Menu

Category Archives: Security

Articles about security

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

Microsoft sheds some light on Russian email heist – and how to learn from Redmond’s mistakes
Wait, security courses aren’t a requirement to graduate with a computer science degree?
Guess the company: Takes your DNA, blames you when criminals steal it, can’t spot a cyberattack for 5 months

* bsc#1218571 Cross-References: * CVE-2023-7207

* bsc#1218728 Cross-References: * CVE-2024-23301

* bsc#1218802 Cross-References: * CVE-2023-51257

* bsc#1218802 Cross-References: * CVE-2023-51257

* bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742

Akira ransomware gang says it stole passport scans from Lush in 110 GB data heist
What’s next on the horizon for telecommunications service providers? A look at 2024 with Red Hat.
Enabling Peer Pods on IBM Z and LinuxONE with Red Hat OpenShift sandboxed containers

Update to 115.7.0 * https://www.mozilla.org/en- US/security/advisories/mfsa2024-04/ * https://www.thunderbird.net/en- US/thunderbird/115.7.0/releasenotes/

Trickbot malware scumbag gets five years for infecting hospitals, businesses

https://security-tracker.debian.org/tracker/DSA-5607-1

AI is already being used by ransomware gangs, warns NCSC
EquiLend drags systems offline after admitting attacker broke in

* bsc#1205463 * bsc#1218189 Cross-References: * CVE-2022-45047

* bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742

* bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742

The chromium-browser-stable package has been updated to the 120.0.6099.224 release. 4 vulnerabilities are fixed; some of them are listed below: High CVE-2024-0517: Out of bounds write in V8. Reported by Toan (suto) Pham of Qrious Secure on 2024-01-06.

The updated packages fix security vulnerabilities: A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record. (CVE-2023-38469) A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function. (CVE-2023-38470)

Patch management needs a revolution, part 3: Vulnerability scores and the concept of trust

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

HPE joins the ‘our executive email was hacked by Russia’ club
Smashing Security podcast #356: Big dumpers, AI defamation, and the slug that slurped
US judge rejects spyware developer NSO’s attempt to bin Apple’s spyware lawsuit

https://security-tracker.debian.org/tracker/DSA-5604-1

https://security-tracker.debian.org/tracker/DSA-5603-1

Mobb unveils vulnerability fixer for GitHub users
SEC Twitter hack blamed on SIM swap attack
Major IT outage at Europe’s largest caravan and RV club makes for not-so-happy campers
Using GoAnywhere MFT for file transfers? Patch now – an exploit’s out for a critical bug
What Microsoft’s latest email breach says about this IT security heavyweight
COVID-19 test lab accused of exposing 1.3 million patient records to open internet
GCHQ’s NCSC warns of ‘realistic possibility’ AI will help state-backed malware evade detection

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

A vulnerability has been discovered in sudo which can lead to execution manipulation through rowhammer-style memory manipulation.

Multiple vulnerabilities have been discovered in GOCR, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Ruby, the worst of which could lead to execution of arbitrary code.

Backport fix for CVE-2023-51257.

Mitigate CVE-2024-0690

https://security-tracker.debian.org/tracker/DSA-5606-1

https://security-tracker.debian.org/tracker/DSA-5605-1

CISA boss swatted: ‘While my own experience was certainly harrowing, it was unfortunately not unique’
Accused PII seller faces jail for running underground fraud op
UK water giant admits attackers broke into system as gang holds it to ransom
A guide to implementing fine-grained authorization
Australia imposes cyber sanctions on Russian it says ransomwared health insurer
Atlassian Confluence Server RCE attacks underway from 600+ IPs
Slug slimes aerospace biz AerCap with ransomware, brags about 1TB theft
EFF adds Street Surveillance Hub so Americans can check who’s checking on them
Ivanti and Juniper Networks accused of bending the rules with CVE assignments
Subway’s data torpedoed by LockBit, ransomware gang claims
With hackers poisoning water systems, US agencies issue incident response guide to boost cybersecurity
ICO fines spam slinging financial services biz
Safeguarding against the global ransomware threat
BreachForums admin ‘Pompourin’ sentenced to 20 years of supervised release
Leveraging Red Hat Service Mesh to encrypt AMQ communication on OpenShift
Unlocking the power of generative AI with Cloudera Data Platform and Red Hat OpenShift
Why many CISOs consider quitting – Week in security with Tony Anscombe

The job of a CISO is becoming increasingly stressful as cybersecurity chiefs face overwhelming workloads and growing concerns over personal liability for security failings

Virtual kidnapping: How to see through this terrifying scam

Phone fraud takes a frightening twist as fraudsters can tap into AI to cause serious emotional and financial damage to the victims

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container suse/rmt-mariadb-client was updated. The following patches have been included in this update:

Russians invade Microsoft exec mail while China jabs at VMware vCenter Server
Five ripped off IT giant with $7M+ in bogus work expenses, prosecutors claim
Is Temu safe? What to know before you ‘shop like a billionaire’

Here are some scams you may encounter on the shopping juggernaut, plus a few simple steps you can take to help safeguard your data while bagging that irresistible deal

Thieves steal 35.5M customers’ data from Vans sneakers maker
35.5 million customers of major apparel brands have their data breached after ransomware attack

* bsc#1218582 * bsc#1218583 * bsc#1218584 * bsc#1218585 * bsc#1218845

Patch management needs a revolution, part 2: The flood of vulnerabilities

The container suse/rmt-mariadb was updated. The following patches have been included in this update:

The container bci/php-fpm was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

IT consultant fined for daring to expose shoddy security
US agencies warn made-in-China drones might help Beijing snoop on the world

https://security-tracker.debian.org/tracker/DSA-5602-1

JPMorgan exec claims bank repels ’45 billion’ cyberattack attempts per day
Future of America’s Cyber Safety Review Board hangs in balance amid calls for rethink
Ransomware attacks hospitalizing security pros, as one admits suicidal feelings
Two more Citrix NetScaler bugs exploited in the wild
Google TAG: Kremlin cyber spies move into malware with a custom backdoor

* bsc#1218728 Cross-References: * CVE-2024-23301

* bsc#1217000 * bsc#1218475 Cross-References: * CVE-2024-22365

* bsc#1218475 Cross-References: * CVE-2024-22365

* bsc#1218413 Cross-References: * CVE-2023-51714

* bsc#1211188 * bsc#1211190 * bsc#1218126 * bsc#1218186 * bsc#1218209

* bsc#1108281 * bsc#1179610 * bsc#1183045 * bsc#1211162 * bsc#1211226

IPv6 approach for TCP SYN Flood attack over VoIP, Part II
IPv6 approach for TCP SYN Flood attack over VoIP, Part III
Vast botnet hijacks smart TVs for prime-time cybercrime
Enter the era of platform-based cloud security
Insurance website’s buggy API leaked Office 365 password and a giant email trove