Menu

Latest articles

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

AT&T, Verizon, Sprint, T-Mobile US fined $200M for selling off people’s location info
Google blocked 2.3M apps from Play Store last year for breaking the G law
Why space exploration is important for Earth and its future: Q&A with David Eicher

We caught up with Astronomy magazine editor-in-chief David Eicher to talk about key challenges facing our planet, the benefits of space exploration, and the possibility of life beyond Earth

London Drugs closes all of its pharmacies following ‘cybersecurity incident’

Multiple problems were discovered in GNU Emacs, the extensible, customisable, self-documenting display editor. CVE-2024-30203 & CVE-2024-30204

Pillow could be made to crash or run programs as an administrator if it opened a specially crafted file.

France willing to buy key Atos assets to keep them French

Several security issues were fixed in libvirt.

Several security issues were fixed in GnuTLS.

Several security issues were fixed in curl.

Several security issues were fixed in Apache HTTP Server.

UK lays down fresh legislation banning crummy default device passwords
Watchdog reveals lingering Google Privacy Sandbox worries
The next step up for high-impact identity authorization
Discord dismantles Spy.pet site that snooped on millions of users

Security vulnerabilities were found in mediawiki, a website engine for collaborative work, that could lead to information disclosure, privilege escalation, or denial of service.

Several vulnerabilities have been found in frr, the FRRouting suite of internet protocols. An attacker could craft packages to trigger buffer overflows with the possibility to gain remote code execution, buffer overreads, crashes or trick the software to enter an infinite loop.

Release 4.2.0

update to 124.0.6367.78 * Critical CVE-2024-4058: Type Confusion in ANGLE * High CVE-2024-4059: Out of bounds read in V8 API * High CVE-2024-4060: Use after free in Dawn

Release 4.2.0

* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222984 * bsc#1222986

* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222984 * bsc#1222986

Major phishing-as-a-service platform disrupted – Week in security with Tony Anscombe

The investigation uncovered at least 40,000 phishing domains that were linked to LabHost and tricked victims into handing over their sensitive details

CVE-2024-3852: GetBoundName in the JIT returned the wrong object CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection CVE-2024-2609: Permission prompt input delay could expire when not in

update to 124.0.6367.78 * Critical CVE-2024-4058: Type Confusion in ANGLE * High CVE-2024-4059: Out of bounds read in V8 API * High CVE-2024-4060: Use after free in Dawn

CVE-2024-3852: GetBoundName in the JIT returned the wrong object CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection CVE-2024-2609: Permission prompt input delay could expire when not in

The chromium-browser-stable package has been updated to the 124.0.6367.60 release. It includes 23 security fixes. Please, do note, only x86_64 is supported from now on. i586 support for linux was stopped some years ago and the community is not able to provide patches anymore for the latest Chromium code.

https://security-tracker.debian.org/tracker/DSA-5674-1

Kaiser Permanente shared 13.4M people’s data with Microsoft Bing, Google, others
What makes Starmus unique? – A Q&A with award-winning filmmaker Todd Miller

The director of the Apollo 11 movie shares his views about the role of technology in addressing pressing global challenges as well as why he became involved with Starmus.

Second time lucky for Thoma Bravo, which scoops up Darktrace for $5.3B

* bsc#1219217 * jsc#PED-3360 * jsc#PED-3361 Cross-References:

UK’s Investigatory Powers Bill to become law despite tech world opposition

* bsc#1213269 * bsc#1218889 * bsc#1222843 * bsc#1222845

* bsc#1222842 Cross-References: * CVE-2024-3651

* bsc#1222950 Cross-References: * CVE-2024-1135

* bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756

* bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756

Four trends to top the CISO’s packed agenda
Flaws in Chinese keyboard apps leave 750 million users open to snooping, researchers claim

https://security-tracker.debian.org/tracker/DSA-5675-1

Cops cuff man for allegedly framing colleague with AI-generated hate speech clip
Ring dinged for $5.6M after, among other claims, rogue insider spied on ‘pretty girls’
Hacker’s Corner: Complete Guide to Keylogging in Linux – Part 1
How technology drives progress – A Q&A with Nobel laureate Michel Mayor

