Menu

Monthly Archives: October 2024

Deno 2.0 arrives, ready to battle Node.js
Marriott settles for a piddly $52M after series of breaches affecting millions

https://security-tracker.debian.org/tracker/DSA-5729-2

National Public Data files for bankruptcy, admits ‘hundreds of millions’ potentially affected
Using iPhone Mirroring at work? You might have just overshared to your boss
Gemini Code Assist Enterprise woos enterprise developers
Cyber insurance, human risk, and the potential for cyber-ratings

Could human risk in cybersecurity be managed with a cyber-rating, much like credit scores help assess people’s financial responsibility?

Microsoft cleans up hot mess of Patch Tuesday preview
Ransomware gang Trinity joins pile of scumbags targeting healthcare
Solving the Puzzle of RBAC with Red Hat Customer Portal
Electron vs. Tauri: Which cross-platform framework is for you?
WebSockets under the hood with Node.js

Patch the code to use https instead of http (CVE-2024-45321)

Fixes CVE-2024-45752: A vulnerability that allows users to remap keys arbitrarily. This allows all users on the system to remap a key unexpectedly to a potentially malicious sequence

Patch the code to use https instead of http (CVE-2024-45321)

Update to 0.3.13.3 and fix gresource generation

Patch the code to use https instead of http (CVE-2024-45321)

https://security-tracker.debian.org/tracker/DSA-5787-1

Microsoft issues 117 patches – some for flaws already under attack
Qualcomm urges device makers to push patches after ‘targeted’ exploitation

The fixes for CVE-2024-38474 and CVE-2024-39884 introduced two regressions in mod_rewrite and mod_proxy. For the stable distribution (bookworm), these problems have been fixed in

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The AI Fix #19: AI spy specs, robot dogs with ladders, and is it AI or the climate?
Databricks says with its new Databricks Apps platform, you can build tailored enterprise apps in 5 minutes

* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References:

* bsc#1023072 * bsc#1023190 * bsc#1027776 * bsc#1027779 * bsc#1027785

California’s vetoed AI bill: Bullet dodged, but not for long
Embracing your inner on-premises self
SAP Build gains AI capabilities to help build autonomous agents
Happy birthday, Putin – you’ve been pwned
Google brings better bricking to Androids, to curtail crims

Fix login QR code not shown in WhatsApp web. Disable PSON by default again in GTK 3 API versions. Disable DMABuf video sink by default to prevent file descriptor leaks. Fix several crashes and rendering issues. Use Skia instead of cairo for 2D rendering and enable GPU rendering by default.

Fix login QR code not shown in WhatsApp web. Disable PSON by default again in GTK 3 API versions. Disable DMABuf video sink by default to prevent file descriptor leaks. Fix several crashes and rendering issues. Use Skia instead of cairo for 2D rendering and enable GPU rendering by default.

Feds reach for sliver of crypto-cash nicked by North Korea’s notorious Lazarus Group
Oracle touts ‘tip and tail’ release model for Java library development
American Water rinsed in cyberattack, turns off app
Rust resumes rise in popularity
The best new features and fixes in Python 3.13
Cops love facial recognition, and withholding info on its use from the courts

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Chinese cyberspies reportedly breached Verizon, AT&T, Lumen
Your robot vacuum cleaner might be spying on you

WEBrick could allow a HTTP request smuggling attack.

An update that fixes three vulnerabilities is now available.

* bsc#1231264 * bsc#1231265 * bsc#1231266 Cross-References:

cups-filters could be made to run programs if it received specially crafted network traffic.

CUPS could be made to crash or run programs if it received specially crafted network traffic.

5 ways data scientists can prepare now for genAI transformation
Open source isn’t going to save AI
Embattled users worn down by privacy options? Let them eat code
5 ways companies can use time series forecasting

Several security issues were fixed in Firefox.

ChatGPT o1-preview excels at code generation

https://security-tracker.debian.org/tracker/DSA-5786-1

Dom Walden discovered that the AbuseFilter extension in MediaWiki, a website engine for collaborative work, performed incomplete authorisation checks.

