Menu

Category Archives: All

Everything

Hackers breach Pokémon game developer, source code and personal information leaks online
Brazilian police claim they’ve cuffed serial cybercrook behind FBI and Airbus attacks
Secure Azure Kubernetes with Advanced Container Networking Services
How to use Task.WhenEach in .NET 9

* bsc#1228349 * bsc#1228786 Cross-References: * CVE-2024-40909

WeChat devs introduced security flaws when they modded TLS, say researchers

* bsc#1227651 * bsc#1228573 Cross-References: * CVE-2021-47291

* bsc#1225312 * bsc#1225739 * bsc#1226325 * bsc#1228573 * bsc#1228786

* bsc#1228573 * bsc#1228786 Cross-References: * CVE-2024-40954

* bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225099 * bsc#1225312

Anonymous Sudan isn’t any more: Two alleged operators named, charged

Prevent command injection by quoting template strings in activation scripts

US contractor pays $300K to settle accusation it didn’t properly look after Medicare users’ data
Smashing Security podcast #389: WordPress vs WP Engine, and the Internet Archive is down
Critical default credential bug in Kubernetes Image Builder allows SSH root access
Volkswagen monitoring data dump threat from 8Base ransomware crew
Critical hardcoded SolarWinds credential now exploited in the wild
China’s infosec leads accuse Intel of NSA backdoor, cite chip security flaws

* bsc#1231284 Cross-References: * CVE-2024-8508

* bsc#1231284 Cross-References: * CVE-2024-8508

* bsc#1095184 * bsc#1118897 * bsc#1118898 * bsc#1118899 * bsc#1121850

* bsc#1225312 * bsc#1226325 * bsc#1227651 * bsc#1228573

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1223059 * bsc#1223363

* bsc#1210619 * bsc#1218487 * bsc#1220145 * bsc#1220537 * bsc#1221302

Get started with the free-threaded build of Python 3.13
WasmGC and the future of front-end Java development
Strengthen your cybersecurity with automation
Internet Archive wobbles back online, with limited functionality
IBM acquires Indian SaaS startup Prescinto to shine a light on renewable energy assets
WhatsApp may expose the OS you use to run it – which could expose you to crooks
Cisco confirms ‘ongoing investigation’ after crims brag about selling tons of data

https://security-tracker.debian.org/tracker/DSA-5792-1

Microsoft says more ransomware stopped before reaching encryption
The AI Fix #20: Elon’s androids, emotional support chickens, and an AI Fix super fan

* bsc#1228123 Cross-References: * CVE-2024-41184

* bsc#1228123 Cross-References: * CVE-2024-41184

* bsc#1225312 * bsc#1225739 * bsc#1226325 * bsc#1228573 * bsc#1228786

* bsc#1219296 * bsc#1220145 * bsc#1220211 * bsc#1220828 * bsc#1220832

* bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225099 * bsc#1225312

* bsc#1223683 * bsc#1225099 * bsc#1225739 * bsc#1228349 * bsc#1228573

Why are we still confused about cloud security?
At the mercy of social media
How to manage generative AI programs – governance, education, regulation
AI amplifies systemic risk to financial sector, says India’s Reserve Bank boss
China again claims Volt Typhoon cyber-attack crew was invented by the US to discredit it
US healthcare org admits up to 400,000 people’s personal info was snatched
Open source package entry points could be used for command jacking
Leveraging AI/ML for next-gen SOC environments
Trump campaign arms up with ‘unhackable’ phones after Iranian intrusion

An update that fixes two vulnerabilities is now available.

Python could me made to bypass some restrictions if it received specially crafted input.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Thousands of Fortinet instances vulnerable to actively exploited flaw
How to head off data breaches with CIAM
Making generative AI work for you
How do we fund open source?
How to leverage APIs for IT-enabled information capability
Crypto-apocalypse soon? Chinese researchers find a potential quantum attack on classical encryption
Schools bombarded by nation-state attacks, ransomware gangs, and everyone in between

Update to 129.0.6668.100 * CVE-2024-9602: Type Confusion in V8 * CVE-2024-9603: Type Confusion in V

Automatic update for buildah-1.37.4-1.fc41, podman-5.2.4-1.fc41. Changelog for buildah * Mon Oct 07 2024 Packit – 2:1.37.4-1 – Update to 1.37.4 upstream release Changelog for podman

Automatic update for buildah-1.37.4-1.fc41, podman-5.2.4-1.fc41. Changelog for buildah * Mon Oct 07 2024 Packit – 2:1.37.4-1 – Update to 1.37.4 upstream release Changelog for podman

https://security-tracker.debian.org/tracker/DSA-5790-1

https://security-tracker.debian.org/tracker/DSA-5791-1

GoldenJackal jumps the air gap … twice – Week in security with Tony Anscombe

ESET research dives deep into a series of attacks that leveraged bespoke toolsets to compromise air-gapped systems belonging to governmental and diplomatic entities

Various file formats are based on the zip file format. In cases of corruption of the underlying zip’s central directory, LibreOffice offers a “repair mode” which will attempt to recover the zip file structure by scanning for secondary local

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in

US and UK govts warn: Russia scanning for your unpatched vulnerabilities

Update to 2.0.19

Redis Community Edition 7.2.6 Released Wed 02 Oct 2024 20:17:04 IDT Upgrade urgency SECURITY: See security fixes below. Security fixes CVE-2024-31449 Lua library commands may lead to stack overflow and potential RCE.

Update rust-brotli-decompressor to 4.0.1, rust-brotli to 7.0.0, and rust-async- compression to 0.4.13. Patch dependent packages as needed to avoid compat packages. Rebuild with the latest Rust crate dependency versions; fix automatic provides on Python extension due to SONAME when built with Rust 1.81 or later.

https://security-tracker.debian.org/tracker/DSA-5789-1

INC ransomware rebrands to Lynx – same code, new name, still up to no good
Ktor 3.0 switches to kotlinx.io library
US lawmakers seek answers on alleged Salt Typhoon breach of telecom giants
Streamlining Third-Party Risk Management with Automation: What Businesses Need to Know
Embedded developers face mounting pressure on security

* bsc#1231298 Cross-References: * CVE-2024-47554

RAC duo busted for stealing and selling crash victims’ data
Keir Starmer hands ex-Darktrace boss investment minister gig

Several security issues were fixed in the Linux kernel.

AI is killing cloud sustainability
FBI created a cryptocurrency so it could watch it being abused
Healthcare attacks spread beyond US – just ask India’s Star Health

The updated packages fix security vulnerabilities References: – https://bugs.mageia.org/show_bug.cgi?id=33614 – https://openssl-library.org/news/vulnerabilities-3.0/

Use-after-free when closing buffers in Vim

HTTP_REDIRECT_STATUS might be controlled via user request FPM log output might be modified by an attacker HTTP POST can be modified by an attacker For other bug fixes consult references

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

Crooks stole personal info of 77k Fidelity Investments customers
TypeScript 5.7 improves error reporting
Secure your AI initiatives
Fore-get about privacy, golf tech biz leaves 32M data records on the fairway
Ransomware attack leaks social security numbers of over 230,000 Comcast customers
CISA adds fresh Ivanti vuln, critical Fortinet bug to hall of shame

Several security issues were fixed in Go.

* bsc#1220826 * bsc#1226145 * bsc#1226666 * bsc#1227487 * bsc#1228466