Spain’s National Police force has arrested a suspected data thief who targeted government and military victims
Daily Archives: February 6, 2025
firefox-135.0-1.fc40
FEDORA-2025-2e627d0672
Packages in this update:
firefox-135.0-1.fc40
Update description:
Updated to latest upstream (135.0)
firefox-135.0-1.fc41
FEDORA-2025-13bbd34b51
Packages in this update:
firefox-135.0-1.fc41
Update description:
Updated to latest upstream (135.0)
LevelBlue Expands Its Partner Program Globally
LevelBlue Expands Its Partner Program Globally
Businesses worldwide are challenged with increasingly sophisticated cyber threats, and the need for advanced security solutions has never been greater. That’s why we’re expanding the LevelBlue Partner Program through strategic alliances to add to our strong global base of managed service providers (MSPs) managed security service providers (MSSPs) and resellers in different regions including Europe and the Middle East.
We’re excited about a new partnership with Renaissance, Ireland’s leading value-added distributor. Through this alliance, Renaissance is bringing LevelBlue’s managed security services to the Irish market, addressing the growing demand for security solutions amid rapid growth in the region.
Ireland’s MSPs and MSSPs are facing challenges in delivering complex cybersecurity services due to resource limitations. Through our collaboration, Renaissance provides Irish MSPs and MSSPs with the ability to complement their security capabilities without requiring substantial investments in building in-house capabilities.
In addition to increasing our footprint in Europe, we’re also expanding our reach within the Middle East. In October of 2024, we strengthened our collaboration with Mindfire Technologies, the largest MSSP in the Middle East. Through our joint efforts, we are bringing cybersecurity services tailored to the needs of organizations within the region, helping them to stay ahead of evolving threats and scale their security operations.
However, our expansion isn’t just about growing our own reach—it’s about fostering a stronger, more resilient cybersecurity ecosystem worldwide. By working closely with regional partners like Renaissance and Mindfire, we ensure that businesses of all sizes can access world-class cybersecurity services tailored to their specific needs.
What This Means for Our Partners
By working with LevelBlue, our partners benefit from offering not just world-class security solutions, but we are a trusted partner, providing key resources for their success including:
Full demo and training environment
Online training and certification
Self-service technical training
Sales enablement
Technical support
Marketing support
Centralized management console
What This Means for Businesses
With our strategic alliances, LevelBlue is simplifying cybersecurity for businesses globally, enabling them to innovate with confidence.
For organizations in Europe, the Middle East, and beyond, our expansion brings numerous benefits:
Access to Award-Winning Security Services: Organizations can leverage LevelBlue’s managed security services to protect their digital assets and maintain compliance.
Stronger Security Posture: With LevelBlue’s expertise, companies can enhance their cybersecurity defenses without needing to build in-house teams from scratch.
Reduced Operational Burden: LevelBlue’s 24/7 support allows internal IT teams to focus on strategic initiatives.
Confidence to Innovate: With a strong security foundation, businesses can pursue digital transformation and growth without fear of cyber threats.
Looking Ahead
As part of our commitment to the LevelBlue Partner Program, we are evolving our offerings to help MSPs and MSSPs open new growth opportunities, In October 2024 we announced four security services to our partners that easily extend and integrate with LevelBlue USM Anywhere, which includes proactive threat intelligence: LevelBlue Managed Threat Detection and Response; LevelBlue Incident Response Retainer; LevelBlue Managed Vulnerability Program; LevelBlue Managed Endpoint Security. The new services give LevelBlue partners and their customers the solutions and expertise needed to navigate today’s complex threat landscape.
Stay tuned for the launch of the enhanced LevelBlue Partner Program in March. There will be even more opportunities for MSPs and MSSPs to help customers safeguard their digital infrastructure.
For more information on LevelBlue’s managed security services and partnership opportunities, visit www.LevelBlue.com.
USN-7256-1: Ruby vulnerabilities
It was discovered that Ruby incorrectly handled parsing of an XML document
that has specific XML characters in an attribute value using REXML gem. An
attacker could use this issue to cause Ruby to crash, resulting in a
denial of service.
USN-7258-1: CKEditor vulnerabilities
Kevin Backhouse discovered that CKEditor did not properly sanitize HTML
content. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-24728)
It was discovered that CKEditor did not properly handle the creation of
editor instances in the Iframe Dialog and Media Embed packages. An
attacker could possibly use this issue to perform cross site scripting
and obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2023-28439)
It was discovered that CKEditor did not properly handle parsing HTML
content. An attacker could possibly use this issue to perform cross site
scripting and obtain sensitive information.
(CVE-2024-24815, CVE-2024-24816)
It was discovered that CKEditor did not properly sanitize version
notifications. An attacker could possibly use this issue to perform cross
site scripting and obtain sensitive information. This issue only affected
Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2024-43411)
Smashing Security podcast #403: Coinbase crypto heists, QR codes, and ransomware in the classroom
In episode 403 of “Smashing Security” we dive into the mystery of $65 million vanishing from Coinbase users faster than J-Lo slipped into Graham’s DMs, Geoff gives a poor grade for PowerSchool’s security, and Carole takes a curious look at QR codes.
All this and more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist’s Geoff White.