Menu

Category Archives: All

Everything

* bsc#1228770 Cross-References: * CVE-2013-4235

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Tomcat could be made to run programs if it received specially crafted network traffic.

Several security issues were fixed in jinja2.

VLC could be made to crash or run programs if it received specially crafted network traffic.

Wacom says crooks probably swiped customer credit cards from its online checkout
Guess who left a database wide open, exposing chat logs, API keys, and more? Yup, DeepSeek
Smashing Security podcast #402: Hackers get hacked, the British Museum IT shutdown, and social media kidnaps

https://security-tracker.debian.org/tracker/DSA-5855-1

https://security-tracker.debian.org/tracker/DSA-5856-1

North Koreans clone open source projects to plant backdoors, steal credentials
Async closure support is stable for Rust 1.85
Java-based organizations mostly use Java for AI development – report
Why is my Mitel phone DDoSing strangers? Oh, it was roped into a new Mirai botnet
Transform your approach to data security

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

‘Bro delete the chat’: Feel the panic shortly before cops bust major online fraud ring
Ex-worker arrested after ‘shutdown’ of British Museum computer systems
Doing authentication right
4 tiny Docker images for lightweight containers
The biggest ideas in software and technology today
Spending watchdog blasts UK govt over sloth-like cyber resilience progress
Now US government agencies can use OpenAI’s ChatGPT too
The curious story of Uncle Sam’s HR dept, a hastily set up email server, and fears of another cyber disaster
Stable values API would speed Java startups
SLAP, Apple, and FLOP: Safari, Chrome at risk of data theft on iPhone, Mac, iPad Silicon
New tweak to Linux kernel could cut data center power usage by up to 30%
Baguette bandits strike again with ransomware and a side of mockery

https://security-tracker.debian.org/tracker/DSA-5851-1

The AI Fix #35: Project Stargate, the AI emergency, and batsh*t AI cryonics
Protecting AWS environments from cyberthreats
Security pros more confident about fending off ransomware, despite being battered by attacks
Most Java-based organizations use Java for AI development – report
Endor Labs’ new tool helps enterprises track the AI models they use

* bsc#1214612 * bsc#1215807 * bsc#1215926 * bsc#1217828 * bsc#1221677

Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2024-50349

The crisis of AI’s hidden costs
A distributed state of mind: Event-driven multi-agent systems
Apple plugs security hole in its iThings that’s already been exploited in iOS

FRR could be made to crash or exhibit degraded performance if it received specially crafted network traffic.

Quagga could be made to crash if it received specially crafted network traffic.

US freezes foreign aid, halting cybersecurity defense and policy funds for allies

* bsc#1225819 * bsc#1227369 * bsc#1227781 * bsc#1227784 * bsc#1228349

Prompt Security adds code sanitization, data leak prevention for GitHub Copilot
DeepSeek limits new accounts amid cyberattack
Google takes action after coder reports ‘most sophisticated attack I’ve ever seen’
Hacked buses blare out patriotic pro-European anthems in Tbilisi, attack government
Sweden seizes cargo ship after another undersea cable hit in suspected sabotage

* bsc#1226324 Cross-References: * CVE-2024-36971

* bsc#1226324 * bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553

CDNs: Great for speeding up the internet, bad for location privacy

An update that fixes two vulnerabilities is now available.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

British Museum says ex-contractor ‘shut down’ IT systems, wreaked havoc
Is ChatGPT making us stupid?
How to pick the right SAST tool
11 cutting-edge programming languages to learn now

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size. (CVE-2025-0395)

Timing side-channel in ECDSA signature computation. (CVE-2024-13176) References: – https://bugs.mageia.org/show_bug.cgi?id=33942 – https://openssl-library.org/news/secadv/20250120.txt

Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8

https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/

Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8

https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/

https://security-tracker.debian.org/tracker/DSA-5850-1

Puppet open source fork OpenVox arrives
Someone is slipping a hidden backdoor into Juniper routers across the globe, activated by a magic packet
UK telco TalkTalk confirms probe into alleged data grab underway

pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.

New version 3.4.1, a couple of fixes for the 3.4.0 release.

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Includes security fixes to the crypto/x509 and net/http packages

Bun 1.2 squashes Node.js compatibility bugs
AI chatbot startup founder, lawyer wife accused of ripping off investors in $60M fraud
Don’t want your Kubernetes Windows nodes hijacked? Patch this hole now
North Korean dev who renamed himself ‘Bane’ accused of IT worker fraud scheme
Be careful what you say about data leaks in Turkey, new law could mean prison for reporting hacks
JetBrains launches AI coding agent
Is cloud-based AI becoming a monopoly?
Ready or not, here it comes: GenAI in 2025
China and friends claim success in push to stamp out tech support cyber-scam slave camps
Court rules FISA Section 702 surveillance of US resident was unconstitutional

Update to latest version Fix CVE-2024-53263

pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.

Update to latest version Fix CVE-2024-53263

PCL could be made to crash if it received specially crafted input.

https://security-tracker.debian.org/tracker/DSA-5849-1

One of Salt Typhoon’s favorite flaws still wide open on 91% of at-risk Exchange Servers

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Palo Alto Networks releases QRNG API framework