Menu

Latest articles

Supply-chain ransomware attack cripples thousands of car dealerships

Multiple vulnerabilities havebenn fixed in DCMTK, a collection of libraries and applications implementing large parts the DICOM standard for medical images.

Cyber insurance as part of the cyber threat mitigation strategy

Why organizations of every size and industry should explore their cyber insurance options as a crucial component of their risk mitigation strategies

Unlock the future of security
Google cuts ties with Entrust in Chrome over trust issues
Microsoft hits snooze again on security certificate renewal

* bsc#1216896 * bsc#1216897 * bsc#1216899 * bsc#1216900

‘Skeleton Key’ attack unlocks the worst of AI, says Microsoft
Polyfill.io owner punches back at ‘malicious defamation’ amid domain shutdown

It was discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash the program, resulting in a denial of service. (CVE-2019-11471) Reza Mirzazade Farkhani discovered that libheif incorrectly handled certain image data. An attacker could possibly use this issue to crash

Possible out-of-bounds read or write when reading malformed MED files. (r19389). [Null-pointer write (32bit platforms) or excessive memory allocation (64bit platforms) when reading close to 4GiB of data from unseekable files (r20336, r20338).

Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image. References:

Update to Emacs 29.4, fixing CVE-2024-39331.

The 6.9.6 stable kernel update contains a number of important fixes across the tree.

GitHub Artifact Attestations now generally available
TeamViewer can’t bring itself to say someone broke into its network – but it happened

If you’re using cyber security software from Kaspersky Lab, Inc, you will need to find an alternative solution soon. On June 20, 2024, the U.S. Department of Commerce banned software from the Russian-owned company, saying it posed an unacceptable risk to national security.  Citing the Russian government’s offensive cyber capabilities and its capacity to influence […]

Several security issues were fixed in FontForge.

US lawmakers wave red flags over Chinese drone dominance

Wget could be made to connect to a different host than expected.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

US charges four FIN9-linked hackers after $71 million cybercrime spree

OpenSSL could be made to consume resources and cause long delays if it processed certain input.

update to 126.0.6478.126 High CVE-2024-6290: Use after free in Dawn High CVE-2024-6291: Use after free in Swiftshader High CVE-2024-6292: Use after free in Dawn High CVE-2024-6293: Use after free in Dawn

Korean telco allegedly infected its P2P users with malware
WhisperGate suspect indicted as US offers a $10M bounty for his capture

https://security-tracker.debian.org/tracker/DSA-5723-1

Smashing Security podcast #378: Julian Assange, inside a DDoS attack, and deepfake traumas
Feds put $5M bounty on ‘CryptoQueen’ Ruja Ignatova

https://security-tracker.debian.org/tracker/DSA-5720-1

https://security-tracker.debian.org/tracker/DSA-5719-1

https://security-tracker.debian.org/tracker/DSA-5718-1

US convicts crypto-robbing gang leader who kidnapped victims before draining their accounts
Introducing… The AI Fix podcast
Batten down the hatches, it’s time to patch some more MOVEit bugs

Several security issues were fixed in the Linux kernel.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Multiple vulnerabilities were found in git, a fast, scalable and distributed revision control system. CVE-2019-1387

libheif could be made to crash if it opened a specially crafted file.

Yahoo! Japan to waive $189 million ad revenue after detecting fraudulent clicks
Organized crime and domestic violence perps are big buyers of tracking devices
Microsoft blamed for million-plus patient record theft at US hospital giant

https://security-tracker.debian.org/tracker/DSA-5722-1

https://security-tracker.debian.org/tracker/DSA-5721-1

If you’re using Polyfill.io code on your site – like 100,000+ are – remove it immediately
GitLab devsecops survey finds progress, new priorities
Fiend touts stolen Neiman Marcus customer info for $150K
Crypto scammers circle back, pose as lawyers, steal an extra $10M in truly devious plan
CISA says crooks used Ivanti bugs to snoop around high-risk chemical facilities

