Menu

Latest articles

Fabian Vogt and Dominik Penner discovered that the Ark archive manager did not sanitize extraction paths, which could result in maliciously crafted archives with symlinks writing outside the extraction directory.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has one errata is now available.

Protecting data now as the quantum era approaches

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

Canada bans Huawei and ZTE from 5G networks, citing national security risks
India slightly softens infosec incident reporting and data retention rules
US won’t prosecute ‘good faith’ security researchers under CFAA
Phishing gang that stole over 400,000 Euros busted in Spain
US recovers a record $15m from the 3ve ad-fraud crew

Webroot Console 6.5 is here To help get us closer to retiring the Endpoint Protection Console, we’ve introduced three new functionality features with Webroot Console 6.5. Friendly name support To help get us closer to retiring the Endpoint Protection Console, we’ve introduced three new functionality features with Webroot Console 6.5. Friendly name support To improve […]

Iran, China-linked gangs join Putin’s disinformation war online
S3 Ep83: Cracking passwords, patching Firefox, and Apple vulns [Podcast]
Critical Vulnerability in Premium WordPress Themes Allows for Site Takeover

OpenLDAP could be made to perform arbitrary modifications to the database.

Hackers are finding it too easy to achieve their initial access, warn agencies

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes 6 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2022:4642

The quantum menace: Quantum computing and cryptography
Hot glare of the spotlight doesn’t slow BlackByte ransomware gang
The flip side of the coin: Why crypto is catnip for criminals

Cybercriminals continue to mine for opportunities in the crypto space – here’s what you should know about coin-mining hacks and crypto theft The post The flip side of the coin: Why crypto is catnip for criminals appeared first on WeLiveSecurity

The cyber threat isn’t going anywhere, but the fight back starts in London
Your snoozing iOS 15 iPhone may actually be sleeping with one antenna open
Patch your VMware gear now – or yank it out, Uncle Sam tells federal agencies
Smashing Security podcast #275: Jail for Bing, and mental health apps may not be good for you
Meet Wizard Spider, the multimillion-dollar gang behind Conti, Ryuk malware

security update

security update

security update

How these crooks backdoor online shops and siphon victims’ credit card info
DOJ Says Doctor is Malware Mastermind
APTs Overwhelmingly Share Known Vulnerabilities Rather Than Attack O-Days
April VMware Bugs Abused to Deliver Mirai Malware, Exploit Log4Shell
Your data’s auctioned off up to 987 times a day, NGO reports
Pwn2Own hacking schedule released – Windows and Linux are top targets
Add security to Azure applications with Azure WAF
Microsoft warns partners to revoke unused authorizations that drive your software
Fake news – why do people believe it?

In the age of the perpetual news cycle and digital media, the risks that stem from the fake news problem are all too real The post Fake news – why do people believe it? appeared first on WeLiveSecurity

State of internet crime in Q1 2022: Bot traffic on the rise, and more
Monero-mining botnet targets Windows, Linux web servers
Google Cloud launches services to bolster open-source security, simplify zero-trust rollouts
FBI warns of North Korean cyberspies posing as foreign IT workers
Pentester pops open Tesla Model 3 using low-cost Bluetooth module
What You Need to Know about the Sysrv-K Cryptomining Botnet in Less than a Minute>
Google assuring open source code to secure software supply chains
Sysrv-K Botnet Targets Windows, Linux

Several security issues were fixed in PCRE.

Several security issues were fixed in Apport.

iPhones Vulnerable to Attack Even When Turned Off

needrestart could be made to run programs.

zlib: A flaw found in zlib when compressing (not decompressing) certain inputs (CVE-2018-25032) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 zlib-1.2.7-20.el7_9.i686.rpm zlib-1.2.7-20.el7_9.x86_64.rpm zlib-debuginfo-1.2.7-20.el7_9.i686.rpm zlib-debuginfo-1.2.7-20 [More…]

Jakub Wilk discovered a local privilege escalation in needrestart, a utility to check which daemons need to be restarted after library upgrades. Regular expressions to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate

Only DevSecOps can save the metaverse
Apple patches zero-day kernel hole and much more – update now!

OpenLDAP could be made to perform arbitrary modifications to the database.

Facebook rated least safe e-commerce option in government rankings
Europe moves closer to stricter cybersecurity standards, reporting regs
Venezuelan cardiologist charged with designing and selling ransomware
Red Hat releases open source StackRox to the community
The State of Kubernetes Security in 2022
China reveals its top five sources of online fraud
US brings first-of-its-kind criminal charges of Bitcoin-based sanctions-busting
Hackers are after your data. So why are you making it so easy for them?
“Incompetent” council leaks details of students with special educational needs
Russian cyber attack on Eurovision foiled by Italian authorities

The ffmpeg project released the new version 3.2.18 with fixes for various issues found by the OSS-Fuzz project. For Debian 9 stretch, this release is packaged in version 7:3.2.18-0+deb9u1.

Microsoft’s May Patch Tuesday Updates Cause Windows AD Authentication Errors

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes 8 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

San Francisco police use driverless cars for surveillance
More money for open source security won’t work
The downside of ‘debugging’ ransomware

The decision to release a ransomware decryptor involves a delicate balancing act between helping victims recover their data and alerting criminals to errors in their code The post The downside of ‘debugging’ ransomware appeared first on WeLiveSecurity

Firefox out-of-band update to 100.0.1 – just in time for Pwn2Own?

Infinite loop vulnerability in the CHM file parser. Issue affects versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions. (CVE-2022-20770) Infinite loop vulnerability in the TIFF file parser. Issue affects versions

cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call. (CVE-2017-9814) References:

CERTINFO never-ending busy-loop. (CVE-2022-27781) TLS and SSH connection too eager reuse. (CVE-2022-27782) References: – https://bugs.mageia.org/show_bug.cgi?id=30410

FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face. (CVE-2022-27404) FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. (CVE-2022-25235) References:

When using Waitress versions 2.1.0 and prior behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 standard, Waitress and the frontend proxy may disagree on where one request starts and where it ends. This would allow requests to be smuggled via the front-end proxy to waitress and later behavior. […]

CVE-2021-3596 A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in information disclosure or denial of service. For Debian 9 stretch, these problems have been fixed in version

The container trento/trento-runner was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

Shopping for malware: $260 gets you a password stealer. $90 for a crypto-miner…
Ukrainian crook jailed in US for selling thousands of stolen login credentials

security update

security update

security update

Another ex-eBay exec admits cyberstalking web souk critics
Software patching must work like car safety recalls, says US cyber boss