Menu

Monthly Archives: November 2024

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Is your software architecture as clean as your code?
Can Wasm replace containers?
Breaking down digital silos

* bsc#1216423 Cross-References: * CVE-2023-45802

* bsc#1216423 Cross-References: * CVE-2023-45802

Alleged Snowflake attacker gets busted by Canadians – politely, we assume

https://security-tracker.debian.org/tracker/DSA-5809-1

https://security-tracker.debian.org/tracker/DSA-5808-1

https://security-tracker.debian.org/tracker/DSA-5807-1

https://security-tracker.debian.org/tracker/DSA-5805-1

A heap-based out-of-bounds write vulnerability was discovered in libarchive, a multi-format archive and compression library, which may result in the execution of arbitrary code if a specially crafted RAR archive is processed.

Invalid low-level GF(2^m) parameters can lead to an OOB memory access. (CVE-2024-9143) References: – https://bugs.mageia.org/show_bug.cgi?id=33736

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478)

In Libheif, insufficient checks in ImageOverlay::parse() while decoding a HEIF file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. (CVE-2024-41311) References:

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parsing `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A

Permission leak via embed or object elements. (CVE-2024-10458) Use-after-free in layout with accessibility. (CVE-2024-10459) Confusing display of origin for external protocol handler prompt. (CVE-2024-10460) XSS due to Content-Disposition being ignored in

https://security-tracker.debian.org/tracker/DSA-5806-1

https://security-tracker.debian.org/tracker/DSA-5804-1

Scattered Spider, BlackCat claw their way back from criminal underground
Secure cloud bursting: Leveraging confidential computing for peace of mind
Recent improvements in Red Hat Enterprise Linux CoreOS security data
Strengthening security of the software supply chain for LLVM

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Serverless computing’s second act
Java app security would get a boost through quantum resistance
Winos4.0 abuses gaming apps to infect, control Windows machines
Don’t open that ‘copyright infringement’ email attachment – it’s an infostealer
IBM: APIs getting AI boost
Jane Goodall: Reasons for hope | Starmus highlights

The trailblazing scientist shares her reasons for hope in the fight against climate change and how we can tackle seemingly impossible problems and keep going in the face of adversity

Cisco scores a perfect CVSS 10 with critical flaw in its wireless system

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Officials warn of Russia’s tech-for-troops deal with North Korea amid Ukraine conflict

New upstream build (132.0)

Smashing Security podcast #392: Pasta spies and private eyes, and are you applying for a ghost job?

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Cybercrooks are targeting Bengal cat lovers in Australia for some reason
Operation Synergia II sees Interpol swoop on global cyber crims
Cyberattackers stole Microlise staff data following DHL, Serco disruption
Red Hat Insights expands its detection capabilities with CrowdStrike integration
Dataframes explained: The modern in-memory data science format
12 Java Enhancement Proposals changing Java
Why scrum is dumb

Update to 128.4.0 https://www.thunderbird.net/en-US/thunderbird/128.4.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-58/

Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0

Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection fix for inline data images #646 Fix count svg #647

Update to 128.4.0 https://www.thunderbird.net/en-US/thunderbird/128.4.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-58/

Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0

Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection fix for inline data images #646 Fix count svg #647

China’s Volt Typhoon reportedly breached Singtel in ‘test-run’ for US telecom attacks
Scumbag puts ‘stolen’ Nokia source code, SSH and RSA keys, more up for sale
Schneider Electric ransomware crew demands $125k paid in baguettes
A Kansas pig butchering: CEO who defrauded bank, church, friends gets 24 years
WSO2 API managers manage AI APIs
Criminals open DocuSign’s Envelope API to make BEC special delivery
The AI Fix #23: Murder most weird, and why 9.11 is bigger than 9.9
Ongoing typosquatting campaign impersonates hundreds of popular npm packages
Washington courts grapple with statewide outage after ‘unauthorized activity’
Meta offers Llama AI to US government for national security
How to support accurate revenue forecasting with data science and dataops
Making the business case for generative AI
Cloud providers make bank with genAI while projects fail
Google claims Big Sleep ‘first’ AI to spot freshly committed security bug that fuzzing missed

https://security-tracker.debian.org/tracker/DSA-5803-1

Visual Studio Code previews AI-powered code editing

https://security-tracker.debian.org/tracker/DSA-5802-1

Columbus, Ohio, confirms 500K people affected by Rhysida ransomware attack
Guide to Automating Third-Party Risk Management in Linux Environments
Why the long name? Okta discloses auth bypass bug affecting 52-character usernames
Public sector cyber break-ins: Our money, our lives, our right to know
The machine learning certifications tech companies want
The cloud reaches its equilibrium point
Six IT contractors accused of swindling Uncle Sam out of millions
Red Hat Insights collaborated with Vulcan Cyber to provide a seamless integration for effective exposure management
Month in security with Tony Anscombe – October 2024 edition

Election interference, American Water and the Internet Archive breaches, new cybersecurity laws, and more – October saw no shortage of impactful cybersecurity news stories

Financial institutions told to get their house in order before the next CrowdStrike strikes
Overcoming data inconsistency with a universal semantic layer

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing or information disclosure.

* bsc#1227471 * bsc#1228349 * bsc#1228573 * bsc#1228786

* bsc#1223363 * bsc#1223683 * bsc#1225011 * bsc#1225012 * bsc#1225013

* bsc#1225011 * bsc#1225012 * bsc#1225309 * bsc#1225311 * bsc#1225819

Several security issues were fixed in the Linux kernel.

How to remove your personal information from Google Search results

Have you ever googled yourself? Were you happy with what came up? If not, consider requesting the removal of your personal information from search results.

Overlooked cloud sustainability issues
Download the AI in the Enterprise (for Real) Spotlight
UK councils bat away DDoS barrage from pro-Russia keyboard warriors
Fired Disney worker accused of hacking into restaurant menus, replacing them with Windings and false peanut allergy information
What is cloud computing? Everything you need to know
Python is the most popular language on GitHub
Hack Nintendo’s alarm clock to show cat pics? Let’s-a-go!