Menu

Category Archives: All

Everything

Fix CVE-2024-9014.

https://security-tracker.debian.org/tracker/DSA-5783-1

https://security-tracker.debian.org/tracker/DSA-5784-1

Visual Studio Code 1.94 improves file search

https://security-tracker.debian.org/tracker/DSA-5780-1

SingleStore acquires BryteFlow to boost data ingestion capabilities
Average North American CISO salary now $565K, mainly thanks to one weird trick
Tick tock.. Operation Cronos arrests more LockBit ransomware gang suspects

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Generative AI has taken the world by storm, transforming how individuals and businesses interact with and trust this new technology. With tools like ChatGPT, Grok, DALL-E, and Microsoft Copilot, everyday users are finding new ways to enhance productivity, creativity, and efficiency. However, as the integration of AI into daily life accelerates, so do the concerns […]

Two British-Nigerian men sentenced over multimillion-dollar business email scam

* bsc#1229930 * bsc#1229931 * bsc#1229932 Cross-References:

* bsc#1230020 * bsc#1230034 Cross-References: * CVE-2023-7256

A smarter way to manage malware with Red Hat Insights

Several security issues were fixed in the Linux kernel.

OpenAI updates API with model distillation, prompt caching abilities
Ransomware crew infects 100+ orgs monthly with new MedusaLocker variant
Brits hate how big tech handles their data, but can’t be bothered to do much about it
Understanding VBS Enclaves, Windows’ new security technology
How to use extension methods in C#

https://security-tracker.debian.org/tracker/DSA-5781-1

https://security-tracker.debian.org/tracker/DSA-5782-1

Smashing Security podcast #387: Breaches in your genes, and Kaspersky switcheroo raises a red flag
OpenAI previews Realtime API for speech-to-speech apps
700K+ DrayTek routers are sitting ducks on the internet, open to remote hijacking
Two simple give-me-control security bugs found in Optigo network switches used in critical manufacturing
Why system resilience should mainly be the job of the OS, not just third-party applications

Building efficient recovery options will drive ecosystem resilience

NIST’s security flaw database still backlogged with 17K+ unprocessed bugs. Not great

* bsc#1230986 Cross-References: * CVE-2024-38286

‘Patch yesterday’: Zimbra mail servers under siege through RCE vuln

A protocol flaw was fixed in AsyncSSH.

Spring AI: An AI framework for Java developers
Docker tutorial: Get started with Docker
Microsoft releases official OpenAI library for .NET
The fix for BGP’s weaknesses has big, scary, issues of its own, boffins find

PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable

Update to new upstream version (closes rhbz#2237124)

PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable

Several packages have been updated for Slackware 15.0 and -current to fix rpath security issues.

* bsc#1230698 Cross-References: * CVE-2024-41996

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Euro cops arrest 4 including suspected LockBit dev chilling on holiday
The AI Fix #18: ChatGPT’s false memories, and would an inner critic stop AI hallucinations?
JDK 24: The new features in Java 24
Evil Corp’s deep ties with Russia and NATO member attacks exposed
NCA unmasks man it suspects is both ‘Evil Corp kingpin’ and LockBit affiliate

From the apps on our smartphones to chatbot assistant services, artificial intelligence (AI) is transforming our lives in both big and small ways. But as exciting as AI can be, it’s also important to understand its potential risks. October is Cybersecurity Awareness Month, making it the perfect time to become more cyber-savvy about AI. Let’s […]

As October rolls around, it’s time to focus on cybersecurity. After all, it’s Cybersecurity Awareness Month—a perfect reminder to check in on the safety of your identity. If you’ve ever had your identity stolen or know someone who has, you understand how serious the problem is. From text scams to stolen passwords, criminals are finding […]

October is the month for pumpkin spice and all things spooky. But protecting your personal information online doesn’t need to be scary. For more than 20 years now, October has also been recognized as Cybersecurity Awareness Month. In our digitally connected world, apps and online accounts can make our lives much more convenient. Sadly, they […]

Two good Visual Studio Code alternatives

Python could be made to bypass some restrictions if it received specially crafted input.

The battle cry of 2025: Do cloud local!
Breaking through AI data bottlenecks
The worst programmer I know
JRuby 10 due to arrive in early-2025
Australian e-tailer digiDirect customers’ info allegedly stolen and dumped online

debian-security-support, the Debian security support coverage checker, has been updated in bullseye-security to mark the end of life of the following packages: * pdns-recursor: See https://bugs.debian.org/1070176

Rackspace internal monitoring web servers hit by zero-day
Ransomware forces hospital to turn away ambulances
T-Mobile US to cough up $31.5M after that long string of security SNAFUs
Large language models hallucinating non-existent developer packages could fuel supply chain attacks

Two vulnerabilities have been fixed in the SQLite database. CVE-2021-36690

Flatpak could be made to read and write files in locations it would not normally have access to.

Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arbitrary code.

British man used genealogy websites to fuel alleged hacking and insider trading scheme
If you’re holding important data, Iran is probably trying spearphish it

An update that fixes four vulnerabilities is now available.

Remote ID verification tech is often biased, bungling, and no good on its own

* bsc#1196018 * bsc#1196823 * bsc#1202346 * bsc#1209636 * bsc#1209799

Cloud threats have execs the most freaked out because they’re not prepared
Explained: How Salesforce Agentforce’s Atlas reasoning engine works to power AI agents
How to succeed with Kubernetes
Crescendo makes AI boring—and profitable
6 ways to apply automation in devsecops

Multiple vulnerabilities have been fixed in the network traffic analyzer Wireshark. CVE-2021-4181

Microsoft gives enterprises new reasons to adopt Fabric
AI code helpers just can’t stop inventing package names
Forget the Kia Boyz: Hackers could hijack your car with just a smartphone
Binance claims it helped to bust Chinese crypto scam app in India

Simone Margaritelli reported several vulnerabilities in cups-filters. Missing validation of IPP attributes returned from an IPP server and multiple bugs in the cups-browsed component can result in the execution

Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arbitrary code.

Red team hacker on how she ‘breaks into buildings and pretends to be the bad guy’

Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted input could cause a heap-buffer-overflow leading to memory corruption and potentially causing the application to crash or allowing arbitrary code execution

Update to new upstream version (closes rhbz#2237124)

https://security-tracker.debian.org/tracker/DSA-5779-1

https://security-tracker.debian.org/tracker/DSA-5778-1

Multiple vulnerabilities have been fixed in ruby-rails-html-sanitizer, a Ruby library for sanitizing HTML fragments in Rails applications. CVE-2022-23517

Multiple vulnerabilities have been fixed in ruby-loofah, a Ruby library for manipulating and transforming HTML/XML documents and fragments. CVE-2022-23514

Gamaredon’s operations under the microscope – Week in security with Tony Anscombe

ESET research examines the group’s malicious wares as used to spy on targets in Ukraine in the past two years

Red Hat’s response to OpenPrinting CUPS vulnerabilities: CVE-2024-47076, CVE-2024-47175, CVE-2024-47176 and CVE-2024-47177
When LLMs day dream: Hallucinations and how to prevent them

multipart/form-data request tampering has been fixed in ruby-httparty, a Ruby library for using Web-based APIs and related services. For Debian 11 bullseye, this problem has been fixed in version

Multiple vulnerabilities have been discovered in nginx, the worst of which could result in denial of service.

Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in denial of service.

Multiple vulnerabilities have been found in yt-dlp, the worst of which could result in arbitrary code execution.

Multiple vulnerabilities have been discovered in Docker, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.

Feds charge 3 Iranians with ‘hack-and-leak’ of Trump 2024 campaign