New phishing kit Xiu Gou, featuring a unique “doggo” mascot, targets users in US, UK, Spain, Australia and Japan with 2000+ scam websites
Monthly Archives: October 2024
iaito-5.9.6-2.el8 radare2-5.9.6-2.el8
FEDORA-EPEL-2024-35583dfe8b
Packages in this update:
iaito-5.9.6-2.el8
radare2-5.9.6-2.el8
Update description:
fix CVE-2024-48241
iaito-5.9.6-1.fc40 radare2-5.9.6-1.fc40
FEDORA-2024-c52c5c8791
Packages in this update:
iaito-5.9.6-1.fc40
radare2-5.9.6-1.fc40
Update description:
fix CVE-2024-48241
iaito-5.9.6-1.fc41 radare2-5.9.6-1.fc41
FEDORA-2024-658aeaa7ea
Packages in this update:
iaito-5.9.6-1.fc41
radare2-5.9.6-1.fc41
Update description:
fix CVE-2024-48241
iaito-5.9.6-1.el9 radare2-5.9.6-1.el9
FEDORA-EPEL-2024-c5986b2cf1
Packages in this update:
iaito-5.9.6-1.el9
radare2-5.9.6-1.el9
Update description:
fix CVE-2024-48241
iaito-5.9.6-1.fc39 radare2-5.9.6-1.fc39
FEDORA-2024-e7c0a0d876
Packages in this update:
iaito-5.9.6-1.fc39
radare2-5.9.6-1.fc39
Update description:
fix CVE-2024-48241
xlibre Xnest security advisory & bugfix releases
Posted by Enrico Weigelt, metux IT consult on Oct 31
XLibre project security advisory
———————————
As Xlibre Xnest is based on Xorg, it is affected by some security issues
which recently became known in Xorg:
CVE-2024-9632: can be triggered by providing a modified bitmap to the
X.Org server.
CVE-2024-9632: Heap-based buffer overflow privilege escalation in
_XkbSetCompatMap
See: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9632
Affected versions:
* 24.1.0…
APPLE-SA-10-29-2024-1 Safari 18.1
Posted by Apple Product Security via Fulldisclosure on Oct 31
APPLE-SA-10-29-2024-1 Safari 18.1
Safari 18.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/121571.
Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.
Safari Downloads
Available for: macOS Ventura and macOS Sonoma
Impact: An attacker may be able to misuse a trust relationship to…
SEC Consult SA-20241030-0 :: Query Filter Injection in Ping Identity PingIDM (formerly known as ForgeRock Identity Management) (CVE-2024-23600)
Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Oct 31
SEC Consult Vulnerability Lab Security Advisory < 20241030-0 >
=======================================================================
title: Query Filter Injection
product: Ping Identity PingIDM (formerly known as ForgeRock Identity
Management)
vulnerable version: v7.0.0 – v7.5.0 (and older unsupported versions)
fixed version: various patches; v8.0
CVE number:…
Misconfigured Git Configurations Targeted in Emeraldwhale Attack
Emeraldwhale breach allowed access to over 10,000 repositories and resulted in the theft of more than 15,000 cloud service credentials