Menu

Latest articles

Microsoft 365 gives you the tools to run your business. But where are the tools to protect it?
Microsoft blocks web installation of its own App Installer files
Who dropped the DB? Find out with Teleport Database Access
Twitter blackout for Vodafone customers

Upstream details at : https://access.redhat.com/errata/RHSA-2022:0442

An update that fixes 18 vulnerabilities is now available.

Several security issues were fixed in Django.

US carriers want to junk three times more Chinese comms kit than planned

Rebuild with 1.58.1 toolchain to incorporate remove_dir_all bug fix

Backport patch for CVE-2021-45930.

Rebuild with 1.58.1 toolchain to incorporate remove_dir_all bug fix

It was found that in libphp-adodb, a PHP database abstraction layer library, an attacker can inject values into the PostgreSQL connection string by bypassing adodb_addslashes(). The function can be bypassed in phppgadmin, for example, by surrounding the username in quotes and

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

Backport patches for CVE-2021-3933 and CVE-2021-3941.

Backport patch for head overflow.

Impacts from a new reality drive the need for an enhanced digital identity framework
Suspected Chinese spies break into cloud accounts of News Corp journalists

security update

security update

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

The 5.16.5 stable kernel rebase contains new features, additional hardware support, and a number of important fixes across the tree.

Security bugs in libmount, CVE-2021-3996 and CVE-2021-3995.

‘Long Live Log4Shell’: CVE-2021-44228 Not Dead Yet
Argo CD Security Bug Opens Kubernetes Cloud Apps to Attackers
Wormhole cryptotrading company turns over $340,000,000 to criminals
Open-source Kubernetes tool Argo CD has a high-severity path traversal flaw: Patch now
Attackers Target Intuit Users by Threatening to Cancel Tax Accounts

An update that solves three vulnerabilities, contains one feature and has one errata is now available.

Several vulnerabilities have been discovered in apng2gif, a tool for converting APNG images to animated GIF format. Improper sanitization of user input can result in denial of service (application crash) or possible execution of arbitrary code if a malformed image file is processed.

An update that fixes three vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

That’s a signature move: How $320m in Ether was stolen from crypto biz Wormhole
Kronos Still Dragging Itself Back From Ransomware Hell
Low-Detection Phishing Kits Increasingly Bypass MFA
Privacy Shield: EU citizens might get right to challenge US access to their data
Phishing kits’ use of man-in-the-middle reverse proxies is growing, warns Proofpoint

This update addresses a bugs in the handling of timestamps in the `recvmsg` and `recvmmsg` on armhpf and i686 ([swbz#28349](https://sourceware.org/bugzilla/show_bug.cgi?id=28349), [swbz#28350](https://sourceware.org/bugzilla/show_bug.cgi?id=28350)). A bug in some optimized versions of `wcsncmp` on x86_64 is fixed

Bump version to 2.0.14-1 —- Security fix for CVE-2021-45720

Critical Cisco Bugs Open VPN Routers to Cyberattacks
JumpCloud joins the patch management crowd, starting with Windows and Mac updates
Wormhole Crypto Platform: ‘Funds Are Safe’ After $314M Heist
Ransomware is terrifying – but never underestimate the damage an employee with unmonitored access can do
BlackCat ransomware – what you need to know
KP Snacks hit by ransomware: Crisps and nuts firm KO’d by modern scourge
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Some fraudsters may use low-tech tactics to steal your sensitive information – peering over your shoulder as you enter that data is one of them The post Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone appeared first on WeLiveSecurity

S3 Ep68: Bugs, scams, privacy …and fonts?! [Podcast + Transcript]
Thousands of Malicious npm Packages Threaten Web Apps
PowerPoint Files Abused to Take Over Computers
Execs keep flinging money at us instead of understanding security, moan infosec pros

An update for the varnish:6 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the varnish:6 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for the varnish:6 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Updated images are now available for Red Hat Advanced Cluster Security for Kubernetes (RHACS). The updated image includes a bug fixes, security patches and new feature enhancements. Red Hat Product Security has rated this update as having a security impact

Release of OpenShift Serverless Client kn 1.20.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Smashing Security podcast #260: New hire mystery, hacktivist ransomware, and digi-dating
Linux Legend “maddog” Shares Exclusive Security Insights with LinuxSecurity>
Crunch! Ransomware hits KP Nuts, Hula Hoops, and McCoys crisps
Welsh home improvement biz fined £200,000 over campaign of 675,478 nuisance calls
FBI says more cyber attacks come from China than everywhere else combined
Worried about occasional npm malware scares? It’s more common than you may think
KP Snacks Left with Crumbs After Ransomware Attack

Threat actors are becoming more sophisticated, agile and relentless in their pursuit of stealing personal information for financial gain. Rapid and evolving shifts in the threat landscape require the knowledge and solutions to prepare and prevent threats that could spell disaster for organizations’ reputations and operations. Organizations of all sizes remain at risk. Small to […]

Supply-Chain Security Is Not a Problem…It’s a Predicament
Remote code execution vulnerability in Samba due to macOS interop module
Elementor WordPress plugin has a gaping security hole – update now
UK think tank proposes Online Safety Bill reviewer to keep tabs on Ofcom decisions
Charming Kitten Sharpens Its Claws with PowerShell Backdoor

A security update is now available for Red Hat Single Sign-On 7.5 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A new image is available for Red Hat Single Sign-On 7.4.10 on OpenJDK, running on OpenShift Container Platform 3.10 and 3.11, and 4.3. 2. Description: Red Hat Single Sign-On is an integrated sign-on solution, available as a

A new image is available for Red Hat Single Sign-On 7.4.10 on OpenJ9, running on OpenShift Container Platform 3.10 and 3.11, and 4.3. 2. Description: Red Hat Single Sign-On is an integrated sign-on solution, available as a

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

DMCA-dot-com XSS vuln reported in 2020 still live today and firm has shrugged it off
What are real organisations doing with zero trust?
FBI: Use a Burner Phone at the Olympics
Unpatched Security Bugs in Medical Wearables Allow Patient Tracking, Data Theft
The Account Takeover Cat-and-Mouse Game

security update

security update

Samba ‘Fruit’ Bug Allows RCE, Full Root User Access
Ransomware means your database IS the front line. How are you defending it?
Linux kernel patches “performance can be harmful” bug in video driver
How to tell if your phone has been hacked

Think your smartphone has been compromised by malware? Here’s how to spot the signs of a hacked phone and how to remove the hacker from your phone. The post How to tell if your phone has been hacked appeared first on WeLiveSecurity

Cyberattacker hits German service station petrol terminal provider
Living Off the Land: How to Defend Against Malicious Use of Legitimate Utilities

An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

This kernel-linus update is based on upstream 5.15.18 and fixes atleast the following security issues: A random memory access flaw was found in the Linux kernels GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU.

This kernel update is based on upstream 5.15.18 and fixes atleast the following security issues: A random memory access flaw was found in the Linux kernels GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU.

Curated, tested and supported: How enterprise vendors mitigate open source supply chain risk

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Russia’s naval exercise near Ireland unlikely to involve cable-tapping shenanigans
Public Exploit Released for Windows 10 Bug
Apple Pays $100.5K Bug Bounty for Mac Webcam Hack