Menu

Monthly Archives: December 2024

27 DDoS-for-hire services disrupted in run-up to holiday season
Apache issues patches for critical Struts 2 RCE bug
No Command Line, No Problem: Practical Linux Security Tips for New Sysadmins
Lights out for 18 more DDoS booters in pre-Christmas Operation PowerOFF push
From surveillance to safety: How Kazakhstan’s Carpet CCTV is reshaping security
Google’s AI coding entry with Jules signals tougher competition in coding tools
British Army zaps drones out of the sky with laser trucks
How to chunk data using LINQ in C#
Azure hardware innovations and the serverless cloud future
InfoWorld’s 2024 Technology of the Year Award winners
Firefox ditches Do Not Track because nobody was listening anyway
Citrix goes shopping in Europe and returns with gifts for security-conscious customers
Smashing Security podcast #397: Snowflake hackers, and under the influence

https://security-tracker.debian.org/tracker/DSA-5829-1

Blocking Chinese spies from intercepting calls? There ought to be a law
Google unveils Gemini 2.0 AI model for agentic era

https://security-tracker.debian.org/tracker/DSA-5827-1

Krispy Kreme Doughnut Corporation admits to hole in security
Three more vulns spotted in Ivanti CSA, all critical, one 10/10
3 takeaways from the Ultralytics AI Python library hack
Intro to Express.js: Advanced programming with templates, data persistence, and forms
OpenSilver 3.1 brings XAML designer for VS Code
The makers and takers of WordPress
US names Chinese national it alleges was behind 2020 attack on Sophos firewalls
Go eclipses Node.js in web API requests, Cloudflare reports
Microsoft holds last Patch Tuesday of the year with 72 gifts for admins
“CP3O” pleads guilty to multi-million dollar cryptomining scheme
US military grounds entire Osprey tiltrotor fleet over safety concerns
3AM ransomware: what you need to know
AMD secure VM tech undone by DRAM meddling
The AI Fix #28: Robot dogs with bombs, and who is David Mayer?
Fully patched Cleo products under renewed ‘zero-day-ish’ mass attack
The Critical Role of Open-Source Encryption Apps in Combating Chinese Telecom Hacking
Heart surgery device maker’s security bypassed, data encrypted and stolen
Databricks unveils synthetic data generation API to help evaluate agents faster
Bitfinex heist gets the Netflix treatment after ‘cringey couple’ sentenced
How to build better AI chatbots
5G never delivered for cloud computing
WhatsApp finally fixes View Once flaw that allowed theft of supposedly vanishing pics
Police arrest suspect in murder of UnitedHealthcare CEO, with grainy pics the only tech involved

https://security-tracker.debian.org/tracker/DSA-5826-1

Python a shoo-in for Tiobe language of the year
Configuring SELinux: An In-Depth Guide to Securing Your Linux System
China’s Salt Typhoon recorded top American officials’ calls, says White House

Multiple vulnerabilities have been fixed in the graphics debugger RenderDoc. CVE-2023-33863

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service, authorization bypass, or information disclosure.

It’s an exciting time to be a managed service provider (MSP). More than ever, small and medium businesses (SMBs) are looking to MSPs as trusted advisors to help safeguard them from today’s growing cyber threats. One of the services in high demand right now? Managed detection and response (MDR). When asked about their biggest growth […]

Crooks stole AWS credentials from misconfigured sites then kept them in open S3 bucket
Supply chain compromise of Ultralytics AI library results in trojanized versions
OpenWrt orders router firmware updates after supply chain attack scare
Microsoft dangles $10K for hackers to hijack LLM email service
Why business teams must stay out of application development
Surveying the LLM application framework landscape
Why AI coding assistants are best for experienced developers
Blue Yonder ransomware termites claim credit

Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially among other effects allowing denial of service, information disclosure, use-after-free or remote code inclusion.

How Chinese insiders are stealing data scooped up by President Xi’s national surveillance system

Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in PostgreSQL, the worst of which could lead to arbitrary code execution.

Update to 131.0.6778.108 High CVE-2024-12053: Type Confusion in V8

Buffer overflow when calculating the quantile value has been fixed in the GNU Scientific Library (GSL). For Debian 11 bullseye, this problem has been fixed in version

Salt Typhoon forces FCC’s hand on making telcos secure their networks

A vulnerability has been discovered in OATH Toolkit, which could lead to local root privilege escalation.

Multiple vulnerabilities have been discovered in Dnsmasq, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in Salt, the worst of which can lead to arbitrary code execution.

Confidential cluster: Running Red Hat OpenShift clusters on confidential nodes

Multiple vulnerabilities have been discovered in Icinga2, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in OpenJDK, the worst of which could lead to remote code execution.

Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.

Clarifai previews AI compute orchestration
Micropatchers share 1-instruction fix for NTLM hash leak flaw in Windows 7+
Facing sale or ban, TikTok tossed under national security bus by appeals court
OpenAI releases o1 LLM, unveils ChatGPT Pro
Better together? Why AWS is unifying data analytics and AI services in SageMaker

* bsc#1233420 Cross-References: * CVE-2024-52616

Badass Russian techie outsmarts FSB, flees Putinland all while being tracked with spyware

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1225429 * bsc#1225733 * bsc#1229273 * bsc#1229553

* bsc#1223683 * bsc#1225099 * bsc#1225429 * bsc#1225733 * bsc#1225739

* bsc#1225733 * bsc#1229553 Cross-References: * CVE-2024-36904

* bsc#1223683 * bsc#1225309 * bsc#1225310 * bsc#1225311 * bsc#1225312

Protect your clouds
What is TypeScript? Strongly typed JavaScript
Public cloud providers are fumbling the AI opportunity
PoC exploit chains Mitel MiCollab 0-day, auth-bypass bug to access sensitive files
Microsoft: Another Chinese cyberspy crew targeting US critical orgs ‘as of yesterday’

https://security-tracker.debian.org/tracker/DSA-5825-1

https://security-tracker.debian.org/tracker/DSA-5824-1

Solana blockchain’s popular web3.js npm package backdoored to steal keys, funds
Explore strategies for effective endpoint control
Russian money-laundering network linked to drugs and ransomware disrupted, 84 arrests

* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168

* bsc#1234115 Cross-References: * CVE-2024-53981

British hospitals hit by cyberattacks still battling to get systems back online
Smashing Security podcast #396: Dishy DDoS dramas, and mining our minds for data
BT Group confirms attackers tried to break into Conferencing division
Shape the future of UK cyber security
Get started with Azure AI Content Understanding

* bsc#1225733 * bsc#1229553 Cross-References: * CVE-2024-36904

* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202