Menu

Category Archives: All

Everything

Ivanti devices hit by wave of exploits for latest security hole
Ignore Uncle Sam’s ‘voluntary’ cybersecurity goals for hospitals at your peril
AnyDesk revokes signing certs, portal passwords after crooks sneak into systems
Lurie Children’s Hospital back to pen and paper after cyberattack

Fixes CVE-2023-52339. No API or ABI changes.

update to 121.0.6167.139 * High CVE-2024-1060: Use after free in Canvas * High CVE-2024-1059: Use after free in WebRTC * High CVE-2024-1077: Use after free in Network

Update to 2.15.1.

Combined update for several fixes as well as security fix for CVE-2023-4001 “` Mon Jan 15 2024 Nicolas Frayer – 2.06-114 grub- core/commands: add flag to only search root dev Resolves: #2223437 Resolves: #2224951 Resolves: #2258096 Resolves: CVE-2023-4001 Sat Jan 13 2024 Hector Martin – 2.06-113 Switch memdisk compression to lzop

Fixes CVE-2023-52339. No API or ABI changes.

Security update for CVE-2024-23334 and CVE-2024-23829 https://github.com/aio- libs/aiohttp/releases/tag/v3.9.2 https://github.com/aio- libs/aiohttp/releases/tag/v3.9.3

SBF likely off the hook for misplaced FTX funds after cops bust SIM swap ring
Red Hat Trusted Artifact Signer with Enterprise Contract: Trustable container images
Accessing Azure blob storage with Red Hat OpenShift sandboxed containers peer-pods

Multiple vulnerabilities have been found in NBD Tools, the worst of which could result in arbitary code execution.

Multiple out-of-bounds read vulnerabilities have been discovered in Wireshark.

Multiple vulnerabilities have been found in OpenSSL, the worst of which could result in denial of service.

Multiple vulnerabilities have been found in Xen, the worst of which can lead to arbitrary code execution.

The updated packages fix security vulnerabilities: A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program

Out of bounds write in ANGLE. (CVE-2024-0741) Failure to update user input timestamp. (CVE-2024-0742) Crash when listing printers on Linux. (CVE-2024-0746)

https://security-tracker.debian.org/tracker/DSA-5615-1

Grandoreiro banking malware disrupted – Week in security with Tony Anscombe

The banking trojan, which targeted mostly Brazil, Mexico and Spain, blocked the victim’s screen, logged keystrokes, simulated mouse and keyboard activity and displayed fake pop-up windows

Researchers remotely exploit devices used to manage safe aircraft landings and takeoffs

Sudo, a program designed to allow a sysadmin to give limited root privileges to users and log root activity, was vulnerable. CVE-2023-7090

Multiple vulnerabilities have been discovered in FreeType, the worst of which can lead to remote code execution.

Multiple vulnerabilities have been discovered in Microsoft Edge, the worst of which could lead to remote code execution.

A vulnerability has been discovered in GNAT Ada Suite which can lead to remote code execution.

Multiple vulnerabilities have been discovered in QtGui which can lead to remote code execution.

A vulnerability has been discovered in SDDM which can lead to privilege escalation.

https://security-tracker.debian.org/tracker/DSA-5614-1

Blackbaud settles with FTC after that IT breach exposed millions of people’s info

https://security-tracker.debian.org/tracker/DSA-5613-1

Critical vulnerability in Mastodon is pounced upon by fast-acting admins
FTC slams Blackbaud for “shoddy security” after hacker stole data belonging to thousands of non-profits and millions of people
China is hacking Wi-Fi routers for attack on US electrical grid and water supplies, FBI warns
Interpol’s latest cybercrime intervention dismantles ransomware, banking malware servers

* bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053

* bsc#1140772 * bsc#1157446 * bsc#1170452 * bsc#1171862 * bsc#1215669

* bsc#1068950 * bsc#1081527 * bsc#1211052 * jsc#PED-6584

Red Hat Satellite webhooks and errata
Patch management needs a revolution, part 4: Sane patching is safe patching is selective patching

