Menu

Latest articles

The container sles-15-sp4-chost-byos-v20230804-arm64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230803-hvm-ssd-x86_64 was updated. The following patches have been included in this update:

The container suse-sles-15-sp4-chost-byos-v20230803-x86_64-gen2 was updated. The following patches have been included in this update:

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For the oldstable distribution (bullseye), these problems have been fixed

security update

security update

Red Hat Insights Compliance: Introducing new customization options for policies

The container bci/golang was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

arm: Guests can trigger a deadlock on Cortex-A77 [XSA-436, CVE-2023-34320] (#2228238) —- bugfix for x86/AMD: Zenbleed [XSA-433, CVE-2023-20593] —- x86/AMD: Zenbleed [XSA-433] omit OCaml 5 patch on fc38

Update to 2.53.17

Update to new upstream version 3.5.4. This brings a fix for a security issue, CVE-2023-30577. This update also fixes the manual pages.

Two US Navy sailors charged with giving Chinese spies secret military info

security update

security update

Alarm raised over Mozilla VPN: Wonky authorization check lets users cause havoc
“Crocodile of Wall Street” and her husband plead guilty to giant-sized cryptocrimes
Smashing Security podcast #333: Barbie and the stalking spouse

An incorrect Authentication Tag length usage was discovered in cjose, a C library implementing the Javascript Object Signing and Encryption (JOSE) standard, which could lead to integrity compromise.

Ransomware attacks cost manufacturing sector $46 billion in downtime since 2018, report claims

It was discovered that ntpd in ntpsec, a secure, hardened, and improved implementation derived from the original NTP project, could crash if NTS is disabled and an NTS-enabled client request (mode 3) is received.

update to 115.0.5790.110. Fixes the following security issue: CVE-2022-4908 CVE-2022-4909 CVE-2022-4910 CVE-2022-4908 CVE-2022-4909 CVE-2022-4910 CVE-2022-4906 CVE-2022-4907 CVE-2022-4906 CVE-2022-4907 CVE-2023-2311 CVE-2023-2313 CVE-2023-2311 CVE-2023-2313 CVE-2023-2929 CVE-2023-2929 CVE-2023-2314 CVE-2023-2314 CVE-2023-3598 CVE-2023-3598

– Updated to latest upstream (116.0)

Fix several crashes and rendering issues Security fixes: CVE-2023-38133, CVE-2023-38572, CVE-2023-38592, CVE-2023-38594, CVE-2023-38595, CVE-2023-38597, CVE-2023-38599, CVE-2023-38600, CVE-2023-38611

librsvg 2.56.3 release, fixing CVE-2023-38633: – Fix arbitrary file read when href has special characters. – Fix cascade for symbol elements being referenced from use elements.

Couple admit they laundered $4B in stolen Bitcoins after Bitfinex super-heist
Russia’s Cozy Bear is back and hitting Microsoft Teams to phish top targets
Old-school hacktivism is back because it never went away
S3 Ep146: Tell us about that breach! (If you want to.)

Several security issues were fixed in MaraDNS.

Brit healthcare body rapped for WhatsApp chat sharing patient data

Several security issues were fixed in Vim.

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Prepare for plenty more pain from Ivanti’s MDM flaws, warn cyber agencies

The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update:

Performance and security clash yet again in “Collide+Power” attack
Web App Testing Today: Ensuring Digital Security and User Satisfaction

An update that fixes 5 vulnerabilities is now available.

It was discovered that there was a protential LDAP injection vulnerability in Bouncy Castle, a cryptographic library for Java. During the certificate validation process, bouncycastle used the certificate’s “Subject Name” into an LDAP search filter without any

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

An update for the mod_auth_openidc:2.3 module is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for openssh is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Australian Senate committee recommends bans on Chinese social media apps
Socket moves beyond JavaScript and Python and gets into Go
Firefox fixes a flurry of flaws in the first of two releases this month
Bad news: Another data-leaking CPU flaw. Good news: It’s utterly impractical
Mattress maker Tempur Sealy says it isolated tech system to contain cyber burglary

librsvg could be made to expose sensitive information.

The container bci/openjdk was updated. The following patches have been included in this update:

The container suse/389-ds was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sles12sp5 was updated. The following patches have been included in this update:

Linux Vulnerabilities: The Poison & The Antidote

Several security issues were fixed in OpenJDK.

US military battling cyber threats from within and without
China bans export of drones some countries have already banned anyway

security update

White House: Losing Section 702 spy powers would be among ‘worst intelligence failures of our time’
SEC demands four-day disclosure limit for cybersecurity breaches

Tavis Ormandy discovered that under specific microarchitectural circumstances, a vector register in “Zen 2” CPUs may not be written to 0 correctly. This flaw allows an attacker to leak register contents across concurrent processes, hyper threads and virtualized guests.

Hikvision and Nvidia named in contract for Uyghur detection

Several security issues were fixed in Wireshark.

What would sustainable security even look like?

A security issue was discovered in Thunderbird, which could result in spoofing of filenames of email attachments. For Debian 10 buster, this problem has been fixed in version

US senator victim-blames Microsoft for Chinese hack

A security issue was discovered in Thunderbird, which could result in spoofing of filenames of email attachments. For the oldstable distribution (bullseye), this problem has been fixed

SA-CORE-2009-001 ( http://drupal.org/node/358957 ) Remember to log in to your site as the admin user before upgrading this package. After upgrading the package, browse to http://host/drupal/update.php to run the upgrade script.

Tavis Ormandy discovered that under specific microarchitectural circumstances, a vector register in AMD “Zen 2” CPUs may not be written to 0 correctly. This flaw allows an attacker to leak sensitive information across concurrent processes, hyper threads

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

security update

security update

Several security issues were fixed in the Linux kernel.

Update to 3.14. Security fix for CVE-2023-38403

Update to 3.14. Security fix for CVE-2023-38403

Florida man accused of hoarding America’s secrets faces fresh charges
Millions of people’s data stolen because web devs forget to check access perms

OpenShift API for Data Protection (OADP) 1.0.11 is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which

FBI boss: Congress must renew Section 702 spy powers – that’s how we get nearly all our cyber intel
Chinese companies evade sanctions, fuel Moscow’s war on Ukraine, says report
SEC requires firms to report cyberattacks within 4 days, but not everyone may like it
Flaw in Ninja Forms WordPress plugin allows hackers to steal submitted data
Hawaii Community College admits paying ransom to extortionists
The lost art of cloud application engineering

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

Security fix for [PUT CVEs HERE]

NATO probes hacktivist crew’s boasts of stolen portal data

security update

security update

It was discovered that the domain check in libmail-dkim-perl, a Perl module to cryptographically identify the sender of email, compares i and d tags case sensitive when t=s is set on the DKIM key which causes spurious fails of legitimate messages.

Medical files of 8M-plus people fall into hands of Clop via MOVEit mega-bug
Think tank calls for monitoring of Chinese AI-enabled products
Heart monitor manufacturer hit by cyberattack, takes systems offline
S3 Ep145: Bugs With Impressive Names!