Menu

Latest articles

Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152

Eclipse joins with industry groups to secure open source

* bsc#1212475 * bsc#1221400 Cross-References: * CVE-2023-45288

New tigervnc packages are available for Slackware 15.0 and -current to fix security issues.

Google sues crypto investment app makers over alleged massive “pig butchering” scam

From 2018 to 2023, healthcare data breaches have increased by 93 percent. And ransomware attacks have grown by 278 percent over the same period. Healthcare organizations can’t afford to let preventable breaches slip by. Globally, the average cost of a healthcare data breach has reached $10.93 million. The situation for healthcare organizations may seem bleak. […]

Ransomware attacks are targeting healthcare organizations more frequently. The number of costly cyberattacks on US hospitals has doubled. So how do you prevent these attacks? Keep reading to learn five ways you can strengthen security at your organization. But first, let’s find out what’s at stake. Why healthcare needs better cybersecurity Healthcare organizations are especially […]

US government excoriates Microsoft for ‘avoidable errors’ but keeps paying for its products
Hotel check-in terminal bug spews out access codes for guest rooms

* bsc#1145903 * bsc#1184799 Cross-References: * CVE-2019-15052

* bsc#1216594 * bsc#1216598 Cross-References: * CVE-2023-38469

Academics probe Apple’s privacy settings and get lost and confused
World’s second-largest eyeglass lens-maker blinded by infosec incident

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5654-1

Security Risks of Open-Source Software & Mitigations to Overcome Them
Feds probe massive alleged classified US govt data theft and leak
Google patches Pixel phone zero-days after exploitation by “forensic companies”
Ivanti commits to secure-by-design overhaul after vulnerability nightmare
Ransomware gang did steal residents’ confidential data, UK city council admits
What makes a ransomware attack eight times as costly? Compromised backups
When AI attacks

USN-6710-1 caused some minor regressions in Firefox.

Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152

Update to 1.22.2 Security fixes for CVE-2023-7158 and CVE-2023-7152

https://security-tracker.debian.org/tracker/DSA-5655-1

Nearly 1M medical records feared stolen from City of Hope cancer centers
Smashing Security podcast #366: Money-making bots, and Incognito isn’t private

New xorg-server packages are available for Slackware 15.0 and -current to fix security issues.

Cyberattack hits Omni Hotels systems, taking out bookings, payments, door locks

Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Claudio Bozzato discovered multiple security issues in gtkwave, a file waveform viewer for VCD (Value Change Dump) files, which may result in the execution of arbitrary code if malformed files are opened.

Mark your calendars for April 9, 2024 The second Tuesday of April marks Identity Management Day — a day dedicated to raising awareness about the importance of safeguarding your digital identity. But what exactly is identity management, and why do we need a whole day for it? In a world where our lives are increasingly […]

Security pioneer Ross Anderson dies at 67
Google bakes new cookie strategy that will leave crooks with a bad taste

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Rust memory safety explained

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Meet clickjacking’s slicker cousin, ‘gesture jacking,’ aka ‘cross window forgery’
Microsoft slammed for lax security that led to China’s cyber-raid on Exchange Online

https://security-tracker.debian.org/tracker/DSA-5653-1

Feds finally decide to do something about years-old SS7 spy holes in phone networks

Brute force attacks illustrate how persistence can pay off. Unfortunately, in this context, it’s for bad actors. Let’s dive into the mechanics of brute force attacks, unraveling their methodology, and focusing on their application. Whether it’s Remote Desktop Protocol (RDP), or direct finance theft, brute force attacks are a prime tactic in the current cybersecurity […]

OWASP server blunder exposes decade of resumes
RDP remains a security concern – Week in security with Tony Anscombe

Much has been written about the risks that poorly-secured RDP connections entail, but many organizations continue to leave themselves at risk and get hit by data breaches as a result

Pandabuy admits to data breach of 1.3 million unique records
Microsoft warns deepfake election subversion is disturbingly easy
Rubrik files to go public following alliance with Microsoft

* bsc#1218946 Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.3

Polish officials may face criminal charges in Pegasus spyware probe
Amazon refuses to refund me £700 for iPhone 15 it didn’t deliver
INC Ransom claims to be behind ‘cyber incident’ at UK city council
Happy 20th birthday Gmail, you’re mostly grown up – now fix the spam
Avoiding the dangers of AI-generated code

* bsc#1222045 Cross-References: * CVE-2024-29025

* bsc#1221815 Cross-References: * CVE-2024-2494

Apple’s GoFetch silicon security fail was down to an obsession with speed

The 6.7.11 stable kernel update contains a number of important fixes across the tree.

Upgrade to 2.44.0: Make the DOM accessibility tree reachable from UI process with GTK4. Removed the X11 and WPE renderers in favor of DMA-BUF. Improved vblank synchronization when rendering. Removed key event reinjection in GTK4 to make keyboard shortcuts work in web

The 6.7.11 stable kernel update contains a number of important fixes across the tree.

Six banks share customer info to help Singapore fight money laundering

https://security-tracker.debian.org/tracker/DSA-5652-1

US House of Reps tells staff: No Microsoft Copilot for you!
Malicious xz backdoor reveals fragility of open source
Nearly 3M people hit in Harvard Pilgrim healthcare data theft
Ex-White House CIO tells The Reg: TikTok ban may be diplomatic disaster
AT&T admits massive 70M+ mid-March customer data dump is real though old

Multiple vulnerabilities were found in libvirt, a C toolkit to interact with the virtualization capabilities of Linux, which could lead to denial of service or information disclosure.

* bsc#1041090 * bsc#1084627 * bsc#1133158 * bsc#1172267 * bsc#1191783

Update to 2.53.18.2

Update to 2.53.18.2

Update to 2.53.18.2

Two security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting or denial of service.

Rust developers at Google are twice as productive as C++ teams

Skyler Ferrante discovered that the wall tool from util-linux does not properly handle escape sequences from command line arguments. A local attacker can take advantage of this flaw for information disclosure.

Urgent security alert for Fedora Linux 40 and Fedora Rawhide users

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23. (CVE-2024-30202) In Emacs before 29.3, Gnus treats inline MIME contents as trusted. (CVE-2024-30203)

Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access. (CVE-2023-22655) Information exposure through microarchitectural state after transient

Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `–with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a

These are bug fix and security releases including MODERATE, HIGH, and CRITICAL issues.

release v1.11.0 release v1.10.1 release v1.10.0

https://security-tracker.debian.org/tracker/DSA-5651-1

https://security-tracker.debian.org/tracker/DSA-5650-1

podman-tui release v1.0.0 Security fix for [CVE-2024-28180]

x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193]

Automatic update for cockpit-314-1.fc39.

This update contains security fixes for CVE-2024-29131 and CVE-2024-29133. See https://github.com/apache/commons-configuration/blob/master/RELEASE- NOTES.txt for changes in versions 2.10.0 and 2.10.1.

Security fix for CVE-2023-35936 and CVE-2023-38745 pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745 pandoc-cli: new package for pandoc binary

Security fix for CVE-2023-35936 and CVE-2023-38745 pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745 pandoc-cli: new package for pandoc binary

Malicious SSH backdoor sneaks into xz, Linux world’s data compression library
Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching

https://security-tracker.debian.org/tracker/DSA-5648-1

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: