Menu

Latest articles

IT worker sued over ‘vengeful’ cyber harassment of policeman who issued a jaywalking ticket

* bsc#1189495 * bsc#1191175 * bsc#1218686 Cross-References:

IBM spin-off Kyndryl accused of discriminating on basis of age, race, disability
Pretty much all the headaches at MSPs stem from cybersecurity
Indian stock exchange finally encrypting all messages to traders

Update to 115.11.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/ https://www.thunderbird.net/en-US/thunderbird/115.11.0/releasenotes/ https://www.thunderbird.net/en-US/thunderbird/115.10.0/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-20/

Update to requests-2.32.0, fixes CVE-2024-35195.

update to 125.0.6422.112 High CVE-2024-5274: Type Confusion in V8

Update to requests-2.32.0, fixes CVE-2024-35195.

Chinese national cuffed on charges of running ‘likely the world’s largest botnet ever’
Miscreants claim they’ve snatched 560M people’s info from Ticketmaster
Multi-day DDoS storm batters Internet Archive
Going going gone! Ransomware attack grabs Christie’s client data for a steal
North Korea building cash reserves using ransomware, video games

* bsc#1221465 * bsc#1222155 * bsc#1222277 * bsc#1222731 * jsc#MSQA-775

* bsc#1221465 * bsc#1222155 * bsc#1222277 * bsc#1222731 * jsc#MSQA-775

* bsc#1223858 * bsc#1224169 * bsc#1224340 Affected Products:

Jinja2 could allow cross-site scripting (XSS) attacks.

* bsc#1223110 Cross-References: * CVE-2024-32462

* bsc#1224168 * bsc#1224170 * bsc#1224171 * bsc#1224172 * bsc#1224173

https://security-tracker.debian.org/tracker/DSA-5700-1

2.8M US folks learn their personal info was swiped months ago in Sav-Rx IT heist
BreachForums returns just weeks after FBI-led takedown
SpiderOak One customers threaten to jump ship following datacenter upgrade

Unbound could be made to take part in a denial of service attack.

amavisd-new could be made to bypass security measures.

LibreOffice could be made to run programs when clicking a graphic.

Several security issues were fixed in WebKitGTK.

Auction house Christie’s confirms criminals stole some client data
What Can Linux Admins Learn from Microsoft’s Zero-Trust DNS Initiative?
Take two APIs and call me in the morning: How healthcare research can cure cyber crime

Netatalk could allow arbitrary code execution if it receives a specially crafted input.

The chromium-browser-stable package has been updated to the 125.0.6422.112 release. It includes 1 security fix. * High CVE-2024-5274: Type Confusion in V8. Reported by Cl©ment Lecigne of Google’s Threat Analysis Group and Brendon Tiszka of Chrome Security on 2024-05-20

The CIA Triad in Open Source Security for Linux Environments: A Primer for Professionals
How’s Uncle Sam getting on with Biden’s AI exec order? Pretty good, we’re told

An update that fixes two vulnerabilities is now available.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Bayer and 12 other major drug companies caught up in Cencora data loss

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

Mandatory reporting for ransomware attacks? – Week in security with Tony Anscombe

As the UK mulls new rules for ransomware disclosure, what would be the wider implications of such a move, how would cyber-insurance come into play, and how might cybercriminals respond?

Introducing Nimfilt: A reverse-engineering tool for Nim-compiled binaries

Available as both an IDA plugin and a Python script, Nimfilt helps to reverse engineer binaries compiled with the Nim programming language compiler by demangling package and function names, and applying structs to strings

An update that fixes three vulnerabilities is now available.

Fossil was broken by fixes of CVE-2024-24795 for apache2 package, and needed an update. As part of the security fix, the Apache webserver

Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in HTTP response splitting, denial of service, or authorization bypass.

crosswords 0.3.13

crosswords 0.3.13

This is the May 2024 security update for .NET 7. This is the last upstream release of .NET 7. After this update, .NET 7 reaches its End of Life (EOL). Full release notes: https://github.com/dotnet/core/blob/main/release- notes/7.0/7.0.19/7.0.19.md

Man behind deepfake Biden robocall indicted on felony charges, faces $6M fine
Best Buy and Geek Squad were most impersonated orgs by scammers in 2023
Suspected supply chain attack backdoors courtroom recording software

GNOME Remote Desktop would allow unintended access to sensitive information or remote desktop connections.

What happens when AI goes rogue (and how to stop it)

As AI gets closer to the ability to cause physical harm and impact the real world, “it’s complicated” is no longer a satisfying response

Almost all citizens of city of Eindhoven have their personal data exposed

* bsc#1219386 Cross-References: * CVE-2023-5992

7.6.7.2

update to 125.0.6422.76 * High CVE-2024-5157: Use after free in Scheduling * High CVE-2024-5158: Type Confusion in V8 * High CVE-2024-5159: Heap buffer overflow in ANGLE * High CVE-2024-5160: Heap buffer overflow in Dawn

Update to 115.11.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/ https://www.thunderbird.net/en-US/thunderbird/115.11.0/releasenotes/

Three-year-old Apache Flink flaw under active attack

https://security-tracker.debian.org/tracker/DSA-5699-1

https://security-tracker.debian.org/tracker/DSA-5698-1

https://security-tracker.debian.org/tracker/DSA-5697-1

Here’s yet more ransomware using BitLocker against Microsoft’s own users

* bsc#1224277 Cross-References: * CVE-2023-45733 * CVE-2023-45745

Casino cyberattacks put a bullseye on Scattered Spider – and the FBI is closing in
Google guru roasts useless phishing tests, calls for fire drill-style overhaul
UK Government ponders major changes to ransomware response – what you need to know
Veeam says critical flaw can’t be abused to trash backups

Several security issues were fixed in klibc.

70% of CISOs worry their org is at risk of a material cyber attack
10 years in prison for $4.5 million BEC scammer who bought Ferrari to launder money

* bsc#1223603 Cross-References: * CVE-2024-4340

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

Several security issues were fixed in the Linux kernel.

An update that fixes four vulnerabilities is now available.

Add implicit rejection in PKCS#1 v1.5 in OpenSSL.

UK data watchdog wants six figures from N Ireland cops after 2023 data leak
How Apple Wi-Fi Positioning System can be abused to track people around the globe
Would you buy Pegasus spyware from this scammer?
‘China-aligned’ spyware slingers operating since 2018 unmasked at last
Lawmakers advance bill to tighten White House grip on AI model exports
Smashing Security podcast #373: iPhone undeleted photos, and stealing Scarlett Johansson’s voice
Go after UnitedHealth, not us, 100+ medical groups urge Uncle Sam
Canada’s London Drugs confirms ransomware attack after LockBit demands $25M
NYSE parent gets $10M wrist tap for failing to report 2021 systems break-in
Laundering cash from healthcare, romance scams lands US man in prison for a decade
Confused by the SEC’s breach reporting rules? Read this
Stopping ransomware in multicloud environments
23-year-old alleged founder of dark web Incognito Market arrested after FBI tracks cryptocurrency payments

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1222685

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1220211 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223514