Menu

Monthly Archives: October 2024

Gang gobbles 15K credentials from cloud and email providers’ garbage Git configs
Grounding with Google Search available in Google AI Studio, Gemini API

* bsc#1223363 * bsc#1223683 * bsc#1225011 * bsc#1225012 * bsc#1225013

Steam the Webinar on demand HERE As we look back on the cybersecurity landscape of 2024, it’s clear that the world of digital threats continues to evolve at an alarming pace in parallel with AI. This year has seen ransomware groups adapt and innovate, pushing the boundaries of their malicious capabilities and evasiveness from law enforcement. In our […]

Is now the right time to invest in implementing agentic AI?
Fraudsters exploit US General Election fever, FBI warns
Enhancing Cybersecurity with Breach and Attack Simulation in Linux Environments
LottieFiles supply chain attack exposes users to malicious crypto wallet drainer
Comprehensive Guide to Fixing and Securing MySQL InnoDB Table Corruption
Smashing Security podcast #391: The secret Strava service, deepfakes, and crocodiles
Why use aspect-oriented programming
OpenHCL: Understanding Microsoft’s open source paravisor
Tower PC case used as ‘creative cavity’ by drug importer
Chinese attackers accessed Canadian government networks – for five years

https://security-tracker.debian.org/tracker/DSA-5801-1

Google’s Flutter framework has been forked
Windows Themes zero-day bug exposes users to NTLM credential theft
Wasmer WebAssembly platform now backs iOS

https://security-tracker.debian.org/tracker/DSA-5800-1

Amazon rolls out a genAI-powered inline chat function for Amazon Q Developer
Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info

Think back to when your brand new laptop or desktop ran the smoothest, operating at peak performance. Is it still that fast, or does even the simplest task seem to take forever? Before you ditch your current PC, there’s a way to get it running like new again. First things first, though—you have to understand […]

Russian spies use remote desktop protocol files in unusual mass phishing drive
Beijing claims it’s found ‘underwater lighthouses’ that its foes use for espionage
Uncle Sam outs a Russian accused of developing Redline infostealing malware
Cast a hex on ChatGPT to trick the AI into writing exploit code
Tony Fadell: Innovating to save our planet | Starmus highlights

As methane emissions come under heightened global scrutiny, learn how a state-of-the-art satellite can pinpoint their sources and deliver the insights needed for targeted mitigation efforts

Belgian cops cuff 2 suspected cybercrooks in Redline, Meta infostealer sting
GitHub Copilot expands AI model support
The story behind the Health Infrastructure Security and Accountability Act
The AI Fix #22: Probing AI tongues and ASCII smuggling attacks
Admins better Spring into action over latest critical open source vuln
Tabnine previews AI code review agent
Merde! Macron’s bodyguards reveal his location by sharing Strava data
AI is transforming the developer experience. Embrace the change
Rise of the cloud computing opposition
Five Eyes nations tell tech startups to take infosec seriously. Again
Wanted. Top infosec pros willing to defend Britain on shabby salaries
OSI unveils Open Source AI Definition 1.0
JPMorgan Chase sues scammers following viral ‘infinite money glitch’
Feds investigate China’s Salt Typhoon amid campaign phone hacks
French ISP Free confirms data breach after hacker puts customer data up for auction
Brazen crims selling stolen credit cards on Meta’s Threads
Delta officially launches lawyers at $500M CrowdStrike problem
Dutch cops pwn the Redline and Meta infostealers, leak ‘VIP’ aliases
Visual Studio Code vs. Sublime Text: Which code editor should you use?
Bridging the performance gap in data infrastructure for AI
Open source gets complicated
WordPress forces user conf organizers to share social media credentials, arousing suspicions

https://security-tracker.debian.org/tracker/DSA-5799-1

Senator accuses sloppy domain registrars of aiding Russian disinfo campaigns
FIPS 140-3 changes for PKCS #12
ESET Research Podcast: CosmicBeetle

Learn how a rather clumsy cybercrime group wielding buggy malicious tools managed to compromise a number of SMBs in various parts of the world

Worker surveillance must comply with credit reporting rules

https://security-tracker.debian.org/tracker/DSA-5798-1

Google expands Responsible GenAI Toolkit

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The updated package provides Firefox 128 for all mandatory arches of Mageia (x86_64, i586 and aarch64), fixing several bugs, including security vulnerabilities, for i586 and aarch64: Fullscreen notification dialog can be obscured by document content. (CVE-2024-7518)

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

US offers $10 million bounty for members of Iranian hacking gang
Just how private is Apple’s Private Cloud Compute? You can test it to find out
Hugging Face pitches HUGS as an alternative to Nvidia’s NIM for open models

* bsc#1220262 Cross-References: * CVE-2023-50782

Strengthen DevSecOps with Red Hat Trusted Software Supply Chain
Secure design principles in the age of artificial intelligence
Confidential Containers with IBM Secure Execution for Linux
What is .NET? Microsoft’s answer to Java is now free and open source
A look at risk, regulation, and lock-in in the cloud

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink. (CVE-2024-47191)

fix CVE-2024-7006 (rhbz#2302997) fix CVE-2023-52356 (rhbz#2260112) fix CVE-2023-6228 (rhbz#2251863)

Putin’s pro-Trump trolls accuse Harris of poaching rhinos

https://security-tracker.debian.org/tracker/DSA-5797-1

https://security-tracker.debian.org/tracker/DSA-5796-1

JetBrains offers free use of WebStorm and Rider IDEs
AWS Cloud Development Kit flaw exposed accounts to full takeover
Next.js 15 arrives with faster bundler
Emergency patch: Cisco fixes bug under exploit in brute-force attacks
NotLockBit: ransomware discovery serves as wake-up call for Mac users

* bsc#1231294 Cross-References: * CVE-2024-47850

* bsc#1224038 * bsc#1224051 * bsc#1229013 Cross-References:

Bitwarden’s FOSS halo slips as new SDK requirement locks down freedoms
Ransomware’s ripple effect felt across ERs as patient care suffers
Enter the Neoverse with Azure’s Cobalt servers

* bsc#1231039 Cross-References: * CVE-2024-23213 * CVE-2024-23271

* bsc#1231039 Cross-References: * CVE-2024-23206 * CVE-2024-23213

* bsc#1231698 Cross-References: * CVE-2024-9676

* bsc#1231698 Cross-References: * CVE-2024-9676

Voice-enabled AI agents can automate everything, even your phone scams
China’s top messaging app WeChat banned from Hong Kong government computers
Anthropic’s latest Claude model can interact with computers – what could go wrong?
Perfctl malware strikes again as crypto-crooks target Docker Remote API servers
Samsung phone users under attack, Google warns
Penn State pays DoJ $1.25M to settle cybersecurity compliance case
Smashing Security podcast #390: When security firms get hacked, and your new North Korean remote worker