Menu

Latest articles

* bsc#1219296 * bsc#1220211 * bsc#1220828 * bsc#1220832 * bsc#1221302

* bsc#1221302 * bsc#1222882 * bsc#1223514 Cross-References:

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

Kentik for Ansible Automation Platform now certified with Red Hat
LockBit dethroned as leading ransomware gang for first time post-takedown
GitHub Enterprise Server patches 10-outta-10 critical hole
Uncle Sam to inject $50M into auto-patcher for hospital IT

https://security-tracker.debian.org/tracker/DSA-5696-1

https://security-tracker.debian.org/tracker/DSA-5695-1

Zoom adds ‘post-quantum’ encryption for video nattering
Critical Fluent Bit bug affects all major cloud providers, say researchers
Arrests made after North Koreans hired for remote tech jobs at US companies

* bsc#1219296 * bsc#1220211 * bsc#1220828 * bsc#1220832 * bsc#1221302

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1222685

* bsc#1220211 * bsc#1220832 * bsc#1222685 * bsc#1223514

* bsc#1210619 * bsc#1218487 * bsc#1222685 * bsc#1223514

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223514

With ransomware whales becoming so dominant, would-be challengers ask ‘what’s the point?’
Big Tech is not much help when fighting a junta, and FOSS doesn’t ride to the rescue
GitLab unveils GitLab 17, AI for devsecops
OpenSSF sings a Siren song to steer developers away from buggy FOSS
Julian Assange can appeal extradition to the US, London High Court rules
Google takes shots at Microsoft for shoddy security record with enterprise apps
Can I phone a friend? How cops circumvent face recognition bans
Empowering Linux and Open-Source Security with AI: Strategies, Tools and Best Practices
Researchers call out QNAP for dragging its heels on patch development

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

DoJ, ByteDance ask court: Hurry up and rule on TikTok ban already
British Library’s candid ransomware comms driven by ’emotional intelligence’
12 principles for improving devsecops

* bsc#1224277 Cross-References: * CVE-2023-45733 * CVE-2023-45745

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1219296 * bsc#1220211 * bsc#1220828 * bsc#1220832 * bsc#1221302

* bsc#1221302 * bsc#1223514 Cross-References: * CVE-2022-48651

Chinese telco gear may become verboten on German networks
Nissan infosec in the spotlight again after breach affecting more than 50K US employees

An update that fixes one vulnerability is now available.

Security fix for CVE-2024-3727 Automatic update for buildah-1.35.4-1.fc39. Changelog for buildah * Fri May 10 2024 Packit – 1.35.4-1 – Update to 1.35.4 upstream release

This is a security and bug fix release.

This is a security and bug fix release.

Backport fix for CVE-2024-34069.

An attorney says she saw her library reading habits reflected in mobile ads. That’s not supposed to happen
The who, where, and how of APT attacks – Week in security with Tony Anscombe

This week, ESET experts released several research publications that shine the spotlight on a number of notable campaigns and broader developments on the threat landscape

Gawd, after that week, we wonder what’s next for China and the Western world
How two brothers allegedly swiped $25M in a 12-second Ethereum heist

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

new upstream update (126.0)

Aussie cops probe MediSecure’s ‘large-scale ransomware data breach’

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1220211 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1222882

Three cuffed for ‘helping North Koreans’ secure remote IT jobs in America

Two vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service. CVE-2023-50387

Nissan reveals ransomware attack exposed 53,000 workers’ social security numbers
First LockBit, now BreachForums: Are cops winning the war or just a few battles?
Automating fapolicyd with RHEL system roles

* bsc#1180833 * bsc#1183101 * bsc#1183102 * bsc#1183103 * bsc#1183105

* bsc#1222992 * bsc#1223423 * bsc#1223424 * bsc#1223425

new upstream update (126.0)

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

Security fix for CVE-2024-3727

https://security-tracker.debian.org/tracker/DSA-5694-1

https://security-tracker.debian.org/tracker/DSA-5693-1

Crims abusing Microsoft Quick Assist to deploy Black Basta ransomware

https://security-tracker.debian.org/tracker/DSA-5692-1

Several security issues were fixed in the Linux kernel.

EU probes Meta over its provisions for protecting children
BreachForums seized! One of the world’s largest hacking forums is taken down by the FBI… again
Stifling Beijing in cyberspace is now British intelligence’s number-one mission

Several security issues were fixed in .NET.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

NCSC CTO: Broken market must be fixed to usher in new tech
Smashing Security podcast #372: The fake deepfake, and Estate insecurity
FBI takes down BreachForums ransomware website and Telegram channel
Crook brags about US Army and $75B defense biz pwnage
Improving cyber defense with open source SIEM and XDR
ESET APT Activity Report Q4 2023–Q1 2024

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2023 and Q1 2024

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

* bsc#1219559 Cross-References: * CVE-2023-52425

* bsc#1190576 * bsc#1192145 * bsc#1204614 * bsc#1211592 * bsc#1218562

https://security-tracker.debian.org/tracker/DSA-5691-1

https://security-tracker.debian.org/tracker/DSA-5690-1

https://security-tracker.debian.org/tracker/DSA-5689-1

Microsoft fixes a bug abused in QakBot attacks plus a second under exploit
FCC names and shames Royal Tiger AI robocall crew

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

How to talk about climate change – and what motivates people to action: An interview with Katharine Hayhoe

We spoke to climate scientist Katharine Hayhoe about climate change, faith and psychology – and how to channel anxiety about the state of our planet into meaningful action

In it to win it! WeLiveSecurity shortlisted for European Security Blogger Awards

We’re thrilled to announce that WeLiveSecurity has been named a finalist in the Corporates – Best Cybersecurity Vendor Blog category of the European Security Blogger Awards 2024

Cybersec chiefs team up with insurers to say ‘no’ to ransomware bullies
Telegram CEO calls out rival Signal, claiming it has ties to US government
Google, Apple gear to raise tracking tag stalker alarm

* bsc#1222548 Cross-References: * CVE-2024-2511