Menu

Category Archives: Security

Articles about security

LockBit ransomware gang steals data related to security of UK military bases
Northern Ireland top cop quits in wake of data breach and disciplinary controversy

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

security update

Attackers accessed UK military data through high-security fencing firm’s Windows 7 rig
Microsoft calls time on ancient TLS in Windows, breaking own stuff in the process
Tsunami watch

Red Hat JBoss Web Server 5.7.4 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, and Windows Server. Red Hat Product Security has rated this release as having a security impact

An update is now available for Red Hat JBoss Web Server 5.7.4 on Red Hat Enterprise Linux versions 7, 8, and 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Several security issues were fixed in BusyBox.

Northern Irish cops release 2 men after Terrorism Act arrests linked to data breach

Several security issues were fixed in atftp.

How to get a handle on shadow AI
Deep Instinct takes a prevention-first approach to stopping ransomware and other malware using deep learning

Several security issues were fixed in Thunderbird.

Apple opens annual applications for free hackable iPhones

Null pointer dereference in ber_memalloc_x() function (CVE-2023-2953) References: – https://bugs.mageia.org/show_bug.cgi?id=32073 – https://ubuntu.com/security/notices/USN-6197-1

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the oldstable distribution (bullseye), these problems have been fixed

The 6.4.13 stable kernel updates contain a number of important fixes across the tree.

The 6.4.13 stable kernel updates contain a number of important fixes across the tree.

Freecycle users told to change passwords after data breach
Cops drill into chat apps, sink plot to smuggle tons of coke into Europe

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

– New upstream version (117.0)

https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/H46H5ZYZG2PYUQ5STK7NWKF7GXYW7H6B/

Updates to Kubernetes for F38 and F39. Security fixes for CVE-2023-3955 and CVE-2023-3676. Related update for rawhide already in stable. Update for F37 is currently in COPR at https://copr.fedorainfracloud.org/coprs/buckaroogeek/copr-k8s-1.25/ due to golang blocker.

security update

More Okta customers trapped in Scattered Spider’s web
Another data breach at Forever 21 leaks details of 500,000 current and former employees
Massive attack

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Improving containerization security with Red Hat OpenShift
Enterprise security challenges for CNI organizations: Overview of security challenges
Persistent volume support with peer-pods: A technical deep dive

The container bci/openjdk was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

Good news for Key Group ransomware victims: Free decryptor out now

security update

security update

Kremlin-backed Sandworm strikes Android devices with data-stealing Infamous Chisel

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container suse/pcp was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

Smashing Security podcast #337: The DEA’s crypto calamity, and scammers’ blue tick bonanza
Barracuda gateway attacks: How Chinese snoops keep a grip on victims’ networks
Microsoft angry over Russian-led UN cybercrime treaty

USN-6263-1 introduced a regression in OpenJDK 11 and OpenJDK 17.

Japan’s cybersecurity agency admits it was hacked for months

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update:

Several security issues were fixed in Firefox.

Toyota Japan back on the road after probably-not-cyber attack halted production

AMD processors may allow an attacker to expose sensitive information due to a speculative execution vulnerability.

– Update moby-engine to 24.0.5 – Security fix for CVE-2021-41803 – Security fix for CVE-2023-28842 – Security fix for CVE-2023-28841 – Security fix for CVE-2023-28840 – Security fix for CVE-2023-0845 – Security fix for CVE-2023-26054 – Security fix for CVE-2022-3064 – Security fix for CVE-2022-40716 – Security fix for CVE-2023-25173 —- Update moby-engine to

Meta reckons China’s troll farms could learn proper OpSec from Russia’s fake news crews
University cuts itself off from internet after mystery security snafu
Apple security boss faces iPads-for-gun-permits bribery charge… again
FBI-led Operation Duck Hunt shoots down Qakbot
More UK cops’ names and photos exposed in supplier breach
The Unseen Potential of Wake-on-LAN

Rebase to qemu 7.2.5

Health, payment info for 1.2M people feared stolen from Purfoods in IT attack

The components for Red Hat OpenShift support for Windows Containers 6.0.2 are now available. This product release includes bug fixes and security updates for the following packages: windows-machine-config-operator and windows-machine-config-operator-bundle.

