Menu

Monthly Archives: July 2024

Multiple vulnerabilities have been discovered in WebKitGTK+, the worst of which could lead to arbitrary code execution

https://security-tracker.debian.org/tracker/DSA-5725-1

Volcano Demon ransomware group rings its victims to extort money
The AI Fix #5: An angry AI girlfriend, and artificial intelligence is stupid
Security vulnerability reporting: Who can you trust?

* bsc#1226642 Cross-References: * CVE-2024-6387

Europol nukes nearly 600 IP addresses in Cobalt Strike crackdown

* bsc#1222050 * bsc#1222052 * bsc#1222053 * bsc#1226957

* bsc#1219217 * bsc#1220266 Cross-References: * CVE-2024-0914

Ransomware scum who hit Indonesian government apologizes, hands over encryption key

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Smashing Security podcast #379: Private nights, evil twins, and crypto home invasions
Traeger security bugs bad news for grillers with neighborly beef

* bsc#1225771 Cross-References: * CVE-2024-5564

* bsc#1227052 Cross-References: * CVE-2024-6104

* bsc#1213720 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5

* bsc#1224282 Cross-References: * CVE-2024-34459

Several security issues were fixed in Firefox.

* bsc#1224282 Cross-References: * CVE-2024-34459

Affirm admits customer info pilfered during ransomware raid at Evolve Bank

USN-6851-1 caused systemctl enable to fail

USN-6844-1 caused the cupsd daemon to never start

How evolving AI regulations impact cybersecurity

* bsc#1226448 Cross-References: * CVE-2024-4032

* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044

* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044

‘Almost every Apple device’ vulnerable to CocoaPods supply chain attack
Baddies hijack Korean ERP vendor’s update systems to spew malware
Nasty regreSSHion bug in OpenSSH puts around 700K Linux boxes at risk

OpenSSH could be made to bypass authentication and remotely access systems without proper credentials.

Juniper Networks flings out emergency patches for perfect 10 router vuln
Polyfill.io claims reveal new cracks in supply chain, but how deep do they go?
CISA director: US is ‘not afraid’ to shout about Big Tech’s security failings

* bsc#1223965 Cross-References: * CVE-2024-33394

The Qualys Threat Research Unit (TRU) discovered that OpenSSH, an implementation of the SSH protocol suite, is prone to a signal handler race condition. If a client does not authenticate within LoginGraceTime seconds (120 by default), then sshd’s SIGALRM handler is called

* bsc#1224044 Cross-References: * CVE-2024-34397

Several security issues were fixed in eSpeak NG.

Multiple vulnerabilities have been discovered in GNU Emacs and Org Mode, the worst of which could lead to arbitrary code execution.

Police allege ‘evil twin’ of in-flight Wi-Fi used to steal passenger’s credentials
Indonesian government didn’t have backups of ransomwared data, because DR was only an option
Microsoft tells yet more customers their emails have been stolen

https://security-tracker.debian.org/tracker/DSA-5724-1