Menu

Latest articles

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Full-time internet surveillance comes to Cambodia this week
Spot the irony: India’s Reserve Bank says outsourcing and offshoring are risky

security update

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed

Security update for CVE-2022-23303, CVE-2022-23304 Update to version 2.10, which upstream maintainer advises for these CVEs.

**Version 3.3.8** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation notice on `round` * Fix call to deprecated `convertToHtml` method

**Version 2.14.11** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation notice on `round` * Fix call to deprecated `convertToHtml` method

**Version 3.3.8** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation notice on `round` * Fix call to deprecated `convertToHtml` method

**Version 2.14.11** (2022-02-04) * Fix a security issue when in a sandbox: the `sort` filter must require a Closure for the `arrow` parameter * Fix deprecation notice on `round` * Fix call to deprecated `convertToHtml` method

Several vulnerabilities have been discovered in Expat, an XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code, if a malformed XML file is processed.

Facebook exposes ‘god mode’ token that could siphon data

security update

Marcel Neumann, Robert Altschaffel, Loris Guba and Dustin Hermann discovered that debian-edu-config, a set of configuration files used for the Debian Edu blend configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.

Apple emits emergency fix for exploited-in-the-wild WebKit vulnerability
Critical MQTT-Related Bugs Open Industrial Networks to RCE Via Moxa

security update

Update to 2.34.5: * Improve VP8 codec selection when using GStreamer 1.20. * Fix connecting to the accessibility bus when using the Bubblewrap sandbox. * Fix links being incorrectly activated when starting a pinch zoom gesture. * Fix touch-based scrolling. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-22589, CVE-2022-22590, CVE-2022-22592

Update to 2.4.4, fixes CVE-2022-23990.

Backport patch for CVE-2021-44648.

This is the December 2021 update for .NET Core 3.1 It updates .NET Core 3.1 to SDK 3.1.416 and Runtime 3.1.22

Cybercrooks Frame Targets by Planting Fabricated Digital Evidence
US govt: Here are another 15 security bugs under attack right now
Hidden in plain sight: How the dark web is spilling onto social media

A trip into the dark corners of Telegram, which has become a magnet for criminals peddling everything from illegal drugs to fake money and COVID-19 vaccine passes The post Hidden in plain sight: How the dark web is spilling onto social media appeared first on WeLiveSecurity

Apple zero-day drama for Macs, iPhones and iPads – patch now!
Apple Patches Actively Exploited WebKit Zero Day
Ransomware crew dumps stolen Optionis files online

Several vulnerabilities were discovered in Samba, a SMB/CIFS file, print, and login server for Unix. CVE-2021-44142

How Pure Storage helps customers guard against ransomware

An update that solves 11 vulnerabilities and has 29 fixes is now available.

CIA illegally harvested US citizens’ data, senators assert

security update

Decryptor Keys Published for Maze, Egregor, Sekhmet Ransomwares
Sharp SIM-Swapping Spike Causes $68M in Losses
This malware gang plants incriminating evidence on PCs, gets victims arrested

The ransomware attacks that make headlines and steer conversations among cybersecurity professionals usually involve major ransoms, huge corporations and notorious hacking groups. Kia Motors, Accenture, Acer, JBS…these companies were some of the largest to be compromised by ransomware in 2021. These were mainly hit with well-known variants, sometimes unleashed by state-backed hacking groups. But it’s […]

security update

– Updated to latest upstream (97.0)

– Update to upstream 2.1-34. 20220207 – Removal of 06-86-04/0x01 (SNR B0) microcode at revision 0xb00000f; – Removal of 06-86-05/0x01 (SNR B1) microcode (in intel-ucode/06-86-04) at revision 0xb00000f; – Removal of 06-86-04/0x01 (SNR B0) microcode (in intel-ucode/06-86-05) at revision 0xb00000f; – Removal of 06-86-05/0x01 (SNR B1) microcode at revision

Security fixes for CVE-2022-0408, CVE-2022-0413, CVE-2022-0393, CVE-2022-0417, CVE-2022-0443

# New features: ## 0.45 – –only-cook ‘! ‘ enables confident mode where every possible prompt that matches a regexp is cooked immediately (so that even prompts that get printed while handling a large paste are cooked). – –no-children (-N) now enables direct mode whenever the client switches to the alternate screen. This makes editors […]

WhiteSource report warns of NPM registry risks
The bizarre couple alleged to be behind one of the biggest cryptocurrency hacks of all time
ESET Threat Report T3 2021

A view of the T3 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T3 2021 appeared first on WeLiveSecurity

SAP Patches Severe ‘ICMAD’ Bugs
Use Zoom on a Mac? You might want to check your microphone settings
PHP Everywhere Bugs Put 30K+ WordPress Sites at Risk of RCE
Beware scammy SMS messages claiming to come from HMRC
More than $400 million drained from hacked blockchain bridges in little more than a week
Smashing Security podcast #261: North Korea hacked, DEA cosplay, and Horizon Worlds drama

Speex could be made to denial of service if it received a specially crafted WAV file.

Red Hat OpenShift Container Platform release 4.9.19 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.9.

Swipe left: Snoops use dating apps to hook sources, says Australian Five Eyes boss

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, bypass of deserialization restrictions or information disclosure.

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

S3 Ep69: WordPress woes, Wormhole holes, and a Microsoft change of heart [Podcast + Transcript]
Cybercriminals Swarm Windows Utility Regsvr32 to Spread Malware
3 Tips for Facing the Harsh Truths of Cybersecurity in 2022, Part I
US: Your AI has to explain its decisions

No more turning a blind eye to algorithmic bias and discrimination if US lawmakers get their way The post US: Your AI has to explain its decisions appeared first on WeLiveSecurity

UK, US, Australia issue joint advisory: Ransomware on the loose, critical national infrastructure affected
Self-styled “Crocodile of Wall Street” arrested with husband over Bitcoin megaheist
MoleRats APT Flaunts New Trojan in Latest Cyberespionage Campaign
Ex-Gumshoe Nabs Cybercrooks with FBI Tactics

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Critical ‘remote escalation’ flaw in Android 12 fixed in Feb security patch batch
Sri Lanka to adopt India’s Aadhaar digital identity scheme
Microsoft manages a mere 51 security fixes for February update bundle
FBI seizes $3.6bn in Bitcoin after New York ‘tech couple’ arrested over Bitfinex robbery

security update

No Critical Bugs for Microsoft February 2022 Patch Tuesday, 1 Zero-Day
Canadian Netwalker ransomware crook pleads guilty to million-dollar crimes
At last! Office macros from the internet to be blocked by default
UK.gov threatens to make adults give credit card details for access to Facebook or TikTok
China Suspected of News Corp Cyberespionage Attack
A US hacker blasted North Korea off the internet following missile tests

An update for aide is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat AMQ Streams 1.6.7 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Red Hat AMQ Streams 2.0.1 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for aide is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update is now available for ansible-runner for Red Hat Ansible Automation Platform 2.0 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for aide is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Vice Society said to be behind digital break-in at UK umbrella and accounting group
Labour reminds UK.gov that it’s supposed to be reforming the Computer Misuse Act
Experience is really everything with SASE
Microsoft to block downloaded VBA macros in Office – you may be able to run ’em anyway
CISA Orders Federal Agencies to Fix Actively Exploited Windows Bug
Medusa Malware Joins Flubot’s Android Distribution Network
LockBit, BlackCat, Swissport, Oh My! Ransomware Activity Stays Strong
QuaDream, 2nd Israeli Spyware Firm, Weaponizes iPhone Bug
Roaming Mantis Expands Android Backdoor to Europe