Menu

Monthly Archives: January 2025

JavaScript dates and times will get easier soon

An update that fixes one vulnerability is now available.

Multiple vulnerabilities have been fixed in DCMTK, a collection of libraries and applications implementing large parts the DICOM standard for medical images.

Vanilla upstream kernel version 6.6.74 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33968

Microsoft’s new DocumentDB rethinks NoSQL on PostgreSQL
The Big Short on Cybersecurity

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Another banner year for ransomware gangs despite takedowns by the cops
Plunge into Python: New tools and tips for Python developers
The quantum computing reality check
Google to Iran: Yes, we see you using Gemini for phishing and scripting. We’re onto you
TypeScript 5.8 arrives in beta
Data resilience and data portability
VMware plugs steal-my-credentials holes in Cloud Foundation

https://security-tracker.debian.org/tracker/DSA-5854-1

https://security-tracker.debian.org/tracker/DSA-5853-1

Trump admin’s purge of US cyber advisory boards was ‘foolish,’ says ex-Navy admiral
Ransomware attack at New York blood services provider – donors turned away during shortage crisis

* bsc#1236518 Cross-References: * CVE-2023-45288

Canvassing apps used by UK political parties riddled with privacy, security issues
Streamline the connectivity between your environment and Red Hat Insights services
WFH with privacy? 85% of Brit bosses snoop on staff
Microsoft’s new DocumentDB builds on PostgreSQL
Browser Use: An open-source AI agent to automate web-based tasks
Sourcegraph unveils AI coding agents

* bsc#1228770 Cross-References: * CVE-2013-4235

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Tomcat could be made to run programs if it received specially crafted network traffic.

Several security issues were fixed in jinja2.

VLC could be made to crash or run programs if it received specially crafted network traffic.

Wacom says crooks probably swiped customer credit cards from its online checkout
Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek
Smashing Security podcast #402: Hackers get hacked, the British Museum IT shutdown, and social media kidnaps

https://security-tracker.debian.org/tracker/DSA-5856-1

https://security-tracker.debian.org/tracker/DSA-5855-1

North Koreans clone open source projects to plant backdoors, steal credentials
Async closure support is stable for Rust 1.85
Java-based organizations mostly use Java for AI development – report
Why is my Mitel phone DDoSing strangers? Oh, it was roped into a new Mirai botnet
Transform your approach to data security

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

‘Bro delete the chat’: Feel the panic shortly before cops bust major online fraud ring
Ex-worker arrested after ‘shutdown’ of British Museum computer systems
The biggest ideas in software and technology today
4 tiny Docker images for lightweight containers
Doing authentication right
Spending watchdog blasts UK govt over sloth-like cyber resilience progress
Now US government agencies can use OpenAI’s ChatGPT too
The curious story of Uncle Sam’s HR dept, a hastily set up email server, and fears of another cyber disaster
Stable values API would speed Java startups
SLAP, Apple, and FLOP: Safari, Chrome at risk of data theft on iPhone, Mac, iPad Silicon
New tweak to Linux kernel could cut data center power usage by up to 30%
Baguette bandits strike again with ransomware and a side of mockery

https://security-tracker.debian.org/tracker/DSA-5851-1

The AI Fix #35: Project Stargate, the AI emergency, and batsh*t AI cryonics
Protecting AWS environments from cyberthreats
Security pros more confident about fending off ransomware, despite being battered by attacks
Most Java-based organizations use Java for AI development – report
Endor Labs’ new tool helps enterprises track the AI models they use

* bsc#1214612 * bsc#1215807 * bsc#1215926 * bsc#1217828 * bsc#1221677

Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2024-50349

A distributed state of mind: Event-driven multi-agent systems
The crisis of AI’s hidden costs
Apple plugs security hole in its iThings that’s already been exploited in iOS

FRR could be made to crash or exhibit degraded performance if it received specially crafted network traffic.

Quagga could be made to crash if it received specially crafted network traffic.

US freezes foreign aid, halting cybersecurity defense and policy funds for allies

* bsc#1225819 * bsc#1227369 * bsc#1227781 * bsc#1227784 * bsc#1228349

Prompt Security adds code sanitization, data leak prevention for GitHub Copilot
DeepSeek limits new accounts amid cyberattack
Google takes action after coder reports ‘most sophisticated attack I’ve ever seen’
Hacked buses blare out patriotic pro-European anthems in Tbilisi, attack government
Sweden seizes cargo ship after another undersea cable hit in suspected sabotage

* bsc#1226324 Cross-References: * CVE-2024-36971

* bsc#1226324 * bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553

CDNs: Great for speeding up the internet, bad for location privacy

An update that fixes two vulnerabilities is now available.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

British Museum says ex-contractor ‘shut down’ IT systems, wreaked havoc
11 cutting-edge programming languages to learn now
How to pick the right SAST tool
Is ChatGPT making us stupid?

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size. (CVE-2025-0395)

Timing side-channel in ECDSA signature computation. (CVE-2024-13176) References: – https://bugs.mageia.org/show_bug.cgi?id=33942 – https://openssl-library.org/news/secadv/20250120.txt

Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8

https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/

Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8