Menu

Monthly Archives: May 2024

Casino cyberattacks put a bullseye on Scattered Spider – and the FBI is closing in
Google guru roasts useless phishing tests, calls for fire drill-style overhaul
UK Government ponders major changes to ransomware response – what you need to know
Veeam says critical flaw can’t be abused to trash backups

Several security issues were fixed in klibc.

70% of CISOs worry their org is at risk of a material cyber attack
10 years in prison for $4.5 million BEC scammer who bought Ferrari to launder money

* bsc#1223603 Cross-References: * CVE-2024-4340

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

Several security issues were fixed in the Linux kernel.

An update that fixes four vulnerabilities is now available.

Add implicit rejection in PKCS#1 v1.5 in OpenSSL.

UK data watchdog wants six figures from N Ireland cops after 2023 data leak
How Apple Wi-Fi Positioning System can be abused to track people around the globe
Would you buy Pegasus spyware from this scammer?
‘China-aligned’ spyware slingers operating since 2018 unmasked at last
Lawmakers advance bill to tighten White House grip on AI model exports
Smashing Security podcast #373: iPhone undeleted photos, and stealing Scarlett Johansson’s voice
Go after UnitedHealth, not us, 100+ medical groups urge Uncle Sam
Canada’s London Drugs confirms ransomware attack after LockBit demands $25M
NYSE parent gets $10M wrist tap for failing to report 2021 systems break-in
Laundering cash from healthcare, romance scams lands US man in prison for a decade
Confused by the SEC’s breach reporting rules? Read this
Stopping ransomware in multicloud environments
23-year-old alleged founder of dark web Incognito Market arrested after FBI tracks cryptocurrency payments

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1222685

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1220211 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223514

* bsc#1219296 * bsc#1220211 * bsc#1220828 * bsc#1220832 * bsc#1221302

* bsc#1221302 * bsc#1222882 * bsc#1223514 Cross-References:

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

Kentik for Ansible Automation Platform now certified with Red Hat
LockBit dethroned as leading ransomware gang for first time post-takedown
GitHub Enterprise Server patches 10-outta-10 critical hole
Uncle Sam to inject $50M into auto-patcher for hospital IT

https://security-tracker.debian.org/tracker/DSA-5696-1

https://security-tracker.debian.org/tracker/DSA-5695-1

Zoom adds ‘post-quantum’ encryption for video nattering
Critical Fluent Bit bug affects all major cloud providers, say researchers
Arrests made after North Koreans hired for remote tech jobs at US companies

* bsc#1219296 * bsc#1220211 * bsc#1220828 * bsc#1220832 * bsc#1221302

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1222685

* bsc#1220211 * bsc#1220832 * bsc#1222685 * bsc#1223514

* bsc#1210619 * bsc#1218487 * bsc#1222685 * bsc#1223514

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223514

With ransomware whales becoming so dominant, would-be challengers ask ‘what’s the point?’
Big Tech is not much help when fighting a junta, and FOSS doesn’t ride to the rescue
GitLab unveils GitLab 17, AI for devsecops
OpenSSF sings a Siren song to steer developers away from buggy FOSS
Julian Assange can appeal extradition to the US, London High Court rules
Google takes shots at Microsoft for shoddy security record with enterprise apps
Can I phone a friend? How cops circumvent face recognition bans
Empowering Linux and Open-Source Security with AI: Strategies, Tools and Best Practices
Researchers call out QNAP for dragging its heels on patch development

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

DoJ, ByteDance ask court: Hurry up and rule on TikTok ban already
British Library’s candid ransomware comms driven by ’emotional intelligence’
12 principles for improving devsecops

* bsc#1224277 Cross-References: * CVE-2023-45733 * CVE-2023-45745

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1219296 * bsc#1220211 * bsc#1220828 * bsc#1220832 * bsc#1221302

* bsc#1221302 * bsc#1223514 Cross-References: * CVE-2022-48651

Chinese telco gear may become verboten on German networks
Nissan infosec in the spotlight again after breach affecting more than 50K US employees

An update that fixes one vulnerability is now available.

Security fix for CVE-2024-3727 Automatic update for buildah-1.35.4-1.fc39. Changelog for buildah * Fri May 10 2024 Packit – 1.35.4-1 – Update to 1.35.4 upstream release

This is a security and bug fix release.

This is a security and bug fix release.

Backport fix for CVE-2024-34069.

An attorney says she saw her library reading habits reflected in mobile ads. That’s not supposed to happen
The who, where, and how of APT attacks – Week in security with Tony Anscombe

This week, ESET experts released several research publications that shine the spotlight on a number of notable campaigns and broader developments on the threat landscape

Gawd, after that week, we wonder what’s next for China and the Western world
How two brothers allegedly swiped $25M in a 12-second Ethereum heist

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

new upstream update (126.0)

Aussie cops probe MediSecure’s ‘large-scale ransomware data breach’

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1220211 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1222882

Three cuffed for ‘helping North Koreans’ secure remote IT jobs in America

Two vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service. CVE-2023-50387

Nissan reveals ransomware attack exposed 53,000 workers’ social security numbers
First LockBit, now BreachForums: Are cops winning the war or just a few battles?
Automating fapolicyd with RHEL system roles

* bsc#1180833 * bsc#1183101 * bsc#1183102 * bsc#1183103 * bsc#1183105

* bsc#1222992 * bsc#1223423 * bsc#1223424 * bsc#1223425

new upstream update (126.0)

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

Security fix for CVE-2024-3727

https://security-tracker.debian.org/tracker/DSA-5694-1

https://security-tracker.debian.org/tracker/DSA-5693-1

Crims abusing Microsoft Quick Assist to deploy Black Basta ransomware

https://security-tracker.debian.org/tracker/DSA-5692-1

Several security issues were fixed in the Linux kernel.

EU probes Meta over its provisions for protecting children
BreachForums seized! One of the world’s largest hacking forums is taken down by the FBI… again
Stifling Beijing in cyberspace is now British intelligence’s number-one mission

Several security issues were fixed in .NET.