Menu

Monthly Archives: September 2024

10 nasty software bugs put thousands of fuel storage tanks at risk of cyberattacks
The AI Fix #17: Why AI is an AWFUL writer and LinkedIn’s outrageous land grab
Cybersecurity and compliance: The dynamic duo of 2024

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

How to spot a North Korean agent before they get comfy inside payroll
Citing security fears, Ukraine bans Telegram on government and military devices
Two men arrested one month after $230 million of cryptocurrency stolen from a single victim
OpenAI Academy to help train developers, offer free credits
A data leak and a data breach
The challenge of cloud computing forensics
Java 23 highlights crypto performance and security
Gleam language reaches 1.5 release

* bsc#1193629 * bsc#1194111 * bsc#1194765 * bsc#1194869 * bsc#1196261

* bsc#1229596 * bsc#1229704 * bsc#1230227 Cross-References:

py7zr could be made to create arbitrary files when extracting the contents of a specially crafted 7z archive.

Multiple vulnerabilities have been found in Tor, the worst of which could result in denial of service.

Some US Kaspersky customers find their security software replaced by ‘UltraAV’
Telegram will now hand over IP addresses, phone numbers of suspects to cops
‘Cybersecurity issue’ takes MoneyGram offline for three days – and counting
Necro malware continues to haunt side-loaders of dodgy Android mods
So how’s Microsoft’s Secure Future Initiative going?

* bsc#1012628 * bsc#1193454 * bsc#1194869 * bsc#1205462 * bsc#1208783

* bsc#1229596 * bsc#1230227 Cross-References: * CVE-2024-6232

* bsc#1228349 Cross-References: * CVE-2024-40909

* bsc#1223521 * bsc#1225099 * bsc#1225313 Cross-References:

UPS supplier’s password policy flip-flops from unlimited, to 32, then 64 characters

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

What you need to know about AI governance
How do you govern a sprawling, disparate API portfolio?
Too much assembly required for AI
Why vector databases aren’t just databases
Move over, Cobalt Strike. Splinter’s the new post-exploit menace in town
Apple’s latest macOS release is breaking security software, network connections

A vulnerability has been found in Emacs and org-mode which could result in arbitrary code execution.

Multiple vulnerabilities have been discovered in liblouis, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in VLC, the worst of which could result in arbitrary code execution.

Multiple vulnerabilities have been discovered in Slurm, the worst of which could result in privilege escalation or code execution.

Multiple vulnerabilities have been discovered in stb, the worst of which lead to a denial of service.

Multiple vulnerabilities have been discovered in gst-plugins-good, the worst of which could lead to denial of service or arbitrary code execution. [More…]

FBI, CISA warning over false claims of hacked voter data – Week in security with Tony Anscombe

With just weeks to go before the US presidential election, the FBI and the CISA are warning about attempts to sow distrust in the electoral process

Google Chrome 129: Addressing Crucial Vulnerabilities and Enhancing Security
Fighting Back Against Hadooken Malware by Strengthening WebLogic Security

Rebase to version 2.6.3

Security fix for CVE-2024-8418

Fix CVE-2024-5535: SSL_select_next_proto buffer overread

Rebase to version 2.6.3

Security fix for CVE-2024-8418

https://security-tracker.debian.org/tracker/DSA-5773-1

How Static Residential Proxies Support Ethical Web Scraping Practices

It was discovered that ruby-saml, a SAML library implementing the client side of a SAML authorization, does not properly verify the signature of the SAML Response, which could result in bypass of authentication in an application using the ruby-saml library.

JavaScript community challenges Oracle’s JavaScript trademark
US indicts two over socially engineered $230M+ crypto heist
Influencing the influencers | Unlocked 403 cybersecurity podcast (ep. 6)

How do analyst relations professionals ‘sort through the noise’ and help deliver the not-so-secret sauce for a company’s success? We spoke with ESET’s expert to find out.

Ivanti patches exploited admin command execution flaw
Cybersecurity Regulations and Compliance for Linux Users

* bsc#1227233 Cross-References: * CVE-2024-5642

* bsc#1227233 Cross-References: * CVE-2024-5642

Cybercrooks strut away with haute couture Harvey Nichols data
Cloud architects: Try thinking like a CFO

* bsc#1223683 * bsc#1225099 * bsc#1228349 Cross-References:

update to 129.0.6668.58 * High CVE-2024-8904: Type Confusion in V8 * Medium CVE-2024-8905: Inappropriate implementation in V8 * Medium CVE-2024-8906: Incorrect security UI in Downloads * Medium CVE-2024-8907: Insufficient data validation in Omnibox

Fix for CVE-2024-44070

CISA boss: Makers of insecure software are the real cyber villains

libell 0.69: Add support for getting remaining microseconds left on a timer. Add support for setting link MTU on a network interface. iwd 2.21: Fix issue with pending scan requests after regdom update.

https://security-tracker.debian.org/tracker/DSA-5774-1

Valencia Ransomware explodes on the scene, claims California city, fashion giant, more as victims
Deno 2.0 moves to release candidate stage
No way? Big Tech’s ‘lucrative surveillance’ of everyone is terrible for privacy, freedom
Iran’s cyber-goons emailed stolen Trump info to Team Biden – which ignored them
New Arm partnerships extend AI performance from edge to cloud
YugabyteDB 2.19 gets new PostgreSQL-compatibility features
Understanding cyber-incident disclosure

Proper disclosure of a cyber-incident can help shield your business from further financial and reputational damage, and cyber-insurers can step in to help

1 in 10 orgs dumping their security vendors after CrowdStrike outage
Thousands of orgs at risk of knowledge base data leaks via ServiceNow misconfigurations

* bsc#1230400 Cross-References: * CVE-2024-23984 * CVE-2024-24968

* bsc#1229907 Cross-References: * CVE-2024-8250

UK activists targeted with Pegasus spyware ask police to charge NSO Group

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Exceptions in Java: Advanced features and types
Bringing Universal Windows Platform apps to .NET 9
How to work with FusionCache in ASP.NET Core
Tor insists its network is safe after German cops convict CSAM dark-web admin

Webroot® once again outperformed competitors in its latest round of testing by the performance benchmarking firm PassMark for February, 2023. In taking the highest score in the category, Webroot beat out competitors including BitDefender, McAfee®, Norton, and ESET® security products. PassMark® Software Party, Ltd. specializes in “the development of high quality performance benchmarking solutions as […]

Smashing Security podcast #385: TFL security derailed, and is Trump the king of crypto?
FBI boss says China ‘burned down’ 260,000-device botnet when confronted by Feds
Swift 6 arrives with improved concurrency, data-race safety

https://security-tracker.debian.org/tracker/DSA-5772-1

https://security-tracker.debian.org/tracker/DSA-5771-1

https://security-tracker.debian.org/tracker/DSA-5770-1

Deja blues… LockBit boasts once again of ransoming IRS-authorized eFile.com
Putin really wants Trump back in the White House
Lebanon: At least nine dead, thousands hurt after Hezbollah pagers explode
Lebanon now hit with deadly walkie-talkie blasts as Israel declares ‘new phase’ of war
Chinese spies spent months inside aerospace engineering firm’s network via legacy IT
Oracle CloudWorld 2024: 10 key takeaways from the big annual event