Menu

Latest articles

Cybersec chiefs team up with insurers to say ‘no’ to ransomware bullies
Telegram CEO calls out rival Signal, claiming it has ties to US government
Google, Apple gear to raise tracking tag stalker alarm

* bsc#1222548 Cross-References: * CVE-2024-2511

* bsc#1222548 Cross-References: * CVE-2024-2511

* bsc#1223690 Cross-References: * CVE-2024-29040

* bsc#1223687 * bsc#1223689 Cross-References: * CVE-2024-29038

Fraudulent security certificates could allow access controls to be bypassed.

Getting started with Red Hat Insights and FedRAMP
Black Basta ransomware group’s techniques evolve, as FBI issues new warning in wake of hospital attack

This release fixes various issues in shim bootloader and updates it to a supported version. Older versions of the shim may eventually be blocked by Secure Boot, so it is strongly advised for Secure Boot enabled systems to upgrade to this newer version to keep the system bootable.

Visualize your critical cyber risks
NHS Digital hints at exploit sightings of Arcserve UDP vulnerabilities
7 application security startups at RSAC 2024
‘Cyberattack’ shutters Christie’s website days before $840M art mega-auction
Uncle Sam urges action after Black Basta ransomware infects Ascension
Prison for cybersecurity expert selling private videos from inside 400,000 homes
AI red-teaming tools helped X-Force break into a major tech manufacturer ‘in 8 hours’

* bsc#1094832 * bsc#1200551 Cross-References: * CVE-2018-11490

* bsc#1218862 * bsc#1218865 Cross-References: * CVE-2024-0553

* bsc#1218571 * bsc#1219238 Cross-References: * CVE-2023-7207

Europol confirms incident following alleged auction of staff data

An update that fixes four vulnerabilities is now available.

Facing down the triple threat
You want us to think of the children? Couldn’t agree more

An update that fixes 35 vulnerabilities is now available.

ASEAN organizations dealing with growing cyber menace
Encrypted mail service Proton hands suspect’s personal info to cops again
Ransomware negotiator weighs in on the extortion payment debate with El Reg

It was discovered that missing input sanitising in the Atril document viewer could result in writing arbitrary files in the users home directory if a malformed epub document is opened.

Multiple vulnerabilities have been discovered in PoDoFo, the worst of which could lead to code execution.

Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.

A vulnerability has been discovered in Kubelet, which can lead to privilege escalation.

A vulnerability has been discovered in Rebar3, which can lead to command injection.

update to 124.0.6367.201 * High CVE-2024-4671: Use after free in Visuals

https://security-tracker.debian.org/tracker/DSA-5688-1

Critical infrastructure security will stay poor unless everyone pulls together
It’s a wrap! RSA Conference 2024 highlights – Week in security with Tony Anscombe

More than 40,000 security experts descended on San Francisco this week. Let’s now look back on some of the event’s highlights – including the CISA-led ‘Secure by Design’ pledge also signed by ESET.

RSA Conference 2024: AI hype overload

Can AI effortlessly thwart all sorts of cyberattacks? Let’s cut through the hyperbole surrounding the tech and look at its actual strengths and limitations.

update to 124.0.6367.155 High CVE-2024-4558: Use after free in ANGLE High CVE-2024-4559: Heap buffer overflow in WebAudio

Security fix for CVE-2023-45681 / CVE-2023-47212

Security fix for CVE-2023-45681 / CVE-2023-47212

update to 124.0.6367.155 High CVE-2024-4558: Use after free in ANGLE High CVE-2024-4559: Heap buffer overflow in WebAudio

https://www.mediawiki.org/wiki/Release_notes/1.41

Fix for CVE-2024-2397

Iran most likely to launch destructive cyber-attack against US – ex-Air Force intel analyst
Cybercriminals hit jackpot as 500k+ Ohio Lottery lovers lose out on their personal data
Microsoft’s Brad Smith summoned by Homeland Security committee over ‘cascade’ of infosec failures
GhostStripe attack haunts self-driving cars by making them ignore road signs
Boeing refused to pay $200 million LockBit ransomware demand
‘Four horsemen of cyber’ look back on 2008 DoD IT breach that led to US Cyber Command