We spoke to Michel Mayor about the importance of public engagement with science and fostering responsibility among the youth for the preservation of our changing planet

The vision behind Starmus – A Q&A with the festival’s co-founder Garik Israelian

Dr. Israelian talks about Starmus’s vision and mission, the importance of inspiring and engaging audiences, and the strong sense of community within the Starmus universe

Two cuffed in Samourai Wallet crypto dirty money sting
“Junk gun” ransomware: the cheap new threat to small businesses
Russia, Iran pose most aggressive threat to 2024 elections, say infoseccers
Hacker posts fake news story about Ukrainians trying to kill Slovak President
What to do in the age of the critical breach
Indian bank’s IT is so shabby it’s been banned from opening new accounts

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in Thunderbird.

Fix for CVE-2024-31497

Fix for CVE-2024-31497

Australia’s spies and cops want ‘accountable encryption’ – aka access to backdoors
Governments issue alerts after ‘sophisticated’ state-backed actor found exploiting flaws in Cisco security boxes
Smashing Security podcast #369: Keeping the lights on after a ransomware attack
Shouldn’t Teams, Zoom, Slack all interoperate securely for the Feds? Wyden is asking
Microsoft cannot keep its own security in order, so what hope for its add-ons customers?
Management company settles for $18.4M after nuclear weapons plant staff fudged their timesheets
Google cools on cookie phase-out while regulators chew on plans
US charges Iranians with cyber snooping on government, companies

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

* bsc#1217325 Cross-References: * CVE-2023-26364

* bsc#1217325 Cross-References: * CVE-2023-26364

* bsc#1118590 * bsc#874743 Cross-References: * CVE-2014-2913

* bsc#1219887 * bsc#1219912 * bsc#1220371 * jsc#MSQA-759 * jsc#PED-7893

City street lights “misbehave” after ransomware attack
If Britain is so bothered by China, why do these .gov.uk sites use Chinese ad brokers?
Mandiant: Orgs are detecting cybercriminals faster than ever

Google Guest Agent and OS Config Agent could be made to crash if it open a specially crafted JSON.

* bsc#1213269 * bsc#1218889 * bsc#1220134 * bsc#1222843 * bsc#1222845

UnitedHealth admits IT security breach could ‘cover substantial proportion of people in America’

* bsc#1190011 * bsc#1198038 * bsc#1207205 * bsc#1212850 * bsc#1213925

* bsc#1223155 Cross-References: * CVE-2024-31744

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Leicester streetlights take ransomware attack personally, shine on 24/7
Over a million Neighbourhood Watch members exposed through web app bug
Misconfigured cloud server leaked clues of North Korean animation scam
Old Windows print spooler bug is latest target of Russia’s Fancy Bear gang

https://security-tracker.debian.org/tracker/DSA-5673-1

FBI and friends get two more years of warrantless FISA Section 702 snooping
Europol becomes latest law enforcement group to plead with big tech to ditch E2EE
Germany arrests trio accused of trying to smuggle naval military tech to China
Watchdog tells Dutch govt: ‘Do not use Facebook if there is uncertainty about privacy’

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service or information disclosure. For Debian 10 buster, these problems have been fixed in version

Pillow could be made to crash or run programs as an administrator if it opened a specially crafted file.

percona-xtrabackup could be made to run programs as your login if it opened a specially crafted file.

US House passes fresh TikTok ban proposal to Senate

* bsc#1221793 * bsc#1221797 Cross-References: * CVE-2024-29131

* bsc#1198101 * bsc#1205588 * bsc#1205855 * bsc#1210382 * bsc#1213945

* bsc#1219435 Cross-References: * CVE-2024-1086

UK data watchdog questions how private Google’s Privacy Sandbox is