Menu

Category Archives: All

Everything

A decade after collapsing, crypto exchange Mt Gox repays some investors

An update that fixes 7 vulnerabilities is now available.

Navigating the Cybersecurity Maze: Advanced Linux Security Practices for Professionals

Update to 2024.07.02

https://security-tracker.debian.org/tracker/DSA-5726-1

A vulnerability has been discovered in Stellarium, which can lead to arbitrary file writes.

Social media and teen mental health – Week in security with Tony Anscombe

Social media sites are designed to make their users come back for more. Do laws restricting children’s exposure to addictive social media feeds have teeth or are they a political gimmick?

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which could arbitrary code execution.

Multiple vulnerabilities have been discovered in the X.Org X11 library, the worst of which could lead to a denial of service.

A vulnerability has been discovered in KDE Plasma Workspaces, which can lead to privilege escalation.

Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.

Devs claim Apple is banning VPNs in Russia ‘more effectively’ than Putin

Two vulnerabilities were discovered in the GSS message token handling in krb5, the MIT implementation of Kerberos. An attacker can take advantage of these flaws to bypass integrity protections or cause a denial of service.

Comprehensive Security Validation and Breach and Attack Simulation for Linux
Cancer patient forced to make terrible decision after Qilin attack on London hospitals
Latest Ghostscript vulnerability haunts experts as the next big breach enabler

Multiple vulnerabilities have been discovered in BusyBox, the worst of which could lead to arbitrary code execution.

A vulnerability has been discovered in Coreutils, which can lead to a heap buffer overflow and possibly aribitrary code execution.

* bsc#1227186 * bsc#1227187 Cross-References: * CVE-2024-37370

Europol says mobile roaming tech is making its job too hard

Multiple vulnerabilities have been discovered in GraphicsMagick, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in TigerVNC, the worst of which could lead to remote code execution.

Multiple vulnerabilities have been discovered in WebKitGTK+, the worst of which could lead to arbitrary code execution

https://security-tracker.debian.org/tracker/DSA-5725-1

Volcano Demon ransomware group rings its victims to extort money
The AI Fix #5: An angry AI girlfriend, and artificial intelligence is stupid
Security vulnerability reporting: Who can you trust?

* bsc#1226642 Cross-References: * CVE-2024-6387

Europol nukes nearly 600 IP addresses in Cobalt Strike crackdown

* bsc#1222050 * bsc#1222052 * bsc#1222053 * bsc#1226957

* bsc#1219217 * bsc#1220266 Cross-References: * CVE-2024-0914

Ransomware scum who hit Indonesian government apologizes, hands over encryption key

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Smashing Security podcast #379: Private nights, evil twins, and crypto home invasions
Traeger security bugs bad news for grillers with neighborly beef

* bsc#1225771 Cross-References: * CVE-2024-5564

* bsc#1227052 Cross-References: * CVE-2024-6104

* bsc#1213720 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5

* bsc#1224282 Cross-References: * CVE-2024-34459

Several security issues were fixed in Firefox.

* bsc#1224282 Cross-References: * CVE-2024-34459

Affirm admits customer info pilfered during ransomware raid at Evolve Bank

USN-6851-1 caused systemctl enable to fail

USN-6844-1 caused the cupsd daemon to never start

How evolving AI regulations impact cybersecurity

* bsc#1226448 Cross-References: * CVE-2024-4032

* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044

* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044

‘Almost every Apple device’ vulnerable to CocoaPods supply chain attack
Baddies hijack Korean ERP vendor’s update systems to spew malware
Nasty regreSSHion bug in OpenSSH puts around 700K Linux boxes at risk

OpenSSH could be made to bypass authentication and remotely access systems without proper credentials.

Juniper Networks flings out emergency patches for perfect 10 router vuln
Polyfill.io claims reveal new cracks in supply chain, but how deep do they go?
CISA director: US is ‘not afraid’ to shout about Big Tech’s security failings

The Qualys Threat Research Unit (TRU) discovered that OpenSSH, an implementation of the SSH protocol suite, is prone to a signal handler race condition. If a client does not authenticate within LoginGraceTime seconds (120 by default), then sshd’s SIGALRM handler is called

* bsc#1223965 Cross-References: * CVE-2024-33394

* bsc#1224044 Cross-References: * CVE-2024-34397

Several security issues were fixed in eSpeak NG.

Multiple vulnerabilities have been discovered in GNU Emacs and Org Mode, the worst of which could lead to arbitrary code execution.

Police allege ‘evil twin’ of in-flight Wi-Fi used to steal passenger’s credentials
Indonesian government didn’t have backups of ransomwared data, because DR was only an option
Microsoft tells yet more customers their emails have been stolen

https://security-tracker.debian.org/tracker/DSA-5724-1

API security: The importance of rate limiting policies in safeguarding your APIs
Post-quantum cryptography: Code-based cryptography
Embracing automated policy as code in financial services

Mojolicious is a Perl Web Application Framework built around the familiar Model-View-Controller philosophy. It supports a simple single file mode via Mojolicious::Lite, RESTful routes, plugins, Perl-ish templates, session management, signed cookies, a testing framework, internationalization, first

Backport fix for CVE-2024-6239.

Update to 1.26.19, fixes CVE-2024-0444.

Update to 1.26.19, fixes CVE-2024-0444.

Key trends shaping the threat landscape in H1 2024 – Week in security with Tony Anscombe

Learn about the categories of threats that ‘topped the charts’ and the kinds of techniques that bad actors leveraged most commonly in the first half of this year.

Everything You Need to Know About Linux Proxy Servers
The State of Kubernetes Security in 2024

A vulnerability was discovered in GNU Emacs, the extensible, customisable, self-documenting display editor. The org-link-expand-abbrev function expanded a %(…) link abbrev even

A vulnerability was discovered in Org-mode, a GNU Emacs major mode for keeping notes, authoring documents, and maintaining to-do lists. The org-link-expand-abbrev function expanded a %(…) link abbrev even

rebuild for rhbz#2292712

Fix CVE-2024-2698 and CVE-2024-3183

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

CISA looked at C/C++ projects and found a lot of C/C++ code. Wanna redo any of it in Rust?
TeamViewer says Russia broke into its corp IT network
Russian hackers read the emails you sent us, Microsoft warns more customers
Supply-chain ransomware attack cripples thousands of car dealerships

Multiple vulnerabilities havebenn fixed in DCMTK, a collection of libraries and applications implementing large parts the DICOM standard for medical images.

Cyber insurance as part of the cyber threat mitigation strategy

Why organizations of every size and industry should explore their cyber insurance options as a crucial component of their risk mitigation strategies

Unlock the future of security
Google cuts ties with Entrust in Chrome over trust issues
Microsoft hits snooze again on security certificate renewal

* bsc#1216896 * bsc#1216897 * bsc#1216899 * bsc#1216900

‘Skeleton Key’ attack unlocks the worst of AI, says Microsoft
Polyfill.io owner punches back at ‘malicious defamation’ amid domain shutdown

It was discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. (CVE-2019-11471) Reza Mirzazade Farkhani discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash

Possible out-of-bounds read or write when reading malformed MED files. (r19389). [Null-pointer write (32bit platforms) or excessive memory allocation (64bit platforms) when reading close to 4GiB of data from unseekable files (r20336, r20338).

Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image. References:

Update to Emacs 29.4, fixing CVE-2024-39331.

The 6.9.6 stable kernel update contains a number of important fixes across the tree.