Menu

Monthly Archives: February 2024

* bsc#1218564 Cross-References: * CVE-2023-52323

* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:

* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:

* bsc#1188609 * bsc#1212850 * bsc#1213210 * bsc#1213925 * bsc#1215311

Imagemagick a graphical software suite for displaying, creating and modifying images was vulnerable. CVE-2023-1289

Giant leak reveals Chinese infosec vendor I-Soon is one of Beijing’s cyber-attackers for hire

Several security issues were fixed in Firefox.

Smashing Security podcast #360: Lockbit locked out, and funeral Facebook scams

https://security-tracker.debian.org/tracker/DSA-5628-1

Biden asks Coast Guard to create an infosec port in a stormy sea of cyber threats
Apple promises to protect iMessage chats from quantum computers
Duo face 20 years in prison over counterfeit iPhone scam
Exploiting the latest max-severity ConnectWise bug is ’embarrassingly easy’
LockBit leaks expose nearly 200 affiliates and bespoke data-stealing malware
Harness the power of security automation
A common goal for European cyber security
Orgs are having a major identity crisis while crims reap the rewards
Europe’s data protection laws cut data storage by making information-wrangling pricier
China could be doing better at censorship, think tank finds

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

Patch for CVE-2024-24258 and CVE-2024-24259

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

Singapore’s monetary authority advises banks to get busy protecting against quantum decryption

https://security-tracker.debian.org/tracker/DSA-5627-1

New libuv packages are available for Slackware 15.0 and -current to fix a security issue.

* bsc#1011205 * bsc#1093641 * bsc#1125882 * bsc#1167400 * bsc#1207973

* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188

Cops turn LockBit ransomware gang’s countdown timers against them
Wyze admits 13,000 users could have viewed strangers’ camera feeds
Insider steals 79,000 email addresses at work to promote own business

The updated packages fix security vulnerabilities: RTPS dissector memory leak. (CVE-2023-5371) SSH dissector invalid read of memory blocks. (CVE-2023-6174) NetScreen File Parsing Heap-based Buffer Overflow. (CVE-2023-6175) GVCP dissector crash via packet injection or crafted capture file.

Vietnam to collect biometrics – even DNA – for new ID cards

Stack buffer overflow in virtio_net_flush_tx (CVE-2023-6693) (rhbz#2256436)

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

LockBit ransomware gang disrupted by global operation
ALPHV gang claims it’s the attacker that broke into Prudential Financial, LoanDepot

* bsc#1219059 Cross-References: * CVE-2024-22563

* bsc#1202903 * bsc#1219187 Cross-References: * CVE-2022-2132

Safeguarding cyber-physical systems for a smart future

* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188

* bsc#1219059 Cross-References: * CVE-2024-22563

Multiple vulnerabilities have been discovered in Samba, the worst of which can lead to remote code execution.

A vulnerability has been discovered in Glade which can lead to a denial of service.

Feds post $15 million bounty for info on ALPHV/Blackcat ransomware crew
Election security threats in 2024 range from AI to … anthrax?

Multiple vulnerabilities have been discovered in QtNetwork, the worst of which could lead to execution of arbitrary code.

A vulnerability has been discovered in Thunar which may lead to arbitrary code execution

A vulnerability has been discovered in libcaca which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Exim, the worst of which can lead to remote code execution.

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can

Multiple vulnerabilities have been discovered in CUPS, the worst of which can lead to arbitrary code execution.

https://security-tracker.debian.org/tracker/DSA-5626-1

https://security-tracker.debian.org/tracker/DSA-5625-1

Cyber-insurance and vulnerability scanning – Week in security with Tony Anscombe

Here’s how the results of vulnerability scans factor into decisions on cyber-insurance and how human intelligence comes into play in the assessment of such digital signals

All eyes on AI | Unlocked 403: A cybersecurity podcast

Artificial intelligence is on everybody’s lips these days, but there are also many misconceptions about what AI actually is and isn’t. We unpack the basics and examine AI’s broader implications.

How to weaponize LLMs to auto-hijack websites
Google open sources file-identifying Magika AI for malware hunters and others

Update to 1.6.5 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Update to 2.11.5

Update to 1.6.5 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Update to 1.7.2 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Rebase to version 2.6.0

Update to 2.28.7 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7 Security Advisories: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-

Zeus, IcedID malware kingpin faces 40 years in slammer
Cutting kids off from the dark web – the solution can only ever be social
Quest Diagnostics pays $5M after mixing patient medical data with hazardous waste

Several security issues were fixed in the Linux kernel.

Feds dismantle Russian GRU botnet built on 1,000-plus home, small biz routers

* bsc#1218429 Cross-References: * CVE-2023-6879

* bsc#1218690 * bsc#1218810 * bsc#1219243 Cross-References:

* bsc#1219113 * bsc#1219604 Cross-References: * CVE-2014-1745

* bsc#1219679 Cross-References: * CVE-2024-0985

https://security-tracker.debian.org/tracker/DSA-5624-1

https://security-tracker.debian.org/tracker/DSA-5623-1

https://security-tracker.debian.org/tracker/DSA-5622-1

Pentagon launches nuke-spotting satellites amid Russian space bomb rumors

Did you know that more than nine million Americans have their identity stolen each year? Your data is stored across countless databases for various purposes, making it a prime target for criminals. With access to your personal information, bad actors can drain your bank account and damage your credit—or worse. But that doesn’t mean you […]

The updated packages fix security vulnerabilities: Parsing large DNS messages may cause excessive CPU load. (CVE-2023-4408) Querying RFC 1918 reverse zones may cause an assertion failure when “nxdomain-redirect” is enabled. (CVE-2023-5517) Enabling both DNS64 and serve-stale may cause an assertion failure

Mitigating AI security risks
Rhysida ransomware cracked! Free decryption tool released
Zoom stomps critical privilege escalation bug plus 6 other flaws
Cybercriminals are stealing Face ID scans to break into mobile banking accounts

* bsc#1108281 * bsc#1193285 * bsc#1215275 * bsc#1216702 * bsc#1217987

Manage smartcards with new p11-kit subcommands
North Korea successfully hacks email of South Korean President’s aide, gains access to sensitive information
Miscreants turn to ad tech to measure malware metrics
European Court of Human Rights declares backdoored encryption is illegal

Several security issues were fixed in UltraJSON.

Several security issues were fixed in the Linux kernel.

North Korea running malware-laden gambling websites as-a-service

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in EDK II.

update to 1.26.2

OpenAI shuts down China, Russia, Iran, N Korea accounts caught doing naughty things
Smashing Security podcast #359: Declaring war on ransomware gangs, mobile muddles, and AI religion
China’s Volt Typhoon spies broke into emergency network of ‘large’ US city
US Air Force’s new cyber, IT skill recruitment plan: Bring back warrant officer ranks