Menu

Latest articles

What software supply chain security really means
Generative AI and coding: Time to rethink software development
Security biz Verkada to pay $3M penalty under deal that also enforces infosec upgrade
White House seizes 32 domains, issues criminal charges in massive election-meddling crackdown
North Korean scammers plan wave of stealth attacks on crypto companies, FBI warns

https://security-tracker.debian.org/tracker/DSA-5766-1

Smashing Security podcast #383: The Godfather club, and AirTags to the rescue
Palo Alto takes a big $500M bite out of IBM QRadar
Copilot for Microsoft 365 might boost productivity if you survive the compliance minefield
Planned Parenthood confirms cyber-attack as RansomHub threatens to leak data
Angular 19 to make standalone the default for components
InfluxData makes performance, storage improvements to InfluxDB 3.0
Cicada ransomware may be a BlackCat/ALPHV rebrand and upgrade

* bsc#1229823 * bsc#1229824 Cross-References: * CVE-2024-45230

* bsc#1228046 * bsc#1228047 * bsc#1228048 * bsc#1228050 * bsc#1228051

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Several security issues were fixed in Twisted.

PostgreSQL tutorial: Get started with PostgreSQL 16
What is HTTP/3? The next-generation web protocol
Qt moves forward on toolkit for .NET-C++ interoperability

* bsc#1176492 Cross-References: * CVE-2014-10401 * CVE-2014-10402

The open source community strikes back

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Telegram apologizes to South Korea and takes down smutty deepfakes
Ex-senior New York State staffer charged in cash-for-favors scandal with China

https://security-tracker.debian.org/tracker/DSA-5765-1

White House thinks it’s time to fix the insecure glue of the internet: Yup, BGP
UK trio pleads guilty to operating $10M MFA bypass biz
The AI Fix #14: There are two Rs in “strawberry”, and an AI makes unsmellable smells
Spamouflage trolls pretend to be American patriots on X, TikTok ahead of US presidential election
Data watchdog fines Clearview AI $33M for ‘illegal’ data collection

It was discovered that there was a series of integer overflow vulnerabilities in LibTomMath, a multiple-precision mathematics library.

A vulnerability was discovered in Nokogiri, an open source XML and HTML library for Ruby. An inefficient regular expression was susceptible to excessive backtracking when attempting to detect encoding in HTML documents. This could lead to denial-of-service.

Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2019-1387

Transport for London confirms cyberattack, assures us all is well
Application builders get ready

* bsc#1224044 Cross-References: * CVE-2024-34397

Path traversal that allowed TZInfo::Timezone.get to load arbitrary files has been fixed in ruby-tzinfo, a Ruby library for working with time zone information.

Fix buffer overrun when giving an offset to Session:receive

https://security-tracker.debian.org/tracker/DSA-5764-1

Telegram CEO was ‘too free’ on content moderation, says Russian minister
Exploring the OpenShift confidential containers solution
The future of Kubernetes and cloud infrastructure
Elastic’s return to open source
IT worker charged over $750,000 cyber extortion plot against former employer
Getting map data right and keeping it right

Several security issues were fixed in Dovecot.

Novel attack on Windows spotted in phishing campaign run from and targeting China

patchlevel 703 Security fixes for CVE-2024-43374, CVE-2024-43802

Update to upstream 2.1-44. 20240813 Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision 0x5003605 up to 0x5003707; Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002802 up to 0x7002904;

New libpcap packages are available for Slackware 15.0 and -current to fix security issues.

Check your IP cameras: There’s a new Mirai botnet on the rise
Use cases and ecosystem for OpenShift confidential containers
Simplify identity management with Red Hat IdM

Update to upstream 2.1-44. 20240813 Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision 0x5003605 up to 0x5003707; Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002802 up to 0x7002904;

Security fix for CVE-2024-8088

error handling in x86 IOMMU identity mapping [XSA-460, CVE-2024-31145] PCI device pass-through with shared resources [XSA-461, CVE-2024-31146]

error handling in x86 IOMMU identity mapping [XSA-460, CVE-2024-31145] PCI device pass-through with shared resources [XSA-461, CVE-2024-31146]

RansomHub hits 210 victims in just 6 months
Green Berets storm building after hacking its Wi-Fi

https://security-tracker.debian.org/tracker/DSA-5761-1

Microsoft .NET Aspire boosts integrations, testing

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-4558

An update that fixes four vulnerabilities is now available.

Stealing cash using NFC relay – Week in Security with Tony Anscombe

The discovery of the NGate malware by ESET Research is another example of how sophisticated Android threats have become

Analysis of two arbitrary code execution vulnerabilities affecting WPS Office

Demystifying CVE-2024-7262 and CVE-2024-7263

Tired of airport security queues? SQL inject yourself into the cockpit, claim researchers

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

* bsc#1227052 Cross-References: * CVE-2024-6104

An update that fixes four vulnerabilities is now available.

Wider horizons: New tools (and languages) for Python developers
The paradox of chaos engineering
Quest Software updates erwin data modeling and data intelligence tools
Iran hunts down double agents with fake recruiting sites, Mandiant reckons

Security fix for CVE-2024-8088

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

https://security-tracker.debian.org/tracker/DSA-5763-1

US indicts duo over alleged Swatting spree that targeted elected officials
TypeScript 5.6 enters release candidate stage
What a coincidence. Spyware makers, Russia’s Cozy Bear seem to share same exploits
Feds claim sinister sysadmin locked up thousands of Windows workstations, demanded ransom
Rock Chrome hard enough and get paid half a million
$2.5 million reward offered for hacker linked to notorious Angler Exploit Kit

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Brain Cipher claims attack on Olympic venue, promises 300 GB data leak
‘Big-game hunting’ – Ransomware gangs are focusing on more lucrative attacks
Crypto scammers who hacked McDonald’s Instagram account say they stole $700,000
Simpler web APIs in .NET with Sisk
Static classes and inner classes in Java
Microsoft .NET Community Toolkit adds .NET 8, NativeAOT support

* bsc#1227353 Cross-References: * CVE-2024-39884

Best practices for handling exceptions in C#
CrowdStrike’s meltdown didn’t dent its market dominance … yet

Security fix for CVE-2024-32487 – less with LESSOPEN mishandles n in paths

https://security-tracker.debian.org/tracker/DSA-5760-1

Several security issues were fixed in the Linux kernel.

Microsoft hosts a security summit but no press, public allowed