Menu

Monthly Archives: December 2024

Smart policing revolution: How Kazakhstan is setting a global benchmark
Create searchable Bluesky bookmarks with R
FAQ: Getting started with Bluesky
Enterprise-grade caching with Azure Managed Redis
Go 1.24 brings full support for generic type aliases
Don’t fall for a mail asking for rapid Docusign action – it may be an Azure account hijack phish

Important: ruby:3.1 security update

Important: postgresql:15 security update

nodejs:22 bug fix and enhancement update

GitHub launches free tier of Copilot AI coding assistant
OpenAI rolls out upgrade to reasoning model, new dev tools
Tabnine code assistant now flags unlicensed code
US reportedly mulls TP-Link router ban over national security risk

https://security-tracker.debian.org/tracker/DSA-5833-1

Microsoft won’t let customers opt out of passkey push
Boffins trick AI model into giving up its secrets
It’s time to stop calling it “pig butchering”
Automatically acquire and renew certificates using mod_md and Automated Certificate Management Environment (ACME) in Identity Management (IdM)

EditorConfig could be made to crash or run programs as your login if it received specially crafted input.

Phishers cast wide net with spoofed Google Calendar invites

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Interpol wants everyone to stop saying ‘pig butchering’

A buffer overflow was discovered in the vhost code of DPDK, a set of libraries for fast packet processing, which could result in denial of service or the execution of arbitrary code by malicious guests/containers.

Critical security hole in Apache Struts under exploit
The AI Fix #29: AI on OnlyFans, and the bot that wants to be a billionaire

* bsc#1233285 * bsc#1233287 * bsc#1233292 Cross-References:

Gemini Code Assist tools target developer productivity from within IDEs
Ireland fines Meta for 2018 ‘View As’ breach that exposed 30M accounts

* bsc#1218644 * bsc#1220382 * bsc#1221309 * bsc#1222590 * bsc#1229345

* bsc#1218644 * bsc#1220382 * bsc#1221309 * bsc#1222590 * bsc#1229808

* bsc#1233813 Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3

* bsc#1225462 Cross-References: * CVE-2024-54661

* bsc#1233285 * bsc#1233287 * bsc#1233292 Cross-References:

Top 5 use cases for small language models
Smarter devops: How to avoid deployment horrors
Does AWS have a complexity problem?
BlackBerry offloads Cylance’s endpoint security products to Arctic Wolf
Australia moves to drop some cryptography by 2030 – before quantum carves it up
JavaScript is still number one – JetBrains report
Ransomware scum blow holes in Cleo software patches, Cl0p (sort of) claims responsibility
Aerospike Vector Search adds self-healing live indexes
Trump administration wants to go on cyber offensive against China
Deloitte says cyberattack on Rhode Island benefits portal carries ‘major security threat’

The managed service provider (MSP) industry is booming with opportunities. At the same time, MSPs face the challenge of balancing customer satisfaction with profitability, making strategic decisions more important than ever. For 35% of MSPs, building cyber resiliency for customers is a top strategic priority, but that goal often runs up against resource constraints and […]

Mitigating Spectre: The Ongoing Security Challenge with Qualcomm CPUs
Rydox cybercrime marketplace seixed by law enforcement, suspected admins arrested
Defeating Chinese Telecom Hacking with Open Source
Balancing Security with Transparency in Open-Source AI
Decoding PUMAKIT: A Deep Dive into Multi-Stage Malware and Advanced Evasion Techniques in Linux

Multiple vulnerabilities have been fixed in the PostgreSQL JDBC Driver. CVE-2022-31197

4 steps to streamline enterprise cloud spending
What tech teams need to know about WebAssembly
Weaponizing generative AI

* bsc#1217070 * bsc#1228324 * bsc#1228553 * bsc#1229806 * bsc#1230294

Fix CVE-2024-45337

The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.

Update to 128.5.2 https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/

The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.

https://security-tracker.debian.org/tracker/DSA-5832-1

Are your Prometheus servers and exporters secure? Probably not
3 key features in Red Hat Advanced Cluster Security for Kubernetes 4.6

Update to upstream 20241210 Update firmware file for Intel BlazarU core amdgpu: numerous firmware updates upstream amdnpu firmware QCA: Add Bluetooth nvm files for WCN785x

This release contains a fix for a security issue: CVE-2024-46901 See https://subversion.apache.org/security/CVE-2024-46901-advisory.txt for more information. Changes in this release are: Fix printf-format build warnings in swig-rb (r1921264)

Update to pytest 8.3.4

An update that fixes one vulnerability is now available.

Multiple multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in privilege escalation.

Update to 131.0.6778.139 High CVE-2024-12381: Type Confusion in V8 High CVE-2024-12382: Use after free in Translate

Python 3.10.16 security release. Security content in this release gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and

Python 3.10.16 security release. Security content in this release gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and

https://security-tracker.debian.org/tracker/DSA-5831-1

Iran-linked crew used custom ‘cyberweapon’ in US critical infrastructure attacks

USN-7157-1 introduced a regression in PHP.

Scumbag gets 30 years in the clink for running CSAM dark-web chatrooms, abusing kids
Google Timeline location purge causes collateral damage

Several security issues were fixed in PHP.

https://security-tracker.debian.org/tracker/DSA-5830-1

Cyber protection made intuitive and affordable
Open Source AI: Risks & Mitigation Strategies for Security Admins
Do software security features matter in the world of vulnerability remediation?
Microsoft introduces Phi-4, an AI model for advanced reasoning tasks
Taming the multi-vault beast
The Python AI library hack that didn’t hack Python
Chicago flunks cloud economics
Microsoft .NET Community Toolkit backs partial properties

Two vulnerabilities were discovered in pgpool2, a connection pool server and replication proxy for PostgreSQL. CVE-2023-22332

CVE-2024-52805, CVE-2024-52815, CVE-2024-53863 Backport fixes from v1.120.1

Update to 131.0.6778.139 High CVE-2024-12381: Type Confusion in V8 High CVE-2024-12382: Use after free in Translate

Update to 128.5.2 https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/

Update to upstream 20241210 Update firmware file for Intel BlazarU core amdgpu: numerous firmware updates upstream amdnpu firmware QCA: Add Bluetooth nvm files for WCN785x

Update to 1.4.8

North Korea’s fake IT worker scam hauled in at least $88 million over six years
Visual Studio Code adds overtype mode, paste with imports

https://security-tracker.debian.org/tracker/DSA-5828-1

Java Applet API heads for the exit
Doughnut orders disrupted! Krispy Kreme suffers hack attack