Menu

Latest articles

An update that solves two vulnerabilities and has 11 fixes is now available.

Several security issues and a regression were fixed in Expat.

Huawei UK board members resign over silence on Ukraine invasion

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure, spoofing or sandbox bypass.

Ukraine invasion: This may be the quiet before the cyber-storm, IT staff warned

New mozilla-thunderbird packages are available for Slackware 15.0, and -current to fix security issues.

SEC proposes four-day rule for public companies to report cyberattacks
APT41 Spies Broke Into 6 US State Networks via a Livestock App

security update

security update

App, security teams need closer bond to fend off cyberattacks
Dell opts out of Microsoft’s Pluton security for Windows
Most ServiceNow Instances Misconfigured, Exposed
Russian APTs Furiously Phish Ukraine – Google
Millions of APC Smart-UPS devices vulnerable to TLStorm

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Securing healthcare: An IT health check on the state of the sector

No sector or organization is immune to rapidly escalating cyberthreats, but when it comes to healthcare, the stakes couldn’t be higher The post Securing healthcare: An IT health check on the state of the sector appeared first on WeLiveSecurity

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Where are the (serious) Russian cyberattacks?

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities, contains one feature is now available.

Internet backbone provider Lumen quits Russia
Ragnar ransomware gang hit 52 critical US orgs, says FBI
Microsoft patches critical remote-code-exec hole in Exchange Server and others
Cow-counting app abused by China ‘to spy on US states’
Microsoft Addresses 3 Zero-Days & 3 Critical Bugs for March Patch Tuesday

security update

security update

security update

security update

What should we do about ‘systemic’ cyber risks? Wait, what even are those
“Dirty Pipe” Linux kernel bug lets anyone to write to any file
IT security is at crisis point – so what are you going to do about it?
Cyber‑readiness in the face of an escalated gray zone conflict

Organizations worldwide should remain on high alert for cyberattacks as the risk of major cyber-spillover from the crisis in Ukraine continues to loom large The post Cyber‑readiness in the face of an escalated gray zone conflict appeared first on WeLiveSecurity

The Uncertain Future of IT Automation
Zero-Click Flaws in Widely Used UPS Devices Threaten Critical Infratructure
Bug in the Linux Kernel Allows Privilege Escalation, Container Escape
Google buys threat intel giant Mandiant for $5.4bn

It was discovered that SPIP, a website engine for publishing, would allow a malicious user to execute arbitrary code. For the oldstable distribution (buster), this problem has been fixed

Redis could be made to run programs if it received specially crafted network traffic from an authenticated user.

China’s annual parliament gives tech industry much to ponder
Azure flaw allowed users to control others’ accounts
Linux distros patch ‘Dirty Pipe’ make-me-root kernel bug

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

Novel Attack Turns Amazon Devices Against Themselves

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

Samsung Confirms Lapsus$ Ransomware Hit, Source Code Leak
UN mulls Russia’s pitch for cybercrime treaty
NVIDIA’s Stolen Code-Signing Certs Used to Sign Malware
Lapsus$ extortionists dump data online as Samsung admits breach
Critical Firefox Zero-Day Bugs Allow RCE, Sandbox Escape
“Alexa, hack yourself” – researchers describe new exploit that turns smart speakers against themselves
Adafruit suffers GitHub data breach – don’t let this happen to you
Forcepoint ONE simplifies your security
Nmap Firewall Evasion Techniques>

An update for the virt:rhel and virt-devel:rhel modules is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in OpenJDK.

Several security issues were fixed in GNU C Library.

Several vulnerabilities have been discovered in Expat, an XML parsing C library, which could result in denial of service or potentially the execution of arbitrary code, if a malformed XML file is processed.

Several security issues were fixed in PHP.

A command injection vulnerability was found in FreeCAD, a parametric 3D modeler, when importing DWF files with crafted filenames. For Debian 9 stretch, this problem has been fixed in version

Prevent hackers by getting into their heads. Here’s how.
Global consultancies quit Russia
Conti ransomware gang, which leaked ransomware victims’ data, has its own data leaked

Several issues have been found in tiff, a library and tools to manipulate and convert files in the Tag Image File Format (TIFF). CVE-2022-22844

It was discovered that the SQL plugin in cyrus-sasl2, a library implementing the Simple Authentication and Security Layer, is prone to a SQL injection attack. An authenticated remote attacker can take advantage

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free (CVE-2022-26485). An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape (CVE-2022-26486).

A bug was found in containerd where containers launched through containerd’s CRI implementation with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive

Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. (CVE-2022-0561)

An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity. (CVE-2021-36370)

Firefox patches two in-the-wild exploits – update now!

An update that fixes one vulnerability is now available.

An update that fixes 15 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

The container suse/sle15 was updated. The following patches have been included in this update:

Leaked stolen Nvidia cert can sign Windows malware

The container suse/sle15 was updated. The following patches have been included in this update:

Russia’s invasion kicks Senate into cybersecurity law mode
Massive Meris Botnet Embeds Ransomware Notes from REvil

security update

Facebook is vile, but banning it in Russia is wrong

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

ESET Research Podcast: Ukraine’s past and present cyberwar

Press play to hear Aryeh Goretsky, Jean-Ian Boutin and Robert Lipovsky discuss how recent malware attacks in Ukraine tie into years of cyberattacks against the country The post ESET Research Podcast: Ukraine’s past and present cyberwar appeared first on WeLiveSecurity

Free HermeticRansom Ransomware Decryptor Released
BBC points Russians to the Tor version of itself
NHS Digital’s demise bad for 55 million patients’ privacy – ex-chairman
TikTok under investigation in US over harms to children

An update that solves two vulnerabilities, contains two features and has two fixes is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences–>Advanced–>HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in […]

Update to 2.34.6: * Fix accessibility not working when the Bubblewrap sandbox is enabled. * Fix rendering of scrollbars when overlay scrollbars are disabled. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-22620 —- Update to 2.34.5: * Improve VP8 codec selection when using GStreamer 1.20. * Fix connecting to the accessiblity bus […]

An update that fixes 12 vulnerabilities is now available.

Amazon Alexa can be hijacked via commands from own speaker
Switzerland’s SWIFT data centre under guard after Russian banks excluded
Phishing Campaign Targeted Those Aiding Ukraine Refugees