Red Hat Insights provides analytics for the IBM X-Force Cloud Threat Report

update to 129.0.6668.89 High CVE-2024-7025: Integer overflow in Layout High CVE-2024-9369: Insufficient data validation in Mojo High CVE-2024-9370: Inappropriate implementation in V8

Amongst other general bug fixes, this release addresses: CVE-2024-46951 CVE-2024-46952 CVE-2024-46953 CVE-2024-46954

The current versions have reached EOL and several security vulnerabilities were fixed by Mozilla. We are having some issues that are delaying the build for some architectures, so for the moment we are releasing this update just for x86_64

Integer overflows flaws were discovered in the Compound Document Binary File format parser of libgsf, the GNOME Project G Structured File Library, which could result in the execution of arbitrary code if a specially crafted file is processed.

* bsc#1230939 Cross-References: * CVE-2024-47176

The complexities of attack attribution – Week in security with Tony Anscombe

As highlighted by new ESET research this week, attributing a cyberattack to a specific threat actor is a complex affair

Ryanair faces GDPR turbulence over customer ID checks
UK’s Sellafield nuke waste processing plant fined £333K for infosec blunders

update to 129.0.6668.89 High CVE-2024-7025: Integer overflow in Layout High CVE-2024-9369: Insufficient data validation in Mojo High CVE-2024-9370: Inappropriate implementation in V8

Update to new upstream version (closes rhbz#2237124)

Fix CVE-2024-39844 https://wiki.znc.in/ChangeLog/1.9.0

https://security-tracker.debian.org/tracker/DSA-5785-1

Node.js previews network inspection support
Google ships Gemini 1.5 Flash-8B AI model
About a quarter million Comcast subscribers had their data stolen from debt collector

Fabian Vogt reported that the PAM module in oath-toolkit, a collection of components to build one-time password authentication systems, does not safely perform file operations in users’s home directories when using the usersfile feature (allowing to place the OTP state in the home

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Unfortunately, when your devices are infected with a virus, it’s not as easy as a little bed rest for them to recover, and the damage can be long-lasting. A cyberattack can compromise your computers, phones and tablets, and open the door for cyber thieves to steal your sensitive personal information. According to a study by […]

Why cloud security outranks cost and scalability
Sellafield nuclear site hit with £332,500 fine after “significant cybersecurity shortfalls”
Visit CyberThreat 2024 to hone your cybersecurity skills
Harvard duo hacks Meta Ray-Bans to dox strangers on sight in seconds

cJSON was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c. (CVE-2024-31755) References:

Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal. (CVE-2023-39327) References:

The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an “SSID Confusion” issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, […]

Use after free in Downloads. (CVE-2024-6988) Use after free in Loader. (CVE-2024-6989) Use after free in Dawn. (CVE-2024-6991) Heap buffer overflow in Layout. (CVE-2024-6994) Inappropriate implementation in Fullscreen. (CVE-2024-6995)

Big names among thousands infected by payment-card-stealing CosmicSting crooks

PHP version 8.2.24 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable

Fix CVE-2024-9014.

https://security-tracker.debian.org/tracker/DSA-5784-1

https://security-tracker.debian.org/tracker/DSA-5783-1

Visual Studio Code 1.94 improves file search

https://security-tracker.debian.org/tracker/DSA-5780-1

SingleStore acquires BryteFlow to boost data ingestion capabilities
Average North American CISO salary now $565K, mainly thanks to one weird trick
Tick tock.. Operation Cronos arrests more LockBit ransomware gang suspects

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Generative AI has taken the world by storm, transforming how individuals and businesses interact with and trust this new technology. With tools like ChatGPT, Grok, DALL-E, and Microsoft Copilot, everyday users are finding new ways to enhance productivity, creativity, and efficiency. However, as the integration of AI into daily life accelerates, so do the concerns […]

Two British-Nigerian men sentenced over multimillion-dollar business email scam

* bsc#1229930 * bsc#1229931 * bsc#1229932 Cross-References:

* bsc#1230020 * bsc#1230034 Cross-References: * CVE-2023-7256

A smarter way to manage malware with Red Hat Insights