Menu

Monthly Archives: July 2023

security update

White House: Losing Section 702 spy powers would be among ‘worst intelligence failures of our time’
SEC demands four-day disclosure limit for cybersecurity breaches

Tavis Ormandy discovered that under specific microarchitectural circumstances, a vector register in “Zen 2” CPUs may not be written to 0 correctly. This flaw allows an attacker to leak register contents across concurrent processes, hyper threads and virtualized guests.

Hikvision and Nvidia named in contract for Uyghur detection

Several security issues were fixed in Wireshark.

What would sustainable security even look like?

A security issue was discovered in Thunderbird, which could result in spoofing of filenames of email attachments. For Debian 10 buster, this problem has been fixed in version

US senator victim-blames Microsoft for Chinese hack

A security issue was discovered in Thunderbird, which could result in spoofing of filenames of email attachments. For the oldstable distribution (bullseye), this problem has been fixed

SA-CORE-2009-001 ( http://drupal.org/node/358957 ) Remember to log in to your site as the admin user before upgrading this package. After upgrading the package, browse to http://host/drupal/update.php to run the upgrade script.

Tavis Ormandy discovered that under specific microarchitectural circumstances, a vector register in AMD “Zen 2” CPUs may not be written to 0 correctly. This flaw allows an attacker to leak sensitive information across concurrent processes, hyper threads

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

security update

security update

Several security issues were fixed in the Linux kernel.

Update to 3.14. Security fix for CVE-2023-38403

Update to 3.14. Security fix for CVE-2023-38403

Florida man accused of hoarding America’s secrets faces fresh charges
Millions of people’s data stolen because web devs forget to check access perms

OpenShift API for Data Protection (OADP) 1.0.11 is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which

FBI boss: Congress must renew Section 702 spy powers – that’s how we get nearly all our cyber intel
Chinese companies evade sanctions, fuel Moscow’s war on Ukraine, says report
SEC requires firms to report cyberattacks within 4 days, but not everyone may like it
Flaw in Ninja Forms WordPress plugin allows hackers to steal submitted data
Hawaii Community College admits paying ransom to extortionists
The lost art of cloud application engineering

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

Security fix for [PUT CVEs HERE]

NATO probes hacktivist crew’s boasts of stolen portal data

security update

security update

It was discovered that the domain check in libmail-dkim-perl, a Perl module to cryptographically identify the sender of email, compares i and d tags case sensitive when t=s is set on the DKIM key which causes spurious fails of legitimate messages.

Medical files of 8M-plus people fall into hands of Clop via MOVEit mega-bug
Think tank calls for monitoring of Chinese AI-enabled products
Heart monitor manufacturer hit by cyberattack, takes systems offline
S3 Ep145: Bugs With Impressive Names!

Several security issues were fixed in Open-iSCSI.

Several security issues were fixed in the Linux kernel.

Weakness risk-patterns: A Red Hat way to identify poor software practices in the secure development lifecycle
Red Hat’s CWE journey

Several security issues were fixed in X.Org X Server.

Several security issues were fixed in LLVM Toolchain.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Crooks pwned your servers? You’ve got four days to tell us, SEC tells public companies
Smashing Security podcast #332: Nudes leak at the plastic surgery, Mali mail mix-up, and WormGPT

security update

Russia throws founder of infosec biz Group-IB in the clink for treason
Following claims by two ransomware groups, Yamaha confirms cyberattack
New Realst Mac malware, disguised as blockchain games, steals cryptocurrency wallets

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

Ambulance patient records system hauled offline for cyber-attack probe
Sneaky Python package security fixes help no one – except miscreants
Ivanti plugs critical bug – but not before it was used against Norwegian government
Zenbleed: How the quest for CPU performance could put your passwords at risk
Apple patches exploited bugs in iPhones plus other holes

Avahi could be made to crash if it received specially crafted DBus traffic.

Django could be made to consume resources if it received specially crafted network traffic.

Unlocking the Secrets of Linux Security: An Expert Analysis

Several security issues were fixed in Graphite-Web.

Sam Wheating discovered that python-git, a Python library to interact with Git repositories, is vulnerable to shell injection due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command.

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

How to write a killer pentest report
TETRA radio comms used by emergency heroes easily cracked, say experts
Apple ships that recent “Rapid Response” spyware patch to everyone, fixes a second zero-day
AMD Zenbleed chip bug leaks secrets fast and easy
Google blocks staff’s internet access to reduce attacks – but will it work?

Update to latest upstream version, see following page for changes: https://www.mozilla.org/en-US/thunderbird/38.1.0/releasenotes/ This update also should fixed problems with thunderbird-lightning-gdata package. Rebase to Thunderbird 38. By this release thunderbird-lightning (calendar) package has become obsolete, because it is a part of Thunderbird 38 package now. For changes see: https://www.mozilla.org/en-US/thunderbird/38.0.1/releasenotes/ [More…]

Update to latest upstream version, see following page for changes: https://www.mozilla.org/en-US/thunderbird/38.1.0/releasenotes/ This update also should fixed problems with thunderbird-lightning-gdata package. Rebase to Thunderbird 38. By this release thunderbird-lightning (calendar) package has become obsolete, because it is a part of Thunderbird 38 package now. For changes see: https://www.mozilla.org/en-US/thunderbird/38.0.1/releasenotes/ [More…]

Hacking police radios: 30-year-old crypto flaws in the spotlight

OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049) * OpenJDK: array indexing integer overflow issue (8304468) (CVE-2023-22045) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Prepare for the next quarterly OpenJDK upstream releas [More…]

OpenJDK: ZIP file parsing infinite loop (8302483) (CVE-2023-22036) * OpenJDK: weakness in AES implementation (8308682) (CVE-2023-22041) * OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049) * harfbuzz: OpenJDK: O(n^2) growth via consecutive marks (CVE-2023-25193) * OpenJDK: HTTP client insufficient file name validation (8302475) (CVE-2023-220 [More…]

A new hope for software security
Google half-patches Cloud Build permissions exploit, the rest is on you

This update provides the upstream 7.0.10 maintenance release that fixes at least the following security vulnerabilities: Vulnerability in the Oracle VM VirtualBox prior to 7.0.10 contains an easily exploitable vulnerability that allows high privileged attacker

security update

Security fix for CVE-2023-38408

The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

The 6.4.4 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.

fix for CVE-2023-36664 (rhbz#2217805)

What happens if AI is wrong? – Week in security with Tony Anscombe

Responses generated by ChatGPT about individual people could be misleading or harmful or spill their personal information. What are the takeaways for you as a ChatGPT user?

8 common work-from-home scams to avoid

That ‘employer’ you’re speaking to may in reality be after your personal information, your money or your help with their illegal activities

Confidential containers with AMD SEV

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-37450

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update: