Menu

Category Archives: All

Everything

White House urges developers to dump C and C++

Cross-References: * CVE-2023-44487 CVSS scores:

* bsc#1185232 * bsc#1185261 * bsc#1185441 * bsc#1185621 * bsc#1187071

* bsc#1166486 * bsc#1185861 * bsc#1185863 * bsc#1186449 * bsc#1191256

* bsc#1177083 * bsc#1181995 * jsc#ECO-3329 * jsc#PM-2475 * jsc#PM-2730

* bsc#1071995 * bsc#1084842 * bsc#1114592 * bsc#1124644 * bsc#1128794

* bsc#1214052 Cross-References: * CVE-2023-4039

Cybercrims: When we hit IT, they sometimes pay, but when we hit OT… jackpot
Broadcom builds a better SASE out of VMware VeloCloud and Symantec
China warns of fake digital currency wallets fleecing netizens
Nevada sues to deny kids access to Meta’s Messenger encryption

Welcome to the wild west of the digital world where cyber scammers lurk around every pixelated corner. Cybercrime isn’t just a futuristic Hollywood plotline, it’s a real threat that targets everyone—from wide-eyed kids to seasoned adults and wise grandparents. And guess what? It’s on the rise faster than your Wi-Fi connection during peak hours (okay, […]

ALPHV/BlackCat responsible for Change Healthcare cyberattack
Back from the dead: LockBit taunts cops, threatens to leak Trump docs
Booking.com refund request? It might be an Agent Tesla malware attack
The LockBit ransomware gang rears its ugly head again, after law enforcement takedown
Everything you need to know about NIS2

A vulnerability has been discovered in btrbk which can lead to remote code execution.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Data watchdog tells off outsourcing giant for scanning staff biometrics despite ‘power imbalance’

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The system could be made to crash under certain conditions.

Fox News ‘hacker’ turns out to be journalist whose lawyers say was doing his job
Unlock the Power of Cybersecurity Education for a Secure Future: A Comprehensive Guide for Linux Admins & Infosec Pros
Security is hard because it has to be right all the time? Yeah, like everything else

It was discovered that iwd, the iNet Wireless Daemon, does not properly handle messages in the 4-way handshake used when connecting to a protected WiFi network for the first time. An attacker can take advantage of this flaw to gain unauthorized access to a protected WiFi

An issue has been found in libjwt, a C library to handle JWT (JSON Web Token). Due to using strcmp(), which does not use constant time during execution, a timing side channel attack might be possible.

Update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy

Backport fix for CVE-2023-5841.

Update to 2.6.0, fixes CVE-2023-52425, CVE-2023-52426.

Update to python3.11.8, backport fix for CVE-2023-27043.

https://security-tracker.debian.org/tracker/DSA-5631-1

PSYOP campaigns targeting Ukraine – Week in security with Tony Anscombe

Coming in two waves, the campaign sought to demoralize Ukrainians and Ukrainian speakers abroad with disinformation messages about war-related subjects

LockBitsupp unmasked!!? My reaction to the FBI and NCA’s LockBit ransomware revelation
Delivering a better view of system vulnerabilities with Red Hat Insights
Bridging innovation and standards compliance: Red Hat’s drive towards the next-generation of government computing standards
Environment-as-a-Service, part 4: External resources and dynamic credentials

Rebase to version 2.6.0

Update to qt-5.15.12.

Update to qt-5.15.12.

Update to qt-5.15.12.

Update to qt-5.15.12.

Update to qt-5.15.12.

LockBit extorted billions of dollars from victims, fresh leaks suggest
U-Haul tells 67K customers that cyber-crooks drove away with their personal info
LockBit identity reveal a bigger letdown than Game of Thrones Season 8
Prescription orders delayed as US pharmacies grapple with “nation-state” cyber attack
Tips on meeting complex cloud security challenges

* bsc#1210638 Cross-References: * CVE-2023-27043

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

X protests forced suspension of accounts on orders of India’s government

Update to latest upstream. Fixes CVE-2023-50387 and CVE-2023-50868

New upstream release (123.0)

update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy

Update to latest upstream. Fixes CVE-2023-50387 and CVE-2023-50868

Avast shells out $17M to shoo away claims it peddled people’s personal data

https://security-tracker.debian.org/tracker/DSA-5629-1

https://security-tracker.debian.org/tracker/DSA-5630-1

Cyberattack downs pharmacies across America
Authorities dismantled LockBit before it could unleash revamped variant
Bring us the head of LockBit! $15 million bounty offered for information on leaders of notorious ransomware gang
Ukrainian police arrest father and son in suspected LockBit affiliate double act
GitHub Copilot makes insecure code even less secure, Snyk says

* bsc#1218564 Cross-References: * CVE-2023-52323

* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:

* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:

* bsc#1188609 * bsc#1212850 * bsc#1213210 * bsc#1213925 * bsc#1215311

Imagemagick a graphical software suite for displaying, creating and modifying images was vulnerable. CVE-2023-1289

Giant leak reveals Chinese infosec vendor I-Soon is one of Beijing’s cyber-attackers for hire

Several security issues were fixed in Firefox.

Smashing Security podcast #360: Lockbit locked out, and funeral Facebook scams

https://security-tracker.debian.org/tracker/DSA-5628-1

Biden asks Coast Guard to create an infosec port in a stormy sea of cyber threats
Apple promises to protect iMessage chats from quantum computers
Duo face 20 years in prison over counterfeit iPhone scam
Exploiting the latest max-severity ConnectWise bug is ’embarrassingly easy’
LockBit leaks expose nearly 200 affiliates and bespoke data-stealing malware
Harness the power of security automation
A common goal for European cyber security
Orgs are having a major identity crisis while crims reap the rewards
Europe’s data protection laws cut data storage by making information-wrangling pricier
China could be doing better at censorship, think tank finds

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

Patch for CVE-2024-24258 and CVE-2024-24259

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

Singapore’s monetary authority advises banks to get busy protecting against quantum decryption

https://security-tracker.debian.org/tracker/DSA-5627-1

New libuv packages are available for Slackware 15.0 and -current to fix a security issue.

* bsc#1011205 * bsc#1093641 * bsc#1125882 * bsc#1167400 * bsc#1207973

* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188

Cops turn LockBit ransomware gang’s countdown timers against them
Wyze admits 13,000 users could have viewed strangers’ camera feeds
Insider steals 79,000 email addresses at work to promote own business

The updated packages fix security vulnerabilities: RTPS dissector memory leak. (CVE-2023-5371) SSH dissector invalid read of memory blocks. (CVE-2023-6174) NetScreen File Parsing Heap-based Buffer Overflow. (CVE-2023-6175) GVCP dissector crash via packet injection or crafted capture file.

Vietnam to collect biometrics – even DNA – for new ID cards

Stack buffer overflow in virtio_net_flush_tx (CVE-2023-6693) (rhbz#2256436)

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link