* bsc#1222849 Cross-References: * CVE-2024-32487

* bsc#1216644 * bsc#1219079 * bsc#1219435 * bsc#1220828

* bsc#1218424 * bsc#1224017 * bsc#1224018 Cross-References:

* bsc#1212475 * bsc#1224017 Cross-References: * CVE-2024-24787

* bsc#1223852 Cross-References: * CVE-2023-52722

* bsc#1223979 Cross-References: * CVE-2024-34069

https://security-tracker.debian.org/tracker/DSA-5687-1

RHEL 9.4 Unveiled: Elevating Enterprise Security with Cutting-Edge Features
$10 million reward offer for apprehension of unmasked LockBit ransomware leader
Ex-White House election threat hunter weighs in on what to expect in November

https://security-tracker.debian.org/tracker/DSA-5685-1

US faith-based healthcare org Ascension says ‘cybersecurity event’ disrupted clinical ops
Dell customer order database of ’49M records’ stolen, now up for sale on dark web
Global attackers targeting US critical infrastructure should be ‘wake-up call’
GitHub takes aim at software supply chain security

Congratulations, graduates! As you gear up for life after high school or college, you’re stepping into a world of exciting firsts—new jobs, new homes, and new adventures. There’s one first you might not have considered: your first identity protection plan. Why is identity protection important? Let’s dive in. Why protecting your identity matters Imagine this: […]

FBI warns US retailers that hackers are targeting their gift card systems

* bsc#1223100 Cross-References: * CVE-2023-3758

* bsc#1223852 Cross-References: * CVE-2023-52722

* bsc#1216853 Cross-References: * CVE-2023-38472

* bsc#1222492 Cross-References: * CVE-2024-21506

* bsc#1223979 Cross-References: * CVE-2024-34069

* bsc#1218424 * bsc#1224017 * bsc#1224018 Cross-References:

Unleashing the potential of Intel® IPU with Red Hat OpenShift
Cancer patients’ sensitive information accessed by “unidentified parties” after being left exposed by screening lab for years

https://security-tracker.debian.org/tracker/DSA-5686-1

https://security-tracker.debian.org/tracker/DSA-5682-2

https://security-tracker.debian.org/tracker/DSA-5684-1

What do Europeans, Americans and Australians have in common? Scammed $50M by fake e-stores
Smashing Security podcast #371: Unmasking LockBitsupp, company extortion, and a Tinder fraudster
Undersea cables must have high-priority protection before they become top targets

https://security-tracker.debian.org/tracker/DSA-5682-1

How to inspire the next generation of scientists | Unlocked 403: Cybersecurity podcast

As Starmus Earth draws near, we caught up with Dr. Garik Israelian to celebrate the fusion of science and creativity and venture where imagination flourishes and groundbreaking ideas take flight

CISA boss: Secure code is the ‘only way to make ransomware a shocking anomaly’
One year on, universities org admits MOVEit attack hit data of 800K people

* bsc#1189495 * bsc#1211301 * bsc#1219559 * bsc#1219666 * bsc#1221260

* bsc#1189495 * bsc#1191175 * bsc#1218686 Cross-References:

UK opens investigation of MoD payroll contractor after confirming attack

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in root privilege escalation.

A vulnerability has been discovered in Epiphany, which can lead to a buffer overflow.

Multiple vulnerabilities have been discovered in qtsvg, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in MariaDB, the worst fo which can lead to arbitrary execution of code.

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
From infosec to skunks, RSA Conference SVP spills the tea
UnitedHealth’s ‘egregious negligence’ led to Change Healthcare ransomware infection

https://security-tracker.debian.org/tracker/DSA-5683-1

America’s War on Drugs and Crime will be AI powered, says Homeland Security boss
Watch out for rogue DHCP servers decloaking your VPN connections
CISA’s early-warning system helped critical orgs close 852 ransomware holes