The flaw resides in the tarfile module, automatically installed in any Python project
Monthly Archives: September 2022
NCSC: British Retailers Need to Move Beyond Passwords
The UK’s national cybersecurity agency also advised organizations on what steps they should take if their brand has been spoofed online
Report: The state of secure identity 2022
A new report from Okta has found that credential stuffing as a means of breaching Customer Identity and Access Management (CIAM) services is accelerating, fuelled by password reuse coupled with malicious bots and other automated tools.
The State of Secure Identity 2022 report, which is based on self-reported data from customers of Okta’s AuthO access management platform across the globe, found that 34% of all traffic across Auth0 network consists of credential stuffing attempts—amounting to nearly 10 billion attempts. In the first quarter of 2022, the Auth0 network tracked two of the largest credential stuffing spikes ever on the platform, with more than 300 million attempts per day.
CVE-2019-5641
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user’s session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last webpage visited by previous user
thunderbird-102.3.0-1.fc37
FEDORA-2022-b4583f536b
Packages in this update:
thunderbird-102.3.0-1.fc37
Update description:
Update to 102.3.0 ;
https://www.mozilla.org/en-US/security/advisories/mfsa2022-42/ ;
https://www.thunderbird.net/en-US/thunderbird/102.3.0/releasenotes/
thunderbird-102.3.0-1.fc35
FEDORA-2022-e88213dd24
Packages in this update:
thunderbird-102.3.0-1.fc35
Update description:
Update to 102.3.0 ;
https://www.mozilla.org/en-US/security/advisories/mfsa2022-42/ ;
https://www.thunderbird.net/en-US/thunderbird/102.3.0/releasenotes/
Multiple Vulnerabilities Discovered in Dataprobe’s iBoot-PDUs
They pose a number of risks to Dataprobe, including giving control of the iBoot-PDU to attackers
thunderbird-102.3.0-1.fc36
FEDORA-2022-feb7bdf6b2
Packages in this update:
thunderbird-102.3.0-1.fc36
Update description:
Update to 102.3.0 ;
https://www.mozilla.org/en-US/security/advisories/mfsa2022-42/ ;
https://www.thunderbird.net/en-US/thunderbird/102.3.0/releasenotes/
qemu-6.2.0-15.fc36
FEDORA-2022-f0a2695054
Packages in this update:
qemu-6.2.0-15.fc36
Update description:
nvme: Fix DMA reentrancy use-after-free (CVE-2021-3929)