Menu

Latest articles

NHS Digital’s demise bad for 55 million patients’ privacy – ex-chairman
TikTok under investigation in US over harms to children

An update that solves two vulnerabilities, contains two features and has two fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences–>Advanced–>HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in […]

Update to 2.34.6: * Fix accessibility not working when the Bubblewrap sandbox is enabled. * Fix rendering of scrollbars when overlay scrollbars are disabled. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-22620 —- Update to 2.34.5: * Improve VP8 codec selection when using GStreamer 1.20. * Fix connecting to the accessiblity bus […]

An update that fixes 12 vulnerabilities is now available.

Amazon Alexa can be hijacked via commands from own speaker
Switzerland’s SWIFT data centre under guard after Russian banks excluded
Phishing Campaign Targeted Those Aiding Ukraine Refugees
Russia Leaks Data From a Thousand Cuts–Podcast
US legislation brings mandatory cyberattack and ransomware reporting one step closer
Smashing Security podcast #264: Hacked car chargers, Telegram sextortionists, and secret bossware
S3 Ep72: AirTag stalking, web server coding woes and Instascams [Podcast + Transcript]
Securing Data With a Frenzied Remote Workforce–Podcast
Pulumi launches Business Critical edition for enterprise customers
Zero trust? Not yet a must for most IT departments
Results that surprised us in The State of Enterprise Open Source report

– Upstream update to 2.4.0 – Fixed CVE-2021-42072 (RHBZ 2022094) – BuildDepends added: gmock-devel, gulrak-filesystem-devel – Address the issue from pull request #1, thanks aekoroglu.

– Upstream update to 2.4.0 – Fixed CVE-2021-42072 (RHBZ 2022094) – BuildDepends added: gmock-devel, gulrak-filesystem-devel – Address the issue from pull request #1, thanks aekoroglu.

Security fix for CVE-2021-4115

containerd would allow unintended access to files over the network.

Several security issues were fixed in PHP.

UK government starts public consultation on telco security

HAProxy could be made to stop responding if it received specially crafted network traffic.

How Attack Path Modelling can help prevent your next cyber-attack
CrowdStrike offers fully managed identity-threat-detection-as-a-service
Who deleted the database? Find out with Teleport
TeaBot Trojan Haunts Google Play Store, Again

security update

Details of ‘120,000 Russian soldiers’ leaked by Ukrainian media
Harvard census identifies most commonly used open source packages
Conti Ransomware Decryptor, TrickBot Source Code Leaked
Conti ransomware group’s source code leaked
EU, US close to replacing defunct Privacy Shield II
Ransomware with a difference: “Derestrict your software, or else!”
The zero-password future can’t come soon enough

Security update for php. See changelog for details. References: – https://bugs.mageia.org/show_bug.cgi?id=30056 – https://www.php.net/ChangeLog-8.php#8.0.16

OpenShift Logging bug fix and security update (5.2.8) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for cyrus-sasl is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for cyrus-sasl is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Update to 6.0.2

Innovation and the Roots of Progress

If you look back at the long arc of history, it’s clear that one of the most crucial drivers of real progress in society is innovation The post Innovation and the Roots of Progress appeared first on WeLiveSecurity

An update that fixes one vulnerability, contains one feature is now available.

Intel’s 12th-gen Alder Lake processors will not include Microsoft’s Pluton security
New flashpoint: US may ask Chinese tech firms to bin Russia
President Biden calls for ban on social media ads aimed at kids
RCE Bugs in Hugely Popular VoIP Apps: Patch Now!
Second data-wiping malware found in Ukraine, says ESET
VMware adds container runtime protection to Carbon Black security portfolio
Daxin Espionage Backdoor Ups the Ante on Chinese Malware
Ukraine Hit with Novel ‘FoxBlade’ Trojan Hours Before Invasion
This JavaScript scanner hunts down malware in libraries
Insurance Aon confirms it has suffered ‘cyber incident’
IsaacWiper and HermeticWizard: New wiper and worm targeting Ukraine

ESET researchers uncover a new wiper that attacks Ukrainian organizations and a worm component that spreads HermeticWiper in local networks The post IsaacWiper and HermeticWizard: New wiper and worm targeting Ukraine appeared first on WeLiveSecurity

Several security issues were fixed in GNU C Library.

