Menu

Monthly Archives: August 2024

Multiple vulnerabilities have been discovered in runc, the worst of which could lead to privilege escalation.

A vulnerability has been discovered in Ruby on Rails, which can lead to remote code execution via serialization of data.

New version 8.5.5

* bsc#1228256 * bsc#1228257 Cross-References: * CVE-2024-1737

* bsc#1220356 * bsc#1227525 Affected Products: * Basesystem Module 15-SP5

Black Hat USA 2024: How cyber insurance is shaping cybersecurity strategies

Cyber insurance is not only a safety net, but it can also be a catalyst for advancing security practices and standards

Multiple vulnerabilities have been discovered in GnuPG, the worst of which could lead to signature spoofing.

Multiple vulnerabilities have been discovered in Bundler, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in GPAC, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in libde265, the worst of which could lead to arbitrary code execution.

Raptor Lake microcode limits Intel chips to a mere 1.55 volts to prevent CPU destruction
Why tech-savvy leadership is key to cyber insurance readiness

Having knowledgeable leaders at the helm is crucial for protecting the organization and securing the best possible cyber insurance coverage

Understanding escalating cyber threats
Pro-Iran groups lay groundwork for ‘chaos and violence’ as US election meddling intensifies

Multiple vulnerabilities have been discovered in ncurses, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in QEMU, the worst of which could lead to a denial of service.

A vulnerability has been discovered in Nautilus, which can lead to a denial of service.

A strategic road map for navigating the cloud skills shortage

Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation. For the oldstable distribution (bullseye), this problem has been fixed

Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation. For the stable distribution (bookworm), this problem has been fixed in

* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671

It’s 2024 and we’re just getting round to stopping browsers insecurely accessing 0.0.0.0
Hello? Are you talking on a Cisco SPA300 or SPA500 IP phone? Now’s the time to junk ’em
AWS closes several cloud services to new customers

https://security-tracker.debian.org/tracker/DSA-5746-1

https://security-tracker.debian.org/tracker/DSA-5745-1

Delta: CrowdStrike’s offer to help in Falcon meltdown was too little, too late
US ‘laptop farm’ man accused of outsourcing his IT jobs to North Korea to fund weapons programs
Node.js unveils experimental TypeScript support
Over $40 million recovered and arrests made within days of firm realising it had fallen for Business Email Compromise scam
Using 1Password on Mac? Patch up if you don’t want your Vaults raided
US elections have never been more secure, says CISA chief

A vulnerability was discovered in odoo, a suite of web based open source business apps. It could result in the execution of arbitrary code.

Multiple cross-site scripting vulnerabilities were discovered in RoundCube webmail. For the stable distribution (bookworm), these problems have been fixed in

Report: Tech misconceptions plague the IT world
Microsoft Teams offers more for developers

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Entrust faces years of groveling to regain browsers’ trust, say rival chiefs
How to use FluentValidation in ASP.NET Core

Kerberos could be made to crash if it received specially crafted input.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Update to upstream 2.1-43. 20240531 Addition of 06-aa-04/0xe6 (MTL-H/U C0) microcode at revision 0x1c; Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-02) at revision 0x4121; Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-03) at revision

Cloud storage lockers from Microsoft and Google used to store and spread state-sponsored malware
Samsung boosts bug bounty to a cool million for cracks of the Knox Vault subsystem

https://security-tracker.debian.org/tracker/DSA-5744-1

https://security-tracker.debian.org/tracker/DSA-5743-1

https://security-tracker.debian.org/tracker/DSA-5742-1

https://security-tracker.debian.org/tracker/DSA-5741-1

Google unveils Flutter GPU API, Dart updates

https://security-tracker.debian.org/tracker/DSA-5739-1

https://security-tracker.debian.org/tracker/DSA-5738-1

Faulty instructions in Alibaba’s T-Head C910 RISC-V CPUs blow away all security
Fighting AI fire with AI fire
Ahead-of-time class loading proposal would speed Java startups
How AI and Machine Learning Are Transforming Cybersecurity Quality Assurance
Small CSS tweaks can help nasty emails slip through Outlook’s anti-phishing net

A vulnerability has been discovered in Bitcoin, which can lead to a denial of service.

* bsc#1228872 Cross-References: * CVE-2024-7383

* bsc#1227296 Cross-References: * CVE-2024-32230

* bsc#1214855 * bsc#1219267 * bsc#1219268 * bsc#1219438 * bsc#1221916

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

Multiple vulnerabilities have been discovered in aiohttp, the worst of which could lead to service compromise.

What is Google Cloud’s generative AI evaluation service?
Police take just 2 days to recover $40M stolen in business email scam
EQT buys majority share in Swiss cybersecurity biz Acronis
Pig-butchering scammer targets BBC journalist
Full-stack development with Java, React, and Spring Boot, Part 3
UK health services call-handling vendor faces $7.7M fine over 2022 ransomware attack
SharpRhino malware targets IT admins – Hunters International gang suspected
Georgia’s voter portal gets a crash course in client versus backend input validation
Microsoft punches back at Delta Air Lines and its legal threats
CrowdStrike hires outside security outfits to review troubled Falcon code

https://security-tracker.debian.org/tracker/DSA-5740-1

JetBrains updates IDEs, improves AI assistant
Google splats device-hijacking exploited-in-the-wild Android kernel bug among others
Sonic Automotive says ransomware-linked CDK software outage cost it $30M
FTC warns consumers of scammers offering to remove all negative information from credit reports
The AI Fix #10: An AI cookery dumpster fire, the ARC prize, and a creepy new AI friend
Bad apps bypass Windows security alerts for six years using newly unveiled trick

Artificial intelligence (AI) and chatbots like ChatGPT are transforming the way educators and students approach education. It’s not just college students leveraging AI to get ahead; high school and even grade school students are using AI resources for their projects and homework. Students can write essays, get math tutoring help, and even create study plans […]

* bsc#1220356 * bsc#1227525 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5

* bsc#1227052 Cross-References: * CVE-2024-6104

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1221302 * bsc#1223059

Users call on Microsoft to update Outlook’s friendly name feature
Extending Red Hat Unified Kernel Images More Securely By Using Addons
Is efficiency on your cloud architect’s radar?

* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671

* bsc#1227147 Cross-References: * CVE-2024-5535

GitHub Copilot: Productivity boost or DORA metrics disaster?
Visual Studio Code 1.92 improves debugging experience
Billion-dollar bust as international op shutters Cryptonator wallet
MDM vendor Mobile Guardian attacked, leading to remote wiping of 13,000 devices
Illinois relaxes biometric privacy law so snafus won’t cost businesses billions
NFL to begin using face scanning tech across all of its stadiums
Python scores its highest rating in Tiobe index
That cyber-heist of 2.9B personal records? There’s a class-action lawsuit looming for that
Your copilot for improved cyber protection
Sneaky SnakeKeylogger slithers into Windows inboxes to steal sensitive secrets

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of Java sandbox restrictions.