Menu

Latest articles

Has the ever-present cyber danger just got worse?
Google all at sea over rising tide of robo-spam
Rarest, strangest, form of Windows saved techie from moment of security madness
Researchers claim Windows Defender can be fooled into deleting databases
China creates ‘Information Support Force’ to improve networked defence capabilities
MITRE admits ‘nation state’ attackers touched its NERVE R&D operation

https://security-tracker.debian.org/tracker/DSA-5672-1

https://security-tracker.debian.org/tracker/DSA-5671-1

https://security-tracker.debian.org/tracker/DSA-5670-1

https://security-tracker.debian.org/tracker/DSA-5669-1

Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Protecting yourself after a medical data breach – Week in security with Tony Anscombe

What are the risks and consequences of having your health data exposed and what are the steps to take if it happens to you?

The many faces of impersonation fraud: Spot an imposter before it’s too late

What are some of the most common giveaway signs that the person behind the screen or on the other end of the line isn’t who they claim to be?

The ABCs of how online ads can impact children’s well-being

From promoting questionable content to posing security risks, inappropriate ads present multiple dangers for children. Here’s how to help them stay safe.

eXotic Visit includes XploitSPY malware – Week in security with Tony Anscombe

Almost 400 people in India and Pakistan have fallen victim to an ongoing Android espionage campaign called eXotic Visit

Bitcoin scams, hacks and heists – and how to avoid them

Here’s how cybercriminals target cryptocurrencies and how you can keep your bitcoin or other crypto safe

Beyond fun and games: Exploring privacy risks in children’s apps

Should children’s apps come with ‘warning labels’? Here’s how to make sure your children’s digital playgrounds are safe places to play and learn.

The devil is in the fine print – Week in security with Tony Anscombe

Temu’s cash giveaway where people were asked to hand over vast amounts of their personal data to the platform puts the spotlight on the data-slurping practices of online services today

update to 124.0.6367.60 High CVE-2024-3832: Object corruption in V8 High CVE-2024-3833: Object corruption in WebAssembly High CVE-2024-3914: Use after free in V8 High CVE-2024-3834: Use after free in Downloads

New upstream release (125.0)

Security fix for CVE-2023-5752

Update to 1.15.8 Fixes CVE-2024-32462

Security fix for CVE-2024-27316

https://security-tracker.debian.org/tracker/DSA-5667-1

4 use cases for AI in cyber security
Learn about trends and best practices from top security experts at Red Hat and NIST’s Cybersecurity Open Forum
Connect hybrid cloud Kubernetes with F5 multicloud networking and Red Hat OpenShift for optimized security footprints

Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.

Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.

Security fixes for CVE-2024-27351 Potential regular expression DOS in django.utils.text.Truncator.words() CVE-2024-24680 denial-of-service in intcomma template filter CVE-2023-43665 Denial-of-service possibility in django.utils.text.Truncator

fix CONTINUATION frames DoS (CVE-2024-28182)

This update includes several bug fixes from the upstream glibc release branch, including a fix for CVE-2024-2961.

Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.

https://security-tracker.debian.org/tracker/DSA-5668-1

Sacramento airport goes no-fly after AT&T internet cable snipped
WhatsApp, Threads, more banished from Apple App Store in China

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1220181 Cross-References: * CVE-2024-24476

* bsc#1222535 Cross-References: * CVE-2024-2609 * CVE-2024-3302

* bsc#1219491 Cross-References: * CVE-2023-46045

Cybercriminals threaten to leak all 5 million records from stolen database of high-risk individuals

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or clickjacking.

