Menu

Category Archives: All

Everything

Why your AI models stumble before the finish line

* bsc#1186511 * bsc#1217826 * bsc#1222121 * bsc#1222815 * bsc#1230551

Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.

Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.

Multiple vulnerabilities have been fixed in libarchive, a multi-format archive and compression library. CVE-2021-36976

New wget packages are available for Slackware 15.0 and -current to fix a security issue.

An out-of-bounds write vulnerability when handling crafted streams was discovered in mpg123, a real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3, which could result in the execution of arbitrary code.

Containerizing WordPress: Best Practices for Robust Security and Management
FBI issues warning as crooks ramp up emergency data request scams
200,000 SelectBlinds customers have their card details skimmed in malware attack
Dark web crypto laundering kingpin sentenced to 12.5 years in prison

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Breaking down digital silos
Can Wasm replace containers?
Is your software architecture as clean as your code?

* bsc#1216423 Cross-References: * CVE-2023-45802

* bsc#1216423 Cross-References: * CVE-2023-45802

Alleged Snowflake attacker gets busted by Canadians – politely, we assume

https://security-tracker.debian.org/tracker/DSA-5808-1

https://security-tracker.debian.org/tracker/DSA-5809-1

https://security-tracker.debian.org/tracker/DSA-5807-1

https://security-tracker.debian.org/tracker/DSA-5805-1

A heap-based out-of-bounds write vulnerability was discovered in libarchive, a multi-format archive and compression library, which may result in the execution of arbitrary code if a specially crafted RAR archive is processed.

Invalid low-level GF(2^m) parameters can lead to an OOB memory access. (CVE-2024-9143) References: – https://bugs.mageia.org/show_bug.cgi?id=33736

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478)

In Libheif, insufficient checks in ImageOverlay::parse() while decoding a HEIF file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. (CVE-2024-41311) References:

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parsing `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A

Permission leak via embed or object elements. (CVE-2024-10458) Use-after-free in layout with accessibility. (CVE-2024-10459) Confusing display of origin for external protocol handler prompt. (CVE-2024-10460) XSS due to Content-Disposition being ignored in

https://security-tracker.debian.org/tracker/DSA-5806-1

https://security-tracker.debian.org/tracker/DSA-5804-1

Scattered Spider, BlackCat claw their way back from criminal underground
Secure cloud bursting: Leveraging confidential computing for peace of mind
Recent improvements in Red Hat Enterprise Linux CoreOS security data
Strengthening security of the software supply chain for LLVM

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Java app security would get a boost through quantum resistance
Serverless computing’s second act
Winos4.0 abuses gaming apps to infect, control Windows machines
Don’t open that ‘copyright infringement’ email attachment – it’s an infostealer
IBM: APIs getting AI boost
Jane Goodall: Reasons for hope | Starmus highlights

The trailblazing scientist shares her reasons for hope in the fight against climate change and how we can tackle seemingly impossible problems and keep going in the face of adversity

Cisco scores a perfect CVSS 10 with critical flaw in its wireless system

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Officials warn of Russia’s tech-for-troops deal with North Korea amid Ukraine conflict

New upstream build (132.0)

Smashing Security podcast #392: Pasta spies and private eyes, and are you applying for a ghost job?

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Cybercrooks are targeting Bengal cat lovers in Australia for some reason
Operation Synergia II sees Interpol swoop on global cyber crims
Cyberattackers stole Microlise staff data following DHL, Serco disruption
Red Hat Insights expands its detection capabilities with CrowdStrike integration
12 Java Enhancement Proposals changing Java
Dataframes explained: The modern in-memory data science format
Why scrum is dumb

Update to 128.4.0 https://www.thunderbird.net/en-US/thunderbird/128.4.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-58/

Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0

Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection fix for inline data images #646 Fix count svg #647

Update to 128.4.0 https://www.thunderbird.net/en-US/thunderbird/128.4.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-58/

Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0

Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection fix for inline data images #646 Fix count svg #647

China’s Volt Typhoon reportedly breached Singtel in ‘test-run’ for US telecom attacks
Scumbag puts ‘stolen’ Nokia source code, SSH and RSA keys, more up for sale
Schneider Electric ransomware crew demands $125k paid in baguettes
A Kansas pig butchering: CEO who defrauded bank, church, friends gets 24 years
WSO2 API managers manage AI APIs
Criminals open DocuSign’s Envelope API to make BEC special delivery
The AI Fix #23: Murder most weird, and why 9.11 is bigger than 9.9
Ongoing typosquatting campaign impersonates hundreds of popular npm packages
Washington courts grapple with statewide outage after ‘unauthorized activity’
Meta offers Llama AI to US government for national security
How to support accurate revenue forecasting with data science and dataops
Cloud providers make bank with genAI while projects fail
Making the business case for generative AI
Google claims Big Sleep ‘first’ AI to spot freshly committed security bug that fuzzing missed

https://security-tracker.debian.org/tracker/DSA-5803-1

Visual Studio Code previews AI-powered code editing

https://security-tracker.debian.org/tracker/DSA-5802-1

Columbus, Ohio, confirms 500K people affected by Rhysida ransomware attack
Guide to Automating Third-Party Risk Management in Linux Environments
Why the long name? Okta discloses auth bypass bug affecting 52-character usernames
Public sector cyber break-ins: Our money, our lives, our right to know
The cloud reaches its equilibrium point
The machine learning certifications tech companies want
Six IT contractors accused of swindling Uncle Sam out of millions
Red Hat Insights collaborated with Vulcan Cyber to provide a seamless integration for effective exposure management
Month in security with Tony Anscombe – October 2024 edition

Election interference, American Water and the Internet Archive breaches, new cybersecurity laws, and more – October saw no shortage of impactful cybersecurity news stories

Financial institutions told to get their house in order before the next CrowdStrike strikes
Overcoming data inconsistency with a universal semantic layer

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing or information disclosure.