The UK has finalized its first independent data adequacy decision since leaving the European Union (EU) which will allow UK organisations to securely transfer personal data to the Republic of Korea without restrictions by the end of the year. The UK government stated that the new legislation, first agreed upon in principle in July, will allow businesses in both countries to share data more easily, enhancing opportunities for cooperation and growth. The decision comes following a full assessment of the Republic of Korea’s personal data legislation, with the UK government concluding that the nation has strong privacy laws in place that will protect data transfers while upholding the rights and protections of UK citizens.
Daily Archives: November 23, 2022
USN-5638-3: Expat vulnerability
USN-5638-1 fixed a vulnerability in Expat. This update provides
the corresponding updates for Ubuntu 16.04 ESM, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-43680)
This update also fixes a minor regression introduced in
Ubuntu 18.04 LTS.
We apologize for the inconvenience.
Original advisory details:
Rhodri James discovered that Expat incorrectly handled memory when
processing certain malformed XML files. An attacker could possibly
use this issue to cause a crash or execute arbitrary code.
mariadb-10.5-3620221121091939.5e5ad4a0
FEDORA-MODULAR-2022-d8e8a4ba1e
Packages in this update:
mariadb-10.5-3620221121091939.5e5ad4a0
Update description:
MariaDB 10.5.18 & Galera 26.4.13
Release notes:
mariadb-10.5-3520221121091939.f27b74a8
FEDORA-MODULAR-2022-87965d9e1f
Packages in this update:
mariadb-10.5-3520221121091939.f27b74a8
Update description:
MariaDB 10.5.18 & Galera 26.4.13
Release notes:
mariadb-10.5-3720221121091939.9e842022
FEDORA-MODULAR-2022-5bfccade30
Packages in this update:
mariadb-10.5-3720221121091939.9e842022
Update description:
MariaDB 10.5.18 & Galera 26.4.13
Release notes:
Yanluowang Ransomware’s Russian Links Laid Bare
USN-5737-1: APR-util vulnerability
It was discovered that APR-util did not properly handle memory when using
SDBM database files. A local attacker with write access to the database
can make a program or process using these functions crash, and cause a
denial of service.
How to reset a Kerberos password and get ahead of coming updates
Do you recall when you last reset your Kerberos password? Hopefully that was not the last time I suggested you change it, back in April of 2021, when I urged you to do a regular reset of the KRBTGT account password. If you’ve followed my advice, you are already one step ahead of the side effects caused by the November updates that introduced Kerberos changes.
While many of you may be waiting to install the “fixed” versions of the updates that deal with the introduced authentication issues, or you may wish to install the out-of-band updates that will fix the side effects, there are more steps to do this patching month and in the months ahead.
Online retailers should prepare for a holiday season spike in bot-operated attacks
With the holiday shopping season in full swing, retail websites can expect a spike in account takeover fraud, DDoS, and other attacks, including attacks via APIs, which now represent almost half of e-commerce traffic.
According to a recent report from application and data security company Imperva, bots account for more than 40% of traffic to online retail websites on average, with around 24% of traffic coming from “bad bots” that engage in various forms of automated attacks.
“The high risk for e-commerce is more noticeable during the holiday shopping season, which now begins as early as October,” the company said. “Bad actors have gotten wise to consumer shopping patterns, which start weeks before significant events like Black Friday due to shipping delays and item availability concerns, as well as marketing tactics such as shops offering unbeatable deals weeks before Black Friday.”
UK Privacy Tsar Defends Controversial Enforcement Strategy
Information commissioner wants to avoid “money-go-round” of government fines