Menu

Monthly Archives: June 2024

Risk of getting malicious extension from Chrome store way worse than Google’s letting on, study suggests

This update includes a rebase from 9.0.83 to 9.0.89. #2269611 CVE-2024-24549 tomcat: CVE-2024-24549: Apache Tomcat: HTTP/2 header handling DoS #2269612 CVE-2024-23672 tomcat: Apache Tomcat: WebSocket DoS with incomplete closing handshake

New emacs packages are available for Slackware 15.0 and -current to fix a security issue.

The long-tail costs of a data breach – Week in security with Tony Anscombe

Understanding and preparing for the potential long-tail costs of data breaches is crucial for businesses that aim to mitigate the impact of security incidents

Multiple vulnerabilities have been discovered in JHead, the worst of which may lead to arbitrary code execution.

From network security to nyet work in perpetuity: What’s up with the Kaspersky US ban?

A vulnerability has been discovered in LZ4, which can lead to memory corruption.

A vulnerability has been discovered in RDoc, which can lead to execution of arbitrary code.

A vulnerability has been discovered in Flatpak, which can lead to a sandbox escape.

A vulnerability has been discovered in GLib, which can lead to privilege escalation.

Update to 2.44.2: Make gamepads visible on axis movements, and not only on button presses. Disable the gst-libav AAC decoder. Make user scripts and style sheets visible in the Web Inspector. Use the geolocation portal where available, with the existing geoclue as

Change Healthcare finally spills the tea on what medical data was stolen by cyber-crew
Uncle Sam sanctions Kaspersky’s top bosses – but not Mr K himself
My health information has been stolen. Now what?

As health data continues to be a prized target for hackers, here’s how to minimize the fallout from a breach impacting your own health records

Phoenix UEFI flaw puts long list of Intel chips in hot seat
Why attack surfaces are expanding

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1012628 * bsc#1065729 * bsc#1181674 * bsc#1187716 * bsc#1193599

* bsc#1127514 * bsc#1127855 * bsc#1131544 Cross-References:

* bsc#1220210 Cross-References: * CVE-2024-26130

* bsc#1203171 * bsc#1225997 * jsc#PED-7982 * jsc#PED-8018

Qilin cyber scum leak data they claim belongs to London hospitals’ pathology provider
Since joining NATO, Sweden claims Russia has been borking Nordic satellites
Coding error in forgotten API blamed for massive data breach
Crooks get their hands on 500K+ radiology patients’ records in cyber-attack
Biden bans Kaspersky: No more sales, updates in US
Car dealer software bigshot CDK pulls systems offline twice amid ‘cyber incident’
Qilin ransomware: What you need to know
Crypto exchange Kraken accuses blockchain security outfit CertiK of extortion
Hacktivism is evolving – and that could be bad news for organizations everywhere

Hacktivism is nothing new, but the increasingly fuzzy lines between traditional hacktivism and state-backed operations make it a more potent threat

Ransomware attacks skyrocket, with LockBit 3.0 at the forefront
The Future of Container Security: Trends and Open Source Tools to Watch

* bsc#1133222 * bsc#1224158 Cross-References: * CVE-2017-17507

Russia’s cyber spies still threatening French national security, democracy
Qilin: We knew our Synnovis attack would cause a healthcare crisis at London hospitals

gdb could be made to crash if it opened a specially crafted file.

Version 2.7.7 2024-06-10 Security: Fixed command injection via malicious git branch name (GHSA-47f6-5gq3-vx9c / CVE-2024-35241) Security: Fixed multiple command injections via malicious git/hg branch names (GHSA-v9qv-c7wm-wgmf / CVE-2024-35242)

Fixing CVE-2023-51765 (smtp smuggling) requires to reject email that include NUL bytes, in some configuration. Previous security version of sendmail, by default, does not

A malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. References: – https://bugs.mageia.org/show_bug.cgi?id=33119

A sensitive data leakage vulnerability was identified in scikit-learn’s TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The vulnerability arises from the unexpected storage of all tokens present in the training data within the `stop_words_` attribute, rather than only storing the subset

https://security-tracker.debian.org/tracker/DSA-5717-1

Smashing Security podcast #377: An unhealthy data dump, railway surveillance, and a cheater sues Apple

https://security-tracker.debian.org/tracker/DSA-5715-1

Huy Nguy¡»’n Ph¡º¡m Nh¡º­t, and Valentin T. and Lutz Wolf of CrowdStrike, discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, did not correctly process and sanitize requests. This would allow an attacker to perform Cross-Side Scripting (XSS) attacks.

