Menu

Category Archives: All

Everything

Critical 9.8-rated VMware vCenter RCE bug exploited after patch fumble
T-Mobile US ‘monitoring’ China’s ‘industry-wide attack’ amid fresh security breach fears

GLib could be made to crash or other undefined behavior if it received a specially crafted input.

Sweden’s ‘Doomsday Prep for Dummies’ guide hits mailboxes today
Deepen your knowledge of Linux security
Hardening your operating system? Red Hat Enterprise Linux to the rescue!

Several issues were fixed in AsyncSSH.

14 great preprocessors for developers who love to code
The dirty little secret of open source contributions
Spin 3.0 supports polyglot development using Wasm components
Designing the APIs that accidentally power businesses

This is the .NET 9.0 GA release. It contains security fixes for CVE-2024-43498 and CVE-2024-43499 Announcement: https://devblogs.microsoft.com/dotnet/announcing-dotnet-9/ Release Notes: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.0/9.0.0.md

Several security issues were fixed in Tomcat.

Teen serial swatter-for-hire busted, pleads guilty, could face 20 years

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Will passkeys ever replace passwords? Can they?

Multiple vulnerabilties were discovered for smarty3, a widely-used PHP templating engine, which potentially allows an attacker to perform an XSS (e.g JavaScript or PHP code injection).

A vulnerability has been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation.

A vulnerability has been discovered in Pillow, which may lead to arbitrary code execution.

CVE-2024-46951 ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space (fedora#2325238) 2325241 – CVE-2024-46952 CVE-2024-46953 CVE-2024-46954 CVE-2024-46955 CVE-2024-46956 ghostscript: various flaws [fedora-41]

DoS due to resource exhaustion has been fixed in waitress, a Python Web Server Gateway Interface. For Debian 11 bullseye, this problem has been fixed in version

https://security-tracker.debian.org/tracker/DSA-5814-1

https://security-tracker.debian.org/tracker/DSA-5813-1

https://security-tracker.debian.org/tracker/DSA-5812-1

Multiple security issues were discovered in PostgreSQL, which may result in the execution of arbitrary code, privilege escalation or log manipulation. For Debian 11 bullseye, these problems have been fixed in version

Rust haters, unite! Fil-C aims to Make C Great Again
Swiss cheesed off as postal service used to spread malware

Update to upstream 2.1-47. 20241112 Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in intel-ucode/06-8f-05) from revision 0x2b0005c0 up to 0x2b000603; Update of 06-8f-05/0x87 (SPR-SP E2) microcode from revision 0x2b0005c0 up to 0x2b000603;

bartlett/php-compatinfo-db 6.12.0 – 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support

Update to version 3.0.1, which resolves CVE-2024-49768 and CVE-2024-49769.

CVE-2024-46951 ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space (fedora#2325237) 2325240 – CVE-2024-46952 CVE-2024-46953 CVE-2024-46954 CVE-2024-46955 CVE-2024-46956 ghostscript: various flaws

bartlett/php-compatinfo-db 6.12.0 – 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support

Bloke behind Helix Bitcoin launderette jailed for three years, hands over $400M
Go language evolving for future hardware, AI workloads
Letting chatbots run robots ends as badly as you’d expect
Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit
Keyboard robbers steal 171K customers’ data from AnnieMac mortgage house
The Dual Edge of Open Source: Examining Key Benefits and Security Challenges
Simplifying endpoint security
Bitfinex burglar bags 5 years behind bars for Bitcoin heist

* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853

* bsc#1232590 Cross-References: * CVE-2024-50602

* bsc#1233282 Cross-References: * CVE-2024-52533

AI meets security: POC to run workloads in confidential containers using NVIDIA accelerated computing

Several security issues were fixed in the Linux kernel.

Microsoft Power Pages misconfigurations exposing sensitive data

Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code

Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code

Fortinet patches VPN app flaw that could give rogue users, malware a privilege boost
Cybercriminal devoid of boundaries gets 10-year prison sentence
ShrinkLocker ransomware: what you need to know
IT specialist Jack Teixeira jailed for 15 years after leaking classified military documents on Discord
Kids’ shoemaker Start-Rite trips over security again, spilling customer card info
OpenSSL in Red Hat Enterprise Linux 10: From engines to providers
NatWest blocks bevy of apps in clampdown on unmonitorable comms
Asda security chief replaced, retailer sheds jobs during Walmart tech divorce
Understanding Hyperlight, Microsoft’s minimal VM manager
How to use DispatchProxy for AOP in .NET Core
Five Eyes infosec agencies list 2024’s most exploited software flaws

Update to 2.46.3

Update to b3561

Backport fix for CVE-2024-50602.

CVE fix for CVE-2024-9632

Reminder: China-backed crews compromised ‘multiple’ US telcos in ‘significant cyber espionage campaign’

Update to 2.46.3

ShrinkLocker ransomware scrambled your files? Free decryption tool to the rescue
Smashing Security podcast #393: Who needs a laptop to hack when you have a Firestick?
Data broker amasses 100M+ records on people – then someone snatches, sells it
Ransomware fiends boast they’ve stolen 1.4TB from US pharmacy network

giflib: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function. (CVE-2023-48161) Array indexing integer overflow. (CVE-2024-21210) HTTP client improper handling of maxHeaderSize. (CVE-2024-21208) Unbounded allocation leads to out-of-memory error. (CVE-2024-21217)

Microsoft slips Task Manager and processor count fixes into Patch Tuesday
Visual Studio 17.12 brings C++, Copilot enhancements
The Agile Manifesto was ahead of its time
Kotlin for Java developers
Docker tutorial: Get started with Docker volumes

Update to 130.0.6723.116

Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch

Update to 130.0.6723.116

Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch

Admins can give thanks this November for dollops of Microsoft patches
China’s Volt Typhoon crew and its botnet surge back with a vengeance
Air National Guardsman gets 15 years after splashing classified docs on Discord

Several security issues were fixed in .NET.

Microsoft’s .NET 9 arrives, emphasizing performance, cloud, and AI
Here’s what we know about the suspected Snowflake data extortionists

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

https://security-tracker.debian.org/tracker/DSA-5811-1

https://security-tracker.debian.org/tracker/DSA-5810-1

Red Hat OpenShift AI unveils model registry, data drift detection
‘Cybersecurity issue’ at Food Lion parent blamed for US grocery mayhem
Go language rises in Tiobe popularity index
The AI Fix #24: Where are the alien AIs, and are we being softened up for superintelligence?
HTTP your way into Citrix’s Virtual Apps and Desktops with fresh exploit code
Managing third-party risks in complex IT environments
Snowflake bares its agentic AI plans by showcasing its Intelligence platform
Red Hat Developer Hub adds AI templates
Amazon confirms employee data exposed in leak linked to MOVEit vulnerability
Winter Fuel Payment scam targets UK citizens via SMS