The components for Red Hat OpenShift support for Windows Containers 7.1.1 are now available. This product release includes bug fixes and security updates for the following packages: windows-machine-config-operator and windows-machine-config-operator-bundle.

security update

cups: Information leak through Cups-Get-Document operation (CVE-2023-32360) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 cups-1.6.3-52.el7_9.x86_64.rpm cups-client-1.6.3-52.el7_9.x86_64.rpm cups-debuginfo-1.6.3-52.el7_9.i686.rpm cups-debuginfo-1.6.3-52.el7_9.x86_ [More…]

An update that fixes 5 vulnerabilities is now available.

Important: subscription-manager security update

Zac Sims discovered a directory traversal in the URL decoder of librsvg, a SAX-based renderer library for SVG files, which could result in read of arbitrary files when processing a specially crafted SVG file with an include element.

Malware loader lowdown: The big 3 responsible for 80% of attacks so far this year
Whiffy malware stinks after tracking location via Wi-FI
Taiwanese infosec researchers challenge Microsoft’s China espionage finding

A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV, an anti-virus utility for Unix, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

Ready to enhance your continuous assessment efforts? Meet PlexTrac

A specific flaw within the processing of recovery volumes exists in RAR, an archive program for rar files. It allows remote attackers to execute arbitrary code on affected installations. User interaction is required to exploit this vulnerability. The target must visit a malicious page or open a

update to 116.0.5845.96. Fixes following security issues: CVE-2023-2312 CVE-2023-4349 CVE-2023-4350 CVE-2023-4351 CVE-2023-4352 CVE-2023-4353 CVE-2023-4354 CVE-2023-4355 CVE-2023-4356 CVE-2023-4357 CVE-2023-4358 CVE-2023-4359 CVE-2023-4360 CVE-2023-4361 CVE-2023-4362

This update takes caddy from 2.5.2 to 2.6.4. The primary purpose is to resolve CVE-2022-41721. This is a fairly significant upgrade with lots of new features and fixes, but after reviewing the upstream release notes I believe it should comply with the Fedora updates policy. The upgrade warnings in the release notes are described as […]

update to xen-4.16.5 which includes x86/AMD: Speculative Return Stack Overflow [XSA-434, CVE-2023-20569] x86/Intel: Gather Data Sampling [XSA-435, CVE-2022-40982] remove patches now included upstream —- arm: Guests can trigger a deadlock on Cortex-A77 [XSA-436, CVE-2023-34320] (#2228238) —- bugfix for x86/AMD: Zenbleed [XSA-433, CVE-2023-20593] —- x86/AMD: Zenbleed

This update takes caddy from 2.5.2 to 2.6.4. The primary purpose is to resolve a long standing FTBFS related to golang 1.20. The current F38 package is actually a carried-foward F37 build because of that reason. It also resolves CVE-2022-41721. This is a fairly significant upgrade with lots of new features and fixes, but after […]

A specific flaw within the processing of recovery volumes exists in UnRAR, an unarchiver for rar files. It allows remote attackers to execute arbitrary code on affected installations. User interaction is required to exploit this vulnerability. The target must visit a malicious page or open a malicious rar

security update

Linux Vulnerabilities: The Antidote to This Linux Security Poison
Tor turns to proof-of-work puzzles to defend onion network from DDoS attacks

security update

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Update to latest upstream git snapshot. Various changes, including bug fix for cookie leak vulnerability.

Update to latest upstream git snapshot. Various changes, including bug fix for cookie leak vulnerability.

FBI: Who was going around hijacking Barracuda email boxes? China, probably

JOSE for C/C++ could be made to crash if it received specially crafted input.

Fast DDS could be made to crash or expose sensitive information if it received specially crafted input.

“Edbo” and Cedric Krier discovered that the Tryton application server does enforce record rules when only reading fields without an SQL type (like Function fields).

Court finds autistic members of LAPSUS$ gang responsible for GTA 6 hack and other high profile breaches