Menu

Category Archives: Security

Articles about security

Smashing Security podcast #355: Fishy Rishi, 23andMe, and the labour of love
Apple, AMD, Qualcomm GPU security hole lets miscreants snoop on AI training and chats
Unveiling the Future of Open-Source Generative AI
XOrg Server and Xwayland Patched Against Multiple Security Vulnerabilities
The 7 deadly cloud security sins and how SMBs can do things better

By eliminating these mistakes and blind spots, your organization can take massive strides towards optimizing its use of cloud without exposing itself to cyber-risk

What’s worse than paying an extortion bot that auto-pwned your database?
JFrog, AWS team up for machine learning in the cloud

* bsc#1218176 * bsc#1218240 * bsc#1218582 * bsc#1218583 * bsc#1218584

* bsc#1179610 * bsc#1211226 * bsc#1215237 * bsc#1215375 * bsc#1217250

* bsc#1218176 * bsc#1218240 * bsc#1218582 * bsc#1218583 * bsc#1218584

* bsc#1179610 * bsc#1205762 * bsc#1210778 * bsc#1212051 * bsc#1212703

* bsc#1108281 * bsc#1109837 * bsc#1179610 * bsc#1202095 * bsc#1211226

* bsc#1218582 * bsc#1218583 * bsc#1218584 * bsc#1218585

Windows Server 2022 patch is breaking apps for some users
Home improvement marketers dial up trouble from regulator
Combination of cheap .cloud domains and fake Shark Tank news fuel unhealthy wellness scams
Nokia walks the walk about its RAN to play on Uncle Sam’s China fears
FBI: Beware of thieves building Androxgh0st botnets using stolen creds
Double trouble for VMware and Atlassian admins – critical flaws to fix
More than 178,000 SonicWall firewalls are exposed to old denial of service bugs
Ivanti zero-day exploits explode as bevy of attackers get in on the act

Xerces-C++ could be made to crash or run programs if it opened a specially crafted file.

A buffer overread vulnerability has been found in libuv.

An update that fixes one vulnerability is now available.

An update that fixes 17 vulnerabilities is now available.

There were security issues in hplip’s `hpps` program due to fixed /tmp path usage in prnt/hpps/hppsfilter.c This update fixes these issues. References:

China’s gambling crackdown spawned wave of illegal online casinos and crypto-crime in Asia

Several security issues were fixed in MySQL.

Thousands of Juniper Networks devices vulnerable to critical RCE bug
Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers
Heartless scammers prey on hundreds of lost pet owners, demanding ransoms or else…
FTC secures first databroker settlement banning sale of sensitive location data
Critical flaw found in WordPress plugin used on over 300,000 websites
Ransomware protection deconstructed
China loathes AirDrop so much it’s publicized an old flaw in Apple’s P2P protocol
Lessons from SEC’s X account hack – Week in security with Tony Anscombe

The cryptocurrency rollercoaster never fails to provide a thrilling ride – this week it was a drama surrounding the hack of SEC’s X account right ahead of the much-anticipated decision about Bitcoin ETFs

Patch management needs a revolution, part 1: Surveying cybersecurity’s lineage
Supercharging chaos testing using AI
Red Hat Enterprise Linux 9 STIG automation released
High automation coverage for Center for Information Security in Red Hat Enterprise Linux 9
Number of orgs compromised via Ivanti VPN zero-days grows as Mandiant weighs in
Why we update… Data-thief malware exploits SmartScreen on unpatched Windows PCs
Exploit for under-siege SharePoint vuln reportedly in hands of ransomware crew
Secret multimillion-dollar cryptojacker snared by Ukrainian police
Secure network operations for hybrid working
So, are we going to talk about how GitHub is an absolute boon for malware, or nah?
Data regulator fines HelloFresh £140K for sending 80M+ spams
How finops can make the cloud more secure
While we fire the boss, can you lock him out of the network?
Drivers: We’ll take that plain dumb car over a flashy data-spilling internet one, thanks

https://security-tracker.debian.org/tracker/DSA-5599-1

https://security-tracker.debian.org/tracker/DSA-5600-1

https://security-tracker.debian.org/tracker/DSA-5601-1

eBay to cough up $3M after cyber-stalking couple who dared criticize the souk

https://security-tracker.debian.org/tracker/DSA-5598-1

Mandiant’s brute-forced X account exposes perils of skimping on 2FA
Attack of the copycats: How fake messaging apps and app mods could bite you

