Menu

Monthly Archives: July 2024

* bsc#1224122 Cross-References: * CVE-2024-3727

How to use HybridCache in ASP.NET Core
Firms skip security reviews of major app updates about half the time

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Release the hounds! Securing datacenters may soon need sniffer dogs

https://security-tracker.debian.org/tracker/DSA-5732-1

Google’s Genkit for Go brings AI app development to Go language
Merged Exabeam and LogRhythm cut jobs, face lawsuit
Smashing Security podcast #381: Trump shooting conspiracy, Squarespace account hijack, and the butt stops here

https://security-tracker.debian.org/tracker/DSA-5731-1

Google rolls out new dev tools focusing on open source and GenAI
Kaspersky gives US customers six months of free updates as a parting gift
Deno adds workspaces for managing monorepos
HardBit ransomware – what you need to know
Ransomware continues to pile on costs for critical infrastructure victims
Salesforce previews Einstein-powered service agent
London council accuses watchdog of ‘exaggerating’ danger of 2020 raid on residents’ data
Mistral’s new Codestral Mamba to aid longer code generation
Exim 4.98 Addresses Critical Vulnerabilities, Bolsters Email Server Security
Frequently sought solutions for JavaScript

* bsc#1227399 Cross-References: * CVE-2024-34750

* bsc#1225771 Cross-References: * CVE-2024-5564

* bsc#1222665 * bsc#1227554 * bsc#1227560 Cross-References:

* bsc#1227554 * bsc#1227560 * bsc#1227561 * bsc#1227562 * bsc#1227563

Theia IDE: Eclipse’s answer to Visual Studio Code
Craig Wright admits he isn’t the inventor of Bitcoin after High Court judgment in UK

This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732

This update fixes CVE-2024-24791

Iran’s MuddyWater phishes Israeli orgs with custom BugSleep backdoor
Microsoft pushes .NET 9 Preview 6 with a range of improvements

https://security-tracker.debian.org/tracker/DSA-5730-1

OpenJDK plan calls for restricting JNI usage
Scattered Spider’s fave new ransomware tools are RansomHub and Qilin
Hello, is it me you’re looking for? How scammers get your phone number

Your humble phone number is more valuable than you may think. Here’s how it could fall into the wrong hands – and how you can help keep it out of the reach of fraudsters.

Exploring Linux 6.10: Guide to Key Security Enhancements & Updates for Admins
The AI Fix #7: Can AI speak dolphin and do robots lick toads?
Don’t be complacent on cybersecurity resilience
Securing IT Assets: Practical Strategies for Linux Admins & IT Teams

Several security issues were fixed in the Linux kernel.

* bsc#1220145 * bsc#1223363 * bsc#1223681 * bsc#1223683

How to Secure Your Data Warehouse in a Linux System
Privacy group complains to UK regulator about Meta scraping user data to train AI

Several security issues were fixed in the Linux kernel.

An update that fixes three vulnerabilities is now available.

Several security issues were fixed in the Linux kernel.

What senior developers do
Learning cloud cost management the hard way

* bsc#1215420 * bsc#1220833 * bsc#1221656 * bsc#1221659 * bsc#1222005

How to master multi-tenant data management
DarkGate, the Swiss Army knife of malware, sees boom after rival Qbot crushed
Kaspersky culls staff, closes doors in US amid Biden’s ban
Disney hacked? NullBulge claims to have stolen 1.1 TB of data from internal Slack channels
ZDI shames Microsoft for – yet another – coordinated vulnerability disclosure snafu
Infoseccers claim Squarespace migration linked to DNS hijackings at Web3 firms

* bsc#1221530 Cross-References: * CVE-2024-21503

* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828

7 reasons analytics and ML fail to meet business objectives

* bsc#1224122 * bsc#1226136 Cross-References: * CVE-2024-24786

Are we thinking too small about generative AI?
How to choose the right database for your application
Google reportedly in talks to buy infosec outfit Wiz for $23 billion
I spy another mSpy breach: Millions more stalkerware buyers exposed
UK cyber-boss slams China’s bug-hoarding laws
Should ransomware payments be banned? – Week in security with Tony Anscombe

The issue of whether to ban ransomware payments is a hotly debated topic in cybersecurity and policy circles. What are the implications of outlawing these payments, and would the ban be effective?

Vanilla upstream kernel version 6.6.37 fix bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33374

Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack. (CVE-2024-37894) References:

This vulnerability allows an attacker performing a meddler-in-the-middle attack between Palo Alto Networks PAN-OS firewall and a RADIUS server to bypass authentication and escalate privileges to ¢”superuser¢” when RADIUS authentication is in use and either CHAP or PAP is selected in the RADIUS server profile.

Beyond the usual suspects: 5 fresh data science tools to try today

* bsc#1216377 Cross-References: * CVE-2023-45803

* bsc#1189936 * bsc#1190531 * bsc#935380 Cross-References:

Three words to send a chill down your spine: Snowflake. Intrusion. Alert
Red Hat VEX files for CVEs are now generally available

Upstream kernel version 6.6.37 fix bugs and vulnerabilities. The dwarves, kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.

This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732

Backport fix for CVE-2024-4067.

Backport security fixes for CVE-2024-4216, CVE-2024-4068, CVE-2024-4067.

Car dealer software slinger CDK Global said to have paid $25M ransom after cyberattack

https://security-tracker.debian.org/tracker/DSA-5729-1

White House urged to double check Microsoft isn’t funneling AI to China via G42 deal
CISA broke into a US federal agency, and no one noticed for a full 5 months
Understanding IoT security risks and how to mitigate them | Cybersecurity podcast

As security challenges loom large on the IoT landscape, how can we effectively counter the risks of integrating our physical and digital worlds?

Identity: the new security perimeter
Break-in at ‘third-party cloud platform’ leaked 110M customer records, says AT&T

* bsc#1226448 Cross-References: * CVE-2024-4032

* bsc#1226495 * bsc#1227239 Cross-References: * CVE-2024-34703

Several security issues were fixed in the Linux kernel.

RansomHub ransomware – what you need to know
Generative AI won’t fix cloud migration

Backport fix for CVE-2024-4032.

Backport fix for CVE-2024-4032.

Singapore’s banks to ditch texted one-time passwords
China’s APT41 crew adds a stealthy malware loader and fresh backdoor to its toolbox
‘Gay furry hackers’ say they’ve disbanded after raiding Project 2025’s Heritage Foundation
HR professionals trust AI recommendations

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5728-1

https://security-tracker.debian.org/tracker/DSA-5727-1

OpenSSH bug leaves RHEL 9 and the RHELatives vulnerable
Amazon Bedrock updated with contextual grounding, RAG connectors
Safety off: Programming in Rust with `unsafe`