USN-7021-4: Linux kernel vulnerabilities

Read Time:22 Second

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
– GPU drivers;
– BTRFS file system;
– F2FS file system;
– GFS2 file system;
– BPF subsystem;
– Netfilter;
– RxRPC session sockets;
– Integrity Measurement Architecture(IMA) framework;
(CVE-2024-41009, CVE-2024-26677, CVE-2024-42160, CVE-2024-39494,
CVE-2024-39496, CVE-2024-38570, CVE-2024-27012, CVE-2024-42228)

Read More

LevelBlue: Driving Cyber Resilience in October (and Beyond)

Read Time:2 Minute, 59 Second

As we navigate the rapidly evolving technology landscape in 2024, Cybersecurity Awareness Month, now in its 21st year, highlights the increasing importance of protecting against the evolving threat environment across all areas of a business. This initiative motivates both individuals and entire organizations to adopt essential practices that enhance online safety.

Every October, Cybersecurity Awareness Month focuses on driving a collaborative effort in fostering cyber education, and like in 2023, it promotes the theme – “Secure Our World.”

As a Cybersecurity Awareness Month Champion, LevelBlue continues to show its dedication to this mission, while promoting the importance of cyber resilience among growing opportunities for innovation that might also increase cyber risk. This means simplifying security, aiming to provide always-on services that make governance, planning, resource allocation, and innovation easier than ever without sacrificing cyber protection.

Aligning on Cyber Resilience Goals Among the C-suite

As cybersecurity threats evolve, one of the biggest challenges facing organizations is the misalignment among C-suite leaders – which weakens overall cyber resilience.

The 2024 LevelBlue Executive Accelerator analyzes the dynamics among C-suite executives to better understand issues that prevent risk reduction, stall or complicate compliance, and create barriers to cyber resilience. According to its findings, 73% of CISOs expressed concern over cybersecurity becoming unwieldy, requiring risk-laden tradeoffs, compared to only 58% of both CIOs and CTOs. This indicates a heightened concern among CISOs about balancing immediate security measures with the practicalities of implementing new technologies and managing resources. That need for tradeoffs suggests that CISOs are struggling to maintain a balance between advancing technological capabilities and ensuring robust cybersecurity measures, potentially leaving organizations exposed to increased risk.

This Cybersecurity Awareness Month, organizations must focus on improved alignment within the C-suite to provide clearer guidance on cybersecurity priorities by fostering a unified approach to risk management and operational resilience. When CIOs, CTOs, and CISOs collaborate closely, they can prioritize investments in cybersecurity technologies that mitigate risks effectively while supporting business objectives. This alignment reduces ambiguity and ensures that resources are allocated strategically, alleviating some of the pressure on CISOs to make unilateral decisions.

Achieving Cyber Resilience with Five Specific Steps

To effectively achieve cyber resilience, LevelBlue promotes five crucial steps that the C-suite and organizations as a whole should take – not only during Cybersecurity Awareness Month, but beyond:

Identify the barriers – This allows organizations to understand unique vulnerabilities and weaknesses in their current systems.
Adopt a “secure by design” approach – Organizations must ensure that security measures are integrated into every phase of product and system development, rather than being an afterthought.
Align cyber investments with business objectives – Resources must be allocated in ways that bolster overall organizational goals while enhancing security posture.
Build a support ecosystem that fosters collaboration and knowledge sharing among stakeholders – This creates a more robust defense against cyber threats.
Transform cybersecurity strategies to be agile and adaptive – This enables organizations to respond to evolving threats effectively, no matter how advanced an attack may become.

During Cybersecurity Awareness Month – and every month following – implementing these steps allows organizations to enhance their resilience against cyber incidents, ensuring not just protection but also the ability to thrive in an increasingly complex digital landscape. This proactive approach, among C-suite alignment, not only mitigates risks but also positions businesses to capitalize on opportunities in a secure manner, ultimately fostering trust among customers and stakeholders alike.

For more information about Cybersecurity Awareness Month and to engage in its various activities throughout the month, visit CISA’s Cybersecurity Awareness Month web page and Stay Safe Online Cybersecurity Awareness Month website.

Read More

LevelBlue: Driving Cyber Resilience in October (and Beyond)

Read Time:2 Minute, 59 Second

As we navigate the rapidly evolving technology landscape in 2024, Cybersecurity Awareness Month, now in its 21st year, highlights the increasing importance of protecting against the evolving threat environment across all areas of a business. This initiative motivates both individuals and entire organizations to adopt essential practices that enhance online safety.

Every October, Cybersecurity Awareness Month focuses on driving a collaborative effort in fostering cyber education, and like in 2023, it promotes the theme – “Secure Our World.”