* bsc#1065729 * bsc#1141539 * bsc#1174585 * bsc#1181674 * bsc#1187716

* bsc#1224158 Cross-References: * CVE-2017-17507 * CVE-2018-11205

* bsc#1224458 * bsc#1225552 Cross-References: * CVE-2024-4741

* bsc#1225491 Cross-References: * CVE-2024-33871

* bsc#1225491 Cross-References: * CVE-2024-33871

* bsc#1216594 * bsc#1216598 * bsc#1226586 Cross-References:

UK and US cops band together to tackle Qilin’s ransomware shakedowns
The Marvin Attack
Passkey is the Future, and the Future is Now with Red Hat Enterprise Linux
Customize your Red Hat OpenShift nodes and keep them updated
Ransomware thieves beware
Julian Assange to go free in guilty plea deal with US
America’s best chance for nationwide privacy law could do more harm than good
Ollama drama as ‘easy-to-exploit’ critical flaw found in open source AI server
Car dealers stuck in the slow lane after cyber woes at software biz CDK
‘Mirai-like’ botnet observed attacking EOL Zyxel NAS devices

Hibernate could be made to expose sensitive information.

Britain’s Ministry of Defence accused of wasting £174M on ‘external advice’

* bsc#1226134 Cross-References: * CVE-2024-37535

Levi’s and more affected in pants-dropping week of data breaches

* bsc#1226423 Cross-References: * CVE-2024-38394

* bsc#1226423 Cross-References: * CVE-2024-38394

* bsc#1225971 Cross-References: * CVE-2024-20696

* bsc#1089090 Cross-References: * CVE-2018-9918

Meta, Microsoft SQL Server make strange bedfellows on a couch of cyber-pain
Admin took out a call center – and almost their career – with a cut and paste error
Snowflake breach snowballs as more victims, perps, come forward

https://security-tracker.debian.org/tracker/DSA-5715-2

Use-after-free in networking. (CVE-2024-5702) Use-after-free in JavaScript object transplant. (CVE-2024-5688) External protocol handlers leaked by timing attack. (CVE-2024-5690) Sandboxed iframes were able to bypass sandbox restrictions to open a new window. (CVE-2024-5691)

Risk of getting malicious extension from Chrome store way worse than Google’s letting on, study suggests

This update includes a rebase from 9.0.83 to 9.0.89. #2269611 CVE-2024-24549 tomcat: CVE-2024-24549: Apache Tomcat: HTTP/2 header handling DoS #2269612 CVE-2024-23672 tomcat: Apache Tomcat: WebSocket DoS with incomplete closing handshake

New emacs packages are available for Slackware 15.0 and -current to fix a security issue.

The long-tail costs of a data breach – Week in security with Tony Anscombe

Understanding and preparing for the potential long-tail costs of data breaches is crucial for businesses that aim to mitigate the impact of security incidents

Multiple vulnerabilities have been discovered in JHead, the worst of which may lead to arbitrary code execution.

From network security to nyet work in perpetuity: What’s up with the Kaspersky US ban?

A vulnerability has been discovered in LZ4, which can lead to memory corruption.

A vulnerability has been discovered in RDoc, which can lead to execution of arbitrary code.

A vulnerability has been discovered in Flatpak, which can lead to a sandbox escape.

A vulnerability has been discovered in GLib, which can lead to privilege escalation.

Update to 2.44.2: Make gamepads visible on axis movements, and not only on button presses. Disable the gst-libav AAC decoder. Make user scripts and style sheets visible in the Web Inspector. Use the geolocation portal where available, with the existing geoclue as

Change Healthcare finally spills the tea on what medical data was stolen by cyber-crew
Uncle Sam sanctions Kaspersky’s top bosses – but not Mr K himself
My health information has been stolen. Now what?

As health data continues to be a prized target for hackers, here’s how to minimize the fallout from a breach impacting your own health records

Phoenix UEFI flaw puts long list of Intel chips in hot seat
Why attack surfaces are expanding

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: