Menu

Latest articles

Protect Your Linux Web Apps and Meet Compliance Standards

Bartek Nowotarski discovered that Apache Traffic Server, a reverse and forward proxy server, was susceptible to denial of service via HTTP2 continuation frames.

Roku makes 2FA mandatory for all after nearly 600K accounts pwned
Delinea Secret Server customers should apply latest patches

Multiple vulnerabilities have been fixed in the Xorg X server. CVE-2024-31080

US senator wants to put the brakes on Chinese EVs
Zambia arrests 77 people in swoop on “scam” call centre

* bsc#1219296 Cross-References: * CVE-2023-52340

Identifying third-party risk
US House approves FISA renewal – warrantless surveillance and all

update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn

New less packages are available for Slackware 15.0 and -current to fix a security issue.

Core: – Corrupted memory in destructor with weak references – GC does not scale well with a lot of objects created in destructor DOM: – Add some missing ZPP checks.

Red Hat Enterprise Linux 7: End of compliance content on June 30, 2024

update to 123.0.6312.122 * High CVE-2024-3157: Out of bounds write in Compositing * High CVE-2024-3516: Heap buffer overflow in ANGLE * High CVE-2024-3515: Use after free in Dawn

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/

Bring all current releases from either version 0.7.3 or 0.6.12 to version 0.7.6 for more bug-fixes and also as to resolve potential security issues: https://lib.openmpt.org/libopenmpt/news/

https://security-tracker.debian.org/tracker/DSA-5659-1

https://security-tracker.debian.org/tracker/DSA-5657-1

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

The 6.8.5 stable kernel update contains a number of important fixes across the tree.

Update to version 0.3.26. Addresses RUSTSEC-2024-0332.

Update to version 0.3.26. Addresses RUSTSEC-2024-0332.

https://security-tracker.debian.org/tracker/DSA-5658-1

Zero-day exploited right now in Palo Alto Networks’ GlobalProtect gateways

Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with “collapsed_forwarding on” are vulnerable. Configurations with “collapsed_forwarding off” or without a “collapsed_forwarding” directive

Rust gets security fix for Windows vulnerability
Google One VPN axed for everyone but Pixel loyalists … for now
Microsoft breach allowed Russian spies to steal emails from US government

* bsc#1221564 Cross-References: * CVE-2021-47154

Understanding the Red Hat security impact scale

* bsc#1218613 * bsc#1219078 * bsc#1219296 * bsc#1219432

French issue alerte rouge after local governments knocked offline by cyber attack
Apple stops warning of ‘state-sponsored’ attacks, now alerts about ‘mercenary spyware’

Security fix for CVE-2024-24576 (Windows command injection)

Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)

Update to upstream 9.2.4, resolves CVE-2024-31309 (CONTINUATION frames DoS)

4.2.3

Space Force boss warns ‘the US will lose’ without help from Musk and Bezos

These new packages fix bugs in SSL certificate validation; these bugs could allow for the compromising of encrypted SSL sessions.

East Central University suffers BlackSuit ransomware attack
DragonForce ransomware – what you need to know
When a breach goes from 25 documents to 1.3 terabytes…
96% of US hospital websites share visitor info with Meta, Google, data brokers

* bsc#1028271 Cross-References: * CVE-2016-10243

* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672

* bsc#1221385 * bsc#1221386 Cross-References: * CVE-2024-23672

Global taxi software vendor exposes details of nearly 300K across UK and Ireland

This is the March 2024 update for .NET 7. Release Notes: https://github.com/dotnet/core/blob/main/release- notes/7.0/7.0.17/7.0.17.md

https://security-tracker.debian.org/tracker/DSA-5656-1

Smashing Security podcast #367: WhatsApp at Westminster, unhealthy AI, and Drew Barrymore

An update that fixes two vulnerabilities is now available.

Strategies for Improving Linux Security Through Cross-Browser Compatibility Testing
It’s 2024 and Intel silicon is still haunted by data-spilling Spectre

util-linux could be made to expose sensitive information.

Rust rustles up fix for 10/10 critical command injection bug on Windows

* bsc#1167896 * bsc#1206261 * bsc#1215301 Cross-References:

X fixes URL blunder that could enable convincing social media phishing campaigns

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Targus business operations disrupted following cyber attack
Turning the tide on third-party risk
Chrome Enterprise Premium promises extra security – for a fee
Synopsys takes aim at software supply chain risks
Microsoft squashes SmartScreen security bypass bug exploited in the wild
Got an unpatched LG ‘smart’ television? It could be watching you back

Bind could be made to crash if it received specially crafted input.

UK businesses shockingly unaware of how to handle security threats

* bsc#1221926 Cross-References: * CVE-2024-30161

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Parasoft unveils safety testing tool for C and C++ apps

* bsc#1207987 * bsc#1220117 * bsc#1221831 Cross-References:

US insurers use drone photos to deny home insurance policies
Home Depot confirms workers’ data snatched after miscreant dumps it online
Puppies, kittens, data at risk after ‘cyber incident’ at veterinary giant
Change Healthcare faces second ransomware dilemma weeks after ALPHV attack

* bsc#1214223 * bsc#1216980 * bsc#1220512 * bsc#1221237 * bsc#1221468

* bsc#1221749 * bsc#1221815 Cross-References: * CVE-2024-2494

* bsc#1221332 * bsc#1221334 Cross-References: * CVE-2023-28746

* bsc#1027519 * bsc#1219885 * bsc#1221332 * bsc#1221334

* bsc#1205316 * bsc#1209554 * bsc#1218484 * bsc#1220062 * bsc#1220065

* bsc#1220239 * bsc#1220242 * bsc#1220248 Cross-References:

Head of Israeli cyber spy unit exposed … by his own privacy mistake

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets.

Andreas Beck discovered that versions of pam_xauth supplied with Red Hat Linux since version 7.1 would forward authorization information from the root account to unprivileged users.

Two Cross-site scripting vulnerabilities have been found that affect SquirrelMail version 1.2.7 and earlier.

A security hole has been found that does not affect the default configuration of Red Hat Linux, but can affect some custom configurations of Red Hat Linux 7.1 only. The bug is specific to the Linux 2.4 kernel series.

CVE-2024-28085 Skyler Ferrante discovered that the wall(1) utility found in util-linux, a collection of system utilities for Linux, does not

Two issues have been found in libcaca, a colour ASCII art library. Both are related to heap buffer overflow, which might lead to memory corruption.

What can be done to protect open source devs from next xz backdoor drama?
Introducing Confidential Containers Trustee: Attestation Services Solution Overview and Use Cases

Two security vulnerabilities have been discovered in the Tomcat servlet and JSP engine. CVE-2024-24549

update to 123.0.6312.105 * High CVE-2024-3156: Inappropriate implementation in V8 * High CVE-2024-3158: Use after free in Bookmarks * High CVE-2024-3159: Out of bounds memory access in V8

4.2.3