Menu

Monthly Archives: May 2024

https://security-tracker.debian.org/tracker/DSA-5686-1

https://security-tracker.debian.org/tracker/DSA-5682-2

https://security-tracker.debian.org/tracker/DSA-5684-1

What do Europeans, Americans and Australians have in common? Scammed $50M by fake e-stores
Smashing Security podcast #371: Unmasking LockBitsupp, company extortion, and a Tinder fraudster
Undersea cables must have high-priority protection before they become top targets

https://security-tracker.debian.org/tracker/DSA-5682-1

How to inspire the next generation of scientists | Unlocked 403: Cybersecurity podcast

As Starmus Earth draws near, we caught up with Dr. Garik Israelian to celebrate the fusion of science and creativity and venture where imagination flourishes and groundbreaking ideas take flight

CISA boss: Secure code is the ‘only way to make ransomware a shocking anomaly’
One year on, universities org admits MOVEit attack hit data of 800K people

* bsc#1189495 * bsc#1211301 * bsc#1219559 * bsc#1219666 * bsc#1221260

* bsc#1189495 * bsc#1191175 * bsc#1218686 Cross-References:

UK opens investigation of MoD payroll contractor after confirming attack

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in root privilege escalation.

A vulnerability has been discovered in Epiphany, which can lead to a buffer overflow.

Multiple vulnerabilities have been discovered in qtsvg, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in MariaDB, the worst fo which can lead to arbitrary execution of code.

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
From infosec to skunks, RSA Conference SVP spills the tea
UnitedHealth’s ‘egregious negligence’ led to Change Healthcare ransomware infection

https://security-tracker.debian.org/tracker/DSA-5683-1

America’s War on Drugs and Crime will be AI powered, says Homeland Security boss
Watch out for rogue DHCP servers decloaking your VPN connections
CISA’s early-warning system helped critical orgs close 852 ransomware holes
TikTok sues America to undo divest-or-die law
Cops finally unmask ‘LockBit kingpin’ after two-month tease
Fortifying Email Security with Infosec Through the SDLC
The truth about KEV: CISA’s vuln deadlines good influence on private-sector patching
Brit security guard biz exposes 1.2M files via unprotected database
Does cloud security have a bad reputation?

* bsc#1223252 Cross-References: * CVE-2024-30171

* bsc#1221984 * bsc#1222302 * bsc#1222453 Cross-References:

* bsc#1027519 * bsc#1221984 * bsc#1222302 * bsc#1222453

* bsc#1216644 * bsc#1219079 * bsc#1219435 Cross-References:

Multiple vulnerabilities have been discovered in libjpeg-turbo, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Xpdf, the worst of which could possibly lead to arbitrary code execution.

Ransomware crooks now SIM swap executives’ kids to pressure their parents
Google, Meta, Spotify break Apple’s device fingerprinting rules – new claim
Fed-run LockBit site back from the dead and vows to really spill the beans on gang
Mastodon delays firm fix for link previews DDoSing sites

As we navigate through 2024, the cyber threat landscape continues to evolve, bringing new challenges for both businesses and individual consumers. The latest OpenText Threat Report provides insight into these changes, offering vital insights that help us prepare and protect ourselves against emerging threats. Here’s what you need to know: The Resilience of Ransomware Ransomware […]

Consultant charged over $1.5M extortion scheme against IT giant
CISA says ‘no more’ to decades-old directory traversal bugs

* bsc#1215947 * bsc#1216853 Cross-References: * CVE-2023-38470

* bsc#1170848 * bsc#1208572 * bsc#1214340 * bsc#1214387 * bsc#1216085

* bsc#1219912 * bsc#1221465 * bsc#1222155 * jsc#MSQA-760 * jsc#PED-7893

* bsc#1008037 * bsc#1008038 * bsc#1010940 * bsc#1019021 * bsc#1038785

* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001

* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001

Germany points finger at Fancy Bear for widespread 2023 hacks, DDoS attacks

https://security-tracker.debian.org/tracker/DSA-5681-1

https://security-tracker.debian.org/tracker/DSA-5680-1

Pay up, or else? – Week in security with Tony Anscombe

Organizations that fall victim to a ransomware attack are often caught between a rock and a hard place, grappling with the dilemma of whether to pay up or not

End-to-end encryption may be the bane of cops, but they can’t close that Pandora’s Box

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to remote code execution.

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to remote code execution.

A vulnerability has been discovered in borgmatic, which can lead to shell injection.

Multiple vulnerabilities have been discovered in Pillow, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in MIT krb5, the worst of which could lead to remote code execution.

A vulnerability has been discovered in Setuptools, which can lead to denial of service.

https://security-tracker.debian.org/tracker/DSA-5679-1

https://security-tracker.debian.org/tracker/DSA-5678-1

https://security-tracker.debian.org/tracker/DSA-5677-1

Dating apps kiss’n’tell all sorts of sensitive personal info
Adding insult to injury: crypto recovery scams

Once your crypto has been stolen, it is extremely difficult to get back – be wary of fake promises to retrieve your funds and learn how to avoid becoming a victim twice over

Multiple vulnerabilities have been found in MediaInfo and MediaInfoLib, the worst of which could allow user-assisted remote code execution.

Multiple vulnerabilities have been discovered in strongSwan, the worst of which could possibly lead to remote code execution.

Multiple vulnerabilities have been discovered in HTMLDOC, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in mujs, the worst of which could lead to remote code execution.

Multiple vulnerabilities have been discovered in MPlayer, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in systemd, the worst of which can lead to a denial of service.

Kaspersky hits back at claims its AI helped Russia develop military drone systems
It may take decade to shore up software supply chain security, says infosec CEO
Beyond the lingo: What does Red Hat Insights and FedRAMP mean for your workload?
Simplify hybrid cloud operations with Red Hat Enterprise Linux 9.4
Mitigating breaches on Red Hat OpenShift with the CrowdStrike Falcon Operator
Understanding Red Hat’s response to the XZ security incident

* bsc#1177529 * bsc#1192145 * bsc#1194869 * bsc#1200465 * bsc#1205316

Europol op shutters 12 scam call centers and cuffs 21 suspected fraudsters
Indonesia sneakily buys spyware, claims Amnesty International
Chinese government website security is often worryingly bad, say Chinese researchers

update to 124.0.6367.118 * High CVE-2024-4331: Use after free in Picture In Picture * High CVE-2024-4368: Use after free in Dawn update to 124.0.6367.91 update to 124.0.6367.78

The 6.8.8 stable kernel update contains a number of important fixes across the tree.

Patch to fix CVE-2024-31031

Update matrix-synapse to v1.105.1 (CVE-2024-31208) Update to v1.105.0

Update matrix-synapse to v1.105.1 (CVE-2024-31208) Update to v1.105.0

Microsoft, Google do a victory lap around passkeys
Florida man gets 6 years behind bars for flogging fake Cisco kit to US military
Patch up – 4 critical bugs in ArubaOS lead to remote code execution
Federal frenzy to patch gaping GitLab account takeover hole
Understanding Microsoft’s Trusted Signing service

Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Think tank: China’s tech giants refine and define Beijing’s propaganda push
REvil ransomware scum sentenced to almost 14 years inside, ordered to pay $16 million

USN-6747-1 caused some minor regressions in Firefox.

A million Australian pubgoers wake up to find personal info listed on leak site

tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039

Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130

tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039

Security update for CVE-2024-27306 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.5 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.4