Menu

Monthly Archives: June 2024

ESET Research Podcast: APT Activity Report Q4 2023–Q1 2024

The I-SOON data leak confirms that this contractor is involved in cyberespionage for China, while Iran-aligned groups step up aggressive tactics following the Hamas-led attack on Israel in 2023

sendmail allowed SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports

A vulnerability was discovered in Atril, a simple document viewer designed for the MATE desktop environment. CVE-2023-52076

Microsoft answered Congress’ questions on security. Now the White House needs to act

https://security-tracker.debian.org/tracker/DSA-5711-1

Stanford Internet Observatory wilts under legal pressure during election year

Unauthorized local user access to the session manager has been fixed in the Plasma Workspace component of the KDE Plasma desktop environment. For Debian 10 buster, this problem has been fixed in version

Meta won’t train AI on Euro posts after all, as watchdogs put their paws down
Nigerian faces up to 102 years in the slammer for $1.5M phishing scam
Arid Viper poisons Android apps with AridSpy

ESET researchers discovered Arid Viper espionage campaigns spreading trojanized apps to Android users in Egypt and Palestine

Ukraine busts SIM farms targeting soldiers with spyware

* bsc#1224122 * bsc#1226136 Cross-References: * CVE-2024-24786

French state bidding for piece of Atos, offers €700M
Security and safety of AI systems
Creating a Web Application Firewall in Red Hat OpenShift
Automating secrets management with HashiCorp Vault and Red Hat Ansible Automation Platform
ANSSI-BP-028 security recommendations updated to version 2.0

* bsc#1226020 Cross-References: * CVE-2024-5171

update to 126.0.6478.55 High CVE-2024-5830: Type Confusion in V8 High CVE-2024-5831: Use after free in Dawn High CVE-2024-5832: Use after free in Dawn High CVE-2024-5833: Type Confusion in V8

Security fix for CVE-2024-34055

update to 126.0.6478.55 High CVE-2024-5830: Type Confusion in V8 High CVE-2024-5831: Use after free in Dawn High CVE-2024-5832: Use after free in Dawn High CVE-2024-5833: Type Confusion in V8

Security fix for CVE-2024-34055

Microsoft bigwig says the Feds catching Chinese spies in Exchange Online is the cloud working as intended

https://security-tracker.debian.org/tracker/DSA-5710-1

US Space Force wanted $77M to reinforce GPS – and Congress shot it down
Oracle Ads have had it: $2B operation shuts down after dwindling to $300M
Ukrainian cops collar Kyiv programmer believed to be Conti, LockBit linchpin
Watch out! CISA warns it is being impersonated by scammers
Google’s Privacy Sandbox more like a privacy mirage, campaigners claim

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Student’s flimsy bin bags blamed for latest NHS data breach
Smashing Security podcast #376: iOS 18 for cheaters, and a model cop extortionist?
Time to zero in on Zero Trust?
Crooks crack customer info at tracking device vendor Tile, issue ‘extortion’ demands
Ransomware crew may have exploited Windows make-me-admin bug as a zero-day
White House report dishes deets on all 11 major government breaches from 2023
China’s FortiGate attacks more extensive than first thought

libndp could be made to crash or run programs if it received specially crafted network traffic.

No Phishing Allowed: Building a Culture of Cybersecurity Smarts

* bsc#1223356 Cross-References: * CVE-2024-0090 * CVE-2024-0091

* bsc#1219273 Cross-References: * CVE-2023-27534

* bsc#1065729 * bsc#1141539 * bsc#1174585 * bsc#1181674 * bsc#1187716

Battered and bruised 23andMe faces probe after hack that stole seven million users’ data

* bsc#1225365 Cross-References: * CVE-2024-35235

* bsc#1223179 * bsc#1225365 Cross-References: * CVE-2024-35235

Let’s kick off our summer with a pwn-me-by-Wi-Fi bug in Microsoft Windows

https://security-tracker.debian.org/tracker/DSA-5709-1

Pure Storage pwned, claims data plundered by crims who broke into Snowflake workspace
WeLiveSecurity wins Best Cybersecurity Vendor Blog award!

The award is an excellent opportunity for us to thank our readers and to recognize the depth of talent of ESET’s security researchers and writers

Cylance clarifies data breach details, except where the data came from
UK and Canada’s data chiefs join forces to investigate 23andMe mega-breach

Several security issues were fixed in the Linux kernel.

* bsc#1223375 Cross-References: * CVE-2024-4141

* bsc#1224262 Cross-References: * CVE-2024-26306

* bsc#1219823 * bsc#1219826 * bsc#1219851 * bsc#1219852 * bsc#1219854

* bsc#1065729 * bsc#1101816 * bsc#1141539 * bsc#1181674 * bsc#1185902

* bsc#1218501 Cross-References: * CVE-2023-50711

A CISO game plan for cloud security
Snowflake customers not using MFA are not unique – over 165 of them have been compromised
Japanese vid-sharing site Niconico needs rebuild after cyberattack

https://security-tracker.debian.org/tracker/DSA-5708-1

https://security-tracker.debian.org/tracker/DSA-5707-1

Christie’s confirms RansomHub crooks stole data on 45K clients

An update that fixes 16 vulnerabilities is now available.

* bsc#1225417 Cross-References: * CVE-2024-33427

Snowflake tells customers to enable MFA as investigations continue

* bsc#1222584 * bsc#1223849 Cross-References: * CVE-2024-4418

* bsc#1221401 * bsc#1222330 * bsc#1222332 Cross-References:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Two arrested in UK over fake cell tower-powered smishing campaign
560 million Ticketmaster customer data for sale? – Week in security with Tony Anscombe

Ticketmaster seems to have experienced a data breach, with the ShinyHunters hacker group claiming to have exfiltrated 560 million customer data. Watch as Tony discusses the story and provides useful tips on how to protect people’s data.

Akira: Perhaps the next big thing in ransomware, says Tidal threat intelligence chief
Uber ex-CSO Joe Sullivan: We need security leaders running to work, not giving up
‘New York Times source code’ leaks online via 4chan

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

FCC takes some action against notorious BGP
Defiant Microsoft pushes ahead with controversial Recall – tho as an opt-in
Frontier Communications: 750k people’s data stolen in April attack on systems
The job hunter’s guide: Separating genuine offers from scams

$90,000/year, full home office, and 30 days of paid leave, and all for a job as a junior data analyst – unbelievable, right? This and many other job offers are fake though – made just to ensnare unsuspecting victims into giving up their data.

16-year-old arrested in France in connection with high-profile Epsilon hacking group attacks
How to navigate NIS2 and secure your vulnerabilities
Cisco fixes WebEx flaw that allowed government, military meetings to be spied on

* bsc#1218424 * bsc#1225973 * bsc#1225974 Cross-References:

* bsc#1212475 * bsc#1225973 * bsc#1225974 Cross-References:

* bsc#1224788 Cross-References: * CVE-2024-35195

Exploring security by design and loosening guides
Easily integrate Secrets Management System with Ansible Automation Platform to update systems passwords
Russian hacktivists vow mass attacks against EU elections
Spam blocklist SORBS closed by its owner, Proofpoint