Menu

Monthly Archives: March 2024

https://security-tracker.debian.org/tracker/DSA-5637-1

We’re not Meta support: State AGs tell Zuck to fix rampant account takeover problem
Possible China link to Change Healthcare ransomware attack
$12.5 billion lost to cybercrime, amid tidal wave of crypto investment fraud
JetBrains TeamCity under attack by ransomware thugs after disclosure mess
Belgian ale legend Duvel’s brewery borked as ransomware halts production

* bsc#1217213 Cross-References: * CVE-2023-44446

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1200528 Cross-References: * CVE-2022-1996

* bsc#1212475 * bsc#1219988 * bsc#1220999 * bsc#1221000 * bsc#1221001

VMware urges emergency action to blunt hypervisor flaws
Here’s something else AI can do: expose bad infosec to give cyber-crims a toehold in your organization
US lawmakers want ByteDance to divest TikTok or face a ban
Lawsuit claims gift card fraud is the gift that keeps on giving, to Google
Chinese chap charged with stealing Google’s AI datacenter secrets
Smashing Security podcast #362: Ransomware fraud, pharmacy chaos, and suicide
FBI: Critical infrastructure suffers spike in ransomware attacks
Irresistible: Hooks, habits and why you can’t put down your phone

Struggle to part ways with your tech? You’re not alone. Here’s why your devices are your vices.

Apple’s trademark tight lips extend to new iPhone, iPad zero-days
Ukraine claims it hacked Russian Ministry of Defence, stole secrets and encryption ciphers
Capita says 2023 cyberattack costs a factor as it reports staggering £100M+ loss

* bsc#1034675 * bsc#1172961 * bsc#1182748 * bsc#1203672 * bsc#1203673

Whoops! ACEMAGIC ships mini PCs with free bonus pre-installed malware
Chip lobby group SEMI to EU: Export restrictions should only be used in self-defense

USN-6649-1 caused some minor regressions in Firefox.

Japan orders local giants LINE and NAVER to disentangle their tech stacks
Uncle Sam intervenes as Change Healthcare ransomware fiasco creates mayhem

https://security-tracker.debian.org/tracker/DSA-5636-1

Improper Domain Lookup in uv_getaddrinfo() has been fixed in libuv, an asynchronous event notification library. For Debian 10 buster, this problem has been fixed in version

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix a security issue.

* bsc#1210638 Cross-References: * CVE-2023-27043

* bsc#1220644 Cross-References: * CVE-2024-1597

https://security-tracker.debian.org/tracker/DSA-5635-1

Cloudflare announces Firewall for AI
Fidelity customers’ financial info feared stolen in suspected ransomware attack
US accuses Army vet cyber-Casanova of sharing Russia-Ukraine war secrets
IP address X-posure now a feature on Musk’s social media platform
Enhancing Security in Linux Web Applications with Advanced Secure Coding Practices
Rapid7 throws JetBrains under the bus for ‘uncoordinated vulnerability disclosure’

* bsc#1219911 Cross-References: * CVE-2024-24814

* bsc#1219911 Cross-References: * CVE-2024-24814

* bsc#1018158 * bsc#1178386 * bsc#1179694 * bsc#1179721 * bsc#1181505

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Spam crusade lands charity in hot water with data watchdog
Cloudflare wants to put a firewall in front of your LLM
American Express admits card data exposed and blames third party

Several security issues were fixed in the Linux kernel.

Change Healthcare attack latest: ALPHV bags $22M in Bitcoin amid affiliate drama

Aviv Keller discovered that the frames.html file generated by YARD, a documentation generation tool for the Ruby programming language, was vulnerable to cross-site scripting.

Seoul accuses North Korea of stealing southern chipmakers’ designs

Let’s delve into the fascinating world of Artificial intelligence (AI), unpacking its concepts, implications, and real-world applications. Brace yourself for an extended journey through the marvels and challenges of artificial intelligence. Part 1: Unleashing marvels in our digital lives Generative AI and chatbots AI has transcended its sci-fi origins to become an integral part of […]

German defense chat overheard by Russian eavesdroppers on Cisco’s WebEx
Ransomware ban backers insist thugs must be cut off from payday

Several security issues were fixed in Node.js.

The federal bureau of trolling hits LockBit, but the joke’s on us

* bsc#1218351 Cross-References: * CVE-2023-51765

* bsc#1218351 Cross-References: * CVE-2023-51765

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 10 buster, these problems have been fixed in version

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

Several security issues were fixed in Thunderbird.

LockBit’s contested claim of fresh ransom payment suggests it’s been well hobbled
Ahead of Super Tuesday, US elections face existential and homegrown threats
Deceptive AI content and 2024 elections – Week in security with Tony Anscombe

As the specter of AI-generated disinformation looms large, tech giants vow to crack down on fabricated content that could sway voters and disrupt elections taking place around the world this year

Insights helps to provide Threat Intelligence

Multiple vulnerabilities have been discovered in UltraJSON, the worst of which could lead to key confusion and value overwriting.

Multiple vulnerabilities have been discovered in Blender, the worst of which could lead to arbitrary code execution.

A vulnerability has been discovered in Tox which may lead to remote code execution.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

An update that fixes one vulnerability is now available.

This is the February 2024 update for .NET 8. Release Notes: – Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.2/8.0.2.md – SDK: https://github.com/dotnet/core/blob/main/release-

fix CVE-2024-24814: prevent DoS when OIDCSessionType client-cookie is set and a crafted Cookie header is supplied

This is the February 2024 update for .NET 8. Release Notes: – Runtime: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.2/8.0.2.md – SDK: https://github.com/dotnet/core/blob/main/release-

Air National Guardsman Teixeira to admit he was Pentagon files leaker
Judge orders NSO to cough up Pegasus super-spyware source code
Biden executive order protects personal data
Iranian charged over attacks against US defense contractors, government agencies
Someone is hacking 3D printers to warn owners of a security flaw
In the vanguard of 21st century cyber threats
Cops visit school of ‘wrong person’s child,’ mix up victims and suspects in epic data fail

* bsc#1219465 Cross-References: * CVE-2023-3966

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Act now to stop WordPress and Tumblr selling your content to AI firms
GitHub rolls out push protection on public repos
Keeping one step ahead of cyber security threats
NTT boss takes early retirement to atone for data leak
GitHub struggles to keep up with automated malicious forks