Germany cuffs alleged Russian spies over plot to bomb industrial and military targets

WordPress 6.4.4 Security Release Security updates included in this release A cross-site scripting (XSS) vulnerability affecting the Avatar block type; reported by John Blackbourn of the WordPress security team. Many thanks to Mat Rollings for assisting with the research.

https://security-tracker.debian.org/tracker/DSA-5666-1

Ransomware feared as IT ‘issues’ force Octapharma Plasma to close 150+ centers
Crooks exploit OpenMetadata holes to mine crypto – and leave a sob story for victims

https://security-tracker.debian.org/tracker/DSA-5665-1

https://security-tracker.debian.org/tracker/DSA-5664-1

https://security-tracker.debian.org/tracker/DSA-5663-1

House passes bill banning Uncle Sam from snooping on citizens via data brokers
Korean researcher details scheme abusing Apple’s third-party pickup policy
Change Healthcare data for sale on dark web as fallout from ransomware attack spirals out of control
3.5 million Omni Hotel guest details held to ransom by Daixin Team
Police smash LabHost international fraud network, 37 arrested
185K people’s sensitive data in the pits after ransomware raid on Cherry Health

GNU C Library could be made to crash or run programs if it processed specially crafted data.

* bsc#1194869 * bsc#1200465 * bsc#1205316 * bsc#1207948 * bsc#1209635

EU tells Meta it can’t paywall privacy

This update includes the changes in tzdata 2024a for the Perl bindings. For the list of changes, see DLA-3789-1. For Debian 10 buster, this problem has been fixed in version

This update includes the changes in tzdata 2024a. Notable changes are: – – Kazakhstan unifies on UTC+5 beginning 2024-03-01.

Prolific phishing-made-easy emporium LabHost knocked offline in cyber-cop op
Java services hit hardest by third-party vulnerabilities, report says
Cisco creates architecture to improve security and sell you new switches
Singapore infosec boss warns China/West tech split will be bad for interoperability
Taiwanese film studio snaps up Chinese surveillance camera specialist Dahua

sosreport: Fix command injection with crafted report names [CVE-2024-2947]

Fix for CVE-2024-31497

Hugely expanded Section 702 surveillance powers set for US Senate vote
Smashing Security podcast #368: Gary Barlow, and a scam turns deadly

https://security-tracker.debian.org/tracker/DSA-5655-2

Kremlin’s Sandworm blamed for cyberattacks on US, European water utilities
Exploit code for Palo Alto Networks zero-day now public
OpenAI’s GPT-4 can exploit real vulnerabilities by reading security advisories

* bsc#1200599 * bsc#1209635 * bsc#1212514 * bsc#1213456 * bsc#1217987

* bsc#1194869 * bsc#1200465 * bsc#1205316 * bsc#1207948 * bsc#1209635

Japanese government rejects Yahoo! infosec improvement plan

New upstream release (125.0)

The 6.8.6 stable kernel update contains a number of important fixes across the tree.

Update to 0.9.0; fix rhbz#2274045 and rhbz#2266791; Security fix for CVE-2024-25713

New version 4.2.4. Includes a fix for CVE-2024-2955

Fire in the Cisco! Networking giant’s Duo MFA message logs stolen in phish attack
Most developers have adopted devops, survey says
MGM says FTC can’t possibly probe its ransomware downfall – watchdog chief Lina Khan was a guest at the time

https://security-tracker.debian.org/tracker/DSA-5661-1

https://security-tracker.debian.org/tracker/DSA-5660-1

Alleged cryptojacker accused of stealing $3.5M from cloud to mine under $1M in crypto
SIM swap crooks solicit T-Mobile US, Verizon staff via text to do their dirty work
Open sourcerers say suspected xz-style attacks continue to target maintainers
Change Healthcare’s ransomware attack costs edge toward $1B so far

* bsc#1216992 Cross-References: * CVE-2023-4218

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603

* bsc#1222244 * bsc#1222384 Cross-References: * CVE-2024-27982

* bsc#1220053 * bsc#1222244 * bsc#1222384 * bsc#1222530 * bsc#1222603

Google location tracking deal could be derailed by politics
Better application networking and security with CAKES

https://security-tracker.debian.org/tracker/DSA-5662-1

CISA in a flap as Chirp smart door locks can be trivially unlocked remotely