Menu

Monthly Archives: June 2024

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

POC exploit code published for 9.8-rated Apache HugeGraph RCE flaw

https://security-tracker.debian.org/tracker/DSA-5706-1

FBI encourages LockBit victims to step right up for free decryption keys
Hit by LockBit? The FBI is waiting to help you with over 7,000 decryption keys

USN-6567-1 introduced a regression in QEMU.

Uncle Sam seeks to claw back $5M+ stolen from trade union through spoofed email
Microsoft shows venerable and vulnerable NTLM security protocol the door
Smashing Security podcast #375: Crashing robo-taxis, and name-dropping rappers
7-year-old Oracle WebLogic bug under active exploitation

Update to upstream 1.3.2, including fix for CVE-2024-3727

Microsoft Research chief scientist has no issue with Windows Recall

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 17.

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

TikTok confirms CNN, other high-profile accounts hijacked via zero-day vulnerability
What is RansomHub? Looks like a Knight ransomware reboot
Emergency patches released for critical vulns impacting EOL Zyxel NAS boxes

* bsc#1225070 Cross-References: * CVE-2024-36039

4 cuffed following probe into holiday scheme for cybercrooks

Fix CVE-2024-36048

This is the May 2024 release for .NET 8. This is a security update for .NET 8. Release notes: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.5/8.0.5.md

Microsoft paid Tenable a bug bounty for an Azure flaw it says doesn’t need a fix, just better documentation

Qt 5.15.14 bugfix update. Fix CVE-2024-36048

Qt 5.15.14 bugfix update. Fix CVE-2024-36048

Qt 5.15.14 bugfix update. Fix CVE-2024-36048

https://security-tracker.debian.org/tracker/DSA-5705-1

https://security-tracker.debian.org/tracker/DSA-5704-1

Command senior chief busted for secretly setting up Wi-Fi on US Navy combat ship
Pentagon ‘doubling down’ on Microsoft despite ‘massive hack,’ senators complain
London hospitals declare critical incident after service partner ransomware attack
Christie’s stolen data sold to highest bidder rather than leaked, RansomHub claims
Microsoft accused of tracking kids with education software

* bsc#1217405 Cross-References: * CVE-2023-22084

* bsc#1202031 * bsc#1202033 * bsc#1203643 * bsc#1219823 * bsc#1219826

Cybercrooks get cozy with BoxedApp to dodge detection

An update that fixes one vulnerability is now available.

Hudson Rock yanks report fingering Snowflake employee creds snafu for mega-leak
NIST turns to IT consultants to clear National Vulnerability Database backlog
Crooks threaten to leak 3B personal records ‘stolen from background check firm’

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Russia takes gold for disinformation as Olympics approach

* bsc#1225417 Cross-References: * CVE-2024-33427

Check Point warns customers to patch VPN vulnerability under active exploitation
Derisking your CNI
Advanced CI/CD: 6 steps to better CI/CD pipelines

* bsc#1212233 Cross-References: * CVE-2023-3164

* bsc#1224806 Cross-References: * CVE-2024-4453

* bsc#1219823 * bsc#1219826 * bsc#1219851 Cross-References:

* bsc#1221940 * bsc#1223423 * bsc#1223424 * bsc#1223425

Researchers crash Baidu robo-cars with tinfoil and paint daubed on cardboard

fix CVE-2023-36308

update to 125.0.6422.141 High CVE-2024-5493: Heap buffer overflow in WebRTC High CVE-2024-5494: Use after free in Dawn High CVE-2024-5495: Use after free in Dawn High CVE-2024-5496: Use after free in Media Session

CVE-2024-36041

Security fix for CVE-2024-21501

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

https://security-tracker.debian.org/tracker/DSA-5703-1

Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

The updated packages fix security vulnerabilities: Excessive time spent checking DSA keys and parameters. (CVE-2024-4603) Use After Free with SSL_free_buffers. (CVE-2024-4741) References:

It was discovered that Jinja2 incorrectly handled certain HTML attributes that were accepted by the xmlattr filter. An attacker could use this issue to inject arbitrary HTML attribute keys and values to potentially execute a cross-site scripting (XSS) attack.

Several security issues were fixed in GNU C Library.

What happens when facial recognition gets it wrong – Week in security with Tony Anscombe

A woman in London has been misidentified as a shoplifter by a facial recognition system amid fresh concerns over the technology’s accuracy and reliability

Stalkerware app pcTattletale announces it is ‘out of business’ after suffering data breach and website defacement
New Research Reveals Linux Vulnerability Exploitation Has Doubled

An integer overflow in the EXIF metadata parsing was discovered in the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed file is processed.

https://security-tracker.debian.org/tracker/DSA-5702-1