Menu

Monthly Archives: January 2024

FBI confirms it issued remote kill command to blow out Volt Typhoon’s botnet
Ransomware payment rates drop to new low – only 29% of victims are forking over cash
Nearly 4-year-old Cisco vuln linked to recent Akira ransomware attacks
We know nations are going after critical systems, but what happens when crims join in?
Ivanti releases patches for VPN zero-days, discloses two more high-severity vulns

Multiple vulnerabilities have been found in containerd, the worst of which could result in privilege escalation.

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218049 * bsc#1218050

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051

* bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053

* bsc#1216207 * bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050

Canada’s ‘most prolific hacker’ jailed for two years

https://security-tracker.debian.org/tracker/DSA-5610-1

US shorts China’s Volt Typhoon crew targeting America’s criticals
Jenkins jitters as 45,000 servers still vulnerable to RCE attacks after patch released
Reg story prompts fresh security bulletin, review of Juniper Networks’ CVE process

Postfix, a popular mail server, allowed SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking

IaC Security Scanning: Ensuring Security in the Open-Source Environment

TinyXML could be made to crash if it opened a specially crafted file.

Protecting against software supply chain attacks
UK biometrics boss bows out, bemoaning bureaucratic blunders

The container bci/python was updated. The following patches have been included in this update:

The container bci/php-fpm was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

https://security-tracker.debian.org/tracker/DSA-5611-1

SolarWinds slams SEC lawsuit against it as ‘unprecedented’ victim blaming
Be the Royal Family’s Cybersecurity Manager, and get a cut-price honey dipper!
Trickbot malware developer jailed for five years
Best Practices for WordPress Site Security on Linux Webservers

Exim could be made to bypass an SPF protection mechanism if it received a specially crafted request.

The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update:

The container suse/rmt-mariadb was updated. The following patches have been included in this update:

The container suse/rmt-mariadb-client was updated. The following patches have been included in this update:

The container suse/nginx was updated. The following patches have been included in this update:

Security fix for CVE-2023-48795

Tesla hacks make big bank at Pwn2Own’s first automotive-focused event
Top 3 Cybersecurity Trends for SME Business Leaders
750 million Indian mobile subscribers’ info for sale on dark web

https://security-tracker.debian.org/tracker/DSA-5608-1

Several vulnerabilities were discovered in the Slurm Workload Manager, a cluster resource management and job scheduling system, which may result in privilege escalation, denial of service, bypass of message hash checks or opening files with an incorrect set of extended groups.

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container bci/php was updated. The following patches have been included in this update:

https://security-tracker.debian.org/tracker/DSA-5609-1

Blackwood hijacks software updates to deploy NSPX30 – Week in security with Tony Anscombe

The previously unknown threat actor used the implant to target Chinese and Japanese companies, as well as individuals in China, Japan, and the UK

Assessing and mitigating supply chain cybersecurity risks

Blindly trusting your partners and suppliers on their security posture is not sustainable – it’s time to take control through effective supplier risk management

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container suse/rmt-server was updated. The following patches have been included in this update:

The container bci/php-apache was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

Microsoft sheds some light on Russian email heist – and how to learn from Redmond’s mistakes
Wait, security courses aren’t a requirement to graduate with a computer science degree?
Guess the company: Takes your DNA, blames you when criminals steal it, can’t spot a cyberattack for 5 months

* bsc#1218571 Cross-References: * CVE-2023-7207

* bsc#1218728 Cross-References: * CVE-2024-23301

* bsc#1218802 Cross-References: * CVE-2023-51257

* bsc#1218802 Cross-References: * CVE-2023-51257

* bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742

Akira ransomware gang says it stole passport scans from Lush in 110 GB data heist
What’s next on the horizon for telecommunications service providers? A look at 2024 with Red Hat.
Enabling Peer Pods on IBM Z and LinuxONE with Red Hat OpenShift sandboxed containers

Update to 115.7.0 * https://www.mozilla.org/en- US/security/advisories/mfsa2024-04/ * https://www.thunderbird.net/en- US/thunderbird/115.7.0/releasenotes/

Trickbot malware scumbag gets five years for infecting hospitals, businesses

https://security-tracker.debian.org/tracker/DSA-5607-1

AI is already being used by ransomware gangs, warns NCSC
EquiLend drags systems offline after admitting attacker broke in

* bsc#1205463 * bsc#1218189 Cross-References: * CVE-2022-45047

* bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742

* bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742

The chromium-browser-stable package has been updated to the 120.0.6099.224 release. 4 vulnerabilities are fixed; some of them are listed below: High CVE-2024-0517: Out of bounds write in V8. Reported by Toan (suto) Pham of Qrious Secure on 2024-01-06.

The updated packages fix security vulnerabilities: A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record. (CVE-2023-38469) A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function. (CVE-2023-38470)

Patch management needs a revolution, part 3: Vulnerability scores and the concept of trust

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

HPE joins the ‘our executive email was hacked by Russia’ club
Smashing Security podcast #356: Big dumpers, AI defamation, and the slug that slurped
US judge rejects spyware developer NSO’s attempt to bin Apple’s spyware lawsuit

https://security-tracker.debian.org/tracker/DSA-5604-1

https://security-tracker.debian.org/tracker/DSA-5603-1

Mobb unveils vulnerability fixer for GitHub users
SEC Twitter hack blamed on SIM swap attack
Major IT outage at Europe’s largest caravan and RV club makes for not-so-happy campers
Using GoAnywhere MFT for file transfers? Patch now – an exploit’s out for a critical bug
What Microsoft’s latest email breach says about this IT security heavyweight
COVID-19 test lab accused of exposing 1.3 million patient records to open internet
GCHQ’s NCSC warns of ‘realistic possibility’ AI will help state-backed malware evade detection

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

A vulnerability has been discovered in sudo which can lead to execution manipulation through rowhammer-style memory manipulation.

Multiple vulnerabilities have been discovered in GOCR, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Ruby, the worst of which could lead to execution of arbitrary code.

Backport fix for CVE-2023-51257.

Mitigate CVE-2024-0690

https://security-tracker.debian.org/tracker/DSA-5606-1

https://security-tracker.debian.org/tracker/DSA-5605-1

CISA boss swatted: ‘While my own experience was certainly harrowing, it was unfortunately not unique’
Accused PII seller faces jail for running underground fraud op