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

An update is now available for Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

OpenShift Logging bug fix and security update (5.3.5) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for rh-maven36-httpcomponents-client is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

The truth about VDI and cloud computing
Microsoft Accounts Targeted by Russian-Themed Credential Harvesting

Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences–>Advanced–>HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in […]

China-linked malware targeted secure networks at ‘multiple governments’
Toyota shutters 14 plants after probable cyberattack
Microsoft: Russia invasion of Ukraine ‘unlawful, unjustified’
Quarter of a million lawyer disciplinary records leak
Ukraine-Russia Cyber Warzone Splits Cyber Underground
Conti ransomware gang leak: 60,000 messages online
Instagram scammers as busy as ever: passwords and 2FA codes at risk
Toyota to Close Japan Plants After Suspected Cyberattack
Beware of charity scams exploiting war in Ukraine

Looking to help people in Ukraine? Donate wisely – do your research first so you give without getting scammed The post Beware of charity scams exploiting war in Ukraine appeared first on WeLiveSecurity

#ShieldsUp – Now is the time to double‑check cybersecurity processes and operations

As the conflict in Ukraine heightens the risk of cyberattacks globally, what can organizations do to improve their resiliency? The post #ShieldsUp – Now is the time to double‑check cybersecurity processes and operations appeared first on WeLiveSecurity

Kremlin and Russia’s TASS news agency websites offline following attacks
Play for Ukraine game aims to knock Russian websites offline

The container trento/trento-db was updated. The following patches have been included in this update:

The container suse-sles-15-sp3-chost-byos-v20220222-gen2 was updated. The following patches have been included in this update:

Nmap Basics: What Is Nmap & How Is It Used?>
Russia is the advanced persistent threat that just triggered. Ready?

Several security issues were fixed in QEMU.

Several security issues were fixed in WebKitGTK.

Several security issues were fixed in MariaDB.

policykit-1 could be made to crash if it received specially crafted data.

Tech world’s Ukraine response mixes evacuation efforts, ad bans, free phones, infosec FUD

The 5.16.11 stable kernel update contains a number of important fixes across the tree.

One issue have been discovered in ujson: ultra fast JSON encoder and decoder for Python. CVE-2021-45958

It was discovered that the SQL plugin in cyrus-sasl2, a library implementing the Simple Authentication and Security Layer, is prone to a SQL injection attack. An authenticated remote attacker can take advantage of this flaw to execute arbitrary SQL commands and for

An update for openshift-gitops-applicationset-container, openshift-gitops-container, openshift-gitops-kam-delivery-container, and openshift-gitops-operator-container is now available for Red Hat OpenShift GitOps 1.3 on OCP 4.7-4.9. (GitOps v1.3.4)

Security fix for CVE-2022-0554 —- Security fixes for CVE-2022-0714, CVE-2022-0729 —- Security fix for CVE-2022-0696 —- Security fix for CVE-2022-0629 —- Security fix for CVE-2022-0572 —- Security fixes for CVE-2022-0408, CVE-2022-0413, CVE-2022-0393, CVE-2022-0417, CVE-2022-0443 —- Security fix for CVE-2022-0685

Ukrainian military personnel targeted with phishing attacks

Several issues have been found in htmldoc, an HTML processor that generates indexed HTML, PS, and PDF.

Nvidia probes cyberattack on internal systems
TrickBot Takes a Break, Leaving Researchers Scratching Their Heads
Microsoft Exchange Bugs Exploited by ‘Cuba’ Ransomware Gang
Ukraine seeks volunteers to defend networks as Russian troops menace Kyiv
6 Cyber-Defense Steps to Take Now to Protect Your Company
Did we learn nothing from Y2K? Why are some coders still stuck on two digit numbers?
Conti ransomware gang: You attack Russia, we’ll hack you back
HermeticWiper: New data‑wiping malware hits Ukraine

Hundreds of computers in Ukraine compromised just hours after a wave of DDoS attacks brings down a number of Ukrainian websites The post HermeticWiper: New data‑wiping malware hits Ukraine appeared first on WeLiveSecurity