Menu

Monthly Archives: January 2025

https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/

https://security-tracker.debian.org/tracker/DSA-5850-1

Puppet open source fork OpenVox arrives
Someone is slipping a hidden backdoor into Juniper routers across the globe, activated by a magic packet
UK telco TalkTalk confirms probe into alleged data grab underway

pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.

New version 3.4.1, a couple of fixes for the 3.4.0 release.

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Includes security fixes to the crypto/x509 and net/http packages

Bun 1.2 squashes Node.js compatibility bugs
AI chatbot startup founder, lawyer wife accused of ripping off investors in $60M fraud
Don’t want your Kubernetes Windows nodes hijacked? Patch this hole now
North Korean dev who renamed himself ‘Bane’ accused of IT worker fraud scheme
Be careful what you say about data leaks in Turkey, new law could mean prison for reporting hacks
Ready or not, here it comes: GenAI in 2025
Is cloud-based AI becoming a monopoly?
JetBrains launches AI coding agent
China and friends claim success in push to stamp out tech support cyber-scam slave camps
Court rules FISA Section 702 surveillance of US resident was unconstitutional

Update to latest version Fix CVE-2024-53263

pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.

Update to latest version Fix CVE-2024-53263

PCL could be made to crash if it received specially crafted input.

https://security-tracker.debian.org/tracker/DSA-5849-1

One of Salt Typhoon’s favorite flaws still wide open on 91% of at-risk Exchange Servers

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Palo Alto Networks releases QRNG API framework
Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management

https://security-tracker.debian.org/tracker/DSA-5847-1

The OpenJDK’s plans for Java in 2025
SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix
Meta’s pay-or-consent model under fire from EU consumer group
FortiGate config leaks: Victims’ email addresses published online
Google BigQuery gets metadata service with Iceberg support

OpenJPEG could be made to crash or run programs if it opened a specially crafted file.

Django could be made to cause a denial of service if it received a specially crafted IPv6 string.

In FRR, the internet routing protocol suite software, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket’s buffer size, default 4K on most OSes.

Who is DDoSing you? Rivals, probably, or cheesed-off users
Biz tax rises, inflation and high interest. Why fewer UK tech firms started in 2024
How to use resource-based authorization in ASP.NET Core
Stratoshark analyzes cloud applications at a syscall level

Multiple vulnerabilities have been discovered in PHP, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to arbitrary code execution.

Asus lets processor security fix slip out early, AMD confirms patch in progress
Kazakhstan’s SOS 102: Redefining Public Safety Through Innovation
Oracle emits 603 patches, names one it wants you to worry about soon
Smashing Security podcast #401: Hacks on the high seas, and how your home can be stolen under your nose

https://security-tracker.debian.org/tracker/DSA-5848-1

Trump ‘waved a white flag to Chinese hackers’ as Homeland Security axed cyber advisory boards
Supply chain attack hits Chrome extensions, could expose millions
Give users confidence in your digital infrastructure
Microsoft issues out-of-band fix for Windows Server 2022 NUMA glitch
Stargate Project launched for OpenAI AI infrastructure
Silk Road’s Dread Pirate Roberts walks free as Trump pardons dark web kingpin
Infosec was literally the last item in Trump’s policy plan, yet major changes are likely on his watch
A Sysadmin’s Guide to Securing the Linux Kernel
EMEA blog [DUTCH] | Red Hat closes Master Agreement with SLM Rijk to strengthen digital autonomy within Dutch government
Introducing confidential containers on bare metal
Half a million hotel guests at risk after hackers accessed sensitive data
Perplexity launches Sonar API, enabling enterprise AI search integration
Ransomware scum make it personal for Reg readers by impersonating tech support
3 Python web frameworks for beautiful front ends
State of JavaScript: Highlights of the JavaScript developer survey
How to deal with a Big Pile of Mud

Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

* bsc#1232762 * jsc#PED-10545 Affected Products: * Containers Module 15-SP6

Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

Software bill-of-materials docs eyed for Python packages
PowerSchool theft latest: Decades of Canadian student records, data from 40-plus US states feared stolen
Patch procrastination leaves 50,000 Fortinet firewalls vulnerable to zero-day
The AI Fix #34: Fake Brad Pitt and why AI means we will lose our jobs

Cybercriminals are becoming increasingly sophisticated, agile, and fast. For managed service providers (MSPs) supporting small and medium-sized businesses (SMBs) with cybersecurity services, staying ahead of these adversaries is crucial. One of the most effective ways to do so is through round-the-clock threat hunting. In this blog, we’ll explore why constant threat hunting is essential, the […]

HPE probes IntelBroker’s bold data theft boasts
Medusa ransomware: what you need to know
The bitter lesson for generative AI adoption
The AI security tsunami
Breaking free from reactive security
Banks must keep ahead of risks and reap AI rewards

https://security-tracker.debian.org/tracker/DSA-5846-1

Hackers game out infowar against China with the US Navy
How to leave the submarine cable cutters all at sea – go Swedish
A Linux Admin’s Guide to Ensuring Data Privacy in 2025
Ransomware attack forces Brit high school to shut doors
Passwords: a thin line between love and hate
From devops to CTO: 5 things to start doing now
5 new features in EDB Postgres AI
Are 10% of your software engineers lazy?
Sage Copilot grounded briefly to fix AI misbehavior
Datacus extractus: Harry Potter publisher breached without resorting to magic
When food delivery apps reached Indonesia, everyone put on weight
Donald Trump proposes US government acquire half of TikTok, which thanks him and restores service
OpenAI’s ChatGPT crawler can be tricked into DDoSing sites, answering your queries
Node.js set to stabilize type stripping