Menu

Category Archives: Security

Articles about security

Cyber-insurance and vulnerability scanning – Week in security with Tony Anscombe

Here’s how the results of vulnerability scans factor into decisions on cyber-insurance and how human intelligence comes into play in the assessment of such digital signals

All eyes on AI | Unlocked 403: A cybersecurity podcast

Artificial intelligence is on everybody’s lips these days, but there are also many misconceptions about what AI actually is and isn’t. We unpack the basics and examine AI’s broader implications.

How to weaponize LLMs to auto-hijack websites
Google open sources file-identifying Magika AI for malware hunters and others

Update to 1.6.5 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Update to 2.11.5

Update to 1.6.5 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Update to 1.7.2 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Rebase to version 2.6.0

Update to 2.28.7 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7 Security Advisories: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-

Zeus, IcedID malware kingpin faces 40 years in slammer
Cutting kids off from the dark web – the solution can only ever be social
Quest Diagnostics pays $5M after mixing patient medical data with hazardous waste

Several security issues were fixed in the Linux kernel.

Feds dismantle Russian GRU botnet built on 1,000-plus home, small biz routers

* bsc#1218429 Cross-References: * CVE-2023-6879

* bsc#1218690 * bsc#1218810 * bsc#1219243 Cross-References:

* bsc#1219113 * bsc#1219604 Cross-References: * CVE-2014-1745

* bsc#1219679 Cross-References: * CVE-2024-0985

https://security-tracker.debian.org/tracker/DSA-5624-1

https://security-tracker.debian.org/tracker/DSA-5623-1

https://security-tracker.debian.org/tracker/DSA-5622-1

Pentagon launches nuke-spotting satellites amid Russian space bomb rumors

Did you know that more than nine million Americans have their identity stolen each year? Your data is stored across countless databases for various purposes, making it a prime target for criminals. With access to your personal information, bad actors can drain your bank account and damage your credit—or worse. But that doesn’t mean you […]

The updated packages fix security vulnerabilities: Parsing large DNS messages may cause excessive CPU load. (CVE-2023-4408) Querying RFC 1918 reverse zones may cause an assertion failure when “nxdomain-redirect” is enabled. (CVE-2023-5517) Enabling both DNS64 and serve-stale may cause an assertion failure

Mitigating AI security risks
Rhysida ransomware cracked! Free decryption tool released
Zoom stomps critical privilege escalation bug plus 6 other flaws
Cybercriminals are stealing Face ID scans to break into mobile banking accounts

* bsc#1108281 * bsc#1193285 * bsc#1215275 * bsc#1216702 * bsc#1217987

Manage smartcards with new p11-kit subcommands
North Korea successfully hacks email of South Korean President’s aide, gains access to sensitive information
Miscreants turn to ad tech to measure malware metrics
European Court of Human Rights declares backdoored encryption is illegal

Several security issues were fixed in UltraJSON.

Several security issues were fixed in the Linux kernel.

North Korea running malware-laden gambling websites as-a-service

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in EDK II.

update to 1.26.2

OpenAI shuts down China, Russia, Iran, N Korea accounts caught doing naughty things
Smashing Security podcast #359: Declaring war on ransomware gangs, mobile muddles, and AI religion
China’s Volt Typhoon spies broke into emergency network of ‘large’ US city
US Air Force’s new cyber, IT skill recruitment plan: Bring back warrant officer ranks
See me speak at webinar about data security for financial services
Prudential Financial finds cybercrims lurking inside its IT systems
Romanian hospital ransomware crisis attributed to third-party breach
Southern Water cyberattack expected to hit hundreds of thousands of customers
Bumblebee malware wakes from hibernation, forgets what year it is, attacks with macros

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service. For the oldstable distribution (bullseye), these problems have been fixed

Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted DNSSEC answers could lead unbound down a very CPU intensive and time costly DNSSEC (CVE-2023-50387) or NSEC3 hash (CVE-2023-50868) validation path,

UltraJSON could be made to crash if it received specially crafted input.

