BeaverTail malware has been used to target tech job seekers through fake recruiters, Palo Alto Networks’ Unit 42 has found
Daily Archives: November 18, 2024
mingw-python3-3.11.10-2.fc41
FEDORA-2024-e6b1e638d1
Packages in this update:
mingw-python3-3.11.10-2.fc41
Update description:
Backport fix for CVE-2024-9287
Update to python-3.11.0.
mingw-python3-3.11.10-2.fc40
FEDORA-2024-d7e2d109e2
Packages in this update:
mingw-python3-3.11.10-2.fc40
Update description:
Backport fix for CVE-2024-9287
Update to python-3.11.0.
FTC Records 50% Drop in Nuisance Calls Since 2021
The US Federal Trade Commission is celebrating a halving of unwanted telemarketing and scam calls since 2021
mingw-libsoup-2.74.3-8.fc40
FEDORA-2024-8c3476dd24
Packages in this update:
mingw-libsoup-2.74.3-8.fc40
Update description:
Backport fixes for CVE-2024-52530 and CVE-2024-52532.
mingw-libsoup-2.74.3-8.fc41
FEDORA-2024-af077c1f85
Packages in this update:
mingw-libsoup-2.74.3-8.fc41
Update description:
Backport fixes for CVE-2024-52530 and CVE-2024-52532.
mingw-glib2-2.82.2-1.fc40
FEDORA-2024-1e29ad7d25
Packages in this update:
mingw-glib2-2.82.2-1.fc40
Update description:
Update to 2.82.2, fixes CVE-2024-52533.
mingw-glib2-2.82.2-1.fc41
FEDORA-2024-67869f1cb3
Packages in this update:
mingw-glib2-2.82.2-1.fc41
Update description:
Update to 2.82.2, fixes CVE-2024-52533.
NCSC Warns UK Shoppers Lost £11.5m Last Christmas
The UK’s National Cyber Security Centre is urging shoppers to stay safe this Christmas after revealing they lost £11.5m to fraudsters in 2023
USN-7108-1: AsyncSSH vulnerabilities
Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that AsyncSSH
did not properly handle the extension info message. An attacker able to
intercept communications could possibly use this issue to downgrade
the algorithm used for client authentication. (CVE-2023-46445)
Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that AsyncSSH
did not properly handle the user authentication request message. An
attacker could possibly use this issue to control the remote end of an SSH
client session via packet injection/removal and shell emulation.
(CVE-2023-46446)