Menu

Monthly Archives: September 2023

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=”.?../../../../../../../../../../etc/passwd” in an xi:include element. (CVE-2023-38633)

Recovery Volume Improper Validation of Array Index Remote Code Execution Vulnerability. (CVE-2023-40477) References: – https://bugs.mageia.org/show_bug.cgi?id=32205

A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition […]

Google warns infoseccers: Beware of North Korean spies sliding into your DMs

security update

Enterprise security challenges for CNI organizations: Security challenges with people and processes

Security fix for CVE-2023-37464

– patchlevel 1872 —- The newest upstream commit Security fixes for CVE-2023-4733, CVE-2023-4752, CVE-2023-4750

Release notes for xrdp v0.9.23 (2023/08/31) General announcements – Running xrdp and xrdp-sesman on separate hosts is still supported by this release, but is now deprecated. This is not secure. A future v1.0 release will replace the TCP socket used between these processes with a Unix Domain Socket, and then cross-host running will not be […]

Security fix for CVE-2023-37464

Release notes for xrdp v0.9.23 (2023/08/31) General announcements – Running xrdp and xrdp-sesman on separate hosts is still supported by this release, but is now deprecated. This is not secure. A future v1.0 release will replace the TCP socket used between these processes with a Unix Domain Socket, and then cross-host running will not be […]

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The container bci/php was updated. The following patches have been included in this update:

The container bci/php-fpm was updated. The following patches have been included in this update:

The container bci/php-apache was updated. The following patches have been included in this update:

Security fix for CVE-2022-45061

New version 4.0.8. Includes fixes for CVE-2023-2906, CVE-2023-4511, CVE-2023-4512, CVE-2023-4513.

Security fix for CVE-2022-45061

security update

Safe delivery

An update is now available for Red Hat OpenShift GitOps 1.9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Apple races to patch the latest zero-day iPhone exploit

Vulnerabilities were found in libssh2, a client-side C library implementing the SSH2 protocol, which could lead to denial of service or remote information disclosure.

Microsoft, recently busted by Beijing, thinks it’s across China’s ever-changing cyber-offensive

It was discovered that there was a potential denial of service vulnerability in Django, a popular Python-based web development framework.

Russian infosec boss gets nine years for $100M insider-trading caper using stolen data

Several security issues were fixed in GRUB2.

It was discovered that there was a potential Denial of Service (DoS) vulnerability in memcached, a high-performance in-memory object caching system.

Update to prevent invalid fragment values from leading to a buffer overrun

US, UK sanction more Russians linked to Trickbot
Lawsuit claims Tesla corp data security is far less advanced than its cars

Cybercrime is on the rise. The number of ransomware attacks has increased by 18%, while the worldwide volume of phishing attacks doubled to 500 million in 2022. Depending on the size of the business, one-third to two-thirds of businesses suffer malware attacks in any given year. And those attacks are costing companies a lot of […]

Thousands of dollars stolen from Texas ATMs using Raspberry Pi

When it comes to keeping sensitive data safe, email encryption is a necessity. But it doesn’t have to be a necessary evil. Too many employees and IT experts have experienced the pain of trying to use a needlessly complicated email encryption solution. There’s the endless steps, the hard-to-navigate portals, and the time-consuming processes that add […]

Pizza Hut Australia leaks one million customers’ details, claims ShinyHunters hacking group

PLIB could be made to execute arbitrary code if it opens a specially crafted TGA file.

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

If you like to play along with the illusion of privacy, smart devices are a dumb idea
UK drops ‘spy clause’ for scanning encrypted messages, admits it’s not ‘feasible’

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-busybox was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-busybox was updated. The following patches have been included in this update:

China reportedly bans iPhones from more government offices
Smashing Security podcast #338: Catfishing services, bad sports, and another cockup
Microsoft: China stole secret key that unlocked US govt email from crash debug dump
Guy who ran Bitcoins4Less tells Feds he had less than zero laundering protections
Coffee Meets Bagel outage caused by cybercriminals deleting data and files
Meatbag mishaps more menacing than malware? CISOs think so

Updated Red Hat OpenShift Distributed Tracing 2.9 container images are now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update that fixes one vulnerability is now available.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

Red Hat OpenShift Container Platform release 4.10.67 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.10.

The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update:

security update

You patched yet? Years-old Microsoft security holes still hot targets for cyber-crooks

security update

Big Tech has failed to police Russian disinformation, EC study concludes
Freecycle gives users the gift of a data breach notice

Multicluster Engine for Kubernetes 2.1.8 General Availability release images, which fix bugs and update container images. Red Hat Product Security has rated this update as having a security impact

An update for kernel-rt is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

An update is now available for Red Hat Ansible Automation Platform 2.4 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.

LockBit ransomware gang steals data related to security of UK military bases
Northern Ireland top cop quits in wake of data breach and disciplinary controversy

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

security update

Attackers accessed UK military data through high-security fencing firm’s Windows 7 rig
Microsoft calls time on ancient TLS in Windows, breaking own stuff in the process
Tsunami watch

Red Hat JBoss Web Server 5.7.4 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, and Windows Server. Red Hat Product Security has rated this release as having a security impact

An update is now available for Red Hat JBoss Web Server 5.7.4 on Red Hat Enterprise Linux versions 7, 8, and 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in BusyBox.

Northern Irish cops release 2 men after Terrorism Act arrests linked to data breach

Several security issues were fixed in atftp.

How to get a handle on shadow AI
Deep Instinct takes a prevention-first approach to stopping ransomware and other malware using deep learning

Several security issues were fixed in Thunderbird.

Apple opens annual applications for free hackable iPhones

Null pointer dereference in ber_memalloc_x() function (CVE-2023-2953) References: – https://bugs.mageia.org/show_bug.cgi?id=32073 – https://ubuntu.com/security/notices/USN-6197-1

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the oldstable distribution (bullseye), these problems have been fixed

The 6.4.13 stable kernel updates contain a number of important fixes across the tree.

The 6.4.13 stable kernel updates contain a number of important fixes across the tree.

Freecycle users told to change passwords after data breach
Cops drill into chat apps, sink plot to smuggle tons of coke into Europe

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

– New upstream version (117.0)

https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/H46H5ZYZG2PYUQ5STK7NWKF7GXYW7H6B/

Updates to Kubernetes for F38 and F39. Security fixes for CVE-2023-3955 and CVE-2023-3676. Related update for rawhide already in stable. Update for F37 is currently in COPR at https://copr.fedorainfracloud.org/coprs/buckaroogeek/copr-k8s-1.25/ due to golang blocker.

security update

More Okta customers trapped in Scattered Spider’s web
Another data breach at Forever 21 leaks details of 500,000 current and former employees
Massive attack

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Improving containerization security with Red Hat OpenShift
Enterprise security challenges for CNI organizations: Overview of security challenges