As a Cybersecurity Awareness Month Champion, LevelBlue continues to show its dedication to this mission, while promoting the importance of cyber resilience among growing opportunities for innovation that might also increase cyber risk. This means simplifying security, aiming to provide always-on services that make governance, planning, resource allocation, and innovation easier than ever without sacrificing cyber protection.

Aligning on Cyber Resilience Goals Among the C-suite

As cybersecurity threats evolve, one of the biggest challenges facing organizations is the misalignment among C-suite leaders – which weakens overall cyber resilience.

The 2024 LevelBlue Executive Accelerator analyzes the dynamics among C-suite executives to better understand issues that prevent risk reduction, stall or complicate compliance, and create barriers to cyber resilience. According to its findings, 73% of CISOs expressed concern over cybersecurity becoming unwieldy, requiring risk-laden tradeoffs, compared to only 58% of both CIOs and CTOs. This indicates a heightened concern among CISOs about balancing immediate security measures with the practicalities of implementing new technologies and managing resources. That need for tradeoffs suggests that CISOs are struggling to maintain a balance between advancing technological capabilities and ensuring robust cybersecurity measures, potentially leaving organizations exposed to increased risk.

This Cybersecurity Awareness Month, organizations must focus on improved alignment within the C-suite to provide clearer guidance on cybersecurity priorities by fostering a unified approach to risk management and operational resilience. When CIOs, CTOs, and CISOs collaborate closely, they can prioritize investments in cybersecurity technologies that mitigate risks effectively while supporting business objectives. This alignment reduces ambiguity and ensures that resources are allocated strategically, alleviating some of the pressure on CISOs to make unilateral decisions.

Achieving Cyber Resilience with Five Specific Steps

To effectively achieve cyber resilience, LevelBlue promotes five crucial steps that the C-suite and organizations as a whole should take – not only during Cybersecurity Awareness Month, but beyond:

Identify the barriers – This allows organizations to understand unique vulnerabilities and weaknesses in their current systems.
Adopt a “secure by design” approach – Organizations must ensure that security measures are integrated into every phase of product and system development, rather than being an afterthought.
Align cyber investments with business objectives – Resources must be allocated in ways that bolster overall organizational goals while enhancing security posture.
Build a support ecosystem that fosters collaboration and knowledge sharing among stakeholders – This creates a more robust defense against cyber threats.
Transform cybersecurity strategies to be agile and adaptive – This enables organizations to respond to evolving threats effectively, no matter how advanced an attack may become.

During Cybersecurity Awareness Month – and every month following – implementing these steps allows organizations to enhance their resilience against cyber incidents, ensuring not just protection but also the ability to thrive in an increasingly complex digital landscape. This proactive approach, among C-suite alignment, not only mitigates risks but also positions businesses to capitalize on opportunities in a secure manner, ultimately fostering trust among customers and stakeholders alike.

For more information about Cybersecurity Awareness Month and to engage in its various activities throughout the month, visit CISA’s Cybersecurity Awareness Month web page and Stay Safe Online Cybersecurity Awareness Month website.

Read More

redis-7.2.6-1.fc40

Read Time:23 Second

FEDORA-2024-5d4eb04e76

Packages in this update:

redis-7.2.6-1.fc40

Update description:

Redis Community Edition 7.2.6 Released Wed 02 Oct 2024 20:17:04 IDT

Upgrade urgency SECURITY: See security fixes below.

Security fixes

CVE-2024-31449 Lua library commands may lead to stack overflow and potential RCE.
CVE-2024-31227 Potential Denial-of-service due to malformed ACL selectors.
CVE-2024-31228 Potential Denial-of-service due to unbounded pattern matching.

Read More

redis-7.2.6-1.fc39

Read Time:23 Second

FEDORA-2024-68f9c0741f

Packages in this update:

redis-7.2.6-1.fc39

Update description:

Redis Community Edition 7.2.6 Released Wed 02 Oct 2024 20:17:04 IDT

Upgrade urgency SECURITY: See security fixes below.

Security fixes

CVE-2024-31449 Lua library commands may lead to stack overflow and potential RCE.
CVE-2024-31227 Potential Denial-of-service due to malformed ACL selectors.
CVE-2024-31228 Potential Denial-of-service due to unbounded pattern matching.

Read More

USN-7052-1: GNOME Shell vulnerabilities

Read Time:23 Second

It was discovered that GNOME Shell mishandled extensions that fail to
reload, possibly leading to extensions staying enabled on the lock screen.
An attacker could possibly use this issue to launch applications, view
sensitive information, or execute arbitrary commands. (CVE-2017-8288)

It was discovered that the GNOME Shell incorrectly handled certain
keyboard inputs. An attacker could possibly use this issue to invoke
keyboard shortcuts, and potentially other actions while the workstation
was locked. (CVE-2019-3820)

Read More

News, Advisories and much more

Exit mobile version