Menu

Monthly Archives: August 2024

New libpcap packages are available for Slackware 15.0 and -current to fix security issues.

Check your IP cameras: There’s a new Mirai botnet on the rise
Use cases and ecosystem for OpenShift confidential containers
Simplify identity management with Red Hat IdM

Update to upstream 2.1-44. 20240813 Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision 0x5003605 up to 0x5003707; Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002802 up to 0x7002904;

Security fix for CVE-2024-8088

error handling in x86 IOMMU identity mapping [XSA-460, CVE-2024-31145] PCI device pass-through with shared resources [XSA-461, CVE-2024-31146]

error handling in x86 IOMMU identity mapping [XSA-460, CVE-2024-31145] PCI device pass-through with shared resources [XSA-461, CVE-2024-31146]

RansomHub hits 210 victims in just 6 months
Green Berets storm building after hacking its Wi-Fi

https://security-tracker.debian.org/tracker/DSA-5761-1

Microsoft .NET Aspire boosts integrations, testing

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-4558

An update that fixes four vulnerabilities is now available.

Stealing cash using NFC relay – Week in Security with Tony Anscombe

The discovery of the NGate malware by ESET Research is another example of how sophisticated Android threats have become

Analysis of two arbitrary code execution vulnerabilities affecting WPS Office

Demystifying CVE-2024-7262 and CVE-2024-7263

Tired of airport security queues? SQL inject yourself into the cockpit, claim researchers

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

* bsc#1227052 Cross-References: * CVE-2024-6104

An update that fixes four vulnerabilities is now available.

Wider horizons: New tools (and languages) for Python developers
The paradox of chaos engineering
Quest Software updates erwin data modeling and data intelligence tools
Iran hunts down double agents with fake recruiting sites, Mandiant reckons

Security fix for CVE-2024-8088

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

https://security-tracker.debian.org/tracker/DSA-5763-1

US indicts duo over alleged Swatting spree that targeted elected officials
TypeScript 5.6 enters release candidate stage
What a coincidence. Spyware makers, Russia’s Cozy Bear seem to share same exploits
Feds claim sinister sysadmin locked up thousands of Windows workstations, demanded ransom
Rock Chrome hard enough and get paid half a million
$2.5 million reward offered for hacker linked to notorious Angler Exploit Kit

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Brain Cipher claims attack on Olympic venue, promises 300 GB data leak
‘Big-game hunting’ – Ransomware gangs are focusing on more lucrative attacks
Crypto scammers who hacked McDonald’s Instagram account say they stole $700,000
Simpler web APIs in .NET with Sisk
Static classes and inner classes in Java
Microsoft .NET Community Toolkit adds .NET 8, NativeAOT support

* bsc#1227353 Cross-References: * CVE-2024-39884

Best practices for handling exceptions in C#
CrowdStrike’s meltdown didn’t dent its market dominance … yet

Security fix for CVE-2024-32487 – less with LESSOPEN mishandles n in paths

https://security-tracker.debian.org/tracker/DSA-5760-1

Several security issues were fixed in the Linux kernel.

Microsoft hosts a security summit but no press, public allowed
Microsoft cuts BinaryFormatter from .NET 9
Proof-of-concept code released for zero-click critical IPv6 Windows hole
Microsoft announces Pinecone .NET SDK
Humble UI offers a Clojure-based desktop UI framework
Iran’s Pioneer Kitten hits US networks via buggy Check Point, Palo Alto gear
Dick’s Sporting Goods discloses cyberattack
From Copilot to Copirate: How data thieves could hijack Microsoft’s chatbot
OpenShift Commons Security Special Interest Group (SIG) at Red Hat Summit 2024
AWS’ Amazon Bedrock GenAI service gets cross-region inferencing feature
University criticised for using Ebola outbreak lure in phishing test
The ultimate dual-use tool for cybersecurity
Better than reflection: Using method handles and variable handles in Java
I switched to a vertical mouse and I’m never looking back. Here’s why.

* bsc#1228696 * bsc#1228697 * bsc#1228698 Cross-References:

Woman uses AirTags to nab alleged parcel-pinching scum

CVE-2024-23184: A large number of address headers in email resulted in excessive CPU usage. CVE-2024-23185: Abnormally large email headers are now truncated or discarded, with a limit of 10MB on a single header and 50MB for all the headers of all the parts of an email.

CVE-2024-23184: A large number of address headers in email resulted in excessive CPU usage. CVE-2024-23185: Abnormally large email headers are now truncated or discarded, with a limit of 10MB on a single header and 50MB for all the headers of all the parts of an email.

Chinese broadband satellites may be Beijing’s flying spying censors, think tank warns
Microsoft donates Mono cross-platform .NET to WineHQ

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1225202 * bsc#1225302 Cross-References: * CVE-2021-47378

* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202

Intel’s Software Guard Extensions broken? Don’t panic
Volt Typhoon suspected of exploiting Versa SD-WAN bug since June
The AI Fix #13: ChatGPT runs for mayor, and should we stop killer robots?
Microsoft security tools questioned for treating employees as threats

* bsc#1226463 * bsc#1227138 Cross-References: * CVE-2024-5535

* bsc#1225202 Cross-References: * CVE-2021-47378

* bsc#1225202 * bsc#1225302 Cross-References: * CVE-2021-47378

Multiple security issues were discovered in Python, a high-level, interactive, object-oriented language: CVE-2024-0397

Quantum computing attacks on cloud-based systems

* bsc#1225983 Cross-References: * CVE-2024-21096

* bsc#1225202 Cross-References: * CVE-2021-47378

What AI regulations mean for software developers
Are you the boss of your feed?
Kotlin update shines on garbage collector

https://security-tracker.debian.org/tracker/DSA-5759-1

Deno 1.46 simplifies CLI
Microsoft mistake blows up admins’ inboxes with fake malware alerts
Watchdog warns FBI is sloppy on secure data storage and destruction
Seattle airport ‘possible cyberattack’ snarls travel yet again
AMD internal data reportedly offered for sale
The Future-Proof Server: Antivirus and Beyond for Linux Admins
31.5M invoices, contracts, patient consent forms, and more exposed to the internet

* bsc#1027519 * bsc#1227355 * bsc#1228574 * bsc#1228575

The definitive guide to data pipelines
The slow evolution of enterprise tech
Developing agile ETL flows with Ballerina

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service or request smuggling.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.