Menu

Category Archives: Security

Articles about security

This update includes the changes in tzdata 2024a for the Perl bindings. For the list of changes, see DLA-3789-1. For Debian 10 buster, this problem has been fixed in version

This update includes the changes in tzdata 2024a. Notable changes are: – – Kazakhstan unifies on UTC+5 beginning 2024-03-01.

Prolific phishing-made-easy emporium LabHost knocked offline in cyber-cop op
Java services hit hardest by third-party vulnerabilities, report says
Cisco creates architecture to improve security and sell you new switches
Singapore infosec boss warns China/West tech split will be bad for interoperability
Taiwanese film studio snaps up Chinese surveillance camera specialist Dahua

sosreport: Fix command injection with crafted report names [CVE-2024-2947]

Fix for CVE-2024-31497

Hugely expanded Section 702 surveillance powers set for US Senate vote
Smashing Security podcast #368: Gary Barlow, and a scam turns deadly

https://security-tracker.debian.org/tracker/DSA-5655-2

Kremlin’s Sandworm blamed for cyberattacks on US, European water utilities
Exploit code for Palo Alto Networks zero-day now public
OpenAI’s GPT-4 can exploit real vulnerabilities by reading security advisories

* bsc#1200599 * bsc#1209635 * bsc#1212514 * bsc#1213456 * bsc#1217987

* bsc#1194869 * bsc#1200465 * bsc#1205316 * bsc#1207948 * bsc#1209635

Japanese government rejects Yahoo! infosec improvement plan

New upstream release (125.0)

The 6.8.6 stable kernel update contains a number of important fixes across the tree.

Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713

New version 4.2.4. Includes a fix for CVE-2024-2955

Fire in the Cisco! Networking giant’s Duo MFA message logs stolen in phish attack
Most developers have adopted devops, survey says
MGM says FTC can’t possibly probe its ransomware downfall – watchdog chief Lina Khan was a guest at the time

https://security-tracker.debian.org/tracker/DSA-5661-1

https://security-tracker.debian.org/tracker/DSA-5660-1

Alleged cryptojacker accused of stealing $3.5M from cloud to mine under $1M in crypto
SIM swap crooks solicit T-Mobile US, Verizon staff via text to do their dirty work
Open sourcerers say suspected xz-style attacks continue to target maintainers
Change Healthcare’s ransomware attack costs edge toward $1B so far

* bsc#1216992 Cross-References: * CVE-2023-4218

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603

Google location tracking deal could be derailed by politics
Better application networking and security with CAKES

https://security-tracker.debian.org/tracker/DSA-5662-1

CISA in a flap as Chirp smart door locks can be trivially unlocked remotely
Protect Your Linux Web Apps and Meet Compliance Standards

Bartek Nowotarski discovered that Apache Traffic Server, a reverse and forward proxy server, was susceptible to denial of service via HTTP2 continuation frames.

Roku makes 2FA mandatory for all after nearly 600K accounts pwned
Delinea Secret Server customers should apply latest patches

Multiple vulnerabilities have been fixed in the Xorg X server. CVE-2024-31080

US senator wants to put the brakes on Chinese EVs
Zambia arrests 77 people in swoop on “scam” call centre

* bsc#1219296 Cross-References: * CVE-2023-52340

Identifying third-party risk
US House approves FISA renewal – warrantless surveillance and all

update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn

New less packages are available for Slackware 15.0 and -current to fix a security issue.

Core: – Corrupted memory in destructor with weak references – GC does not scale well with a lot of objects created in destructor DOM: – Add some missing ZPP checks.

Red Hat Enterprise Linux 7: End of compliance content on June 30, 2024

update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/

Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/

https://security-tracker.debian.org/tracker/DSA-5659-1

https://security-tracker.debian.org/tracker/DSA-5657-1

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

Update to version 0.3.26. Addresses RUSTSEC-2024-0332.

Update to version 0.3.26. Addresses RUSTSEC-2024-0332.

https://security-tracker.debian.org/tracker/DSA-5658-1

Zero-day exploited right now in Palo Alto Networks’ GlobalProtect gateways

Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with “collapsed_forwarding on” are vulnerable. Configurations with “collapsed_forwarding off” or without a “collapsed_forwarding” directive

Rust gets security fix for Windows vulnerability
Google One VPN axed for everyone but Pixel loyalists … for now
Microsoft breach allowed Russian spies to steal emails from US government

* bsc#1221564 Cross-References: * CVE-2021-47154

Understanding the Red Hat security impact scale

* bsc#1218613 * bsc#1219078 * bsc#1219296 * bsc#1219432

French issue alerte rouge after local governments knocked offline by cyber attack
Apple stops warning of ‘state-sponsored’ attacks, now alerts about ‘mercenary spyware’

Security fix for CVE-2024-24576 (Windows command injection)

Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)

Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)

4.2.3

Space Force boss warns ‘the US will lose’ without help from Musk and Bezos

These new packages fix bugs in SSL certificate validation; these bugs could allow for the compromising of encrypted SSL sessions.

East Central University suffers BlackSuit ransomware attack
DragonForce ransomware – what you need to know
When a breach goes from 25 documents to 1.3 terabytes…
96% of US hospital websites share visitor info with Meta, Google, data brokers

* bsc#1028271 Cross-References: * CVE-2016-10243

* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672

* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672

Global taxi software vendor exposes details of nearly 300K across UK and Ireland

This is the March 2024 update for .NET 7. Release Notes: https://github.com/dotnet/core/blob/main/release- notes/7.0/7.0.17/7.0.17.md

https://security-tracker.debian.org/tracker/DSA-5656-1

Smashing Security podcast #367: WhatsApp at Westminster, unhealthy AI, and Drew Barrymore

An update that fixes two vulnerabilities is now available.

Strategies for Improving Linux Security Through Cross-Browser Compatibility Testing
It’s 2024 and Intel silicon is still haunted by data-spilling Spectre

util-linux could be made to expose sensitive information.

Rust rustles up fix for 10/10 critical command injection bug on Windows

* bsc#1167896 * bsc#1206261 * bsc#1215301 Cross-References: