Menu

Category Archives: Security

Articles about security

Add implicit rejection in PKCS#1 v1.5 in OpenSSL.

Whizkids jimmy OpenAI, Google’s closed models
March Patch Tuesday sees Hyper-V join the guest-host escape club

https://security-tracker.debian.org/tracker/DSA-5639-1

Meta sues ex infra VP for allegedly stealing top-secret datacenter blueprints
Biden’s budget proposal boosts CISA funding to $3B
JetBrains is still mad at Rapid7 for the ransomware attacks on its customers

Rack could be made do denial of service if it received a specially crafted header.

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

Several security issues were fixed in Open vSwitch.

UK council yanks IT systems and phone lines offline following cyber ambush
French government sites disrupted by très grande DDoS
White House and lawmakers increase pressure on UnitedHealth to ease providers’ pain

An update that fixes one vulnerability is now available.

Kremlin accuses America of plotting cyberattack on Russian voting systems
British Library pushes the cloud button, says legacy IT estate cause of hefty rebuild

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Two vulnerabilities were discovered in tiff, Tag Image File Format library. CVE-2023-3576

* bsc#1027519 * bsc#1218851 * bsc#1219080 * bsc#1219885

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

How do you lot feel about Pay or say OK to ads model, asks ICO
Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability
APT attacks taking aim at Tibetans – Week in security with Tony Anscombe

Evasive Panda has been spotted targeting Tibetans in several countries and territories with payloads that included a previously undocumented backdoor ESET has named Nightdoor

It was discovered that the uv_getaddrinfo() function in libuv, an asynchronous event notification library, incorrectly truncated certain hostnames, which may result in bypass of security measures on internal APIs or SSRF attacks.

2267205 – CVE-2024-24246 qpdf – Heap Buffer Overflow vulnerability in qpdf [fedora-all]

backport fix for PEAP client (CVE-2023-52160)

2267205 – CVE-2024-24246 qpdf – Heap Buffer Overflow vulnerability in qpdf [fedora-all]

Update to latest version Security fix for CVE-2023-39325

https://security-tracker.debian.org/tracker/DSA-5638-1

Incorrect handling of extension attributes in PAX archives has been fixed in the GNU tar archiving utility. For Debian 10 buster, this problem has been fixed in version

Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache. Due to programming errors in Squid’s HTTP request parsing, remote attackers may be able to execute a denial of service attack by sending large X-Forwarded-For header or trigger a stack buffer overflow while

Confidential Containers for Financial Services on Public Cloud

upstream security release 122.0.6261.111 – High CVE-2024-2173: Out of bounds memory access in V8 – High CVE-2024-2174: Inappropriate implementation in V8 – High CVE-2024-2176: Use after free in FedCM

Cybercrime crew Magnet Goblin bursts onto the scene exploiting Ivanti holes

* bsc#1218571 * bsc#1219238 Cross-References: * CVE-2023-7207

* bsc#1218571 * bsc#1219238 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5

Top 10 scams targeting seniors – and how to keep your money safe

The internet can be a wonderful place. But it’s also awash with fraudsters targeting people who are susceptible to fraud.

Microsoft confirms Russian spies stole source code, accessed internal systems
Change Healthcare registers pulse after crippling ransomware attack

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

Swiss cheese security? Play ransomware gang milks government of 65,000 files
Font security ‘still a Helvetica of a problem’ says Australian graphics outfit Canva
Securing open source software: Whose job is it, anyway?

https://security-tracker.debian.org/tracker/DSA-5637-1

We’re not Meta support: State AGs tell Zuck to fix rampant account takeover problem
Possible China link to Change Healthcare ransomware attack
$12.5 billion lost to cybercrime, amid tidal wave of crypto investment fraud
JetBrains TeamCity under attack by ransomware thugs after disclosure mess
Belgian ale legend Duvel’s brewery borked as ransomware halts production

* bsc#1217213 Cross-References: * CVE-2023-44446

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1200528 Cross-References: * CVE-2022-1996

* bsc#1212475 * bsc#1219988 * bsc#1220999 * bsc#1221000 * bsc#1221001

VMware urges emergency action to blunt hypervisor flaws
Here’s something else AI can do: expose bad infosec to give cyber-crims a toehold in your organization
US lawmakers want ByteDance to divest TikTok or face a ban
Lawsuit claims gift card fraud is the gift that keeps on giving, to Google
Chinese chap charged with stealing Google’s AI datacenter secrets
Smashing Security podcast #362: Ransomware fraud, pharmacy chaos, and suicide
FBI: Critical infrastructure suffers spike in ransomware attacks
Irresistible: Hooks, habits and why you can’t put down your phone

Struggle to part ways with your tech? You’re not alone. Here’s why your devices are your vices.

Apple’s trademark tight lips extend to new iPhone, iPad zero-days
Ukraine claims it hacked Russian Ministry of Defence, stole secrets and encryption ciphers
Capita says 2023 cyberattack costs a factor as it reports staggering £100M+ loss

* bsc#1034675 * bsc#1172961 * bsc#1182748 * bsc#1203672 * bsc#1203673

Whoops! ACEMAGIC ships mini PCs with free bonus pre-installed malware
Chip lobby group SEMI to EU: Export restrictions should only be used in self-defense

USN-6649-1 caused some minor regressions in Firefox.

Japan orders local giants LINE and NAVER to disentangle their tech stacks
Uncle Sam intervenes as Change Healthcare ransomware fiasco creates mayhem

https://security-tracker.debian.org/tracker/DSA-5636-1

Improper Domain Lookup in uv_getaddrinfo() has been fixed in libuv, an asynchronous event notification library. For Debian 10 buster, this problem has been fixed in version

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix a security issue.

* bsc#1210638 Cross-References: * CVE-2023-27043

* bsc#1220644 Cross-References: * CVE-2024-1597

https://security-tracker.debian.org/tracker/DSA-5635-1

Cloudflare announces Firewall for AI
Fidelity customers’ financial info feared stolen in suspected ransomware attack
US accuses Army vet cyber-Casanova of sharing Russia-Ukraine war secrets
IP address X-posure now a feature on Musk’s social media platform
Enhancing Security in Linux Web Applications with Advanced Secure Coding Practices
Rapid7 throws JetBrains under the bus for ‘uncoordinated vulnerability disclosure’

* bsc#1219911 Cross-References: * CVE-2024-24814

* bsc#1219911 Cross-References: * CVE-2024-24814

* bsc#1018158 * bsc#1178386 * bsc#1179694 * bsc#1179721 * bsc#1181505

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Spam crusade lands charity in hot water with data watchdog
Cloudflare wants to put a firewall in front of your LLM
American Express admits card data exposed and blames third party