Menu

Monthly Archives: July 2024

Oops. Apple relied on bad code while flaming Google Chrome’s Topics ad tech
Why Meta’s Llama 3.1 is a boon for enterprises and a bane for other LLM vendors
Uncle Sam opens probe into CrowdStrike turbulence at Delta Air Lines
Windows Patch Tuesday update might send a user to the BitLocker recovery screen
Data pilfered from Pentagon IT supplier Leidos

Security fix for CVE-2024-33869 Security fixes for CVE-2024-29509, CVE-2024-29508, CVE-2024-29507, CVE-2024-29506

update xmedcon to 0.24.0 fixes: Bug 2283157 – xmedcon-0.24.0 is available Bug 2283100 – CVE-2024-29421 xmedcon: Heap overview when parsing DICOM medical files [fedora-all]

provd could be made to run programs as an administrator.

What is GraphQL? Better APIs by design
How to create an operational data store with TiDB
School gets an F for using facial recognition on kids in canteen
Forget security – Google’s reCAPTCHA v2 is exploiting users for profit

A vulnerability has been discovered in Freenet, which can lead to deanonymization due to path folding.

Multiple vulnerabilities have been discovered in ExifTool, the worst of which could lead to arbitrary code execution.

A vulnerability has been discovered in Dmidecode, which can lead to privilege escalation.

CrowdStrike blames a test software bug for that giant global mess it made
Security biz KnowBe4 hired fake North Korean techie, who got straight to work … on evil
Philippines wipes out its legit online gambling industry to take down scammers
Microsoft .NET Aspire automates Dockerfile builds
How did a CrowdStrike config file crash millions of Windows computers? We take a closer look at the code
Shiny for Python adds chat component for generative AI chatbots
Administrators have update lessons to learn from the CrowdStrike outage
Protecting AI systems from cyber threats
Google Cloud Spanner gets dual-region configuration option
Agentic AI drives enterprises away from public clouds
Cybercrooks spell trouble with typosquatting domains amid CrowdStrike crisis
British teen arrested in connection with MGM Resorts ransomware attack
Alphabet’s reported $23B bet on Wiz fizzles out
DDoS-for-hire site DigitalStress taken down by police, suspected owner arrested
The AI Fix #8: Emergence, a rancid donkey, and the world’s funniest joke

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Deciding and iterating with Java statements

* bsc#1227268 * bsc#1227269 * bsc#1227272 Cross-References:

* bsc#1219660 Cross-References: * CVE-2024-24577

* bsc#1219660 Cross-References: * CVE-2024-24577

* bsc#1214980 * bsc#1222804 * bsc#1222807 * bsc#1222811 * bsc#1222813

Retrieval-augmented generation refined and reinforced
Securing AI around the world
Google’s plan to drop third-party cookies in Chrome crumbles
IBM adds Mistral Large language model to watsonx.ai
Global cops power down world’s ‘most prolific’ DDoS dealership
LA County Superior Court closes doors to reboot justice after ransomware attack
Cybercrooks crafting solo careers in wake of ransomware takedowns
Oracle coughs up $115M to make privacy case go away

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

EU gave CrowdStrike the keys to the Windows kernel, claims Microsoft
Two Russians sanctioned over cyberattacks on US critical infrastructure
10 more big devops gotchas to watch out for
Focusing open source on security, not ideology

* bsc#1205628 Cross-References: * CVE-2022-4065

Semantic Kernel: Diving into Microsoft’s AI orchestration SDK

Several security issues were fixed in Thunderbird.

Cellebrite got into Trump shooter’s Samsung device in just 40 minutes

Update to 115.13.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-31/ https://www.thunderbird.net/en-US/thunderbird/115.13.0/releasenotes/

CrowdStrike’s Falcon Sensor also linked to Linux kernel panics and crashes
The Risks Inherent in Including Security Modules At Kernel Level: Lessons From CrowdStrike Incident

Memory corruption in WebGL API. (CVE-2024-6600) Race condition in permission assignment. (CVE-2024-6601) Memory corruption in thread creation. (CVE-2024-6603) Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13. (CVE-2024-6604)

Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features:

Backport fix for CVE-2023-49528 and backport fixes for compatibility with Mesa 24.0.6+ / 24.1.4+ for VA-API

update to 126.0.6478.182 High CVE-2024-6772: Inappropriate implementation in V8 High CVE-2024-6773: Type Confusion in V8 High CVE-2024-6774: Use after free in Screen Capture High CVE-2024-6775: Use after free in Media Stream

Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features:

An update that fixes 22 vulnerabilities is now available.

Beyond the blue screen of death: Why software updates matter

The widespread IT outages triggered by a faulty CrowdStrike update have put software updates in the spotlight. Here’s why you shouldn’t dread them.

The complexities of cybersecurity update processes

If a software update process fails, it can lead to catastrophic consequences, as seen today with widespread blue screens of death blamed on a bad update by CrowdStrike

update to 126.0.6478.182 High CVE-2024-6772: Inappropriate implementation in V8 High CVE-2024-6773: Type Confusion in V8 High CVE-2024-6774: Use after free in Screen Capture High CVE-2024-6775: Use after free in Media Stream

Update to 3.0.4

New bugfix and security update

Rebase to v2.19.5

Update to 3.24.43

Update to 3.0.4

UK cops arrest teen suspect in MGM Resorts cyberattack probe

https://security-tracker.debian.org/tracker/DSA-5733-1

CrowdStrike Windows patchpocalypse could take weeks to fix, IT admins fear

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Messy data is holding enterprises back from AI
CrowdStrike file update bricks Windows machines around the world
North Korea likely behind takedown of Indian crypto exchange WazirX
Beijing’s attack gang Volt Typhoon was a false flag inside job conspiracy: China

This is the July 2024 security update for .NET 6. Release Notes SDK: https://github.com/dotnet/core/blob/main/release- notes/6.0/6.0.32/6.0.132.md Runtime: https://github.com/dotnet/core/blob/main/release-

Security fixes for https://nvd.nist.gov/vuln/detail/CVE-2024-38875 https://nvd.nist.gov/vuln/detail/CVE-2024-39329 https://nvd.nist.gov/vuln/detail/CVE-2024-3930 https://nvd.nist.gov/vuln/detail/CVE-2024-39614

Fix for CVE-2024-38517.

Developer productivity poorly understood, report says
Judge mostly drags SEC’s lawsuit against SolarWinds into the recycling bin
Kaspersky challenges US government to put up or shut up about Kremlin ties
Russia’s FIN7 is peddling its EDR-nerfing malware to ransomware gangs

* bsc#1220145 * bsc#1223363 * bsc#1223681 * bsc#1223683 * bsc#1225211

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1210619 * bsc#1220537 * bsc#1223363 * bsc#1223683 * bsc#1225211

Red Hat Enterprise Linux and Secure Boot in the cloud
Red Hat Advanced Cluster Security Cloud Service is now Generally Available
Red Hat’s path to post-quantum cryptography
Maximum-severity Cisco vulnerability allows attackers to change admin passwords
Talk of GitLab sale highlights growing importance of DevSecOps platforms

stunnel could allow unintended access to network services.

Building next-generation applications with the Windows Application SDK