Menu

Monthly Archives: September 2024

Generative AI and coding: Time to rethink software development
Security biz Verkada to pay $3M penalty under deal that also enforces infosec upgrade
White House seizes 32 domains, issues criminal charges in massive election-meddling crackdown
North Korean scammers plan wave of stealth attacks on crypto companies, FBI warns

https://security-tracker.debian.org/tracker/DSA-5766-1

Smashing Security podcast #383: The Godfather club, and AirTags to the rescue
Palo Alto takes a big $500M bite out of IBM QRadar
Copilot for Microsoft 365 might boost productivity if you survive the compliance minefield
Planned Parenthood confirms cyber-attack as RansomHub threatens to leak data
Angular 19 to make standalone the default for components
InfluxData makes performance, storage improvements to InfluxDB 3.0
Cicada ransomware may be a BlackCat/ALPHV rebrand and upgrade

* bsc#1229823 * bsc#1229824 Cross-References: * CVE-2024-45230

* bsc#1228046 * bsc#1228047 * bsc#1228048 * bsc#1228050 * bsc#1228051

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Several security issues were fixed in Twisted.

PostgreSQL tutorial: Get started with PostgreSQL 16
What is HTTP/3? The next-generation web protocol
Qt moves forward on toolkit for .NET-C++ interoperability

* bsc#1176492 Cross-References: * CVE-2014-10401 * CVE-2014-10402

The open source community strikes back

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Telegram apologizes to South Korea and takes down smutty deepfakes
Ex-senior New York State staffer charged in cash-for-favors scandal with China

https://security-tracker.debian.org/tracker/DSA-5765-1

White House thinks it’s time to fix the insecure glue of the internet: Yup, BGP
UK trio pleads guilty to operating $10M MFA bypass biz
The AI Fix #14: There are two Rs in “strawberry”, and an AI makes unsmellable smells
Spamouflage trolls pretend to be American patriots on X, TikTok ahead of US presidential election
Data watchdog fines Clearview AI $33M for ‘illegal’ data collection

It was discovered that there was a series of integer overflow vulnerabilities in LibTomMath, a multiple-precision mathematics library.

A vulnerability was discovered in Nokogiri, an open source XML and HTML library for Ruby. An inefficient regular expression was susceptible to excessive backtracking when attempting to detect encoding in HTML documents. This could lead to denial-of-service.

Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2019-1387

Transport for London confirms cyberattack, assures us all is well
Application builders get ready

* bsc#1224044 Cross-References: * CVE-2024-34397

Path traversal that allowed TZInfo::Timezone.get to load arbitrary files has been fixed in ruby-tzinfo, a Ruby library for working with time zone information.

Fix buffer overrun when giving an offset to Session:receive

https://security-tracker.debian.org/tracker/DSA-5764-1

Telegram CEO was ‘too free’ on content moderation, says Russian minister
Exploring the OpenShift confidential containers solution
The future of Kubernetes and cloud infrastructure
Elastic’s return to open source
IT worker charged over $750,000 cyber extortion plot against former employer
Getting map data right and keeping it right

Several security issues were fixed in Dovecot.

Novel attack on Windows spotted in phishing campaign run from and targeting China

patchlevel 703 Security fixes for CVE-2024-43374, CVE-2024-43802

Update to upstream 2.1-44. 20240813 Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision 0x5003605 up to 0x5003707; Update of 06-55-0b/0xbf (CPX-SP A1) microcode from revision 0x7002802 up to 0x7002904;