WhatsApp, Telegram and Signal clones and mods remain a popular vehicle for malware distribution. Don’t get taken for a ride.

Infoseccers think attackers backed by China are behind Ivanti zero-day exploits
Believing they would be paid a fortune for having sex with women, hundreds of Indian men scammed out of cash
Security firm Mandiant says it didn’t have 2FA enabled on its hacked Twitter account
Twitter says it’s not its fault the SEC’s account got hacked
Smashing Security podcast #354: Chuck Norris and the fake CEO, artificial KYC, and an Airbnb scam
Fidelity National now says 1.3M customers had data stolen by cyber-crooks
Uncle Sam tells hospitals: Meet security standards or no federal dollars for you
Be honest. Would you pay off a ransomware crew?
US Navy sailor swaps sea for cell after accepting bribes from Chinese snoops
Cybercrooks play dress-up as ‘helpful’ researchers in latest ransomware ruse
Love is in the AI: Finding love online takes on a whole new meaning

Is AI companionship the future of not-so-human connection – and even the cure for loneliness?

SEC’s Twitter account hacked to say Bitcoin ETFs approved. Politicians and lawyers demand investigation into security breach
ShinyHunters chief phisherman gets 3 years, must cough up $5M
Jeffrey Epstein email scams rear their ugly head
New year, new updates for security holes in Windows, Adobe, Android and more
SEC Twitter hijacked to push fake news of hotly anticipated Bitcoin ETF approval
And that’s a wrap for Babuk Tortilla ransomware as free decryptor released
Midwives clinic takes nine months to deliver news of data breach
Sexual assault in the metaverse investigated by British police
Apache OFBiz zero-day pummeled by exploit attempts after disclosure
Hackers hijack Beirut airport departure and arrival boards
Stuxnet: The malware that cost a billion dollars to develop?
British Library: Finances remain healthy as ransomware recovery continues
Facebook, Instagram now mine web links you visit to fuel targeted ads
Cybersecurity trends and challenges to watch out for in 2024 – Week in security with Tony Anscombe

What are some of the key cybersecurity trends that people and organizations should have on their radars this year?

Ransomware payment ban: Wrong idea at the wrong time
After injecting cancer hospital with ransomware, crims threaten to swat patients

https://security-tracker.debian.org/tracker/DSA-5597-1

https://security-tracker.debian.org/tracker/DSA-5596-1

Lost and found: How to locate your missing devices and more

Losing your keys, your wallet – or anything else, really – can be a pain, but there is a wide world of trackers that can help you locate your missing things – with awesome accuracy

BreachForums boss busted for bond blunders – including using a VPN
Sandworm’s Kyivstar attack should serve as a reminder of the Kremlin crew’s ‘global reach’
X-ploited: Mandiant restores hijacked Twitter account after attempted crypto heist
Infosec experts divided over 23andMe’s ‘victim-blaming’ stance on data breach
Cryptocurrency wallet CEO loses $125,000 in wallet-draining scam
Infostealer malware, weak password leaves Orange Spain RIPE for plucking
As lawmakers mull outlawing poor security, what can they really do to tackle online gangs?
Three Chinese balloons float near Taiwanese airbase
Microsoft kills off Windows app installation from the web, again

https://security-tracker.debian.org/tracker/DSA-5595-1

Freight giant Estes refuses to deliver ransom, says personal data opened and stolen

https://security-tracker.debian.org/tracker/DSA-5594-1

Atos confirms talks with Airbus over cybersecurity wing sale