Menu

Monthly Archives: August 2024

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Alleged Karakut ransomware scumbag charged in US

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

https://security-tracker.debian.org/tracker/DSA-5758-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

* bsc#1224188 Cross-References: * CVE-2021-36386

* bsc#1129596 Cross-References: * CVE-2019-9656

PWA phishing on Android and iOS – Week in security with Tony Anscombe

Phishing using PWAs? ESET Research’s latest discovery might just ruin some users’ assumptions about their preferred platform’s security

Method overloading in the JVM
US sues Georgia Tech over alleged cybersecurity failings as a Pentagon contractor

An update that fixes 20 vulnerabilities is now available.

* bsc#1228574 * bsc#1228575 Cross-References: * CVE-2024-31145

* bsc#1226316 * bsc#1228648 Cross-References: * CVE-2024-6600

* bsc#1219559 * bsc#1221563 Cross-References: * CVE-2023-52425

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695 * bsc#1228696

Navigating the AI frontier
JDK 24 preps for restrictions on JNI use
Uniting the brightest minds in security, network and cloud

Bump to version 5.9.4

https://security-tracker.debian.org/tracker/DSA-5757-1

SolarWinds left critical hardcoded credentials in its Web Help Desk product
The reality of AI-centric coding
CrowdStrike deja vu as ‘performance issue’ leaves systems sluggish
How regulatory standards and cyber insurance inform each other

Should the payment of a ransomware demand be illegal? Should it be regulated in some way? These questions are some examples of the legal minefield that cybersecurity teams must deal with

Halliburton probes ‘an issue’ disrupting business ops

* bsc#1224044 Cross-References: * CVE-2024-34397

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Ransomware batters critical industries, but takedowns hint at relief
Hacker leaks upcoming episodes of Netflix shows online following security breach
Authentication and Authorization in Red Hat OpenShift and Microservices Architectures
Deployment considerations for Red Hat OpenShift Confidential Containers solution
Over 100,000 Oregon Zoo visitors warned that their payment card details were stolen in security breach
This uni thought it would be a good idea to do a phishing test with a fake Ebola scare
Why you’ll love dev containers
Kick off early Octoberfest with an EUC-fest
Visual Studio boosts C++ development
How to avoid exceptions in C#

Several security issues were fixed in QEMU.

Cisco calls for United Nations to revisit cyber crime Convention
Foiling bot attacks with AI-powered telemetry

Fix web process cache suspend/resume when sandbox is enabled. Fix accelerated images disappearing after scrolling. Fix video flickering with DMA-BUF sink. Fix pointer lock on X11. Fix movement delta on mouse events in GTK3.

You probably want to patch this critical GitHub Enterprise Server bug now

Several security issues were fixed in the Linux kernel.

GitHub survey finds nearly all developers using AI coding tools
The AI Fix #12: AI made from human brain cells, and is there life after death?
110K domains targeted in ‘sophisticated’ AWS cloud extortion campaign
Russia tells citizens to switch off home surveillance because the Ukrainians are coming

* bsc#1177179 Cross-References: * CVE-2020-26159

* bsc#1228574 * bsc#1228575 Cross-References: * CVE-2024-31145

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Martin Kaesberger discovered a vulnerability which affects multiple OpenStack components (Nova, Glance and Cinder): Malformed QCOW2 disk images may result in the disclosure of arbitrary files.

Microsoft’s new Phi 3.5 LLM models surpass Meta and Google
State of JavaScript: Insights from the latest JavaScript developer survey
3 languages changing data science
API security starts with API discovery
Deadbeat dad faked his own death by hacking government databases
Meta working on a Self-Taught Evaluator for LLMs
Chipmaker Microchip reveals cyber attack whacked manufacturing capacity

https://security-tracker.debian.org/tracker/DSA-5756-1

https://security-tracker.debian.org/tracker/DSA-5755-1

https://security-tracker.debian.org/tracker/DSA-5754-1

https://security-tracker.debian.org/tracker/DSA-5753-1

https://security-tracker.debian.org/tracker/DSA-5752-1

Use the AI S-curve to drive meaningful technological change
Plane tracker FlightAware admits user passwords, SSNs exposed for years

Several security issues were fixed in Cacti.

* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222986 * bsc#1222987

* bsc#1228046 * bsc#1228047 * bsc#1228048 * bsc#1228050 * bsc#1228051

* bsc#1228046 * bsc#1228047 * bsc#1228048 * bsc#1228050 * bsc#1228051

* bsc#1212968 * bsc#1215311 * bsc#1227322 Cross-References:

* bsc#1228143 Cross-References: * CVE-2024-1013

Achieving cloudops excellence
Java polymorphism and its types
Download the high-performance AI enterprise buyer’s guide
Iran named as source of Trump campaign phish, leaks
Digital wallets can allow purchases with stolen credit cards
Microsoft .NET 9 previews C#, runtime, SDK improvements
OpenAI kills Iranian accounts using ChatGPT to write US election disinfo

Introducing key EDR functionality In today’s rapidly evolving cyber landscape, staying ahead of threats requires not just robust defenses, but also smart, efficient tools that empower defenders without overburdening them. Webroot by OpenText recognizes the vital role that endpoint detection and response (EDR) capabilities play in a comprehensive cybersecurity strategy. As we continue our EDR […]

Multiple flaws in Microsoft macOS apps unpatched despite potential risks
National Public Data tells officials ‘only’ 1.3M people affected by intrusion

* bsc#1011205 * bsc#1093641 * bsc#1125882 * bsc#1167400 * bsc#1207973

* bsc#1223155 Cross-References: * CVE-2024-31744

* bsc#1192145 * bsc#1209657 * bsc#1218336 * bsc#1218447 * bsc#1218479

* bsc#1222835 * bsc#1222837 * jsc#SLE-23879 Cross-References:

* bsc#1184942 * bsc#1186060 * bsc#1192145 * bsc#1194516 * bsc#1208995

* bsc#1160688 * bsc#1223100 * jsc#PED-7677 * jsc#SLE-9298

How to bring runaway cloud costs under control
Cutting Kubernetes costs with virtual clusters
Security takes a front seat
RansomHub-linked EDR-killing malware spotted in the wild

https://security-tracker.debian.org/tracker/DSA-5751-1

https://security-tracker.debian.org/tracker/DSA-5750-1