Cisco Talos has observed the financially motivated threat actor targeting organizations globally with a MedusaLocker ransomware variant called “BabyLockerKZ”
chromium-129.0.6668.89-1.fc39
FEDORA-2024-7aba3c1531
Packages in this update:
chromium-129.0.6668.89-1.fc39
Update description:
update to 129.0.6668.89
High CVE-2024-7025: Integer overflow in Layout
High CVE-2024-9369: Insufficient data validation in Mojo
High CVE-2024-9370: Inappropriate implementation in V8
chromium-129.0.6668.89-1.fc40
FEDORA-2024-452b60addf
Packages in this update:
chromium-129.0.6668.89-1.fc40
Update description:
update to 129.0.6668.89
High CVE-2024-7025: Integer overflow in Layout
High CVE-2024-9369: Insufficient data validation in Mojo
High CVE-2024-9370: Inappropriate implementation in V8
Some SIM / USIM card security (and ecosystem) info
Posted by Security Explorations on Oct 04
Hello All,
Those interested in SIM / USIM card security might find some
information at our spin-off project page dedicated to the topic
potentially useful:
https://security-explorations.com/sim-usim-cards.html
We share there some information based on the experiences gained in the
SIM / USIM card security space, all in a hope this leads to the
increase of public awareness on the topic, change perspective on the
SIM / USIM card industry and…
chromium-129.0.6668.89-1.el8
FEDORA-EPEL-2024-a3d9061962
Packages in this update:
chromium-129.0.6668.89-1.el8
Update description:
update to 129.0.6668.89
* High CVE-2024-7025: Integer overflow in Layout
* High CVE-2024-9369: Insufficient data validation in Mojo
* High CVE-2024-9370: Inappropriate implementation in V8
chromium-129.0.6668.89-1.el9
FEDORA-EPEL-2024-ae299cc269
Packages in this update:
chromium-129.0.6668.89-1.el9
Update description:
update to 129.0.6668.89
* High CVE-2024-7025: Integer overflow in Layout
* High CVE-2024-9369: Insufficient data validation in Mojo
* High CVE-2024-9370: Inappropriate implementation in V8
Sellafield Fined for Cybersecurity Failures at Nuclear Site
A UK court has fined Sellafield Ltd £332,500 for cybersecurity failings related to the running of the Sellafield nuclear facility
apache-commons-io-2.11.0-5.fc39
FEDORA-2024-5d581b2365
Packages in this update:
apache-commons-io-2.11.0-5.fc39
Update description:
Fixes possible denial of service attack on untrusted input
Sellafield nuclear site hit with £332,500 fine after “significant cybersecurity shortfalls”
The UK’s Sellafield nuclear waste processing and storage site has been fined £332,500 by regulators after its IT systems were found to have been left vulnerable to hackers and unauthorised access for years.
Read more in my article on the Hot for Security blog.
CRI Releases Guidance on Avoiding Ransomware Payments
The Counter Ransomware Initiative has released new guidance discouraging organizations from making ransomware payments