Australian Tax Office probed 150 staff over social media refund scam
Crims found and exploited these two Microsoft bugs before Redmond fixed ’em

https://security-tracker.debian.org/tracker/DSA-5620-1

https://security-tracker.debian.org/tracker/DSA-5621-1

Just one bad packet can bring down a vulnerable DNS server thanks to DNSSEC
QNAP vulnerability disclosure ends up an utter shambles
ALPHV blackmails Canadian pipeline after ‘stealing 190GB of vital info’

In the digital age, the quest for love has moved online, but so have the fraudsters, with romance scams reaching record highs. These scams don’t just harm individuals financially and emotionally; they can also pose significant risks to businesses. Let’s explore how these scams work, their impact, and how both businesses and consumers can protect […]

Several security issues were fixed in WebKitGTK.

Glance_store could be made to expose sensitive information.

Crooks hook hundreds of exec accounts after phishing in Azure C-suite pond

Several security issues were fixed in OpenSSL.

* bsc#1217654 * bsc#1219131 Cross-References: * CVE-2023-50269

Meta says risk of account theft after phone number recycling isn’t its problem to solve
Infosys subsidiary named as source of Bank of America data leak
Korean eggheads crack Rhysida ransomware and release free decryptor tool

Update to 1.0.5

20+ hospitals in Romania hit hard by ransomware attack on IT service provider

* bsc#1218174 Affected Products: * Containers Module 15-SP5 * openSUSE Leap 15.5

Dutch insurers demand nudes from breast cancer patients despite ban
FCC gets tough: Telcos must now tell you when your personal info is stolen
Jet engine dealer to major airlines discloses ‘unauthorized activity’
“Smart” helmet flaw exposes location tracking and privacy risks
Europe’s largest caravan club admits wide array of personal data potentially accessed
Deploying Red Hat OpenShift Dedicated clusters on Shielded Virtual Machines
Mon Dieu! Nearly half the French population have data nabbed in massive breach

Update to the latest stable version: Features Implement a new plugin manager from scratch to replace Yapsy, which does not work on Python 3.12 due to Python 3.12 carelessly removing parts of the standard library (Issue #3719)

Update to 121.0.6167.160 High CVE-2024-1284: Use after free in Mojo High CVE-2024-1283: Heap buffer overflow in Skia

Apply fix for CVE-2023-28531

Update to the latest stable version: Features Implement a new plugin manager from scratch to replace Yapsy, which does not work on Python 3.12 due to Python 3.12 carelessly removing parts of the standard library (Issue #3719)

Ransomware payments hit a record high in 2023 – Week in security with Tony Anscombe

Called a “watershed year for ransomware”, 2023 marked a reversal from the decline in ransomware payments observed in the previous year

Fix webkit_web_context_allow_tls_certificate_for_host to handle IPv6 URIs produced by SoupURI. Ignore stops with offset zero before last one when rendering gradients with cairo. Write bwrapinfo.json to disk for xdg-desktop-portal.

New version 4.0.12. Includes fixes for CVE-2023-5371, CVE-2023-6174, CVE-2023-6175, CVE-2024-0208.

Security fix for CVE-2024-21626

The updated packages fix security vulnerabilities: Logic bug in text extractor led to invalid memory access. (CVE-2022-30524) Integer overflow in rasterizer. (CVE-2022-30775) PDF object loop in Catalog::countPageTree. (CVE-2022-33108)

Meet VexTrio, a network of 70K hijacked websites crooks use to sling malware, fraud

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Ivanti discloses fifth vulnerability, doesn’t credit researchers who found it

https://security-tracker.debian.org/tracker/DSA-5618-1

OpenText is committed to providing you with the latest intelligence and tips to safeguard your digital life, especially during high-risk periods like tax season. Our threat analysts are constantly monitor the ebb and flow of various threats. One trend that has recently caught our attention is the notable spike in malware-infected cracked software, particularly as […]