Menu

Latest articles

An update for openssl is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for openssl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for expat is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The first step to data privacy is admitting you have a problem, Google
Under the hood of Wslink’s multilayered virtual machine

ESET researchers describe the structure of the virtual machine used in samples of Wslink and suggest a possible approach to see through its obfuscation techniques The post Under the hood of Wslink’s multilayered virtual machine appeared first on WeLiveSecurity

Will Chinese giants defy US sanctions on Russia? We asked a ZTE whistleblower
Okta acknowledges ‘mistake’ in handling of Lapsus$ attack
Kaspersky, China Telecom, China Mobile named ‘threats to US national security’

security update

The container bci/rust was updated. The following patches have been included in this update:

Prepare Your Business for the Future of Cyberwar: A Review of The Art of Cyberwarfare>

This is the March 2022 update for .NET Core 3.1: SDK 3.1.417 and Runtime 3.1.23 Release notes: https://github.com/dotnet/core/blob/main/release- notes/3.1/3.1.23/3.1.23.md This includes fixes for CVE-2022-24464, CVE-2022-24512 and CVE-2020-8927

CVE-2022-24302: Creation of new private key files using `~paramiko.pkey.PKey` subclasses was subject to a race condition between file creation and mode modification, which could be exploited by an attacker with knowledge of where the Paramiko-using code would write out such files; this has been patched by using `os.open` and `os.fdopen` to ensure new files are […]

This is the March 2022 update for .NET Core 3.1: SDK 3.1.417 and Runtime 3.1.23 Release notes: https://github.com/dotnet/core/blob/main/release- notes/3.1/3.1.23/3.1.23.md This includes fixes for CVE-2022-24464, CVE-2022-24512 and CVE-2020-8927

CVE-2022-24302: Creation of new private key files using `~paramiko.pkey.PKey` subclasses was subject to a race condition between file creation and mode modification, which could be exploited by an attacker with knowledge of where the Paramiko-using code would write out such files; this has been patched by using `os.open` and `os.fdopen` to ensure new files are […]

Fix for CVE-2022-0860

The container bci/ruby was updated. The following patches have been included in this update:

The container suse/rmt-nginx was updated. The following patches have been included in this update:

The container suse/rmt-mariadb was updated. The following patches have been included in this update:

The container suse/rmt-mariadb-client was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

‘Precursor malware’ infection may be sign you’re about to get ransomware, says startup
DOJ Indicts Russian Gov’t Employees Over Targeting Power Sector

security update

Unit 42: Ransomware demands we’re aware of averaged $2.2m last year

Think of all the important files sitting on your computer right now. If your computer crashed tomorrow, would you be able to retrieve your important files? Would your business suffer as a result? As more and more of our daily activities incorporate digital and online files, it’s important for businesses and consumers to back up […]

Optimistic father of LAPSUS$ hacking suspect says he’s going to try to stop him using computers
Is a nation‑state digital deterrent scenario so far‑fetched?

Why has the conflict in Ukraine not caused the much anticipated global cyber-meltdown? The post Is a nation‑state digital deterrent scenario so far‑fetched? appeared first on WeLiveSecurity

Crypto malware in patched wallets targeting Android and iOS devices

ESET Research uncovers a sophisticated scheme that distributes trojanized Android and iOS apps posing as popular cryptocurrency wallets The post Crypto malware in patched wallets targeting Android and iOS devices appeared first on WeLiveSecurity

Atlassian flags Bitbucket and Confluence Data Center flaws
Hackers remotely start, unlock Honda Civics with $300 tech
Google Chrome Zero-Day Bugs Exploited Weeks Ahead of Patch
How AI can fend off supply-chain attacks
US DoJ reveals Russian supply chain attack targeting energy sector

The container suse/sles12sp3 was updated. The following patches have been included in this update:

The container ses/7/prometheus-webhook-snmp was updated. The following patches have been included in this update:

The container ses/7/ceph/prometheus-server was updated. The following patches have been included in this update:

