Menu

Latest articles

TikTok sues America to undo divest-or-die law
Cops finally unmask ‘LockBit kingpin’ after two-month tease
Fortifying Email Security with Infosec Through the SDLC
The truth about KEV: CISA’s vuln deadlines good influence on private-sector patching
Brit security guard biz exposes 1.2M files via unprotected database
Does cloud security have a bad reputation?

* bsc#1223252 Cross-References: * CVE-2024-30171

* bsc#1221984 * bsc#1222302 * bsc#1222453 Cross-References:

* bsc#1027519 * bsc#1221984 * bsc#1222302 * bsc#1222453

* bsc#1216644 * bsc#1219079 * bsc#1219435 Cross-References:

Multiple vulnerabilities have been discovered in libjpeg-turbo, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Xpdf, the worst of which could possibly lead to arbitrary code execution.

Ransomware crooks now SIM swap executives’ kids to pressure their parents
Google, Meta, Spotify break Apple’s device fingerprinting rules – new claim
Fed-run LockBit site back from the dead and vows to really spill the beans on gang
Mastodon delays firm fix for link previews DDoSing sites

As we navigate through 2024, the cyber threat landscape continues to evolve, bringing new challenges for both businesses and individual consumers. The latest OpenText Threat Report provides insight into these changes, offering vital insights that help us prepare and protect ourselves against emerging threats. Here’s what you need to know: The Resilience of Ransomware Ransomware […]

Consultant charged over $1.5M extortion scheme against IT giant
CISA says ‘no more’ to decades-old directory traversal bugs

* bsc#1215947 * bsc#1216853 Cross-References: * CVE-2023-38470

* bsc#1170848 * bsc#1208572 * bsc#1214340 * bsc#1214387 * bsc#1216085

* bsc#1219912 * bsc#1221465 * bsc#1222155 * jsc#MSQA-760 * jsc#PED-7893

* bsc#1008037 * bsc#1008038 * bsc#1010940 * bsc#1019021 * bsc#1038785

* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001

* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001

Germany points finger at Fancy Bear for widespread 2023 hacks, DDoS attacks

https://security-tracker.debian.org/tracker/DSA-5681-1

https://security-tracker.debian.org/tracker/DSA-5680-1

Pay up, or else? – Week in security with Tony Anscombe

Organizations that fall victim to a ransomware attack are often caught between a rock and a hard place, grappling with the dilemma of whether to pay up or not

End-to-end encryption may be the bane of cops, but they can’t close that Pandora’s Box

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to remote code execution.

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to remote code execution.

A vulnerability has been discovered in borgmatic, which can lead to shell injection.

Multiple vulnerabilities have been discovered in Pillow, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in MIT krb5, the worst of which could lead to remote code execution.

A vulnerability has been discovered in Setuptools, which can lead to denial of service.

https://security-tracker.debian.org/tracker/DSA-5679-1

https://security-tracker.debian.org/tracker/DSA-5678-1

https://security-tracker.debian.org/tracker/DSA-5677-1

Dating apps kiss’n’tell all sorts of sensitive personal info
Adding insult to injury: crypto recovery scams

Once your crypto has been stolen, it is extremely difficult to get back – be wary of fake promises to retrieve your funds and learn how to avoid becoming a victim twice over

Multiple vulnerabilities have been found in MediaInfo and MediaInfoLib, the worst of which could allow user-assisted remote code execution.

Multiple vulnerabilities have been discovered in strongSwan, the worst of which could possibly lead to remote code execution.

Multiple vulnerabilities have been discovered in HTMLDOC, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in mujs, the worst of which could lead to remote code execution.

Multiple vulnerabilities have been discovered in MPlayer, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in systemd, the worst of which can lead to a denial of service.

