Menu

Monthly Archives: November 2024

https://security-tracker.debian.org/tracker/DSA-5817-1

New php packages are available for Slackware 15.0 and -current to fix security issues.

Andrew Tate’s site ransacked, subscriber data stolen
1000s of Palo Alto Networks firewalls hijacked as miscreants exploit critical hole

https://security-tracker.debian.org/tracker/DSA-5812-2

An update that fixes 8 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

TypeScript 5.7 arrives with improved error reporting
Examining the Significance of the Recent Real-time Linux Kernel v6.12 Release
How to master endpoint security

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-40866

AWS prepares to command an army of AI agents
SafePay ransomware gang claims Microlise attack that disrupted prison van tracking

Fix null pointer dereference in opendmarc_policy.c. (CVE-2024-25768) References: – https://bugs.mageia.org/show_bug.cgi?id=33756

Upstream kernel version 6.6.61 fixes bugs and vulnerabilities. The bluez, kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.

Vanilla upstream kernel version 6.6.61 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33776

An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function. (CVE-2024-48241) References: – https://bugs.mageia.org/show_bug.cgi?id=33755

In versions prior to 1.2.31 an authenticated user is able to perform a SQL injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations the code improperly uses the PicoDB library to update/insert new information.

Helpline for Yakuza victims fears it leaked their personal info
Here’s what happens if you don’t layer network security – or remove unused web shells
Angular 19 bolsters server-side rendering with incremental hydration
Red Hat Linux to be official WSL distro
DARPA-backed voting system for soldiers abroad savaged
Mastering Business Intelligence with Open-Source Tools: A Guide for Secure and Cost-Effective Linux Solutions
Low-Code, High Security: Integrating Open Source Tools for Robust Application Development

Potential disclosure of plaintext in OpenPGP encrypted message. (CVE-2024-11159) References: – https://bugs.mageia.org/show_bug.cgi?id=33763

Remove ClamAV subdirectory because of viruses in input files: These were the findings: MultiSource/Applications/ClamAV/inputs/rtf-test/rtf1.rtf: Eicar-Signature MultiSource/Applications/ClamAV/inputs/clam.zip: Clamav.Test.File-6 MultiSource/Applications/ClamAV/inputs/rtf-test/docCLAMexe.rtf:

Remove ClamAV subdirectory because of viruses in input files: These were the findings: MultiSource/Applications/ClamAV/inputs/rtf-test/rtf1.rtf: Eicar-Signature MultiSource/Applications/ClamAV/inputs/clam.zip: Clamav.Test.File-6 MultiSource/Applications/ClamAV/inputs/rtf-test/docCLAMexe.rtf:

Update to 130.0.6723.116

Several security issues were fixed in the Linux kernel.

750,000 patients’ medical records exposed after data breach at French hospital
Chinese ship casts shadow over Baltic subsea cable snipfest
‘Alarming’ security bugs lay low in Linux’s needrestart server utility for 10 years

With the rise of online scams and privacy risks, virtual private networks (VPNs) are becoming more popular for day-to-day use. Or at least I feel like they are based on the number of ads I hear for them on my favorite podcasts. So maybe you’ve heard of VPNs but aren’t actually sure what they are. […]

Embracing the Future of Linux: Understanding NVMe Enhancements in the 6.13 Kernel
Managed Identity and Workload Identity support in Azure Red Hat OpenShift
Security of LLMs and LLM systems: Key risks and safeguards
Now Online Safety Act is law, UK has ‘priorities’ – but still won’t explain ‘spy clause’
Advanced programming with Java generics
Put your usernames and passwords in your will, advises Japan’s government

Several security issues were fixed in Ruby.

RHEL AI, JBoss EAP 8 coming to Azure cloud
Five Scattered Spider suspects indicted for phishing spree and crypto heists
Smashing Security podcast #394: Digital arrest scams and stream-jacking
Chinese cyberspies, Musk’s Beijing ties, labelled ‘real risk’ to US security by senator
Azure Container Apps launches Python, JavaScript interpreters
Mega US healthcare payments network restores system 9 months after ransomware attack
Google’s AI bug hunters sniff out two dozen-plus code gremlins that humans missed
D-Link tells users to trash old VPN routers over bug too dangerous to identify
What is Rust? Safe, fast, and easy software development
Kotlin for Java developers: Classes and coroutines
Azure AI Foundry tools for changes in AI applications

A security issue was discovered in Thunderbird, which could result in the disclosure of OpenPGP encrypted messages. For Debian 11 bullseye, this problem has been fixed in version

Data is the new uranium – incredibly powerful and amazingly dangerous
Microsoft unveils imaging APIs for Windows Copilot Runtime
Healthcare org Equinox notifies 21K patients and staff of data theft

The system could be made to crash under certain conditions.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer
Russian suspected Phobos ransomware admin extradited to US over $16M extortion
Microsoft extends Entra ID to WSL, WinGet
America’s drinking water systems have a hard-to-swallow cybersecurity problem
The AI Fix #25: Beware of the superintelligence, and a spam-eating AI super gran
Palo Alto Networks tackles firewall-busting zero-days with critical patches
Navigating third-party risks
Microsoft rebrands Azure AI Studio to Azure AI Foundry
Crook breaks into AI biz, points $250K wire payment at their own account
Malware delivered via malicious QR codes sent in the post
Join in the festive cybersecurity fun
A GRC framework for securing generative AI
How to transform your architecture review board
Succeeding with observability in the cloud
iOS 18 added secret and smart security feature that reboots iThings after three days

Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid

Update to 2.6.4. Backport fix for CVE-2024-50602.

Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid

Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid

Update to 2.6.4. Backport fix for CVE-2024-50602.

F# 9 adds nullable reference types

https://security-tracker.debian.org/tracker/DSA-5816-1

https://security-tracker.debian.org/tracker/DSA-5815-1

Ford ‘actively investigating’ after employee data allegedly parked on leak site
Akka distributed computing platform adds Java SDK
Critical 9.8-rated VMware vCenter RCE bug exploited after patch fumble
T-Mobile US ‘monitoring’ China’s ‘industry-wide attack’ amid fresh security breach fears

GLib could be made to crash or other undefined behavior if it received a specially crafted input.

Sweden’s ‘Doomsday Prep for Dummies’ guide hits mailboxes today
Deepen your knowledge of Linux security
Hardening your operating system? Red Hat Enterprise Linux to the rescue!

Several issues were fixed in AsyncSSH.

14 great preprocessors for developers who love to code
Designing the APIs that accidentally power businesses
Spin 3.0 supports polyglot development using Wasm components
The dirty little secret of open source contributions

This is the .NET 9.0 GA release. It contains security fixes for CVE-2024-43498 and CVE-2024-43499 Announcement: https://devblogs.microsoft.com/dotnet/announcing-dotnet-9/ Release Notes: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.0/9.0.0.md

Several security issues were fixed in Tomcat.

Teen serial swatter-for-hire busted, pleads guilty, could face 20 years