Menu

Latest articles

* bsc#1219465 Cross-References: * CVE-2023-3966

* bsc#1050549 * bsc#1186484 * bsc#1200599 * bsc#1212514 * bsc#1213456

Truck-to-truck worm could infect – and disrupt – entire US commercial fleet
FBI v the bots: Feds urge denial-of-service defense after critical infrastructure alert
Microsoft faces bipartisan criticism for alleged censorship on Bing in China
Congress votes unanimously to ban brokers selling American data to enemies
AI used extensively for security but not for coding, JFrog survey finds
Yacht dealer to the stars attacked by Rhysida ransomware gang
UK council won’t say whether two-week ‘cyber incident’ impacted resident data
Exposed: Chinese smartphone farms that run thousands of barebones mobes to do crime
It’s 2024 and North Korea’s Kimsuky gang is exploiting Windows Help files

Update to 4.14 for CVE-2024-2357, v6 SAN name and TFC padding fix for AEAD

A security flaw was found on rubygem-yard that documents generated by yard may be vulnerable to XSS attack. This issue is now assigned as CVE-2024-27285 . This new rpm is supposed to fix this issue.

Security fix for CVE-2024-1048

Update to 115.9.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-14/ https://www.thunderbird.net/en-US/thunderbird/115.9.0/releasenotes/

Update to 4.14 for CVE-2024-2357, v6 SAN name and TFC padding fix for AEAD

Smashing Security podcast #364: Bing pop-up wars, and the British Library ransomware scandal

https://security-tracker.debian.org/tracker/DSA-5643-1

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5641-1

It’s tax season, and scammers are a step ahead of filers, Microsoft says
US task force aims to plug security leaks in water sector
GitHub previews AI-powered code scanning autofix
AI used extensively for security but not coding, JFrog survey finds
A prescription for privacy protection: Exercise caution when using a mobile health app

Given the unhealthy data-collection habits of some mHealth apps, you’re well advised to tread carefully when choosing with whom you share some of your most sensitive data

London Clinic probes claim staffer tried to peek at Princess Kate’s records
Fraudsters are posing as the FTC to scam consumers
Serial extortionist of medical facilities pleads guilty to cybercrime charges
Gotta Hack ‘Em All: Pokémon passwords reset after attack
Stalkerware usage surging, despite data privacy concerns
Introducing OpenShift Service Mesh 2.5
Red Hat Advanced Cluster Security 4.4: What’s included
Five Eyes tell critical infra orgs: take these actions now to protect against China’s Volt Typhoon

A memory leak was found in imagemagick a popular software suite for displaying, creating, converting, modifying, and editing raster images. For Debian 10 buster, this problem has been fixed in version

How to deploy software to Linux-based IoT devices at scale

Several security issues were fixed in Firefox.

The updated packages fix security vulnerabilities: Heap buffer overflow in sqlite. (CVE-2023-2137) A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler.

Updated to 124.0

Updated to 124.0

Australian techie jailed for accessing museum’s accounting system and buying himself stuff

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

https://security-tracker.debian.org/tracker/DSA-5626-2

https://security-tracker.debian.org/tracker/DSA-5642-1

Red Hat Quay 3.11: Smarter permissions, lifecycle, and AWS integration
Beijing-backed cyberspies attacked 70+ orgs across 23 countries
Crypto scams more costly to the US than ransomware, Feds say
Crypto wallet providers urged to rethink security as criminals drain them of millions

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Atos says Airbus flew off, no longer interested in infosec and big data biz

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Update to 2.6.1, backport fix for CVE-2024-28757.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Don’t be like these 900+ websites and expose millions of passwords via Firebase
Fujitsu reveals malware installed on internal systems, risk of customer data spill
More than 133,000 Fortinet appliances still vulnerable to month-old critical bug
Cyber baddies leak 70M+ files online, claim they’re from AT&T
C++ creator rebuts White House warning
Fujitsu hack raises questions, after firm confirms customer data breach
Cyberattack gifts esports pros with cheats, forcing Apex Legends to postpone tournament

* bsc#1219465 Cross-References: * CVE-2023-3966

* bsc#1213590 * bsc#1214686 * bsc#1214687 * bsc#1221187 * bsc#960589

Infosec teams must be allowed to fail, argues Gartner
Filipino police free hundreds of slaves toiling in romance scam operation

Several security issues were fixed in OpenJDK 8.

Protecting distributed branch office environments from ransomware
ChatGPT side-channel attack has easy fix: Token obfuscation

Update to shim-15.8

Update to shim-15.8

Update to shim-15.8

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. (CVE-2020-36518) In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the

The updated packages fix security vulnerabilities: Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. (CVE-2022-38398) Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML

Red Hat OpenShift Service on AWS obtains FedRAMP “Ready” designation
Zero Trust MLOps with OpenShift Platform Plus
In the rush to build AI apps, please, please don’t leave security behind

curl was affected by a path traversal vulnerability. SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate

Healthcare still a prime target for cybercrime gangs – Week in security with Tony Anscombe

Healthcare organizations remain firmly in attackers’ crosshairs, representing 20 percent of all victims of ransomware attacks among critical infrastructure entities in the US in 2023

Threat intelligence explained | Unlocked 403: A cybersecurity podcast

We break down the fundamentals of threat intelligence and its role in anticipating and countering emerging threats

upstream security release 122.0.6261.128 High CVE-2024-2400: Use after free in Performance Manager

Security fix for CVE-2007-4559.

New upstream release with security fixes for CVE-2023-5992 and CVE-2024-1454

Path traversal in moment.locale. (CVE-2022-24785) Inefficient parsing algorithim resulting in DoS. (CVE-2022-31129) References: – https://bugs.mageia.org/show_bug.cgi?id=30664

Security fix for CVE-2007-4559.

Update to 3.2.2 It indirectly fix CVE-2023-3966 and CVE-2023-5366

As if working at Helldesk weren’t bad enough, IT helpers now targeted by cybercrims
How to share sensitive files securely online

Here are a few tips for secure file transfers and what else to consider when sharing sensitive documents so that your data remains safe

Scareware scam: Restoro and Reimage fined $26 million by FTC

* bsc#1219836 Cross-References: * CVE-2024-1062

Cop shop rapped for ‘completely avoidable’ web form blunder

It was discovered that composer, a dependency manager for the PHP language, processed files in the local working directory. This could lead to local privilege escalation or malicious code execution. Due to a technical issue this email was not sent on 2024-02-26 like it should

* jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593

* jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593

* bsc#1221134 * bsc#1221151 Cross-References: * CVE-2023-42465

* bsc#1221134 * bsc#1221151 Cross-References: * CVE-2023-42465

Forget TikTok – Chinese spies want to steal IP by backdooring digital locks
FTC goes undercover to probe suspected antivirus scam, scores $26M settlement
LockBit ransomware kingpin gets 4 years behind bars
Google gooses Safe Browsing with real-time protection that doesn’t leak to ad giant
Record breach of French government exposes up to 43 million people’s data