Menu

Monthly Archives: July 2024

OpenSilver 3.0 previews AI-powered UI designer for .NET
Exposed! The AI-enhanced social media bot farm that pumped out Kremlin propaganda on Twitter
Smashing Security podcast #380: Teachers TikTok targeted, and fraud in the doctors’ waiting room
Advance Auto Parts: 2.3M people’s data accessed when crims broke into our Snowflake account

* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828

Privacy expert put away for 9 years after ‘grotesque’ cyberstalking campaign
How to use FastEndpoints in ASP.NET Core
Microsoft updates its serverless Azure Functions

* bsc#1220145 * bsc#1223363 * bsc#1223683 * bsc#1225211

You had a year to patch this Veeam flaw and now it’s going to hurt
Japanese space agency spotted zero-day attacks while cleaning up attack on M365

Updated to latest upstream (128.0)

Fix CVE-2024-39936.

Security fix for CVE-2024-5187

This is the May 2024 release for .NET 8. This is a security update for .NET 8. Release notes: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.5/8.0.5.md

Microsoft moves forward with C# 13, offering overload resolution
Snowflake lets admins make MFA mandatory across all user accounts
Enhancing your cyber defense with Wazuh threat intelligence integrations
Malware that is ‘not ransomware’ wormed its way through Fujitsu Japan’s systems

* bsc#1224123 Cross-References: * CVE-2024-3727

* bsc#1220145 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223059

Ransomware crews investing in custom data stealing malware
How platform teams lead to better, faster, stronger enterprises
Progressive web app essentials: Service worker background sync

* bsc#1119113 * bsc#1191958 * bsc#1195065 * bsc#1195254 * bsc#1195775

Several security issues were fixed in Firefox.

Big Tech’s eventual response to my LLM-crasher bug report was dire

Multiple vulnerabilities have been discovered in Buildah, the worst of which could lead to privilege escalation.

ViperSoftX variant spotted abusing .NET runtime to disguise data theft

Several security issues were fixed in dotnet6, dotnet8.

RADIUS networking protocol blasted into submission through MD5-based flaw
Critical Windows licensing bugs – plus two others under attack – top Patch Tuesday
FBI, cyber-cops zap ~1K Russian AI disinfo Twitter bots
Google, Udacity offer free course on Gemini API
8 reasons developers love Go—and 8 reasons they don’t
AI’s moment of disillusionment
The next 10 years for cloud computing
What’s new in MySQL 9.0
Understanding DiskANN, a foundation of the Copilot Runtime
How to use Refit to consume APIs in ASP.NET Core
Visual Studio Code previews incoming/outgoing changes graph
ECMAScript 2024 JavaScript standard approved
JetBrains launches Qodana Self-Hosted
AWS approach to RAG evaluation could help enterprises reduce AI spending
How to get started with GraphQL
Intro to multithreaded JavaScript
Rust types team moves forward on next-gen trait solver
Qdrant unveils vector-based hybrid search for RAG
Download our NoSQL database enterprise buyer’s guide
The AI Fix #6: AI lobotomies, and bots scam scam bots
Judge dismisses lawsuit over GitHub Copilot AI coding assistant
Ransomware attack on blood-testing service puts lives in danger in South Africa
Elexon’s Insight into UK electricity felled by expired certificate
Evolve Bank & Trust confirms LockBit stole 7.6 million people’s data

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Multiple vulnerabilities have been discovered in LIVE555 Media Server, the worst of which could lead to a denial of service.

Houthi rebels are operating their own GuardZoo spyware
All the brilliance of AI on minimalist platforms
Microsoft China staff can’t log on with an Android, so Redmond buys them iThings
Scammers double-scam victims by offering to help recover from scams
China’s APT40 gang is ready to attack vulns within hours or days of public release
Researchers reveal flaws in AI agent benchmarking
Rust leaps forward in language popularity index
FTC’s non-compete ban almost certainly dead, based on a Texas federal court decision
ChatGPT for Mac app flaw left users’ chat history exposed
Microsoft forgets about SwiftKey’s support site

In recognition of its profound impact, July 16 is celebrated as Artificial Intelligence (AI) Appreciation Day. AI is one of the defining technologies of our era, and its adoption is skyrocketing. People are using AI tools like OpenAI’s ChatGPT and Microsoft Copilot for a wide range of personal applications. Indeed, AI is integrated into various […]

Avast secretly gave DoNex ransomware decryptors to victims before crims vanished

* bsc#1222045 Cross-References: * CVE-2024-29025

* bsc#1223965 Cross-References: * CVE-2024-33394

* bsc#1226469 Cross-References: * CVE-2024-37891

Navigating Europe’s digital identity crossroads
Selfie-based authentication raises eyebrows among infosec experts
Not-so-OpenAI allegedly never bothered to report 2023 data breach
A decade after collapsing, crypto exchange Mt Gox repays some investors

An update that fixes 7 vulnerabilities is now available.

Navigating the Cybersecurity Maze: Advanced Linux Security Practices for Professionals

Update to 2024.07.02

https://security-tracker.debian.org/tracker/DSA-5726-1

A vulnerability has been discovered in Stellarium, which can lead to arbitrary file writes.

Social media and teen mental health – Week in security with Tony Anscombe

Social media sites are designed to make their users come back for more. Do laws restricting children’s exposure to addictive social media feeds have teeth or are they a political gimmick?

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which could arbitrary code execution.

Multiple vulnerabilities have been discovered in the X.Org X11 library, the worst of which could lead to a denial of service.

A vulnerability has been discovered in KDE Plasma Workspaces, which can lead to privilege escalation.

Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.

Devs claim Apple is banning VPNs in Russia ‘more effectively’ than Putin

Two vulnerabilities were discovered in the GSS message token handling in krb5, the MIT implementation of Kerberos. An attacker can take advantage of these flaws to bypass integrity protections or cause a denial of service.

Comprehensive Security Validation and Breach and Attack Simulation for Linux
Cancer patient forced to make terrible decision after Qilin attack on London hospitals
Latest Ghostscript vulnerability haunts experts as the next big breach enabler

Multiple vulnerabilities have been discovered in BusyBox, the worst of which could lead to arbitrary code execution.

A vulnerability has been discovered in Coreutils, which can lead to a heap buffer overflow and possibly aribitrary code execution.

* bsc#1227186 * bsc#1227187 Cross-References: * CVE-2024-37370

Europol says mobile roaming tech is making its job too hard

Multiple vulnerabilities have been discovered in GraphicsMagick, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in TigerVNC, the worst of which could lead to remote code execution.