Menu

Latest articles

Red Hat Risk Report: A tour of 2020’s branded security flaws

Security fix for CVE-2021-27803

Update to CVE release 3002.5-1 for Python 3 Fixed on this release: CVE-2021-25283 Fixed in 3002.3: CVE-2020-28243 CVE-2020-28972 CVE-2020-35662 CVE-2021-3148 CVE-2021-3144 CVE-2021-25281 CVE-2021-25282 CVE-2021-25283 CVE-2021-25284 CVE-2021-25284 CVE-2021-3197

Update to CVE release 3001.6-1 for Python 3 Fixed in 3001.5: CVE-2020-28243 CVE-2020-28972 CVE-2020-35662 CVE-2021-3148 CVE-2021-3144 CVE-2021-25281 CVE-2021-25282 CVE-2021-25283 CVE-2021-25284 CVE-2021-3197

* Bring back the WebKitPluginProcess that was removed by mistake. (It will disappear again soon.) * Fix RunLoop objects leaked in worker threads. * Use Internet Explorer quirk for Google Docs. (Yes, even this new quirk is broken already.) * Security fixes: CVE-2020-13558

Gootkit malware crew using SEO to get pwned websites in front of unwitting marks
Perl.com theft blamed on social engineering attack: Registrar ‘convinced’ to alter DNS records by miscreants

security update

Mobile Adware Booms, Online Banks Become Prime Target for Attacks
Malware Loader Abuses Google SEO to Expand Payload Delivery
Passwords, Private Posts Exposed in Hack of Gab Social Network
Chinese businessman plotted with GE insider to steal transistor secrets, say Feds
Malware attack that crippled Mumbai’s power system came from China, claims infosec intel outfit Recorded Future
Firewall Vendor Patches Critical Auth Bypass Flaw
“Mentally ill demon hackers” blamed for massive Gab data leak

Update to security and bugfix release 2.9.18.

bind: Buffer overflow in the SPNEGO implementation affecting GSSAPI security policy negotiation (CVE-2020-8625) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 bind-debuginfo-9.11.4-26.P2.el7_9.4.i686.rpm bind-debuginfo-9.11.4-26.P2.el7_9.4.x86_64.rpm bind-export-libs-9 [More…]

Update to security and bugfix release 2.9.18.

Gizmodo gives poor password advice

An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for bind is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for podman is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Cyber-attackers work 24/7 … but what about your security team?
Mobile spyware fan Saudi Crown Prince accused by US intel of Khashoggi death

security update

– New upstream version (86.0)

Update to 88.0.4324.182. Fixes CVE-2021-21149 CVE-2021-21150 CVE-2021-21151 CVE-2021-21152 CVE-2021-21153 CVE-2021-21154 CVE-2021-21155 CVE-2021-21156 CVE-2021-21157

Get started with CrowdSec v.1.0.X>

The container suse/sle15 was updated. The following patches have been included in this update:

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that solves 5 vulnerabilities and has one errata is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2021:0661

Upstream details at : https://access.redhat.com/errata/RHSA-2021:0656

Upstream details at : https://access.redhat.com/errata/RHSA-2021:0024

Upstream details at : https://access.redhat.com/errata/RHSA-2020:5408

Upstream details at : https://access.redhat.com/errata/RHSA-2020:5402

Beast Glatisant and Jelmer Vernooij reported that python-aiohttp, a async HTTP client/server framework, is prone to an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a different website.

security update

Amazon Dismisses Claims Alexa ‘Skills’ Can Bypass Security Vetting Process
Imperva pretty adamant that security analytics aggregator product Sonar is not ‘one dashboard to rule them all’
Stalkerware Volumes Remain Concerningly High, Despite Bans
Lazarus Targets Defense Companies with ThreatNeedle Malware
Yeezy Fans Face Sneaker-Bot Armies for Boost ‘Sun’ Release  
Malware Gangs Partner Up in Double-Punch Security Threat
Podcast: Ransomware Attacks Exploded in Q4 2020
Protecting Sensitive Cardholder Data in Today’s Hyper-Connected World

An update that fixes one vulnerability is now available.

