This is really neat demo of the security problems arising from reusing nonces with a symmetric cipher in GCM mode.
Monthly Archives: June 2024
Microsoft Admits Security Failings Allowed China to Access US Government Emails
Microsoft President Brad Smith told US Congress that the tech giant accepts responsibility for security failings regarding the 2023 China hack
ghostscript-10.02.1-3.fc39
FEDORA-2024-029fa02f7a
Packages in this update:
ghostscript-10.02.1-3.fc39
Update description:
Security fix for CVE-2024-33871
ZDI-24-776: (Pwn2Own) Oracle VirtualBox OHCI USB Controller Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.2. The following CVEs are assigned: CVE-2024-21121.
ZDI-24-777: Linux Kernel ksmbd Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Linux Kernel. Authentication may or may not be required to exploit this vulnerability, depending upon configuration. Furthermore, only systems with ksmbd enabled are vulnerable. The ZDI has assigned a CVSS rating of 4.0.
ZDI-24-778: Linux Kernel USB Core Out-Of-Bounds Read Local Privilege Escalation Vulnerability
This vulnerability allows physically present attackers to escalate privileges on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1.
DSA-5710-1 chromium – security update
Security issues were discovered in Chromium, which could result
in the execution of arbitrary code, denial of service or information
disclosure.
python39-jinja2-epel-3.1.3-1.2.el8
FEDORA-EPEL-2024-f52b6219ca
Packages in this update:
python39-jinja2-epel-3.1.3-1.2.el8
Update description:
Backported fix for CVE-2024-34064
Watch out! CISA warns it is being impersonated by scammers
The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that scammers are impersonating its employees, in an attempt to commit fraud.
Impersonation scams are on the rise, warns the agency.
Read more, and learn how to protect yourself, in my article on the Tripwire State of Security blog.
Ascension Attack Caused by Employee Downloading Malicious File
Healthcare firm Ascension said that ransomware attackers gained access to its systems after an employee accidently downloaded a malicious file