Kaspersky hits back at claims its AI helped Russia develop military drone systems
It may take decade to shore up software supply chain security, says infosec CEO
Beyond the lingo: What does Red Hat Insights and FedRAMP mean for your workload?
Simplify hybrid cloud operations with Red Hat Enterprise Linux 9.4
Mitigating breaches on Red Hat OpenShift with the CrowdStrike Falcon Operator
Understanding Red Hat’s response to the XZ security incident

* bsc#1177529 * bsc#1192145 * bsc#1194869 * bsc#1200465 * bsc#1205316

Europol op shutters 12 scam call centers and cuffs 21 suspected fraudsters
Indonesia sneakily buys spyware, claims Amnesty International
Chinese government website security is often worryingly bad, say Chinese researchers

update to 124.0.6367.118 * High CVE-2024-4331: Use after free in Picture In Picture * High CVE-2024-4368: Use after free in Dawn update to 124.0.6367.91 update to 124.0.6367.78

The 6.8.8 stable kernel update contains a number of important fixes across the tree.

Patch to fix CVE-2024-31031

Update matrix-synapse to v1.105.1 (CVE-2024-31208) Update to v1.105.0

Update matrix-synapse to v1.105.1 (CVE-2024-31208) Update to v1.105.0

Microsoft, Google do a victory lap around passkeys
Florida man gets 6 years behind bars for flogging fake Cisco kit to US military
Patch up – 4 critical bugs in ArubaOS lead to remote code execution
Federal frenzy to patch gaping GitLab account takeover hole
Understanding Microsoft’s Trusted Signing service

Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Think tank: China’s tech giants refine and define Beijing’s propaganda push
REvil ransomware scum sentenced to almost 14 years inside, ordered to pay $16 million

USN-6747-1 caused some minor regressions in Firefox.

A million Australian pubgoers wake up to find personal info listed on leak site

tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039

Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130

tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039

Security update for CVE-2024-27306 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.5 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.4

Dropbox dropped the ball on security, haemorrhaging customer and third-party info
Block accused of mass compliance failures that saw digi-dollars reach terrorists

https://security-tracker.debian.org/tracker/DSA-5676-1

Smashing Security podcast #370: The closed loop conundrum, default passwords, and Baby Reindeer
Infosec biz boss accused of BS’ing the world about his career, anti-crime product, customers
US charges 16 over ‘depraved’ grandparent scams
Qantas app glitch sees boarding passes fly to other accounts
Open source programming language R patches gnarly arbitrary code exec flaw
Cyber-bastard jailed for stealing psychotherapy files, blackmailing patients

Gerbv could be made to crash if it opened a specially crafted input file.

Several issues have been found in qtbase-opensource-src, a collection of several Qt modules/libraries. The issues are related to buffer overflows, infinite loops or application

A bug that could allow an attacker with access to the machine to potentially access data in a temporary directory created by the Guava. (CVE-2020-8908) Predictable temporary files and directories used in FileBackedOutputStream. (CVE-2023-2976)

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. (CVE-2024-26458) Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. (CVE-2024-26461)

This release is a security release and addresses multiple issues: [Low] OutOfBound Read in zgfx_decompress_segment. [Moderate] Integer overflow & OutOfBound Write in clear_decompress_residual_data. [Low] integer underflow in nsc_rle_decode.

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. (CVE-2023-50471) cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. (CVE-2023-50472)

UnitedHealth CEO: ‘Decision to pay ransom was mine’
NSA guy who tried and failed to spy for Russia gets 262 months in the slammer
European Commission starts formal probe of Meta over election misinformation

* bsc#1222518 Cross-References: * CVE-2024-31948

JSON5 could allow unintended access to network services or have other unspecified impact.

Multiple problems were discovered in Org-mode, a GNU Emacs major mode for keeping notes, authoring documents, and maintaining to-do lists. CVE-2024-30203 & CVE-2024-30204

Anope could be made to bypass authentication checks for suspended accounts.

Apple’s ‘incredibly private’ Safari is not so private in Europe

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: