Menu

Category Archives: All

Everything

High-risk open source vulnerabilities on the rise, Synopsys reports
Matthew Perry’s Twitter account hacked by cryptocurrency scammers
Palo Alto investor sues over 28% share tumble

* bsc#1219152 * bsc#1219724 * bsc#1219992 * bsc#1219993 * bsc#1219994

* bsc#1219724 * bsc#1219992 * bsc#1219993 * bsc#1219997 * bsc#1220014

* bsc#1219049 Cross-References: * CVE-2024-22211

* bsc#1219049 Cross-References: * CVE-2024-22211

Uncle Sam tells nosy nations to keep their hands off Americans’ personal data
That home router botnet the Feds took down? Moscow’s probably going to try again

The 6.7.6 stable kernel update contains a number of important fixes across the tree.

Update to 115.8.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-07/ https://www.thunderbird.net/en-US/thunderbird/115.8.0/releasenotes/

Sandvine put on America’s export no-fly list after Egypt used network tech for spying
NIST updates Cybersecurity Framework after a decade of lessons
White House urges developers to dump C and C++

Cross-References: * CVE-2023-44487 CVSS scores:

* bsc#1185232 * bsc#1185261 * bsc#1185441 * bsc#1185621 * bsc#1187071

* bsc#1166486 * bsc#1185861 * bsc#1185863 * bsc#1186449 * bsc#1191256

* bsc#1177083 * bsc#1181995 * jsc#ECO-3329 * jsc#PM-2475 * jsc#PM-2730

* bsc#1071995 * bsc#1084842 * bsc#1114592 * bsc#1124644 * bsc#1128794

* bsc#1214052 Cross-References: * CVE-2023-4039

Cybercrims: When we hit IT, they sometimes pay, but when we hit OT… jackpot
Broadcom builds a better SASE out of VMware VeloCloud and Symantec
China warns of fake digital currency wallets fleecing netizens
Nevada sues to deny kids access to Meta’s Messenger encryption

Welcome to the wild west of the digital world where cyber scammers lurk around every pixelated corner. Cybercrime isn’t just a futuristic Hollywood plotline, it’s a real threat that targets everyone—from wide-eyed kids to seasoned adults and wise grandparents. And guess what? It’s on the rise faster than your Wi-Fi connection during peak hours (okay, […]

ALPHV/BlackCat responsible for Change Healthcare cyberattack
Back from the dead: LockBit taunts cops, threatens to leak Trump docs
Booking.com refund request? It might be an Agent Tesla malware attack
The LockBit ransomware gang rears its ugly head again, after law enforcement takedown
Everything you need to know about NIS2

A vulnerability has been discovered in btrbk which can lead to remote code execution.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Data watchdog tells off outsourcing giant for scanning staff biometrics despite ‘power imbalance’

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The system could be made to crash under certain conditions.

Fox News ‘hacker’ turns out to be journalist whose lawyers say was doing his job
Unlock the Power of Cybersecurity Education for a Secure Future: A Comprehensive Guide for Linux Admins & Infosec Pros
Security is hard because it has to be right all the time? Yeah, like everything else

It was discovered that iwd, the iNet Wireless Daemon, does not properly handle messages in the 4-way handshake used when connecting to a protected WiFi network for the first time. An attacker can take advantage of this flaw to gain unauthorized access to a protected WiFi

An issue has been found in libjwt, a C library to handle JWT (JSON Web Token). Due to using strcmp(), which does not use constant time during execution, a timing side channel attack might be possible.

Update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy

Backport fix for CVE-2023-5841.

Update to 2.6.0, fixes CVE-2023-52425, CVE-2023-52426.

Update to python3.11.8, backport fix for CVE-2023-27043.

https://security-tracker.debian.org/tracker/DSA-5631-1

PSYOP campaigns targeting Ukraine – Week in security with Tony Anscombe

Coming in two waves, the campaign sought to demoralize Ukrainians and Ukrainian speakers abroad with disinformation messages about war-related subjects

LockBitsupp unmasked!!? My reaction to the FBI and NCA’s LockBit ransomware revelation
Delivering a better view of system vulnerabilities with Red Hat Insights
Bridging innovation and standards compliance: Red Hat’s drive towards the next-generation of government computing standards
Environment-as-a-Service, part 4: External resources and dynamic credentials

Rebase to version 2.6.0

Update to qt-5.15.12.

Update to qt-5.15.12.

Update to qt-5.15.12.

Update to qt-5.15.12.

Update to qt-5.15.12.

LockBit extorted billions of dollars from victims, fresh leaks suggest
U-Haul tells 67K customers that cyber-crooks drove away with their personal info
LockBit identity reveal a bigger letdown than Game of Thrones Season 8
Prescription orders delayed as US pharmacies grapple with “nation-state” cyber attack
Tips on meeting complex cloud security challenges

* bsc#1210638 Cross-References: * CVE-2023-27043

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

X protests forced suspension of accounts on orders of India’s government

Update to latest upstream. Fixes CVE-2023-50387 and CVE-2023-50868

New upstream release (123.0)

update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy

Update to latest upstream. Fixes CVE-2023-50387 and CVE-2023-50868

Avast shells out $17M to shoo away claims it peddled people’s personal data

https://security-tracker.debian.org/tracker/DSA-5629-1

https://security-tracker.debian.org/tracker/DSA-5630-1

Cyberattack downs pharmacies across America
Authorities dismantled LockBit before it could unleash revamped variant
Bring us the head of LockBit! $15 million bounty offered for information on leaders of notorious ransomware gang
Ukrainian police arrest father and son in suspected LockBit affiliate double act
GitHub Copilot makes insecure code even less secure, Snyk says

* bsc#1218564 Cross-References: * CVE-2023-52323

* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:

* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:

* bsc#1188609 * bsc#1212850 * bsc#1213210 * bsc#1213925 * bsc#1215311

Imagemagick a graphical software suite for displaying, creating and modifying images was vulnerable. CVE-2023-1289

Giant leak reveals Chinese infosec vendor I-Soon is one of Beijing’s cyber-attackers for hire

Several security issues were fixed in Firefox.

Smashing Security podcast #360: Lockbit locked out, and funeral Facebook scams

https://security-tracker.debian.org/tracker/DSA-5628-1

Biden asks Coast Guard to create an infosec port in a stormy sea of cyber threats
Apple promises to protect iMessage chats from quantum computers
Duo face 20 years in prison over counterfeit iPhone scam
Exploiting the latest max-severity ConnectWise bug is ’embarrassingly easy’
LockBit leaks expose nearly 200 affiliates and bespoke data-stealing malware
Harness the power of security automation
A common goal for European cyber security
Orgs are having a major identity crisis while crims reap the rewards
Europe’s data protection laws cut data storage by making information-wrangling pricier
China could be doing better at censorship, think tank finds

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

Patch for CVE-2024-24258 and CVE-2024-24259

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf