Menu

Monthly Archives: August 2023

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

FTX crypto-clown Sam Bankman-Fried couldn’t even do house arrest. Now he’s in jail
Microsoft: Codesys PLC bugs could be exploited to ‘shut down power plants’
Maker of Chrome extension with 300,000+ users tells of constant pressure to sell out
Electoral Commission had internet-facing server with unpatched vuln
Magento shopping cart attack targets critical vulnerability revealed in early 2022

Ubuntu security team noted after extensive testing that DLA-3495-1 was incomplete as one PoC for CVE-2022-2400 (particularly the chroot escape) was still working on the patched version of the package.

CVE-2022-40982 Daniel Moghimi discovered Gather Data Sampling (GDS), a hardware vulnerability for Intel CPUs which allows unprivileged speculative

This update ships updated CPU microcode for some types of Intel CPUs and provides mitigations for security vulnerabilities. CVE-2022-40982

Privacy-invading LetMeSpy stalkerware announces it is shutting down after hack

The container bci/php-fpm was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

US Cyber Command boss says China’s spooky cyber skills still behind
There’s a good chance your VPN is vulnerable to privacy-menacing TunnelCrack attack
10,000 N Ireland police officers and staff have their details exposed after spreadsheet screw-up
S3 Ep147: What if you type in your password during a meeting?

An update is now available for Red Hat Ansible Automation Platform 2.3 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Rhysida ransomware – what you need to know
The State of Edge Security Report
Hardening SSH connections to managed hosts with Red Hat Ansible Automation Platform

Velocity Engine could be made to run arbitrary code if it opened a specially crafted file.

Get your staff’s consent before you monitor them, tech inquiry warns

The container suse/postgres was updated. The following patches have been included in this update:

The container bci/php was updated. The following patches have been included in this update:

The container bci/php-apache was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

Smashing Security podcast #334: Acoustic attacks, and the tears of a crypto rapper
Nearly every AMD CPU since 2017 vulnerable to Inception data-leak attacks

security update

security update

Microsoft Patch Tuesday: 74 CVEs plus 2 “Exploit Detected” advisories
Rapid7 prepares to toss 18% of workforce to cut costs
Northern Ireland police may have endangered its own officers by posting details online in error

Several security issues were fixed in GNU binutils.

A hardening measure was added to OpenSSH.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Multiple security vulnerabilities were discovered in HDF5, a Hierarchical Data Format and a library for scientific data. Memory leaks, out-of-bound reads and division by zero errors may lead to a denial of service when processing a malformed HDF file.

INTERPOL shutters ’16shop’ phishing-as-a-service outfit

Update to 2.53.17

Microsoft, Intel lead this month’s security fix emissions

security update

Cyber-extortionists pillage Colorado education dept
Serious Security: Why learning to touch-type could protect you from audio snooping
UK voter data exposed for over a year in attack on Electoral Commission
Navigating Software Scalability: A Practical Guide to Building Scalable Systems with Linux
China – which surveils everyone everywhere – floats facial recognition rules

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for kpatch-patch-4_18_0-147_78_1, kpatch-patch-4_18_0-147_80_1, kpatch-patch-4_18_0-147_81_1, kpatch-patch-4_18_0-147_83_1, and kpatch-patch-4_18_0-147_85_1 is now available for Red Hat Enterprise Linux 8.1. Update Services for SAP Solutions.

An update for kernel is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

North Korean hackers had access to Russian missile maker for months, say researchers
Stalkerware slinger LetMeSpy shuts down for good after database robbery

security update

security update

security update

Keep your sensitive data secure by using Encrypted Forms 2.0 from Jotform

An update for thunderbird is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update that fixes one vulnerability is now available.

Microsoft hits back at Tenable criticism of its infosec practices
Five Eyes nations detail dirty dozen most exploited vulnerabilities

The components for Red Hat OpenShift support for Windows Containers 6.0.1 are now available. This product release includes bug fixes and security update for the following packages: windows-machine-config-operator and windows-machine-config-operator-bundle.

Update `llhttp` to 8.1.1 and `python-aiohttp` to 3.8.5. Fixes CVE-2023-30589.

Multiple security vulnerabilities have been discovered in OpenImageIO, a library for reading and writing images. Buffer overflows and out-of-bounds read and write programming errors may lead to a denial of service (application crash) or the execution of arbitrary code if a malformed image

An update that contains security fixes can now be installed.

Several vulnerabilities were discovered in python-werkzeug, a collection of utilities for WSGI applications. CVE-2023-23934

A stack overflow in the MD5 function has been fixed in pdfcrack, a tool for recovering passwords and content from PDF files. For Debian 10 buster, this problem has been fixed in version 0.16-3+deb10u1.

The container sles-15-sp4-chost-byos-v20230804-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230803-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230803-x86_64-gen2 was updated. The following patches have been included in this update:

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the oldstable distribution (bullseye), these problems have been fixed

security update

security update

Red Hat Insights Compliance: Introducing new customization options for policies

The container bci/golang was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

arm: Guests can trigger a deadlock on Cortex-A77 [XSA-436, CVE-2023-34320] (#2228238) —- bugfix for x86/AMD: Zenbleed [XSA-433, CVE-2023-20593] —- x86/AMD: Zenbleed [XSA-433] omit OCaml 5 patch on fc38

Update to 2.53.17

Update to new upstream version 3.5.4. This brings a fix for a security issue, CVE-2023-30577. This update also fixes the manual pages.

Two US Navy sailors charged with giving Chinese spies secret military info

security update

security update

Alarm raised over Mozilla VPN: Wonky authorization check lets users cause havoc
“Crocodile of Wall Street” and her husband plead guilty to giant-sized cryptocrimes
Smashing Security podcast #333: Barbie and the stalking spouse

An incorrect Authentication Tag length usage was discovered in cjose, a C library implementing the Javascript Object Signing and Encryption (JOSE) standard, which could lead to integrity compromise.

Ransomware attacks cost manufacturing sector $46 billion in downtime since 2018, report claims

It was discovered that ntpd in ntpsec, a secure, hardened, and improved implementation derived from the original NTP project, could crash if NTS is disabled and an NTS-enabled client request (mode 3) is received.

update to 115.0.5790.110. Fixes the following security issue: CVE-2022-4908 CVE-2022-4909 CVE-2022-4910 CVE-2022-4908 CVE-2022-4909 CVE-2022-4910 CVE-2022-4906 CVE-2022-4907 CVE-2022-4906 CVE-2022-4907 CVE-2023-2311 CVE-2023-2313 CVE-2023-2311 CVE-2023-2313 CVE-2023-2929 CVE-2023-2929 CVE-2023-2314 CVE-2023-2314 CVE-2023-3598 CVE-2023-3598

– Updated to latest upstream (116.0)

Fix several crashes and rendering issues Security fixes: CVE-2023-38133, CVE-2023-38572, CVE-2023-38592, CVE-2023-38594, CVE-2023-38595, CVE-2023-38597, CVE-2023-38599, CVE-2023-38600, CVE-2023-38611

librsvg 2.56.3 release, fixing CVE-2023-38633: – Fix arbitrary file read when href has special characters. – Fix cascade for symbol elements being referenced from use elements.

Couple admit they laundered $4B in stolen Bitcoins after Bitfinex super-heist
Russia’s Cozy Bear is back and hitting Microsoft Teams to phish top targets