Menu

Monthly Archives: February 2024

See me speak at webinar about data security for financial services
Prudential Financial finds cybercrims lurking inside its IT systems
Romanian hospital ransomware crisis attributed to third-party breach
Southern Water cyberattack expected to hit hundreds of thousands of customers
Bumblebee malware wakes from hibernation, forgets what year it is, attacks with macros

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service. For the oldstable distribution (bullseye), these problems have been fixed

Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted DNSSEC answers could lead unbound down a very CPU intensive and time costly DNSSEC (CVE-2023-50387) or NSEC3 hash (CVE-2023-50868) validation path,

UltraJSON could be made to crash if it received specially crafted input.

Australian Tax Office probed 150 staff over social media refund scam
Crims found and exploited these two Microsoft bugs before Redmond fixed ’em

https://security-tracker.debian.org/tracker/DSA-5621-1

https://security-tracker.debian.org/tracker/DSA-5620-1

Just one bad packet can bring down a vulnerable DNS server thanks to DNSSEC
QNAP vulnerability disclosure ends up an utter shambles
ALPHV blackmails Canadian pipeline after ‘stealing 190GB of vital info’

In the digital age, the quest for love has moved online, but so have the fraudsters, with romance scams reaching record highs. These scams don’t just harm individuals financially and emotionally; they can also pose significant risks to businesses. Let’s explore how these scams work, their impact, and how both businesses and consumers can protect […]

Several security issues were fixed in WebKitGTK.

Glance_store could be made to expose sensitive information.

Crooks hook hundreds of exec accounts after phishing in Azure C-suite pond

Several security issues were fixed in OpenSSL.

* bsc#1217654 * bsc#1219131 Cross-References: * CVE-2023-50269

Meta says risk of account theft after phone number recycling isn’t its problem to solve
Infosys subsidiary named as source of Bank of America data leak
Korean eggheads crack Rhysida ransomware and release free decryptor tool

Update to 1.0.5

20+ hospitals in Romania hit hard by ransomware attack on IT service provider

* bsc#1218174 Affected Products: * Containers Module 15-SP5 * openSUSE Leap 15.5

Dutch insurers demand nudes from breast cancer patients despite ban
FCC gets tough: Telcos must now tell you when your personal info is stolen
Jet engine dealer to major airlines discloses ‘unauthorized activity’
“Smart” helmet flaw exposes location tracking and privacy risks
Europe’s largest caravan club admits wide array of personal data potentially accessed
Deploying Red Hat OpenShift Dedicated clusters on Shielded Virtual Machines
Mon Dieu! Nearly half the French population have data nabbed in massive breach

Update to the latest stable version: Features Implement a new plugin manager from scratch to replace Yapsy, which does not work on Python 3.12 due to Python 3.12 carelessly removing parts of the standard library (Issue #3719)

Update to 121.0.6167.160 High CVE-2024-1284: Use after free in Mojo High CVE-2024-1283: Heap buffer overflow in Skia

Apply fix for CVE-2023-28531

Update to the latest stable version: Features Implement a new plugin manager from scratch to replace Yapsy, which does not work on Python 3.12 due to Python 3.12 carelessly removing parts of the standard library (Issue #3719)

Ransomware payments hit a record high in 2023 – Week in security with Tony Anscombe

Called a “watershed year for ransomware”, 2023 marked a reversal from the decline in ransomware payments observed in the previous year

Fix webkit_web_context_allow_tls_certificate_for_host to handle IPv6 URIs produced by SoupURI. Ignore stops with offset zero before last one when rendering gradients with cairo. Write bwrapinfo.json to disk for xdg-desktop-portal.

New version 4.0.12. Includes fixes for CVE-2023-5371, CVE-2023-6174, CVE-2023-6175, CVE-2024-0208.

Security fix for CVE-2024-21626

The updated packages fix security vulnerabilities: Logic bug in text extractor led to invalid memory access. (CVE-2022-30524) Integer overflow in rasterizer. (CVE-2022-30775) PDF object loop in Catalog::countPageTree. (CVE-2022-33108)

Meet VexTrio, a network of 70K hijacked websites crooks use to sling malware, fraud

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Ivanti discloses fifth vulnerability, doesn’t credit researchers who found it

https://security-tracker.debian.org/tracker/DSA-5618-1

OpenText is committed to providing you with the latest intelligence and tips to safeguard your digital life, especially during high-risk periods like tax season. Our threat analysts are constantly monitor the ebb and flow of various threats. One trend that has recently caught our attention is the notable spike in malware-infected cracked software, particularly as […]

Closing the Security Gap: Navigating Modern Technology and Outdated Systems in Linux Security
Fortinet’s week to forget: Critical vulns, disclosure screw-ups, and that toothbrush DDoS attack claim
The ever-present state of cyber security alert

* bsc#1219048 Cross-References: * CVE-2023-50447

Several security issues were fixed in the Linux kernel.

Running Windows 11 and 2022 Server Virtual Machines in Red Hat OpenShift with persistent vTPM
Patch management needs a revolution, part 5: How open source and transparency can force positive change

Multiple denial of service vulnerabilities have been found in libxml2.

* bsc#1210638 Cross-References: * CVE-2023-27043

India to make its digital currency programmable
Crime gang targeted jobseekers across Asia, looted two million email addresses
Uncle Sam sweetens the pot with $15M bounty on Hive ransomware gang members

Upstream version 6.6.14 with many bugfixes and at least the following security fixes: An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.

fix gcc14 build error and another epub crash use https://github.com/mate-desktop/atril/commit/479e927 use https://github.com/mate-desktop/atril/commit/d901a9d update to 1.26.2 fix security security advisory

FBI: Give us warrantless Section 702 snooping powers – or China wins

https://security-tracker.debian.org/tracker/DSA-5619-1

Fake LastPass lookalike made it into Apple App Store
Round 3! The toothbrush DDoS attack saga continues: Newspaper counters Fortinet’s translation claim in contentious interview
Raspberry Robin devs are buying exploits for faster attacks
US insurance firms sound alarm after 66,000 individuals impacted by SIM swap attack
Surge in deepfake “Face Swap” attacks puts remote identity verification at risk
Cybercrime duo accused of picking $2.5M from Apple’s orchard

* bsc#1218303 Cross-References: * CVE-2023-6704

Tooth be told: Toothbrush DDoS attack claim was lost in translation, says Fortinet

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Rust can help make software secure – but it’s no cure-all

Several security issues were fixed in the Linux kernel.

IT suppliers hacked off with Uncle Sam’s demands in aftermath of cyberattacks
Smashing Security podcast #358: Hong Kong hijinks, pig butchers, and poor ransomware gangs

https://security-tracker.debian.org/tracker/DSA-5617-1

Several security issues were fixed in the Linux kernel.

Volt Typhoon not the only Chinese crew lurking in US energy, critical networks
The toothbrush DDoS attack: How misinformation spreads in the cybersecurity world
Half of polled infosec pros say their degree was less than useful for real-world work

* bsc#1216044 * bsc#1217522 * bsc#1218255 Cross-References:

New expat packages are available for Slackware 15.0 and -current to fix security issues.

US says China’s Volt Typhoon is readying destructive cyberattacks
Iran’s cyber operations in Israel a potential prelude to US election interference
Raspberry Pi Pico cracks BitLocker in under a minute
JetBrains urges swift patching of latest critical TeamCity flaw

* bsc#1217522 * bsc#1218255 Cross-References: * CVE-2023-6176

* bsc#1210619 Cross-References: * CVE-2023-1829

Red Hat and RISC-V: To the far edge and beyond
eBPF wrapped 2023