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051

* bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051

Wikileaks source and former CIA worker Joshua Schulte sentenced to 40 years jail
Managing the hidden risks of shadow APIs
Cloudflare sheds more light on Thanksgiving security breach in which tokens, source code accessed by suspected spies
Rise of deepfake threats means biometric security measures won’t be enough
Biden will veto attempts to rip up SEC breach reporting rule
ESET Research Podcast: ChatGPT, the MOVEit hack, and Pandora

An AI chatbot inadvertently kindles a cybercrime boom, ransomware bandits plunder organizations without deploying ransomware, and a new botnet enslaves Android TV boxes

ESET takes part in global operation to disrupt the Grandoreiro banking trojan

ESET provided technical analysis, statistical information, known C&C servers and was able to get a glimpse of the victimology

LockBit shows no remorse for ransomware attack on children’s hospital
Guide to Secure Data Backup for Linux Users

* bsc#1217654 * bsc#1219131 Cross-References: * CVE-2023-50269

* bsc#1218894 Cross-References: * CVE-2024-21626

* bsc#1218894 Cross-References: * CVE-2024-21626

Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780. CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER containing a long program name failed to update the required buffer size, leading to the allocation and overflow of a too-small buffer on the heap. CVE-2023-6779: __vsyslog_internal used the return value of

Update to 115.7.0 * https://www.mozilla.org/en- US/security/advisories/mfsa2024-04/ * https://www.thunderbird.net/en- US/thunderbird/115.7.0/releasenotes/

Congress told how Chinese attackers plan to incite ‘societal chaos’ in the US

Security fix for CVE-2023-6246, CVE-2023-6779, and CVE-2023-6780. CVE-2023-6246: __vsyslog_internal did not handle a case where printing a SYSLOG_HEADER containing a long program name failed to update the required buffer size, leading to the allocation and overflow of a too-small buffer on the heap. CVE-2023-6779: __vsyslog_internal used the return value of

Smashing Security podcast #357: Interview with an iPhone thief, anti-AI, and have we gone too far?

https://security-tracker.debian.org/tracker/DSA-5612-1

FBI confirms it issued remote kill command to blow out Volt Typhoon’s botnet
Ransomware payment rates drop to new low – only 29% of victims are forking over cash
Nearly 4-year-old Cisco vuln linked to recent Akira ransomware attacks
We know nations are going after critical systems, but what happens when crims join in?
Ivanti releases patches for VPN zero-days, discloses two more high-severity vulns

Multiple vulnerabilities have been found in containerd, the worst of which could result in privilege escalation.

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218049 * bsc#1218050

* bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050 * bsc#1218051

* bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053

* bsc#1216207 * bsc#1216869 * bsc#1217711 * bsc#1218046 * bsc#1218050

Canada’s ‘most prolific hacker’ jailed for two years

https://security-tracker.debian.org/tracker/DSA-5610-1

US shorts China’s Volt Typhoon crew targeting America’s criticals
Jenkins jitters as 45,000 servers still vulnerable to RCE attacks after patch released
Reg story prompts fresh security bulletin, review of Juniper Networks’ CVE process

Postfix, a popular mail server, allowed SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking

IaC Security Scanning: Ensuring Security in the Open-Source Environment

TinyXML could be made to crash if it opened a specially crafted file.

Protecting against software supply chain attacks
UK biometrics boss bows out, bemoaning bureaucratic blunders

The container bci/python was updated. The following patches have been included in this update:

The container bci/php-fpm was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

https://security-tracker.debian.org/tracker/DSA-5611-1

SolarWinds slams SEC lawsuit against it as ‘unprecedented’ victim blaming
Be the Royal Family’s Cybersecurity Manager, and get a cut-price honey dipper!
Trickbot malware developer jailed for five years
Best Practices for WordPress Site Security on Linux Webservers

Exim could be made to bypass an SPF protection mechanism if it received a specially crafted request.

The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update:

The container suse/rmt-mariadb was updated. The following patches have been included in this update:

The container suse/rmt-mariadb-client was updated. The following patches have been included in this update:

The container suse/nginx was updated. The following patches have been included in this update:

Security fix for CVE-2023-48795

Tesla hacks make big bank at Pwn2Own’s first automotive-focused event
Top 3 Cybersecurity Trends for SME Business Leaders
750 million Indian mobile subscribers’ info for sale on dark web