Menu

Monthly Archives: August 2024

* bsc#1082555 * bsc#1193454 * bsc#1193554 * bsc#1193787 * bsc#1194324

* bsc#1065729 * bsc#1179610 * bsc#1186463 * bsc#1216834 * bsc#1218820

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695

* bsc#1228105 Cross-References: * CVE-2024-6345

How a BEC scam cost a company $60 Million – Week in security with Tony Anscombe

Business email compromise (BEC) has once again proven to be a costly issue, with a company losing $60 million in a wire transfer fraud scheme

After nearly 3B personal records leak online, Florida data broker confirms it was ransacked by cyber-thieves
Unicoin hints at potential data meddling after G-Suite compromise
String comparisons in Java
Navigating the future of cybersecurity

* bsc#1229129 Cross-References: * CVE-2023-42667 * CVE-2023-49141

* bsc#1229069 Cross-References: * CVE-2023-31315

* bsc#1229069 Cross-References: * CVE-2023-31315

* bsc#1214327 * bsc#1218413 * bsc#1222120 * bsc#1227426 * bsc#1227513

* bsc#1065729 * bsc#1088701 * bsc#1149446 * bsc#1179610 * bsc#1186463

Revolutionizing cloud security with AI
Everything’s coming up Python!

* bsc#1082555 * bsc#1156395 * bsc#1190336 * bsc#1191958 * bsc#1193454

Rust team announces 2024 development goals
GitHub rolls out AI-powered fixes for code vulnerabilities
Anthropic adds prompt caching to Claude, cutting costs for developers

https://security-tracker.debian.org/tracker/DSA-5749-1

DARPA, ARPA-H award $14m to 7 AIxCC semifinalists, with a catch
Google raps Iran’s APT42 for raining down spear-phishing attacks

* bsc#1156395 * bsc#1190336 * bsc#1191958 * bsc#1193454 * bsc#1193554

* bsc#1228535 Cross-References: * CVE-2024-7264

* bsc#1226463 * bsc#1227138 Cross-References: * CVE-2024-5535

* bsc#1225907 * bsc#1226463 * bsc#1227138 Cross-References:

Russian man who sold logins to nearly 3,000 accounts gets 40 months in jail
Mad Liberator extortion crew emerges on the cyber-crook scene

* bsc#1227178 Cross-References: * CVE-2024-39134

* bsc#1227178 Cross-References: * CVE-2024-39134

Over 40 million Kakao Pay users’ data somehow ended up with Alipay
China-linked cyber-spies infect Russian govt, IT sector

https://security-tracker.debian.org/tracker/DSA-5743-2

Russian cyber snoops linked to massive credential-stealing campaign
Texas sues GM for selling driver data to analytics, insurance companies
Enzo Biochem ordered to cough up $4.5 million over lousy security that led to ransomware disaster
Ransomware kingpin who called himself “J P Morgan” extradited to United States
Palo Alto Networks execs apologize for ‘hostesses’ dressed as lamps at Black Hat booth

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1065729 * bsc#1088701 * bsc#1149446 * bsc#1179610 * bsc#1186463

* bsc#1156395 * bsc#1190336 * bsc#1191958 * bsc#1193454 * bsc#1193554

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695

Improved vulnerability reporting on Quay.io
Is Lenovo a blind spot in US anti-China security measures?
Functional programming with Java collections
UK Prime Minister Keir Starmer and Prince William deepfaked in investment scam campaign
The magic of RAG is in the retrieval
Indian telcos to cut off scammy, spammy, telemarketers for two whole years
NIST finalizes trio of post-quantum encryption standards
Patch Tuesday brings 90 new Microsoft CVEs, six already under exploit
Go 1.23 arrives with faster PGO build times

https://security-tracker.debian.org/tracker/DSA-5748-1

Six ransomware gangs behind over 50% of 2024 attacks
US accuses man of being ‘elite’ ransomware pioneer they’ve hunted for years
Linux Foundation’s adoption of OMI could pave way for ethical LLMs, analysts say
The great location leak: Privacy risks in dating apps

Convenience may come at a cost – such as when your favorite app reveals your exact coordinates to someone you’d rather keep at a distance

The AI Fix #11: AI gods, a robot dentist, and an angry human
Feds bust minor league Radar/Dispossessor ransomware gang
JDK 23: The new features in Java 23

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Orion SA says scammers conned company out of $60 million
BlackHat USA 2024: Key Takeaways for Linux Admins & InfoSec Pros
Staying a Step Ahead of Adversaries: Mitigating Chromium’s Security Flaws on Linux
Who uses LLM prompt injection attacks IRL? Mostly unscrupulous job seekers, jokesters and trolls
Remember quantum computing in the cloud?
Why I don’t buy Apple products
iPaaS in an AI-driven world
‘Digital arrest’ scams are big in India and may be spreading
AMD won’t patch Sinkclose security bug on older Zen CPUs
Tauri 2.0 moves core functionality to plugins
Attacker steals personal data of 200k+ people with links to Arizona tech school
5 Key Benefits Of Code Signing Solutions
Mega money, unfathomable violence pervade thriving underground doxxing scene
5 Open-Source Blockchain Technologies That Linux Users Need to Know About
Google Cloud adds 3 new Apache Airflow operators to Vertex AI
The BlackSuit ransomware gang has demanded over $500 million since 2022

Multiple vulnerabilities have been discovered in protobuf-c, the worst of which could result in denial of service.

5 things great data science product managers do
Evolve your cloud security knowledge
Practical strategies for mitigating API security risks
Tabnine AI coding assistant flexes its models
Most AI software will stay proprietary

Multiple vulnerabilities have been discovered in PHP, the worst of which can lead to a denial of service.

A vulnerability has been discovered in protobuf and protobuf-python, which can lead to a denial of service.

A vulnerability has been discovered in dpkg, which allows for directory traversal.

Multiple vulnerabilities have been discovered in MuPDF, the worst of which could lead to arbitrary code execution.

Trump campaign cites Iran election phish claim as evidence leaked docs were stolen

Update NSS to 3.103.0 Update to Firefox 129.0

The UN unanimously agrees that cybercrime is bad, mkay?

https://security-tracker.debian.org/tracker/DSA-5747-1

Black Hat USA 2024 recap – Week in security with Tony Anscombe

Unsurprisingly, many discussions focused on the implications of the recent CrowdStrike outage, including the lessons it may have offered for bad actors

Black Hat USA 2024: All eyes on election security

In this high-stakes year for democracy, the importance of robust election safeguards and national cybersecurity strategies cannot be understated