Menu

Monthly Archives: July 2024

Ransomware infection cuts off blood supply to 250+ hospitals
More than 83K certs from nearly 7K DigiCert customers must be swapped out now
Russia takes aim at Sitting Ducks domains, bags 30,000+

Several security issues were fixed in Python.

Chrome adopts app-bound encryption to stymie cookie-stealing malware
Embedding AI security from the get go
‘Error’ in Microsoft’s DDoS defenses amplified 8-hour Azure outage
How to get started with MySQL
Full-stack development with Java, React, and Spring Boot, Part 2
UK Electoral Commission slapped for basic cybersecurity fails
Why Apache Iceberg is on fire right now

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 17.

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

Update to 1.3.3 https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3

DigiCert gives unlucky folks 24 hours to replace doomed certificates after code blunder
White House opts to not add regulatory restrictions on AI development – for now
Delta Air Lines dials up Microsoft’s legal nemesis over CrowdStrike losses
‘LockBit of phishing’ EvilProxy used in more than a million attacks every month
The AI Fix #9: When AI detectors fail (spectacularly), and OpenAI’s five steps to Skynet

* bsc#1228184 Cross-References: * CVE-2024-40897

* bsc#916845 Cross-References: * CVE-2013-4235

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Ransomware gangs are loving this dumb but deadly make-me-admin ESXi vulnerability

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Who should own cloud costs?
The rise and fall of Stack Overflow
How AI will transform data analytics
Proofpoint phishing palaver plagues millions with ‘perfectly spoofed’ emails from IBM, Nike, Disney, others
Malaysia is working on an internet ‘kill switch’, says minister
Meta’s AI safety system defeated by the space bar
US border cops really must get a warrant in NY before searching your phones, devices
Hacking gang leaks documents stolen from Pentagon IT provider
Intruders at HealthEquity rifled through storage, stole 4.3M people’s data

Several security issues were fixed in the Linux kernel.

Google apologizes for breaking password manager for millions of Windows users with iffy Chrome update

Affected Products: * openSUSE Leap 15.5

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

How to choose the right low-code, no-code, or process automation platform
Qdrant review: A highly flexible option for vector search
The other shoe drops on generative AI
Get ready for more Java licensing changes
NIST releases new tool to check AI models’ security
Microsoft admits 8.5M CrowdStruck machines estimate was lowballed

Several security issues were fixed in EDK II.

Several security issues were fixed in Lua.

China ponders creating a national ‘cyberspace ID’
Secure Boot useless on hundreds of PCs from major vendors after key leak

https://security-tracker.debian.org/tracker/DSA-5734-2

The security update announced as DSA 5734-1 caused a regression on configurations using the Samba DLZ module. Updated packages are now available to correct this issue.

Telegram for Android hit by a zero-day exploit – Week in security with Tony Anscombe

Attackers abusing the “EvilVideo” vulnerability could share malicious Android payloads via Telegram channels, groups, and chats, all while making them appear as legitimate multimedia files

Update to 1.16 fixes rhbz#2259096

Update to 2.11.2

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Update to 1.16 fixes rhbz#2259096

Update to 2.11.2

TypeScript takes aim at truthy and nullish bugs

https://security-tracker.debian.org/tracker/DSA-5734-1

CrowdStrike meets Murphy’s Law: Anything that can go wrong will
Progress discloses second critical flaw in Telerik Report Server in as many months
The case for multicloud: Lessons from the CrowdStrike outage
Python pick: Shiny for Python—now with chat

* bsc#1222693 Cross-References: * CVE-2023-29483

* bsc#1198880 * bsc#1214678 Cross-References: * CVE-2022-28506

BMC report examines DataOps practices

Update to 115.13.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-31/ https://www.thunderbird.net/en-US/thunderbird/115.13.0/releasenotes/

Backport upstream patch for CVE-2023-49606.

North Korean chap charged for attacks on US hospitals, military, NASA – and even China
Malware crew Stargazers Goblin used 3,000 GitHub accounts to make bank

Update to v1.29.7 for FC40. Resolves CVE-2024-5321: Incorrect permissions on Windows containers logs. Additional bug and regression fixes from upstream.

Update to version 1.11.2 to fix CVE-2023-49606.

CrowdStrike update blunder may cost world billions – and insurance ain’t covering it all
Beware of fake CrowdStrike domains pumping out Lumma infostealing malware
FYI: Data from deleted GitHub repos may not actually be deleted
Rust 1.80 adds lazy types
OpenAI announces free fine-tuning for GPT-4o mini model
Robot dog trained to jam wireless devices during police raids
Uncle Sam accuses telco IT pro of decade-long spying campaign for China
Building cyber-resilience: Lessons learned from the CrowdStrike incident

Organizations, including those that weren’t struck by the CrowdStrike incident, should resist the temptation to attribute the IT meltdown to exceptional circumstances

SEXi / APT Inc ransomware – what you need to know
You should probably fix this 5-year-old critical Docker vuln fairly sharpish

An update that fixes one vulnerability is now available.

Kaspersky says Uncle Sam snubbed proposal to open up its code for third-party review
Mistral AI unveils Mistral Large 2 amid rising AI competition
Build and manage LLM prompts with Prompty
Patch management still seemingly abysmal because no one wants the job

Security fix for CVE-2024-5569 (rhbz#2297117)

New libxml2 packages are available for Slackware XXX 15.0 and -current to fix a security issue.

New htdig packages are available for Slackware 15.0 and -current to fix a security issue.

How a cheap barcode scanner helped fix CrowdStrike’d Windows PCs in a flash

Update to 1.3.3 https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3

Security fix for CVE-2024-5569 (rhbz#2297118)

The months and days before and after CrowdStrike’s fatal Friday
Smashing Security podcast #382: CrowdStrike, Dark Wire, and the Paris Olympics
Visual Studio Code Java extension backs JDK 23