Menu

Category Archives: All

Everything

Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74

Automatic update for tomcat-9.0.98-1.fc40. Changelog for tomcat * Mon Dec 09 2024 Packit – 1:9.0.98-1 – Update to version 9.0.98 – Resolves: rhbz#2331168

The AI Fix #30: ChatGPT reveals the devastating truth about Santa (Merry Christmas!)
How Androxgh0st rose from Mozi’s ashes to become ‘most prevalent malware’

* bsc#1129772 * bsc#1152803 * bsc#1154838 * bsc#1181400 * bsc#1230961

What do ransomware and Jesus have in common? A birth month and an unwillingness to die
One third of adults can’t delete device data
The AI backlash couldn’t have come at a better time

In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte

Update to 3.12.8

Update to 3.12.8

‘That’s not a bug, it’s a feature’ takes on a darker tone when malware’s involved

* bsc#1220490 * jsc#PED-10258 * jsc#PED-10751 Cross-References:

Suspected LockBit dev, facing US extradition, ‘did it for the money’

* bsc#1047218 * bsc#1233297 Cross-References: * CVE-2024-47535

* bsc#1220618 * bsc#1229238 * bsc#1231373 Cross-References:

UK ICO not happy with Google’s plans to allow device fingerprinting
The exciting new world of Redis
How generative AI could aid Kubernetes operations
Overcoming modern observability challenges

release v1.14.0

release v1.14.0

Update to 131.0.6778.204 High CVE-2024-12692: Type Confusion in V8 High CVE-2024-12693: Out of bounds memory access in V8 High CVE-2024-12694: Use after free in Compositing High CVE-2024-12695: Out of bounds write in V8

Update to 1.24.10, fixes multiple CVEs.

Update to 1.24.10, fixes multiple CVEs.

Update to 1.24.10, fixes multiple CVEs.

Update to 1.24.10, fixes multiple CVEs.

Update to 1.24.10, fixes multiple CVEs.

* bsc#1223098 Cross-References: * CVE-2024-27306

Update to 2.46.5: Fix several crashes and rendering issues. CVE-2024-54479, CVE-2024-54502, CVE-2024-54508, CVE-2024-54505

Update to v2.14

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Update to 4.3.3 (rhbz#2331357)

* bsc#1234371 Cross-References: * CVE-2021-3156

* bsc#1233973 Cross-References: * CVE-2024-53008

* bsc#1233894 Cross-References: * CVE-2024-53920

Cost-conscious repatriation strategies
Infosec experts divided on AI’s potential to assist red teams

https://security-tracker.debian.org/tracker/DSA-5834-1

Smashing Security podcast #398: Fake CAPTCHAs, Harmageddon, and Krispy Kreme

* bsc#1234068 Cross-References: * CVE-2024-11053

* bsc#1233282 Cross-References: * CVE-2024-52533

* bsc#1232528 Cross-References: * CVE-2024-9681

Smart policing revolution: How Kazakhstan is setting a global benchmark
Go 1.24 brings full support for generic type aliases
Enterprise-grade caching with Azure Managed Redis
FAQ: Getting started with Bluesky
Create searchable Bluesky bookmarks with R
Don’t fall for a mail asking for rapid Docusign action – it may be an Azure account hijack phish

nodejs:22 bug fix and enhancement update

Important: postgresql:15 security update

Important: ruby:3.1 security update

GitHub launches free tier of Copilot AI coding assistant
OpenAI rolls out upgrade to reasoning model, new dev tools
Tabnine code assistant now flags unlicensed code
US reportedly mulls TP-Link router ban over national security risk

https://security-tracker.debian.org/tracker/DSA-5833-1

Microsoft won’t let customers opt out of passkey push
Boffins trick AI model into giving up its secrets
It’s time to stop calling it “pig butchering”
Automatically acquire and renew certificates using mod_md and Automated Certificate Management Environment (ACME) in Identity Management (IdM)

EditorConfig could be made to crash or run programs as your login if it received specially crafted input.

Phishers cast wide net with spoofed Google Calendar invites

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Interpol wants everyone to stop saying ‘pig butchering’

A buffer overflow was discovered in the vhost code of DPDK, a set of libraries for fast packet processing, which could result in denial of service or the execution of arbitrary code by malicious guests/containers.

Critical security hole in Apache Struts under exploit
The AI Fix #29: AI on OnlyFans, and the bot that wants to be a billionaire

* bsc#1233285 * bsc#1233287 * bsc#1233292 Cross-References:

Gemini Code Assist tools target developer productivity from within IDEs
Ireland fines Meta for 2018 ‘View As’ breach that exposed 30M accounts

* bsc#1218644 * bsc#1220382 * bsc#1221309 * bsc#1222590 * bsc#1229345

* bsc#1218644 * bsc#1220382 * bsc#1221309 * bsc#1222590 * bsc#1229808

* bsc#1233813 Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3

* bsc#1225462 Cross-References: * CVE-2024-54661

* bsc#1233285 * bsc#1233287 * bsc#1233292 Cross-References:

Does AWS have a complexity problem?
Smarter devops: How to avoid deployment horrors
Top 5 use cases for small language models
BlackBerry offloads Cylance’s endpoint security products to Arctic Wolf
Australia moves to drop some cryptography by 2030 – before quantum carves it up
JavaScript is still number one – JetBrains report
Ransomware scum blow holes in Cleo software patches, Cl0p (sort of) claims responsibility
Aerospike Vector Search adds self-healing live indexes
Trump administration wants to go on cyber offensive against China
Deloitte says cyberattack on Rhode Island benefits portal carries ‘major security threat’

The managed service provider (MSP) industry is booming with opportunities. At the same time, MSPs face the challenge of balancing customer satisfaction with profitability, making strategic decisions more important than ever. For 35% of MSPs, building cyber resiliency for customers is a top strategic priority, but that goal often runs up against resource constraints and […]

Mitigating Spectre: The Ongoing Security Challenge with Qualcomm CPUs
Rydox cybercrime marketplace seixed by law enforcement, suspected admins arrested
Defeating Chinese Telecom Hacking with Open Source