Menu

Latest articles

5G edge and security deployment evolution, trends and insights

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

GitLab issues critical update after hard-coding passwords into accounts
Two teenagers charged in relation to LAPSUS$ hacking group investigation
More charged in UK Lapsus$ investigation
Apple Rushes Out Patches for 0-Days in MacOS, iOS

Bump version to 2.0.15

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

Danilo Ramos discovered that incorrect memory handling in zlib’s deflate handling could result in denial of service or potentially the execution of arbitrary code if specially crafted input is processed.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes four vulnerabilities is now available.

Google: Russian credential thieves target NATO, Eastern European military
LAPSUS$ hacks Globant. 70GB of data leaked from IT firm
Modem-wiping malware caused Viasat satellite broadband outage in Europe
National Security Agency employee indicted for ‘leaking top secret info’

security update

Apple pushes out two emergency 0-day updates – get ’em now!
Apple emits macOS, iOS, iPadOS patches for ‘exploited’ security bugs
FBI adds LAPSUS$ data extortion gang to its “Most Wanted” list
Belarusian ‘Ghostwriter’ Actor Picks Up BitB for Ukraine-Related Attacks
Two different “VMware Spring” bugs at large – we cut through the confusion
Patch now: RCE Spring4shell hits Java Spring framework
Automaker Cybersecurity Lagging Behind Tech Adoption, Experts Warn
Nvidia DGX systems prone to side channel, covert attacks
S3 Ep76: Deadbolt, LAPSUS$, Zlib, and a Chrome 0-day [Podcast]
QNAP Customers Adrift, Waiting on Fix for OpenSSL Bug
A Blockchain Primer and a Bored Ape Headscratcher – Podcast

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Expect ‘long tail of cyber retaliation’ from Russia for sanctions, says ExtraHop CEO
Cryptomining groups fight fiercely for cloud resources
UK spy boss warns China hopes Russia will help it take over tech standards
Russia, Iran, Saudi Arabia are top sources of online misinformation
Yale finance director stole $40m in computers to resell on the sly
Zlib crash-an-app bug finally squashed, 17 years later
Smashing Security podcast #268: LinkedIn deepfakes, doxxing Russian spies, and a false alarm
Shutterfly, hit by Conti ransomware group, warns staff their data has been stolen
Ubiquiti sues Krebs on Security for defamation
RCE Bug in Spring Cloud Could Be the Next Log4Shell, Researchers Warn
Cyberattackers Target UPS Backup Power Devices in Mission-Critical Environments
Forcepoint ONE helps firms simplify their security
Viasat spills on the Russian attack, warns of continued risks
“VMware Spring Cloud” Java bug gives instant remote code execution – update now!
Lapsus$ ‘Back from Vacation’
Google Chrome Bug Actively Exploited as Zero-Day
VMware Horizon platform pummeled by Log4j-fueled attacks
World Backup Day: 5 data recovery tips for everyone!

zlib could be made to crash or run programs if it received specially crafted input.

MSHTML Flaw Exploited to Attack Russian Dissidents

zlib could be made to crash or run programs if it received specially crafted input.

An update that solves 12 vulnerabilities and has 25 fixes is now available.

An update that fixes one vulnerability is now available.

An update that solves 12 vulnerabilities and has 25 fixes is now available.

Electric Vehicle DC charging tripped by a wireless hack

An update that solves 22 vulnerabilities and has 22 fixes is now available.

Women in tech: Unique insights from a lifelong pursuit of innovation

Leading Slovak computer scientist Mária Bieliková shares her experience working as a woman driving technological innovation and reflects on how to inspire the next generation of talent in tech The post Women in tech: Unique insights from a lifelong pursuit of innovation appeared first on WeLiveSecurity

UK Cyber Security Centre advises review of risk posed by Russian tech
Lapsus$ back? Researchers claim extortion gang attacked software consultancy Globant
Detailed: Critical hijacking bugs that took months to patch in Microsoft Azure Defender for IoT
Mutating Verblecon malware in illicit cryptomining … so far
Log4JShell Used to Swarm VMware Servers with Miners, Backdoors
Zlib data compressor fixes 17-year-old security bug – patch, errr, now
Ransomware driving you to distraction? Here’s how to recover
Mnuchin’s private equity firm buys security startup Zimperium for $525m
Ukraine security agency shutters Russian disinformation bot farms
Exchange Servers Speared in IcedID Phishing Campaign

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

This kernel-linus update is based on upstream 5.15.32 and fixes at least the following security issues: An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts

This kernel update is based on upstream 5.15.32 and fixes at least the following security issues: An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts

5 security considerations for edge implementations

An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Cybercrooks target students with fake job opportunities
Mozilla unveils vision for web evolution
Europe’s quest for energy independence – and how cyber‑risks come into play

Soaring energy prices and increased geopolitical tensions amid the Russian invasion of Ukraine bring a sharp focus on European energy security The post Europe’s quest for energy independence – and how cyber‑risks come into play appeared first on WeLiveSecurity

5.5 years in a US prison for Estonian man linked to $53 million ransomware attacks
US charges Russian agents over cyber attacks on oil refineries and nuclear power plants
IcedID malware, in the hijacked email thread, with the insecure Exchange servers

security update

Sophos fixes critical hijack flaw in firewall offering
Google Chrome, Microsoft Edge patched in race against exploitation
Okta Says It Goofed in Handling the Lapsus$ Attack
Critical Sophos Security Bug Allows RCE on Firewalls
China APT group using Russia invasion, COVID-19 in phishing attacks
Google Chrome patches mysterious new zero-day bug – update now
Triton malware still a threat to energy sector, FBI warns

openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssl-1.0.2k-25.el7_9.x86_64.rpm openssl-debuginfo-1.0.2k-25.el7_9.i686.rpm openssl-debuginfo-1.0.2k-25.el7_9.x86_64.rpm ope [More…]

expat: Malformed 2- and 3-byte UTF-8 sequences can lead to arbitrary code execution (CVE-2022-25235) * expat: Namespace-separator characters in “xmlns[:prefix]” attribute values can lead to arbitrary code execution (CVE-2022-25236) * expat: Integer overflow in storeRawNames() (CVE-2022-25315) * expat: Large number of prefixed XML attributes on a single tag can crash libexpat (CVE-2021-4596 [More…]

Red Hat OpenShift Container Platform release 4.10.6 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.