Menu

Monthly Archives: October 2024

FortiManager critical vulnerability under active attack
‘Satanic’ data thief claims to have slipped into 350M Hot Topic shoppers info
Microsoft SharePoint RCE flaw exploits in the wild – you’ve had 3 months to patch
Syncfusion open-sources UI controls for .NET MAUI
How developers can automate ‘computer use’ with Anthropic’s new LLM

* bsc#1230683 Cross-References: * CVE-2024-45405

The best Python libraries for parallel processing
Why we get buggy software
The power of prime numbers in computing

libheif could be made to crash or read sensitive data if it opened a specially crafted file

Several security issues were fixed in Go.

Various security, performance, accuracy, and stability issues have been fixed.

New version 4.2.8 Fix for CVE-2024-9781

Millions of Android and iOS users at risk from hardcoded creds in popular apps
Developers embracing API-first development, survey says

It was discovered that there was a potential out-of-bounds read vulnerability in libheif, a decoder and encoder for the HEIF and AVIF image formats.

US lawmakers push DoJ to prosecute tax prep firms for leaking taxpayer data to big tech

https://security-tracker.debian.org/tracker/DSA-5795-1

TSMC blows whistle on potential sanctions-busting shenanigans from Huawei
VMware fixes critical RCE, make-me-root bugs in vCenter – for the second time
Tech firms to pay millions in SEC penalties for misleading SolarWinds disclosures
AI chatbots can be tricked by hackers into helping them steal your private data
Akira ransomware is encrypting victims again following pure extortion fling
The AI Fix #21: Virtual Trump, barking mad AI, and a robot dog with a flamethrower

Unbound could be made to stop responding if it received specially crafted DNS traffic.

Understanding Linux Persistence Mechanisms and Detection Tools
Musk’s xAI unveils a new API service for Grok models
Agile and devops for SaaS and low-code development
Why Python is the language of choice for AI
Is data gravity no longer centered in the cloud?

A heap-based pointer disclosure problem was found in Ghostscript, an interpreter for the PostScript language and for PDF. This could lead to information disclosure.

Firefox could be made to crash or run programs as your login

Multiple vulnerabilities were discovered in libsepol, a set of userspace utilities and libraries for manipulating SELinux policies. CVE-2021-36084, CVE-2021-36085, CVE-2021-36086

Pixel perfect Ghostpulse malware loader hides inside PNG image files
China’s Spamouflage cranks up trolling of US Senator Rubio as election day looms

New openssl packages are available for Slackware 15.0 to fix a security issue.

Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The billionaire behind Trump’s ‘unhackable’ phone is on a mission to fight Tesla’s FSD
macOS HM Surf vuln might already be under exploit by major malware family
IBM works to address the developer skills gap with AI
Boost Your Linux Server Security with SSH Mastery
11 open source AI projects that developers will love
How Kubecost shines a light on GPU efficiency
Stopping the rot in AI spending
Tesla, Intel, deny they’re the foreign company China just accused of making maps that threaten national security
Internet Archive exposed again – this time through Zendesk

AMD processors may allow a privileged local attacker to further escalate their privileged and execute arbitrary code within the processor’s firmware layer.

https://security-tracker.debian.org/tracker/DSA-5794-1

Two issues have been found in asterisk, an Open Source Private Branch Exchange.

Open source LLM tool primed to sniff out Python zero-days

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Update to 130.0.6723.58 * High CVE-2024-9954: Use after free in AI * Medium CVE-2024-9955: Use after free in Web Authentication * Medium CVE-2024-9956: Inappropriate implementation in Web Authentication * Medium CVE-2024-9957: Use after free in UI

Fixes possible denial of service attack on untrusted input

https://security-tracker.debian.org/tracker/DSA-5793-1

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

True multithreading in Python at last!
Threat actors exploiting zero-days faster than ever – Week in security with Tony Anscombe

The average time it takes attackers to weaponize a vulnerability, either before or after a patch is released, shrank from 63 days in 2018-2019 to just five days last year

Update to 130.0.6723.58 * High CVE-2024-9954: Use after free in AI * Medium CVE-2024-9955: Use after free in Web Authentication * Medium CVE-2024-9956: Inappropriate implementation in Web Authentication * Medium CVE-2024-9957: Use after free in UI

Fix for CVE-2024-48957 Automatic update for libarchive-3.7.2-6.fc40.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Jetpack fixes 8-year-old flaw affecting millions of WordPress sites

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Protecting children from grooming | Unlocked 403 cybersecurity podcast (ep. 7)

“Hey, wanna chat?” This innocent phrase can take on a sinister meaning when it comes from an adult to a child online – and even be the start of a predatory relationship

Alleged Bitcoin crook faces 5 years after SEC’s X account pwned
ESET denies it was compromised as Israeli orgs targeted with ‘ESET-branded’ wipers
Free-threaded programming in Python 3.13
AI stagnation: The gap between AI investment and AI adoption

* bsc#1229910 Cross-References: * CVE-2024-42934

* bsc#1231689 Cross-References: * CVE-2024-47874

* bsc#1231651 Cross-References: * CVE-2024-8184

Intel hits back at China’s accusations it bakes in NSA backdoors
Biz hired, and fired, a fake North Korean IT worker – then the ransom demands began
Uncle Sam puts $10M bounty on Russian troll farm Rybar
Troubled US insurance giant hit by extortion after data leak

The fixes for CVE-2024-38474 and CVE-2024-39884 introduced two regressions in mod_rewrite and mod_proxy. For Debian 11 bullseye, these problems have been fixed in version

A glimmer of good news on the ransomware front, as encryption rates plummet

The more devices, digital apps and online accounts you use, the more efficient and convenient your life becomes. But all that ease of use comes with a price. Your devices are constantly collecting your personal data to fine-tune your user experience. At the same time, hackers, and other cyber criminals are working round the clock […]

Hackers breach Pokémon game developer, source code and personal information leaks online
Brazilian police claim they’ve cuffed serial cybercrook behind FBI and Airbus attacks
How to use Task.WhenEach in .NET 9
Secure Azure Kubernetes with Advanced Container Networking Services

* bsc#1228349 * bsc#1228786 Cross-References: * CVE-2024-40909

WeChat devs introduced security flaws when they modded TLS, say researchers

* bsc#1227651 * bsc#1228573 Cross-References: * CVE-2021-47291

* bsc#1225312 * bsc#1225739 * bsc#1226325 * bsc#1228573 * bsc#1228786

* bsc#1228573 * bsc#1228786 Cross-References: * CVE-2024-40954

* bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225099 * bsc#1225312

Anonymous Sudan isn’t any more: Two alleged operators named, charged

Prevent command injection by quoting template strings in activation scripts

US contractor pays $300K to settle accusation it didn’t properly look after Medicare users’ data
Smashing Security podcast #389: WordPress vs WP Engine, and the Internet Archive is down
Critical default credential bug in Kubernetes Image Builder allows SSH root access
Volkswagen monitoring data dump threat from 8Base ransomware crew