The container ses/7/ceph/prometheus-node-exporter was updated. The following patches have been included in this update:

The container ses/7/ceph/prometheus-alertmanager was updated. The following patches have been included in this update:

Distributor dumps Kaspersky to show solidarity with Ukraine
UK police arrest 7 hacking suspects – have they bust the LAPSUS$ gang?
We blocked North Korea’s Chrome exploit, says Google
Microsoft Azure developers targeted by 200-plus data-stealing npm packages
British cops arrest seven in Lapsus$ crime gang probe

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

UK Cops Collar 7 Suspected Lapsus$ Gang Members
Microsoft Azure Developers Awash in PII-Stealing npm Packages
Just-Released Dark Souls Game, Elden Ring, Includes Killer Bug
HP finance manager went on $5m personal spending spree with company card
HubSpot Data Breach Ripples Through Crytocurrency Industry
Mustang Panda’s Hodur: Old tricks, new Korplug variant

ESET researchers have discovered Hodur, a previously undocumented Korplug variant spread by Mustang Panda, that uses phishing lures referencing current events in Europe, including the invasion of Ukraine The post Mustang Panda’s Hodur: Old tricks, new Korplug variant appeared first on WeLiveSecurity

Chinese APT Combines Fresh Hodur RAT with Complex Anti-Detection
S3 Ep75: Okta hack, CryptoRom, OpenSSL, and CafePress [Podcast]
Microsoft Help Files Disguise Vidar Malware
Top 3 Attack Trends in API Security – Podcast
Tax-Season Scammers Spoof Fintechs, Including Stash, Public

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

USN-5321-1 introduced minor regressions in Firefox.

An update for python-twisted is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for openstack-nova is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for numpy is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

UK Ministry of Defence takes recruitment system offline, confirms data leak
IT outage at Scotland’s Heriot-Watt University enters second week
Check Point spreads AI goodness throughout its security portfolio
F-Secure spins out new enterprise security business: WithSecure
Smashing Security podcast #267: Virtual kidnapping, two helipads, and a naughty Apple employee

security update

VMware fixes command injection, file upload flaws in Carbon Black security tool
Simplify your security with Forcepoint ONE
US says Russian ran online marketplace of stolen logins
Nestlé says it leaked its own test data, not Anonymous
Serious Security: DEADBOLT – the ransomware that goes straight for for your backups
AvosLocker ransomware – what you need to know
Cybercriminals made $7bn in pure profit in 2021, says FBI
DeadBolt Ransomware Resurfaces to Hit QNAP Again
Microsoft: Lapsus$ Used Employee Account to Steal Source Code
Lockbit wins ransomware speed test, encrypts 25,000 files per minute

Red Hat OpenShift Container Platform release 4.6.56 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.6.

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 17 vulnerabilities is now available.

An update that solves three vulnerabilities and has one errata is now available.

Fresh concerns about ‘indefinite’ UK government access to doctors’ patient data

An update that fixes 17 vulnerabilities is now available.

Okta now says: Lapsus$ may in fact have accessed customer info
Nvidia’s Morpheus AI security framework to land in April
Lapsus$ Data Kidnappers Claim Snatches From Microsoft, Okta

security update

Well done patching Log4j. Now, are you ready for the next zero day disaster?
Sandworm: A tale of disruption told anew

As the war rages, the APT group with a long résumé of disruptive cyberattacks enters the spotlight again The post Sandworm: A tale of disruption told anew appeared first on WeLiveSecurity

Russia Lays Groundwork for Cyberattacks on US Infrastructure – White House
FIDO: Here’s Another Knife to Help Murder Passwords
Serpent Backdoor Slithers into Orgs Using Chocolatey Installer

Several security issues were fixed in CKEditor.

Authentication oufit Okta investigating Lapsus$ breach report

An update for rh-mariadb105-mariadb and rh-mariadb105-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for rh-mariadb103-mariadb and rh-mariadb103-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes three vulnerabilities is now available.