Menu

Category Archives: All

Everything

Microsoft dangles $10K for hackers to hijack LLM email service
Why AI coding assistants are best for experienced developers
Surveying the LLM application framework landscape
Why business teams must stay out of application development
Blue Yonder ransomware termites claim credit

Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially among other effects allowing denial of service, information disclosure, use-after-free or remote code inclusion.

How Chinese insiders are stealing data scooped up by President Xi’s national surveillance system

Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in PostgreSQL, the worst of which could lead to arbitrary code execution.

Update to 131.0.6778.108 High CVE-2024-12053: Type Confusion in V8

Buffer overflow when calculating the quantile value has been fixed in the GNU Scientific Library (GSL). For Debian 11 bullseye, this problem has been fixed in version

Salt Typhoon forces FCC’s hand on making telcos secure their networks

A vulnerability has been discovered in OATH Toolkit, which could lead to local root privilege escalation.

Multiple vulnerabilities have been discovered in Dnsmasq, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in Salt, the worst of which can lead to arbitrary code execution.

Confidential cluster: Running Red Hat OpenShift clusters on confidential nodes

Multiple vulnerabilities have been discovered in Icinga2, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in OpenJDK, the worst of which could lead to remote code execution.

Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.

Clarifai previews AI compute orchestration
Micropatchers share 1-instruction fix for NTLM hash leak flaw in Windows 7+
Facing sale or ban, TikTok tossed under national security bus by appeals court
OpenAI releases o1 LLM, unveils ChatGPT Pro
Better together? Why AWS is unifying data analytics and AI services in SageMaker

* bsc#1233420 Cross-References: * CVE-2024-52616

Badass Russian techie outsmarts FSB, flees Putinland all while being tracked with spyware

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1225429 * bsc#1225733 * bsc#1229273 * bsc#1229553

* bsc#1223683 * bsc#1225099 * bsc#1225429 * bsc#1225733 * bsc#1225739

* bsc#1225733 * bsc#1229553 Cross-References: * CVE-2024-36904

* bsc#1223683 * bsc#1225309 * bsc#1225310 * bsc#1225311 * bsc#1225312

Protect your clouds
Public cloud providers are fumbling the AI opportunity
What is TypeScript? Strongly typed JavaScript
PoC exploit chains Mitel MiCollab 0-day, auth-bypass bug to access sensitive files
Microsoft: Another Chinese cyberspy crew targeting US critical orgs ‘as of yesterday’

https://security-tracker.debian.org/tracker/DSA-5824-1

https://security-tracker.debian.org/tracker/DSA-5825-1

Solana blockchain’s popular web3.js npm package backdoored to steal keys, funds
Explore strategies for effective endpoint control
Russian money-laundering network linked to drugs and ransomware disrupted, 84 arrests

* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168

* bsc#1234115 Cross-References: * CVE-2024-53981

British hospitals hit by cyberattacks still battling to get systems back online
Smashing Security podcast #396: Dishy DDoS dramas, and mining our minds for data
BT Group confirms attackers tried to break into Conferencing division
Shape the future of UK cyber security
Get started with Azure AI Content Understanding

* bsc#1225733 * bsc#1229553 Cross-References: * CVE-2024-36904

* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202

Ransomware hangover, Putin grudge blamed for vodka maker’s bankruptcy

Improve memory consumption and performance of Canvas getImageData. Fix preserve-3D intersection rendering. Fix video dimensions since GStreamer 1.24.9. Fix the HTTP-based remote Web Inspector not loading in Chromium. Fix content filters not working on about:blank iframes.

Update to 128.5.0 https://www.thunderbird.net/en-US/thunderbird/128.5.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-68/

T-Mobile US CSO: Spies jumped from one telco to another in a way ‘I’ve not seen in my career’
AI chatbot startup WotNot leaks 346,000 files, including passports and medical records
Cops arrest suspected admin of German-language crime bazaar
Ransomware-hit vodka maker Stoli files for bankruptcy in the United States
Microsoft says premature patch could make Windows Recall forget how to work
AWS amplifies developer tools with new gen AI features

* bsc#1227378 * bsc#1231795 * bsc#1233307 Cross-References:

* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168

* bsc#1232747 * bsc#1233631 * bsc#1233632 Cross-References:

* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168

Meta quietly leans on rival GPT-4 despite Zuckerberg’s bold Llama claims
Tech support scams leverage Google ads again and again, fleecing unsuspecting internet users
Just say no to JavaScript
Intro to Express.js: Endpoints, parameters, and routes
Cython tutorial: How to speed up Python

* bsc#1027519 * bsc#1230366 * bsc#1232542 * bsc#1232622 * bsc#1232624

* bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553

Eurocops take down ‘secure’ criminal chat system known as Matrix
FTC scolds two data brokers for allegedly selling your location to the meter
Heroku PaaS adds .NET support
Perfect 10 directory traversal vuln hits SailPoint’s IAM solution
Kotlin previews guard conditions in when expressions

https://security-tracker.debian.org/tracker/DSA-5815-2

https://security-tracker.debian.org/tracker/DSA-5823-1

Major energy contractor reports ‘limited’ access to IT after ransomware locks files
The AI Fix #27: Why is AI full of real-life Bond villains?

* bsc#1233773 Cross-References: * CVE-2024-10524

* bsc#1233651 * bsc#1233702 * bsc#1233703 Cross-References:

* bsc#1233650 * bsc#1233695 Cross-References: * CVE-2024-11691

* bsc#1227378 * bsc#1231795 * bsc#1233307 Cross-References:

* bsc#1233815 Cross-References: * CVE-2024-53849

* bsc#1231795 * bsc#1232750 * bsc#1233307 Cross-References:

Severity of the risk facing the UK is widely underestimated, NCSC annual review warns
North Korean hackers masquerade as remote IT workers and venture capitalists to steal crypto and secrets
No guarantees of payday for ransomware gang that claims to have hacked children’s hospital
AWS Database Migration Service gets gen AI-powered schema conversion
Open-washing and the illusion of AI openness
How AI agents will transform the future of work
Understanding unstructured data in the context of AI
Russia gives life sentence to Hydra dark web kingpin after seizing a ton of drugs
Data on 760K workers from Xerox, Nokia, BofA, Morgan Stanley and more dumped online
Rust 1.83 expands const capabilities
AWS unveils cloud security IR service for a mere $7K a month
Red Hat Ansible service comes to AWS Marketplace
AWS PartyRock updated with free daily usage for developers
Download the Cloud Optimization Enterprise Spotlight
Discover the future of Linux security