Menu

Monthly Archives: April 2024

https://security-tracker.debian.org/tracker/DSA-5661-1

https://security-tracker.debian.org/tracker/DSA-5660-1

Alleged cryptojacker accused of stealing $3.5M from cloud to mine under $1M in crypto
SIM swap crooks solicit T-Mobile US, Verizon staff via text to do their dirty work
Open sourcerers say suspected xz-style attacks continue to target maintainers
Change Healthcare’s ransomware attack costs edge toward $1B so far

* bsc#1216992 Cross-References: * CVE-2023-4218

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603

Google location tracking deal could be derailed by politics
Better application networking and security with CAKES

https://security-tracker.debian.org/tracker/DSA-5662-1

CISA in a flap as Chirp smart door locks can be trivially unlocked remotely
Protect Your Linux Web Apps and Meet Compliance Standards

Bartek Nowotarski discovered that Apache Traffic Server, a reverse and forward proxy server, was susceptible to denial of service via HTTP2 continuation frames.

Roku makes 2FA mandatory for all after nearly 600K accounts pwned
Delinea Secret Server customers should apply latest patches

Multiple vulnerabilities have been fixed in the Xorg X server. CVE-2024-31080

US senator wants to put the brakes on Chinese EVs
Zambia arrests 77 people in swoop on “scam” call centre

* bsc#1219296 Cross-References: * CVE-2023-52340

Identifying third-party risk
US House approves FISA renewal – warrantless surveillance and all

update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn

New less packages are available for Slackware 15.0 and -current to fix a security issue.

Core: – Corrupted memory in destructor with weak references – GC does not scale well with a lot of objects created in destructor DOM: – Add some missing ZPP checks.

Red Hat Enterprise Linux 7: End of compliance content on June 30, 2024

update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/

Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/

https://security-tracker.debian.org/tracker/DSA-5659-1

https://security-tracker.debian.org/tracker/DSA-5657-1

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

Update to version 0.3.26. Addresses RUSTSEC-2024-0332.

Update to version 0.3.26. Addresses RUSTSEC-2024-0332.

https://security-tracker.debian.org/tracker/DSA-5658-1

Zero-day exploited right now in Palo Alto Networks’ GlobalProtect gateways

Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with “collapsed_forwarding on” are vulnerable. Configurations with “collapsed_forwarding off” or without a “collapsed_forwarding” directive

Rust gets security fix for Windows vulnerability
Google One VPN axed for everyone but Pixel loyalists … for now
Microsoft breach allowed Russian spies to steal emails from US government

* bsc#1221564 Cross-References: * CVE-2021-47154

Understanding the Red Hat security impact scale

* bsc#1218613 * bsc#1219078 * bsc#1219296 * bsc#1219432

French issue alerte rouge after local governments knocked offline by cyber attack
Apple stops warning of ‘state-sponsored’ attacks, now alerts about ‘mercenary spyware’

Security fix for CVE-2024-24576 (Windows command injection)

Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)

Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)

4.2.3

Space Force boss warns ‘the US will lose’ without help from Musk and Bezos

These new packages fix bugs in SSL certificate validation; these bugs could allow for the compromising of encrypted SSL sessions.

East Central University suffers BlackSuit ransomware attack
DragonForce ransomware – what you need to know
When a breach goes from 25 documents to 1.3 terabytes…
96% of US hospital websites share visitor info with Meta, Google, data brokers

* bsc#1028271 Cross-References: * CVE-2016-10243

* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672

* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672

Global taxi software vendor exposes details of nearly 300K across UK and Ireland

This is the March 2024 update for .NET 7. Release Notes: https://github.com/dotnet/core/blob/main/release- notes/7.0/7.0.17/7.0.17.md

https://security-tracker.debian.org/tracker/DSA-5656-1

Smashing Security podcast #367: WhatsApp at Westminster, unhealthy AI, and Drew Barrymore

An update that fixes two vulnerabilities is now available.

Strategies for Improving Linux Security Through Cross-Browser Compatibility Testing
It’s 2024 and Intel silicon is still haunted by data-spilling Spectre

util-linux could be made to expose sensitive information.

Rust rustles up fix for 10/10 critical command injection bug on Windows

* bsc#1167896 * bsc#1206261 * bsc#1215301 Cross-References:

X fixes URL blunder that could enable convincing social media phishing campaigns

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Targus business operations disrupted following cyber attack
Turning the tide on third-party risk
Chrome Enterprise Premium promises extra security – for a fee
Synopsys takes aim at software supply chain risks
Microsoft squashes SmartScreen security bypass bug exploited in the wild
Got an unpatched LG ‘smart’ television? It could be watching you back

Bind could be made to crash if it received specially crafted input.

UK businesses shockingly unaware of how to handle security threats

* bsc#1221926 Cross-References: * CVE-2024-30161

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Parasoft unveils safety testing tool for C and C++ apps

* bsc#1207987 * bsc#1220117 * bsc#1221831 Cross-References:

US insurers use drone photos to deny home insurance policies
Home Depot confirms workers’ data snatched after miscreant dumps it online
Puppies, kittens, data at risk after ‘cyber incident’ at veterinary giant
Change Healthcare faces second ransomware dilemma weeks after ALPHV attack

* bsc#1214223 * bsc#1216980 * bsc#1220512 * bsc#1221237 * bsc#1221468

* bsc#1221749 * bsc#1221815 Cross-References: * CVE-2024-2494