Menu

Monthly Archives: January 2025

https://security-tracker.debian.org/tracker/DSA-5841-1

The fix for CVE-2024-6923 in the python3.9 source package which was released as part of a suite of updates in DLA 3980-1 [0] introduced safer processing of input in the email module to order to increase the security around email header injection attacks.

Several vulnerabilities were discovered in OpenAFS, an implementation of the AFS distributed filesystem, which may result in theft of credentials in Unix client PAGs (CVE-2024-10394), fileserver crashes and information leak on StoreACL/FetchACL (CVE-2024-10396) or buffer overflows in XDR

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or privilege escalation.

Important: kernel-rt security update

Important: webkit2gtk3 security update

Oracle refuses to yield JavaScript trademark, Deno Land says
Chinese cyber-spies peek over shoulder of officials probing real-estate deals near American military bases
Drug addiction treatment service admits attackers stole sensitive patient data
Canadian man loses a cryptocurrency fortune to scammers – here’s how you can stop it happening to you

* jsc#PED-11136 Cross-References: * CVE-2024-12678 * CVE-2024-25131

Why JavaScript’s still on top in 2025
Ephemeral environments in cloud-native development
Cohere goes ‘North’ with agentic AI
Devs sent into security panic by ‘feature that was helpful … until it wasn’t’

* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:

* bsc#1234991 Cross-References: * CVE-2025-0237 * CVE-2025-0238

Rust 1.84 introduces strict provenance APIs
Researchers build a bridge from C to Rust and memory safety
Look for the label: White House rolls out ‘Cyber Trust Mark’ for smart devices

https://security-tracker.debian.org/tracker/DSA-5839-1

Smashing Security podcast #399: Honey in hot water, and reset your devices
Space Bears ransomware: what you need to know
Zero-day exploits plague Ivanti Connect Secure appliances for second year running
Security pros baited with fake Windows LDAP exploit traps

* bsc#1235029 Cross-References: * CVE-2024-56826

United Nations aviation agency hacked, recruitment database plundered

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

How to use the new Lock object in C# 13
Working with minimal APIs in .NET

xfpt could be made to crash or run programs if it opened a specially crafted file.

Thunderbird could be made to bypass security restrictions.

Several security issues were fixed in Firefox.

Japanese police claim China ran five-year cyberattack campaign targeting local orgs

Updated to latest upstream (134.0)

Database tables of student, teacher info stolen from PowerSchool in cyberattack

https://security-tracker.debian.org/tracker/DSA-5840-1

I tried hard, but didn’t fix all of cybersecurity, admits outgoing US National Cyber Director
GlassFish update fixes restart hangs, random 403 responses
Mitel 0-day, 5-year-old Oracle RCE bug under active exploit
DNA sequencers found running ancient BIOS, posing risk to clinical research
UN’s aviation agency confirms attack on recruitment database
Oracle offers price-performance boost with Exadata X11M update
Building generative AI applications is too hard, developers say

* bsc#1082555 * bsc#1176081 * bsc#1206344 * bsc#1213034 * bsc#1218562

* bsc#1082555 * bsc#1157160 * bsc#1218644 * bsc#1221977 * bsc#1222364

Tinyproxy could be made to crash or run programs if it received specially crafted input.

Crims backdoored the backdoors they supplied to other miscreants. Then the domains lapsed
Why the C programming language still rules
Intro to Ktor: The HTTP server for Kotlin

* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:

Akamai to quit its CDN in China, seemingly not due to trouble from Beijing

Several security issues were fixed in HTMLDOC.

FCC boss urges speedy spectrum auction to fund ‘Rip’n’Replace’ of Chinese kit
Gleam 1.7 brings faster record updates
Almost nothing remains of Software AG
The AI Fix #32: Agentic AI, killer robot fridges, and the robosexual revolution
Turbulence at UN aviation agency as probe into potential data theft begins
DEF CON’s hacker-in-chief faces fortune in medical bills after paralyzing neck injury

* bsc#1234809 Cross-References: * CVE-2024-56326

5 ways data teams must lead in AI-driven organizations
Agentic AI: The top challenges and how to overcome them
Cloud providers are running out of ‘next big things’
US adds web and gaming giant Tencent to list of Chinese military companies

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in the Linux kernel.

Python wins Tiobe language of the year honors

Several security issues were fixed in the Linux kernel.

Charter, Consolidated, Windstream reportedly join China’s Salt Typhoon victim list
FireScam infostealer poses as Telegram Premium app to surveil Android devices

In today’s digital-first world, small and medium-sized businesses (SMBs) face cybersecurity challenges that grow more complex by the day. SMBs are prime targets for attackers hoping to gain a foothold inside any organization that doesn’t have extensive security measures. As threats increase, so does the need for comprehensive, reliable, and accessible protection. This is where […]

MediaTek rings in the new year with a parade of chipset vulns
Demand for AI skills soars, while demand for programming skills falls – O’Reilly report

* bsc#1234809 Cross-References: * CVE-2024-56326

* bsc#1234718 Cross-References: * CVE-2024-11614

* bsc#1202473 * bsc#1205224 * bsc#1211507 Cross-References:

Essential Tips for Updating & Upgrading Your Linux Distro

tinyproxy could be made to expose sensitive information.

After China’s Salt Typhoon, the reconstruction starts now
My robot teacher: The challenge of AI in computer science education
3 forecasts about time-series forecasting
Someone needs to make AI easy
Taiwan reportedly claims China-linked ship damaged one of its submarine cables
Telemetry data from 800K VW Group EVs exposed online

Vulnerabilities were found in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are prior to 7.0.22 and prior to 7.1.2. A difficult to exploit vulnerability allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise an Oracle

The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many ` `. (CVE-2024-39908)

Encryption backdoor debate ‘done and dusted,’ former White House tech advisor says
Securing Linux Environments in AWS: Best Practices and Common Pitfalls
Atos denies Space Bears’ ransomware claims – with a ‘but’