Menu

Monthly Archives: September 2024

* bsc#1230353 Cross-References: * CVE-2023-29483

* bsc#1230353 Cross-References: * CVE-2023-29483

Cops across the world arrest 51 in orchestrated takedown of Ghost crime platform

Several security issues were fixed in the Linux kernel.

A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. An attacker could generate a malicious dump file which could execute shell commands from the MariaDB client.

Despite Russia warnings, Western critical infrastructure remains unprepared
Intro to Deno Fresh: A fresh take on full-stack JavaScript
Text in, docs out: Popular Markdown documentation tools compared

* bsc#1227378 * bsc#1227999 * bsc#1228780 * bsc#1229596

* bsc#1228780 Cross-References: * CVE-2024-6923

How Cloud Custodian conquered cloud resource management
Can Java rival Python in AI development?
Australian Police conducted supply chain attack on criminal collaborationware
WhatsApp fix to make View Once chats actually disappear is beaten in less than a week
C++ Alliance takes aim at C++ memory safety
VMware patches remote make-me-root holes in vCenter Server, Cloud Foundation
Google Cloud Document AI flaw (still) allows data theft despite bounty payout
The AI Fix #16: GPT-4o1, AI time travelers, and where’s my driverless car?
Hezbollah claims dozens dead as its pagers go boom, not beep
Rhysida ransomware gang ships off Port of Seattle data for $6M
Secure your organization
Predator spyware kingpins added to US sanctions list

An update that solves four vulnerabilities and has one errata is now available.

A new stable version was released for galera-4, a synchronous multimaster replication engine for MySQL and MariaDB. This fixes several issues detailed at:

Several security issues were fixed in libxmltok.

How Red Hat is integrating post-quantum cryptography into our products

Several security issues were fixed in ClamAV.

Several security issues were fixed in DCMTK.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Ticketmaster boss who repeatedly hacked rival firm sentenced
China claims Starlink signals can reveal stealth aircraft – and what that really means
Chinese national accused by Feds of spear-phishing for NASA, military source code
Microsoft confirms IE bug squashed in Patch Tuesday was exploited zero-day
The empire of C++ strikes back with Safe C++ blueprint
Snowflake slams ‘more MFA’ button again – months after Ticketmaster, Santander breaches
Germany’s CDU still struggling to restore data months after June cyberattack

An update that fixes four vulnerabilities is now available.

* bsc#1176447 * bsc#1195668 * bsc#1195928 * bsc#1195957 * bsc#1196018

* bsc#1229907 * bsc#1230372 Cross-References: * CVE-2024-8250

* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629

* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629

Prison just got rougher as band of heinously violent cybercrims sentenced to lengthy stints

OpenSSH could be made to crash or run programs as your login if it received a specially crafted input.

9 hacks for a better nightly build
When your cloud strategy is ‘it depends’
China’s quantum* crypto tech may be unhackable, but it’s hardly a secret
3 common misconceptions around biometrics and authentication
AWS hands OpenSearch to the Linux Foundation
23andMe settles class-action breach lawsuit for $30 million

Update to 1.0.7 CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files. CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser

flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.

flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.

Update to 1.15.10 (CVE-2024-42472)

https://security-tracker.debian.org/tracker/DSA-5769-1

Node.js a JavaScript runtime environment that executes JavaScript code outside a web browser (server side) was vulnerable. CVE-2023-30589

New libarchive packages are available for Slackware 15.0 and -current to fix security issues.

CosmicBeetle joins the ranks of RansomHub affiliates – Week in security with Tony Anscombe

ESET research also finds that CosmicBeetle attempts to exploit the notoriety of the LockBit ransomware gang to advance its own ends

update to 128.0.6613.137 * High CVE-2024-8636: Heap buffer overflow in Skia * High CVE-2024-8637: Use after free in Media Router * High CVE-2024-8638: Type Confusion in V8 * High CVE-2024-8639: Use after free in Autofill

Update to expat-2.6.3.

Update to 1.0.7 CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files. CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser

Update to 115.15.0 https://www.thunderbird.net/en-US/thunderbird/115.15.0esr/releasenotes/

Update to expat-2.6.3.

Update to 3.6.1 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-3.6.1 Update to 3.6.0

Feeld dating app’s security too open-minded as private data swings into public view
Decoding OpenAI’s o1 family of large language models

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Life without Python’s ‘dead batteries’
New AI reporting regulations

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Cambodian senator sanctioned by US over alleged forced labor cyber-scam camps
Australia’s government spent the week boxing Big Tech
What’s in the cards for MariaDB?
Feds pull plug on domains linked to import of Chinese gun conversion devices
Fortinet admits miscreant got hold of customer data in the cloud
‘Hadooken’ Linux malware targets Oracle WebLogic servers
JFrog Platform adds runtime security for containers
Microsoft moves .NET 9 to release candidate stage
I stole 20 GB of data from Capgemini – and now I’m leaking it, says cybercrook

https://security-tracker.debian.org/tracker/DSA-5768-1

Mastercard splurges $2.65B on another big cyber purchase – Recorded Future
Adobe fixed Acrobat bug, neglected to mention whole zero-day exploit thing
Kong API platform adds service catalog
6 common Geek Squad scams and how to defend against them

Learn about the main tactics used by scammers impersonating Best Buy’s tech support arm and how to avoid falling for their tricks

Google Chrome gets a mind of its own for some security fixes
WordPress plugin and theme developers told they must use 2FA
Transport for London confirms 5,000 users’ bank data exposed, pulls large chunks of IT infra offline

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in libxmltok.

Several security issues were fixed in Expat.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

EU kicks off an inquiry into Google’s AI model
About that Windows Installer ‘make me admin’ security hole. Here’s how it’s exploited
Smashing Security podcast #384: A room with a view, AI music shenanigans, and a cocaine bear
Mind your header! There’s nothing refreshing about phishers’ latest tactic