* bsc#1226027 Cross-References: * CVE-2024-5688 * CVE-2024-5690

* bsc#1226007 Cross-References: * CVE-2023-52890

Amtrak confirms crooks are breaking into user accounts, derailing email addresses
Reducing the significant risk of known exploitable vulnerabilities in Red Hat software
That PowerShell ‘fix’ for your root cert ‘problem’ is a malware loader in disguise

https://security-tracker.debian.org/tracker/DSA-5716-1

Rogue uni IT director pleads guilty after fraudulently buying $2.1M of tech
Dark-web kingpin puts ‘stolen’ internal AMD databases, source code up for sale
EU attempt to sneak through new encryption-eroding law slammed by Signal, politicians

Git could be made to run programs as your login if it clones a crafted repository.

Data breach at Total Fitness exposed almost half a million people’s photos – no password required
CHERI Alliance formed to promote memory security tech … but where’s Arm?
Uncle Sam ends financial support to orgs hurt by Change Healthcare attack

* bsc#1223252 Cross-References: * CVE-2024-30171

* bsc#1223852 Cross-References: * CVE-2023-52722

* bsc#1223979 Cross-References: * CVE-2024-34069

* bsc#1226020 Cross-References: * CVE-2024-5171

* bsc#1225551 Cross-References: * CVE-2024-4741

* bsc#1222849 Cross-References: * CVE-2024-32487

NHS boss says Scottish trust wouldn’t give cyberattackers what they wanted
Severe Linux Kernel Privilege Escalation Bugs Could Compromise Entire Systems
Thunderbird, Firefox DoS, Info Disclosure Vulns Fixed in Ubuntu and Debian
Convicted BEC scammer could face over 100 years in prison
VMware by Broadcom warns of two critical vCenter flaws, plus a nasty sudo bug
Arm security defense shattered by speculative execution 95% of the time
Rethinking WiFi and Router Security: A Deep Dive into the Recent ASUS Flaw and Secure Alternatives

https://security-tracker.debian.org/tracker/DSA-5714-1

Shoddy infosec costs PwC spinoff and NMA $11.3M in settlement with Uncle Sam
Suspected bosses of $430M dark-web Empire Market charged in US
Blackbaud has to cough up a few million dollars more over 2020 ransomware attack
Emojis as Weapons: Dissecting DISGOMOJI’s Malware Assault on Government Security
Cops cuff 22-year-old Brit suspected of being Scattered Spider leader

An out-of-bounds read in the ‘bson’ module allowed deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.

AWS is pushing ahead with MFA for privileged accounts. What that means for you …

A symlink attack with emergency file saving has been fixed in the text editor nano. For Debian 10 buster, this problem has been fixed in version

UK’s Total Fitness exposed nearly 500k images of members and staff through unprotected database

* bsc#1219823 * bsc#1219826 * bsc#1219851 * bsc#1219852 * bsc#1219854

* bsc#1225551 Cross-References: * CVE-2024-4741

* bsc#1225551 Cross-References: * CVE-2024-4741

* bsc#1222857 * bsc#1222858 * bsc#1226073 Cross-References:

Notorious cyber gang UNC3944 attacks vSphere and Azure to run VMs inside victims’ infrastructure
That didn’t take long: Replacement for SORBS spam blacklist arises … sort of
Japan’s space junk cleaner hunts down major target

https://security-tracker.debian.org/tracker/DSA-5712-1

Multiple security issues were discovered in Thunderbird, which could result inthe execution of arbitrary code. For the oldstable distribution (bullseye), these problems have been fixed

Security fix for CVE-2024-3049

https://security-tracker.debian.org/tracker/DSA-5713-1

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink. (CVE-2024-5742)

Use-after-free in networking. (CVE-2024-5702) Use-after-free in JavaScript object transplant. (CVE-2024-5688) External protocol handlers leaked by timing attack. (CVE-2024-5690) Sandboxed iframes were able to bypass sandbox restrictions to open a new window. (CVE-2024-5691)

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

How Arid Viper spies on Android users in the Middle East – Week in security with Tony Anscombe

The spyware, called AridSpy by ESET, is distributed through websites that pose as various messaging apps, a job search app, and a Palestinian Civil Registry app