Google looks at bypass in Chromium’s ASLR security defense, throws hands up, won’t patch garbage issue
Npower scraps app, and urges customers to change passwords, after data breach
Championing worthy causes: How ESET gives a helping hand

A snapshot of some of the ways ESET makes an impact supporting the well-being of people, communities and the environment The post Championing worthy causes: How ESET gives a helping hand appeared first on WeLiveSecurity

Half a million stolen French medical records, drowned in feeble excuses

Several issues have been found in python-pysaml2, a pure python implementation of SAML Version 2 Standard. CVE-2017-1000433

The container suse/sles12sp5 was updated. The following patches have been included in this update:

India’s demand to identify people on chat apps will ‘break end-to-end encryption’, say digital rights warriors

security update

security update

Update postgresql and libpq to the new upstream release.

Update postgresql and libpq to the new upstream release.

Linux: display frontend “be-alloc” mode is unsupported (comment only) [XSA-363, CVE-2021-26934] (#1929549) arm: The cache may not be cleaned for newly allocated scrubbed pages [XSA-364, CVE-2021-26933] (#1929547)

Cyberattacks Launch Against Vietnamese Human-Rights Activists
1Password has none, KeePass has none… So why are there seven embedded trackers in the LastPass Android app?
Facebook ramps up fight against child abuse content

Two new tools will warn users about the risks of searching for and sharing content that exploits children, including the potential legal consequences of doing so The post Facebook ramps up fight against child abuse content appeared first on WeLiveSecurity

Health Website Leaks 8 Million COVID-19 Test Results
Malicious Mozilla Firefox Extension Allows Gmail Takeover
Google’s Password Checkup tool rolling out to Android devices

People who use devices running Android 9 or newer will be alerted if their login credentials have been stolen The post Google’s Password Checkup tool rolling out to Android devices appeared first on WeLiveSecurity

Cisco Warns of Critical Auth-Bypass Security Flaw
Recorded Future’s free Cyber Daily newsletter brings trending threat insights straight to your inbox
UK’s National Cyber Security Centre sidles in to help firm behind hacked NurseryCam product secure itself
Ever felt that a few big tech companies are following you around the internet? That’s because … they are
Defense in depth with Red Hat Insights

An update that fixes one vulnerability is now available.

Alexa, swap out this code that Amazon approved for malware… Installed Skills can double-cross their users

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or information disclosure.

The package mumble before version 1.3.4-1 is vulnerable to arbitrary code execution.

The package postgresql before version 13.2-1 is vulnerable to information disclosure.

The package ansible-base before version 2.10.6-1 is vulnerable to information disclosure.

The package keycloak before version 12.0.3-1 is vulnerable to cross- site scripting.

Smashing Security podcast #216: Playboy, prison, and digital ploys – with Garry Kasparov
Tax Season Ushers in Quickbooks Data-Theft Spike
Mozilla Patches Bugs in Firefox, Now Blocks Cross-Site Cookie Tracking
Revealed: The military radar system swiped from aerospace biz, leaked online by Clop ransomware gang
VMWare Patches Critical RCE Flaw in vCenter Server
‘We’re finding bugs way faster than we can fix them’: Google sponsors 2 full-time devs to improve Linux security
Nvidia’s Anti-Cryptomining GPU Chip May Not Discourage Attacks
Microsoft Lures Populate Half of Credential-Swiping Phishing Emails

An update for ansible is now available for Ansible Engine 2 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for ansible is now available for Ansible Engine 2.9 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Red Hat OpenShift Container Platform release 4.7.0 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Introducing Red Hat Vulnerability Scanner Certification
The history of open source risk reporting

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Think you know all about security pen-testing in the cloud? Here’s how to prove it
Mozilla Firefox keeps cookies kosher with quarantine scheme, 86s third-party cookies in new browser build
What’s CNAME of your game? This DNS-based tracking defies your browser privacy defenses
Indian Railways suffers unspecified security ‘breaches in various IT applications’
Microsoft president asks Congress to force private-sector orgs to publicly admit when they’ve been hacked
VMware warns of critical remote code execution flaw in vSphere HTML5 client