Menu

Latest articles

He cracked passwords for a living – now he’s serving 4 years in prison
Most organizations hit by ransomware would pay up if hit again
Malware Builder Leverages Discord Webhooks
How to spot and avoid a phishing attack – Week in security with Tony Anscombe

Can you spot the tell-tale signs of a phishing attempt and check if an email that has landed in your inbox is legit? The post How to spot and avoid a phishing attack – Week in security with Tony Anscombe appeared first on WeLiveSecurity

Upstream details at : https://access.redhat.com/errata/RHSA-2022:1440

Upstream details at : https://access.redhat.com/errata/RHSA-2022:2191

Upstream details at : https://access.redhat.com/errata/RHSA-2022:2213

Upstream details at : https://access.redhat.com/errata/RHSA-2022:1487

‘Peacetime in cyberspace is a chaotic environment’ says senior US advisor
Iran-linked Cobalt Mirage extracts money, info from US orgs – report
Threat Actors Use Telegram to Spread ‘Eternity’ Malware-as-a-Service
Researchers find 134 flaws in the way Word, PDFs, handle scripts
To predict the targets of Chinese malware, look at the target of Chinese laws
Anatomy of a campaign to inject JavaScript into compromised WordPress sites

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

* Updating for Keylime release v6.4.0 * Fixes CVE-2022-1053

If you’ve got Intel inside, you probably need to get these security patches inside, too
S3 Ep82: Bugs, bugs, bugs (and Colonial Pipeline again) [Podcast]
Serious Security: Learning from curl’s latest bug update
Ransomware the final nail in coffin for small university
Smashing Security podcast #274: Hands off my biometrics, and a wormhole squirmish

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the subversion:1.10 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

You Can’t Eliminate Cyberattacks, So Focus on Reducing the Blast Radius
Novel ‘Nerbian’ Trojan Uses Advanced Anti-Detection Tricks
9 questions you should ask about your cloud security
10 reasons why we fall for scams

The ‘it won’t happen to me’ mindset leaves you unprepared – here are some common factors that put any of us at risk of online fraud The post 10 reasons why we fall for scams appeared first on WeLiveSecurity

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don’t check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2’s buffer functions, for example libxslt through 1.1.35, is affected as well.

APT gang ‘Sidewinder’ goes on two-year attack spree across Asia
It’s time to kick China off social media, says tech governance expert
Europe proposes tackling child abuse by killing privacy, strong encryption
Ukraine war a sorting hat for cyber-governance loyalties: Black Hat founder Jeff Moss
Five Eyes turn spotlight on MSPs: Potential weak links in IT supply-chain security
Fresh ransomware samples indicate REvil is back

An update for the virt:av and virt-devel:av modules is now available for Advanced Virtualization for RHEL 8.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Red Hat OpenStack Platform 16.2 (Train) director Operator containers are available for technology preview. 2. Description: Release osp-director-operator images

An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Intel Memory Bug Poses Risk for Hundreds of Products
Novel Phishing Trick Uses Weird Links to Bypass Spam Filters

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Managing Red Hat Enterprise Linux at the edge
Actively Exploited Zero-Day Bug Patched by Microsoft
Ransomware Deals Deathblow to 157-year-old College
Progress launches Chef Cloud Security to extend DevSecOps to cloud-native assets
US college set to permanently close after 157 years, following ransomware attack
Opportunity out of crisis: Tapping the Great Resignation to close the cybersecurity skills gap

What can organizations do to capitalize on the current fluidity in the job market and bring fresh cybersecurity talent into the fold? The post Opportunity out of crisis: Tapping the Great Resignation to close the cybersecurity skills gap appeared first on WeLiveSecurity

Yahoo Japan strives for universal passwordless authentication
Microsoft closes Windows LSA hole under active attack
Email domain for NPM lib with 6m downloads a week grabbed by expert to make a point
US, Europe formally blame Russia for data wiper attacks against Ukraine, Viasat

security update

Colonial Pipeline facing $1,000,000 fine for poor recovery plans
Malware goes regional as attackers change tactics

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Hackers Actively Exploit F5 BIG-IP Bug

An update for libpq is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for c-ares is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for the maven:3.5 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for libtiff is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Conti Ransomware Attack Spurs State of Emergency in Costa Rica
Industry pushes back against India’s data security breach reporting requirements
Low-rent RAT Worries Researchers
Biden signs cybercrime tracking bill into law

security update

It costs just $7 to rent DCRat to backdoor your network
FBI: Rise in Business Email-based Attacks is a $43B Headache
US offers $15m reward for information about Conti ransomware gang
Tractor giant AGCO hit by ransomware, halts production and sends home staff
RubyGems supply chain rip-and-replace bug fixed – check your logs!
Russian TV listings hacked with messages about war crimes in Ukraine
Ransomware plows through farm machinery giant AGCO

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

Microsoft Security Experts: Humans and automation to fight off cyber threats
Colonial Pipeline faces nearly $1m fine one year after ransomware attack

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Podcast: The State of the Secret Sprawl
China wants its youth to stop giving livestreamers money
Common LinkedIn scams: Beware of phishing attacks and fake job offers

LinkedIn scammers attack when we may be at our most vulnerable – here’s what to look out for and how to avoid falling victim to fraud when using the platform The post Common LinkedIn scams: Beware of phishing attacks and fake job offers appeared first on WeLiveSecurity

Update to 91.9.0

Release of OpenShift Serverless Client kn 1.22.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes two vulnerabilities is now available.

India’s ongoing outrage over Pegasus malware tells a bigger story about privacy law problems

Potential heap buffer overflow in TCP syslog server (receiver) components (CVE-2022-24903) References: – https://bugs.mageia.org/show_bug.cgi?id=30383

Fix for possible DOS by regex. (CVE-2022-24836) References: – https://bugs.mageia.org/show_bug.cgi?id=30322 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/XMDCWRQXJQ3TFSETPCEFMQ6RR6ME5UA3/

– Fixed h.264 video playback over va-api (https://bugzilla.mozilla.org/show_bug.cgi?id=1762725) —- – New upstream version (100.0)

Oracle 04/2022 critical path update * https://www.oracle.com/security- alerts/cpuapr2022.html#AppendixJAVA * Cross fingers I had not messed up system JDK. * java-maint tests passed * **Still karma is highly appreciated**

Oracle 04/2022 critical path update * https://www.oracle.com/security- alerts/cpuapr2022.html#AppendixJAVA * Cross fingers I had not messed up system JDK. * java-maint tests passed * **Still karma is highly appreciated**

Oracle 04/2022 critical path update * https://www.oracle.com/security- alerts/cpuapr2022.html#AppendixJAVA * Cross fingers I had not messed up system JDK. * java-maint tests passed * **Still karma is highly appreciated**

Defending against APT attacks – Week in security with Tony Anscombe

The conflict in Ukraine has highlighted the risks of cyberespionage attacks that typically involve Advanced Persistent Threat groups and often target organizations’ most valuable data The post Defending against APT attacks – Week in security with Tony Anscombe appeared first on WeLiveSecurity

One security issue has been found in a compression library libz-mingw-w64. Danilo Ramos discovered that incorrect memory handling in

False-flag cyberattacks a red line for nation-states, says Mandiant boss

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container suse/sles12sp3 was updated. The following patches have been included in this update: