-2022-24801) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 python-twisted-web-12.1.0-8.el7_9.x86_64.rpm – Scientific Linux Development Team

Beijing-backed baddies target unpatched networking kit to attack telcos
US cyber chiefs: Moving to Shields Down isn’t gonna happen

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

Ukraine’s secret cyber-defense that blunts Russian attacks: Excellent backups

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

GitHub adds supply chain security tools for Rust language
RSA – Spot the real fake

How erring on the side of privacy might ultimately save you from chasing down a virtual rendition of you doing the bidding of a scammer The post RSA – Spot the real fake appeared first on WeLiveSecurity

Know your enemy! Learn how cybercrime adversaries get in…
Cyber Risk Retainers: Not Another Insurance Policy
Conducting Modern Insider Risk Investigations
Follina Exploited by State-Sponsored Hackers
Complete Guide to Keylogging in Linux: Part 2
Attackers Use Public Exploits to Throttle Atlassian Confluence Flaw

An update for rh-postgresql13-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A patch update (from 7.10.2 to 7.10.2.P1) is now available for Red Hat on OpenShift for EAP, Karaf, and Spring Boot. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact

An update for python-twisted-web is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Several security issues were fixed in ntfs-3g.

Cybersecurity awareness training: What is it and what works best?

Give employees the knowledge needed to spot the warning signs of a cyberattack and to understand when they may be putting sensitive data at risk The post Cybersecurity awareness training: What is it and what works best? appeared first on WeLiveSecurity

IBM buys Randori to address multicloud security messes
Microsoft seizes 41 domains tied to ‘Iranian phishing ring’
Cisco EVP: We need to lift everyone above the cybersecurity poverty line

Security fixes for CVE-2022-1886, CVE-2022-1942 —- Security fixes for CVE-2022-1851, CVE-2022-1898, CVE-2022-1897, CVE-2022-1927

Apple protected App Store users from $1.5 billion fraud last year

FreeRDP could allow unintended access to network services.

Several security issues were fixed in Vim.

Several security vulnerabilities were found in glib2.0, a general-purpose utility library for the GNOME environment. CVE-2021-27218

An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-nodejs12-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for rh-postgresql12-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Maximize your cloud security with isolation zones
Costa Rican government held up by ransomware … again
Yandex CEO Arkady Volozh resigns after being added to EU sanctions list

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

Security fixes for CVE-2022-1851, CVE-2022-1898, CVE-2022-1897, CVE-2022-1927

The 5.17.12 stable kernel update contains a number of important fixes across the tree.

The 5.17.12 stable kernel update contains a number of important fixes across the tree.

Upstream release notes: https://github.com/dotnet/core/blob/main/release- notes/3.1/3.1.25/3.1.25.md

An update for thunderbird is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Key insights from ESET’s latest Threat Report – Week in security with Tony Anscombe

A review of the key trends that defined the threatscape in the first four months of 2022 and what these developments mean for your cyber-defenses The post Key insights from ESET’s latest Threat Report – Week in security with Tony Anscombe appeared first on WeLiveSecurity

100 days of war in Ukraine: How the conflict is playing out in cyberspace

It’s been 100 days since Russia invaded Ukraine, and we look back at various cyberattacks connected to the conflict The post 100 days of war in Ukraine: How the conflict is playing out in cyberspace appeared first on WeLiveSecurity

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed

Linux Cybersecurity Education & Training is Integral to Growing Your Career
Feeling highly stressed about your job? You must be a CISO

An update for the postgresql:12 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the postgresql:10 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for compat-openssl11 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Even Russia’s Evil Corp now favors software-as-a-service

– New upstream update (101.0) —- – Fixed missing popups in some scenarios on Wayland (https://bugzilla.mozilla.org/show_bug.cgi?id=1771104)

To cut off all nearby phones with these Chinese chips, this is the bug to exploit
ESET Threat Report T 1 2022

A view of the T 1 2022 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T 1 2022 appeared first on WeLiveSecurity

Atlassian announces 0-day hole in Confluence Server – update soon!
Old Hacks Die Hard: Ransomware, Social Engineering Top Verizon DBIR Threats – Again
Evil Corp Pivots LockBit to Dodge U.S. Sanctions
Clipminer rakes in $1.7m in crypto hijacking scam

An update that solves two vulnerabilities and has two fixes is now available.

An update that solves 27 vulnerabilities, contains four features and has 17 fixes is now available.

Healthcare organizations face rising ransomware attacks – and are paying up

This update upgrades Thunderbird to version 91.10.0. * Mozilla: Braille space character caused incorrect sender email to be shown for a digitally signed email (CVE-2022-1834) * Mozilla: Cross-Origin resource’s length leaked (CVE-2022-31736) * Mozilla: Heap buffer overflow in WebGL (CVE-2022-31737) * Mozilla: Browser window spoof using fullscreen mode (CVE-2022-31738) * Mozilla: Register all [More…]

Sebastian Krause discovered that manipulated inline images can force PyPDF2, a pure Python PDF library, into an infinite loop, if a maliciously crafted PDF file is processed.

Red Hat OpenShift Container Platform release 4.7.47 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.7.

An update for gzip is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Atlassian: Unpatched years-old flaw under attack right now to hijack Confluence
FBI, CISA: Don’t get caught in Karakurt’s extortion web

security update

Conti spotted working on exploits for Intel Management Engine flaws

The popularity of online gaming surged during the COVID-19 pandemic—and so did cyberattacks against gamers. If you’re the parent of a gamer, or if you’re a gamer yourself, it’s important to learn about the risks. Why are cyber threats to gamers on the rise? It might seem strange that cybercriminals are targeting gamers. But there […]

The cyber threat landscape keeps evolving at lightning-speed. According to the latest 2022 BrightCloud® Threat Report, small to medium-sized businesses (SMBs) are particularly vulnerable to becoming a victim of a ransomware attack. Cybercriminals also are becoming more selective of the organizations they target. Without human security experts and solutions at their disposable, these businesses remain […]

Yet another zero-day (sort of) in Windows “search URL” handling
S3 Ep85: Now THAT’S what I call a Microsoft Office exploit! [Podcast]

Several security issues were fixed in cifs-utils.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Cybercriminals Expand Attack Radius and Ransomware Pain Points

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Scammers Target NFT Discord Channel
Dear Europe, here again are the reasons why scanning devices for unlawful files is not going to fly
International Authorities Take Down Flubot Malware Network
Being prepared for adversarial attacks
Super-spreader FluBot squashed by Europol
ExpressVPN moves servers out of India to escape customer data retention law
US ran offensive cyber ops to support Ukraine, says general