Menu

Monthly Archives: January 2024

UK water giant admits attackers broke into system as gang holds it to ransom
A guide to implementing fine-grained authorization
Australia imposes cyber sanctions on Russian it says ransomwared health insurer
Atlassian Confluence Server RCE attacks underway from 600+ IPs
Slug slimes aerospace biz AerCap with ransomware, brags about 1TB theft
EFF adds Street Surveillance Hub so Americans can check who’s checking on them
Ivanti and Juniper Networks accused of bending the rules with CVE assignments
Subway’s data torpedoed by LockBit, ransomware gang claims
With hackers poisoning water systems, US agencies issue incident response guide to boost cybersecurity
ICO fines spam slinging financial services biz
Safeguarding against the global ransomware threat
BreachForums admin ‘Pompourin’ sentenced to 20 years of supervised release
Leveraging Red Hat Service Mesh to encrypt AMQ communication on OpenShift
Unlocking the power of generative AI with Cloudera Data Platform and Red Hat OpenShift
Why many CISOs consider quitting – Week in security with Tony Anscombe

The job of a CISO is becoming increasingly stressful as cybersecurity chiefs face overwhelming workloads and growing concerns over personal liability for security failings

Virtual kidnapping: How to see through this terrifying scam

Phone fraud takes a frightening twist as fraudsters can tap into AI to cause serious emotional and financial damage to the victims

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container suse/rmt-mariadb-client was updated. The following patches have been included in this update:

Russians invade Microsoft exec mail while China jabs at VMware vCenter Server
Five ripped off IT giant with $7M+ in bogus work expenses, prosecutors claim
Is Temu safe? What to know before you ‘shop like a billionaire’

Here are some scams you may encounter on the shopping juggernaut, plus a few simple steps you can take to help safeguard your data while bagging that irresistible deal

Thieves steal 35.5M customers’ data from Vans sneakers maker
35.5 million customers of major apparel brands have their data breached after ransomware attack

* bsc#1218582 * bsc#1218583 * bsc#1218584 * bsc#1218585 * bsc#1218845

Patch management needs a revolution, part 2: The flood of vulnerabilities

The container suse/rmt-mariadb was updated. The following patches have been included in this update:

The container bci/php-fpm was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

IT consultant fined for daring to expose shoddy security
US agencies warn made-in-China drones might help Beijing snoop on the world

https://security-tracker.debian.org/tracker/DSA-5602-1

JPMorgan exec claims bank repels ’45 billion’ cyberattack attempts per day
Future of America’s Cyber Safety Review Board hangs in balance amid calls for rethink
Ransomware attacks hospitalizing security pros, as one admits suicidal feelings
Two more Citrix NetScaler bugs exploited in the wild
Google TAG: Kremlin cyber spies move into malware with a custom backdoor

* bsc#1218728 Cross-References: * CVE-2024-23301

* bsc#1217000 * bsc#1218475 Cross-References: * CVE-2024-22365

* bsc#1218475 Cross-References: * CVE-2024-22365

* bsc#1218413 Cross-References: * CVE-2023-51714

* bsc#1211188 * bsc#1211190 * bsc#1218126 * bsc#1218186 * bsc#1218209

* bsc#1108281 * bsc#1179610 * bsc#1183045 * bsc#1211162 * bsc#1211226

IPv6 approach for TCP SYN Flood attack over VoIP, Part II
IPv6 approach for TCP SYN Flood attack over VoIP, Part III
Vast botnet hijacks smart TVs for prime-time cybercrime
Enter the era of platform-based cloud security
Insurance website’s buggy API leaked Office 365 password and a giant email trove
Smashing Security podcast #355: Fishy Rishi, 23andMe, and the labour of love
Apple, AMD, Qualcomm GPU security hole lets miscreants snoop on AI training and chats
Unveiling the Future of Open-Source Generative AI
XOrg Server and Xwayland Patched Against Multiple Security Vulnerabilities
The 7 deadly cloud security sins and how SMBs can do things better

By eliminating these mistakes and blind spots, your organization can take massive strides towards optimizing its use of cloud without exposing itself to cyber-risk

What’s worse than paying an extortion bot that auto-pwned your database?
JFrog, AWS team up for machine learning in the cloud

* bsc#1218176 * bsc#1218240 * bsc#1218582 * bsc#1218583 * bsc#1218584

* bsc#1179610 * bsc#1211226 * bsc#1215237 * bsc#1215375 * bsc#1217250

* bsc#1218176 * bsc#1218240 * bsc#1218582 * bsc#1218583 * bsc#1218584

* bsc#1179610 * bsc#1205762 * bsc#1210778 * bsc#1212051 * bsc#1212703

* bsc#1108281 * bsc#1109837 * bsc#1179610 * bsc#1202095 * bsc#1211226

* bsc#1218582 * bsc#1218583 * bsc#1218584 * bsc#1218585

Windows Server 2022 patch is breaking apps for some users
Home improvement marketers dial up trouble from regulator
Combination of cheap .cloud domains and fake Shark Tank news fuel unhealthy wellness scams
Nokia walks the walk about its RAN to play on Uncle Sam’s China fears
FBI: Beware of thieves building Androxgh0st botnets using stolen creds
Double trouble for VMware and Atlassian admins – critical flaws to fix
More than 178,000 SonicWall firewalls are exposed to old denial of service bugs
Ivanti zero-day exploits explode as bevy of attackers get in on the act

Xerces-C++ could be made to crash or run programs if it opened a specially crafted file.

A buffer overread vulnerability has been found in libuv.

An update that fixes one vulnerability is now available.

An update that fixes 17 vulnerabilities is now available.

There were security issues in hplip’s `hpps` program due to fixed /tmp path usage in prnt/hpps/hppsfilter.c This update fixes these issues. References:

China’s gambling crackdown spawned wave of illegal online casinos and crypto-crime in Asia

Several security issues were fixed in MySQL.

Thousands of Juniper Networks devices vulnerable to critical RCE bug
Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers
Heartless scammers prey on hundreds of lost pet owners, demanding ransoms or else…
FTC secures first databroker settlement banning sale of sensitive location data
Critical flaw found in WordPress plugin used on over 300,000 websites
Ransomware protection deconstructed
China loathes AirDrop so much it’s publicized an old flaw in Apple’s P2P protocol
Lessons from SEC’s X account hack – Week in security with Tony Anscombe

The cryptocurrency rollercoaster never fails to provide a thrilling ride – this week it was a drama surrounding the hack of SEC’s X account right ahead of the much-anticipated decision about Bitcoin ETFs

Patch management needs a revolution, part 1: Surveying cybersecurity’s lineage
Supercharging chaos testing using AI
Red Hat Enterprise Linux 9 STIG automation released
High automation coverage for Center for Information Security in Red Hat Enterprise Linux 9
Number of orgs compromised via Ivanti VPN zero-days grows as Mandiant weighs in
Why we update… Data-thief malware exploits SmartScreen on unpatched Windows PCs
Exploit for under-siege SharePoint vuln reportedly in hands of ransomware crew
Secret multimillion-dollar cryptojacker snared by Ukrainian police
Secure network operations for hybrid working
So, are we going to talk about how GitHub is an absolute boon for malware, or nah?
Data regulator fines HelloFresh £140K for sending 80M+ spams