Menu

Category Archives: All

Everything

Balancing Security with Transparency in Open-Source AI
Decoding PUMAKIT: A Deep Dive into Multi-Stage Malware and Advanced Evasion Techniques in Linux

Multiple vulnerabilities have been fixed in the PostgreSQL JDBC Driver. CVE-2022-31197

Weaponizing generative AI
What tech teams need to know about WebAssembly
4 steps to streamline enterprise cloud spending

* bsc#1217070 * bsc#1228324 * bsc#1228553 * bsc#1229806 * bsc#1230294

Fix CVE-2024-45337

The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.

Update to 128.5.2 https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/

The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.

https://security-tracker.debian.org/tracker/DSA-5832-1

Are your Prometheus servers and exporters secure? Probably not
3 key features in Red Hat Advanced Cluster Security for Kubernetes 4.6

Update to upstream 20241210 Update firmware file for Intel BlazarU core amdgpu: numerous firmware updates upstream amdnpu firmware QCA: Add Bluetooth nvm files for WCN785x

This release contains a fix for a security issue: CVE-2024-46901 See https://subversion.apache.org/security/CVE-2024-46901-advisory.txt for more information. Changes in this release are: Fix printf-format build warnings in swig-rb (r1921264)

Update to pytest 8.3.4

An update that fixes one vulnerability is now available.

Multiple multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in privilege escalation.

Update to 131.0.6778.139 High CVE-2024-12381: Type Confusion in V8 High CVE-2024-12382: Use after free in Translate

Python 3.10.16 security release. Security content in this release gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and

Python 3.10.16 security release. Security content in this release gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and

https://security-tracker.debian.org/tracker/DSA-5831-1

Iran-linked crew used custom ‘cyberweapon’ in US critical infrastructure attacks

USN-7157-1 introduced a regression in PHP.

Scumbag gets 30 years in the clink for running CSAM dark-web chatrooms, abusing kids
Google Timeline location purge causes collateral damage

Several security issues were fixed in PHP.

https://security-tracker.debian.org/tracker/DSA-5830-1

Cyber protection made intuitive and affordable
Open Source AI: Risks & Mitigation Strategies for Security Admins
Do software security features matter in the world of vulnerability remediation?
Microsoft introduces Phi-4, an AI model for advanced reasoning tasks
Taming the multi-vault beast
Microsoft .NET Community Toolkit backs partial properties
Chicago flunks cloud economics
The Python AI library hack that didn’t hack Python

Two vulnerabilities were discovered in pgpool2, a connection pool server and replication proxy for PostgreSQL. CVE-2023-22332

CVE-2024-52805, CVE-2024-52815, CVE-2024-53863 Backport fixes from v1.120.1

Update to 131.0.6778.139 High CVE-2024-12381: Type Confusion in V8 High CVE-2024-12382: Use after free in Translate

Update to 128.5.2 https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/

Update to upstream 20241210 Update firmware file for Intel BlazarU core amdgpu: numerous firmware updates upstream amdnpu firmware QCA: Add Bluetooth nvm files for WCN785x

Update to 1.4.8

North Korea’s fake IT worker scam hauled in at least $88 million over six years
Visual Studio Code adds overtype mode, paste with imports

https://security-tracker.debian.org/tracker/DSA-5828-1

Java Applet API heads for the exit
Doughnut orders disrupted! Krispy Kreme suffers hack attack
27 DDoS-for-hire services disrupted in run-up to holiday season
Apache issues patches for critical Struts 2 RCE bug
No Command Line, No Problem: Practical Linux Security Tips for New Sysadmins
Lights out for 18 more DDoS booters in pre-Christmas Operation PowerOFF push
From surveillance to safety: How Kazakhstan’s Carpet CCTV is reshaping security
Google’s AI coding entry with Jules signals tougher competition in coding tools
British Army zaps drones out of the sky with laser trucks
InfoWorld’s 2024 Technology of the Year Award winners
Azure hardware innovations and the serverless cloud future
How to chunk data using LINQ in C#
Firefox ditches Do Not Track because nobody was listening anyway
Citrix goes shopping in Europe and returns with gifts for security-conscious customers
Smashing Security podcast #397: Snowflake hackers, and under the influence

https://security-tracker.debian.org/tracker/DSA-5829-1

Blocking Chinese spies from intercepting calls? There ought to be a law
Google unveils Gemini 2.0 AI model for agentic era

https://security-tracker.debian.org/tracker/DSA-5827-1

Krispy Kreme Doughnut Corporation admits to hole in security
Three more vulns spotted in Ivanti CSA, all critical, one 10/10
The makers and takers of WordPress
OpenSilver 3.1 brings XAML designer for VS Code
Intro to Express.js: Advanced programming with templates, data persistence, and forms
3 takeaways from the Ultralytics AI Python library hack
US names Chinese national it alleges was behind 2020 attack on Sophos firewalls
Go eclipses Node.js in web API requests, Cloudflare reports
Microsoft holds last Patch Tuesday of the year with 72 gifts for admins
“CP3O” pleads guilty to multi-million dollar cryptomining scheme
US military grounds entire Osprey tiltrotor fleet over safety concerns
3AM ransomware: what you need to know
AMD secure VM tech undone by DRAM meddling
The AI Fix #28: Robot dogs with bombs, and who is David Mayer?
Fully patched Cleo products under renewed ‘zero-day-ish’ mass attack
The Critical Role of Open-Source Encryption Apps in Combating Chinese Telecom Hacking
Heart surgery device maker’s security bypassed, data encrypted and stolen
Databricks unveils synthetic data generation API to help evaluate agents faster
Bitfinex heist gets the Netflix treatment after ‘cringey couple’ sentenced
5G never delivered for cloud computing
How to build better AI chatbots
WhatsApp finally fixes View Once flaw that allowed theft of supposedly vanishing pics
Police arrest suspect in murder of UnitedHealthcare CEO, with grainy pics the only tech involved

https://security-tracker.debian.org/tracker/DSA-5826-1

Python a shoo-in for Tiobe language of the year
Configuring SELinux: An In-Depth Guide to Securing Your Linux System
China’s Salt Typhoon recorded top American officials’ calls, says White House

Multiple vulnerabilities have been fixed in the graphics debugger RenderDoc. CVE-2023-33863

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service, authorization bypass, or information disclosure.

It’s an exciting time to be a managed service provider (MSP). More than ever, small and medium businesses (SMBs) are looking to MSPs as trusted advisors to help safeguard them from today’s growing cyber threats. One of the services in high demand right now? Managed detection and response (MDR). When asked about their biggest growth […]

Crooks stole AWS credentials from misconfigured sites then kept them in open S3 bucket
Supply chain compromise of Ultralytics AI library results in trojanized versions
OpenWrt orders router firmware updates after supply chain attack scare