Menu

Category Archives: Security

Articles about security

DragonForce ransomware – what you need to know
When a breach goes from 25 documents to 1.3 terabytes…
96% of US hospital websites share visitor info with Meta, Google, data brokers

* bsc#1028271 Cross-References: * CVE-2016-10243

* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672

* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672

Global taxi software vendor exposes details of nearly 300K across UK and Ireland

This is the March 2024 update for .NET 7. Release Notes: https://github.com/dotnet/core/blob/main/release- notes/7.0/7.0.17/7.0.17.md

https://security-tracker.debian.org/tracker/DSA-5656-1

Smashing Security podcast #367: WhatsApp at Westminster, unhealthy AI, and Drew Barrymore

An update that fixes two vulnerabilities is now available.

Strategies for Improving Linux Security Through Cross-Browser Compatibility Testing
It’s 2024 and Intel silicon is still haunted by data-spilling Spectre

util-linux could be made to expose sensitive information.

Rust rustles up fix for 10/10 critical command injection bug on Windows

* bsc#1167896 * bsc#1206261 * bsc#1215301 Cross-References:

X fixes URL blunder that could enable convincing social media phishing campaigns

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Targus business operations disrupted following cyber attack
Turning the tide on third-party risk
Chrome Enterprise Premium promises extra security – for a fee
Synopsys takes aim at software supply chain risks
Microsoft squashes SmartScreen security bypass bug exploited in the wild
Got an unpatched LG ‘smart’ television? It could be watching you back

Bind could be made to crash if it received specially crafted input.

UK businesses shockingly unaware of how to handle security threats

* bsc#1221926 Cross-References: * CVE-2024-30161

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Parasoft unveils safety testing tool for C and C++ apps

* bsc#1207987 * bsc#1220117 * bsc#1221831 Cross-References:

US insurers use drone photos to deny home insurance policies
Home Depot confirms workers’ data snatched after miscreant dumps it online
Puppies, kittens, data at risk after ‘cyber incident’ at veterinary giant
Change Healthcare faces second ransomware dilemma weeks after ALPHV attack

* bsc#1214223 * bsc#1216980 * bsc#1220512 * bsc#1221237 * bsc#1221468

* bsc#1221749 * bsc#1221815 Cross-References: * CVE-2024-2494

* bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746

* bsc#1027519 * bsc#1219885 * bsc#1221332 * bsc#1221334

* bsc#1205316 * bsc#1209554 * bsc#1218484 * bsc#1220062 * bsc#1220065

* bsc#1220239 * bsc#1220242 * bsc#1220248 Cross-References:

Head of Israeli cyber spy unit exposed … by his own privacy mistake

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets.

Andreas Beck discovered that versions of pam_xauth supplied with Red Hat Linux since version 7.1 would forward authorization information from the root account to unprivileged users.

Two Cross-site scripting vulnerabilities have been found that affect SquirrelMail version 1.2.7 and earlier.

A security hole has been found that does not affect the default configuration of Red Hat Linux, but can affect some custom configurations of Red Hat Linux 7.1 only. The bug is specific to the Linux 2.4 kernel series.

CVE-2024-28085 Skyler Ferrante discovered that the wall(1) utility found in util-linux, a collection of system utilities for Linux, does not

Two issues have been found in libcaca, a colour ASCII art library. Both are related to heap buffer overflow, which might lead to memory corruption.

What can be done to protect open source devs from next xz backdoor drama?
Introducing Confidential Containers Trustee: Attestation Services Solution Overview and Use Cases

Two security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2024-24549

update to 123.0.6312.105 * High CVE-2024-3156: Inappropriate implementation in V8 * High CVE-2024-3158: Use after free in Bookmarks * High CVE-2024-3159: Out of bounds memory access in V8

4.2.3

Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152

Eclipse joins with industry groups to secure open source

* bsc#1212475 * bsc#1221400 Cross-References: * CVE-2023-45288

New tigervnc packages are available for Slackware 15.0 and -current to fix security issues.

Google sues crypto investment app makers over alleged massive “pig butchering” scam

From 2018 to 2023, healthcare data breaches have increased by 93 percent. And ransomware attacks have grown by 278 percent over the same period. Healthcare organizations can’t afford to let preventable breaches slip by. Globally, the average cost of a healthcare data breach has reached $10.93 million. The situation for healthcare organizations may seem bleak. […]

Ransomware attacks are targeting healthcare organizations more frequently. The number of costly cyberattacks on US hospitals has doubled. So how do you prevent these attacks? Keep reading to learn five ways you can strengthen security at your organization. But first, let’s find out what’s at stake. Why healthcare needs better cybersecurity Healthcare organizations are especially […]

US government excoriates Microsoft for ‘avoidable errors’ but keeps paying for its products
Hotel check-in terminal bug spews out access codes for guest rooms

* bsc#1145903 * bsc#1184799 Cross-References: * CVE-2019-15052

* bsc#1216594 * bsc#1216598 Cross-References: * CVE-2023-38469

Academics probe Apple’s privacy settings and get lost and confused
World’s second-largest eyeglass lens-maker blinded by infosec incident

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5654-1

Security Risks of Open-Source Software & Mitigations to Overcome Them
Feds probe massive alleged classified US govt data theft and leak
Google patches Pixel phone zero-days after exploitation by “forensic companies”
Ivanti commits to secure-by-design overhaul after vulnerability nightmare
Ransomware gang did steal residents’ confidential data, UK city council admits
What makes a ransomware attack eight times as costly? Compromised backups
When AI attacks

USN-6710-1 caused some minor regressions in Firefox.

Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152

Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152

https://security-tracker.debian.org/tracker/DSA-5655-1

Nearly 1M medical records feared stolen from City of Hope cancer centers
Smashing Security podcast #366: Money-making bots, and Incognito isn’t private

New xorg-server packages are available for Slackware 15.0 and -current to fix security issues.

Cyberattack hits Omni Hotels systems, taking out bookings, payments, door locks

Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Claudio Bozzato discovered multiple security issues in gtkwave, a file waveform viewer for VCD (Value Change Dump) files, which may result in the execution of arbitrary code if malformed files are opened.

Mark your calendars for April 9, 2024 The second Tuesday of April marks Identity Management Day — a day dedicated to raising awareness about the importance of safeguarding your digital identity. But what exactly is identity management, and why do we need a whole day for it? In a world where our lives are increasingly […]

Security pioneer Ross Anderson dies at 67
Google bakes new cookie strategy that will leave crooks with a bad taste

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Rust memory safety explained

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: