Menu

Category Archives: All

Everything

Google Chrome 129: Addressing Crucial Vulnerabilities and Enhancing Security
Fighting Back Against Hadooken Malware by Strengthening WebLogic Security

Rebase to version 2.6.3

Security fix for CVE-2024-8418

Fix CVE-2024-5535: SSL_select_next_proto buffer overread

Rebase to version 2.6.3

Security fix for CVE-2024-8418

https://security-tracker.debian.org/tracker/DSA-5773-1

How Static Residential Proxies Support Ethical Web Scraping Practices

It was discovered that ruby-saml, a SAML library implementing the client side of a SAML authorization, does not properly verify the signature of the SAML Response, which could result in bypass of authentication in an application using the ruby-saml library.

JavaScript community challenges Oracle’s JavaScript trademark
US indicts two over socially engineered $230M+ crypto heist
Influencing the influencers | Unlocked 403 cybersecurity podcast (ep. 6)

How do analyst relations professionals ‘sort through the noise’ and help deliver the not-so-secret sauce for a company’s success? We spoke with ESET’s expert to find out.

Ivanti patches exploited admin command execution flaw
Cybersecurity Regulations and Compliance for Linux Users

* bsc#1227233 Cross-References: * CVE-2024-5642

* bsc#1227233 Cross-References: * CVE-2024-5642

Cybercrooks strut away with haute couture Harvey Nichols data
Cloud architects: Try thinking like a CFO

* bsc#1223683 * bsc#1225099 * bsc#1228349 Cross-References:

update to 129.0.6668.58 * High CVE-2024-8904: Type Confusion in V8 * Medium CVE-2024-8905: Inappropriate implementation in V8 * Medium CVE-2024-8906: Incorrect security UI in Downloads * Medium CVE-2024-8907: Insufficient data validation in Omnibox

Fix for CVE-2024-44070

CISA boss: Makers of insecure software are the real cyber villains

libell 0.69: Add support for getting remaining microseconds left on a timer. Add support for setting link MTU on a network interface. iwd 2.21: Fix issue with pending scan requests after regdom update.

https://security-tracker.debian.org/tracker/DSA-5774-1

Valencia Ransomware explodes on the scene, claims California city, fashion giant, more as victims
Deno 2.0 moves to release candidate stage
No way? Big Tech’s ‘lucrative surveillance’ of everyone is terrible for privacy, freedom
Iran’s cyber-goons emailed stolen Trump info to Team Biden – which ignored them
New Arm partnerships extend AI performance from edge to cloud
YugabyteDB 2.19 gets new PostgreSQL-compatibility features
Understanding cyber-incident disclosure

Proper disclosure of a cyber-incident can help shield your business from further financial and reputational damage, and cyber-insurers can step in to help

1 in 10 orgs dumping their security vendors after CrowdStrike outage
Thousands of orgs at risk of knowledge base data leaks via ServiceNow misconfigurations

* bsc#1230400 Cross-References: * CVE-2024-23984 * CVE-2024-24968

* bsc#1229907 Cross-References: * CVE-2024-8250

UK activists targeted with Pegasus spyware ask police to charge NSO Group

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Bringing Universal Windows Platform apps to .NET 9
Exceptions in Java: Advanced features and types
How to work with FusionCache in ASP.NET Core
Tor insists its network is safe after German cops convict CSAM dark-web admin

Webroot® once again outperformed competitors in its latest round of testing by the performance benchmarking firm PassMark for February, 2023. In taking the highest score in the category, Webroot beat out competitors including BitDefender, McAfee®, Norton, and ESET® security products. PassMark® Software Party, Ltd. specializes in “the development of high quality performance benchmarking solutions as […]

Smashing Security podcast #385: TFL security derailed, and is Trump the king of crypto?
FBI boss says China ‘burned down’ 260,000-device botnet when confronted by Feds
Swift 6 arrives with improved concurrency, data-race safety

https://security-tracker.debian.org/tracker/DSA-5772-1

https://security-tracker.debian.org/tracker/DSA-5771-1

https://security-tracker.debian.org/tracker/DSA-5770-1

Deja blues… LockBit boasts once again of ransoming IRS-authorized eFile.com
Putin really wants Trump back in the White House
Lebanon: At least nine dead, thousands hurt after Hezbollah pagers explode
Lebanon now hit with deadly walkie-talkie blasts as Israel declares ‘new phase’ of war
Chinese spies spent months inside aerospace engineering firm’s network via legacy IT
Oracle CloudWorld 2024: 10 key takeaways from the big annual event

* bsc#1230353 Cross-References: * CVE-2023-29483

* bsc#1230353 Cross-References: * CVE-2023-29483

Cops across the world arrest 51 in orchestrated takedown of Ghost crime platform

Several security issues were fixed in the Linux kernel.

A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. An attacker could generate a malicious dump file which could execute shell commands from the MariaDB client.

Despite Russia warnings, Western critical infrastructure remains unprepared
Text in, docs out: Popular Markdown documentation tools compared
Intro to Deno Fresh: A fresh take on full-stack JavaScript

* bsc#1227378 * bsc#1227999 * bsc#1228780 * bsc#1229596

* bsc#1228780 Cross-References: * CVE-2024-6923

How Cloud Custodian conquered cloud resource management
Can Java rival Python in AI development?
Australian Police conducted supply chain attack on criminal collaborationware
WhatsApp fix to make View Once chats actually disappear is beaten in less than a week
C++ Alliance takes aim at C++ memory safety
VMware patches remote make-me-root holes in vCenter Server, Cloud Foundation
Google Cloud Document AI flaw (still) allows data theft despite bounty payout
The AI Fix #16: GPT-4o1, AI time travelers, and where’s my driverless car?
Hezbollah claims dozens dead as its pagers go boom, not beep
Rhysida ransomware gang ships off Port of Seattle data for $6M
Secure your organization
Predator spyware kingpins added to US sanctions list

An update that solves four vulnerabilities and has one errata is now available.

A new stable version was released for galera-4, a synchronous multimaster replication engine for MySQL and MariaDB. This fixes several issues detailed at:

Several security issues were fixed in libxmltok.

How Red Hat is integrating post-quantum cryptography into our products

Several security issues were fixed in ClamAV.

Several security issues were fixed in DCMTK.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Ticketmaster boss who repeatedly hacked rival firm sentenced
China claims Starlink signals can reveal stealth aircraft – and what that really means
Chinese national accused by Feds of spear-phishing for NASA, military source code
Microsoft confirms IE bug squashed in Patch Tuesday was exploited zero-day
The empire of C++ strikes back with Safe C++ blueprint
Snowflake slams ‘more MFA’ button again – months after Ticketmaster, Santander breaches
Germany’s CDU still struggling to restore data months after June cyberattack

An update that fixes four vulnerabilities is now available.

* bsc#1176447 * bsc#1195668 * bsc#1195928 * bsc#1195957 * bsc#1196018

* bsc#1229907 * bsc#1230372 Cross-References: * CVE-2024-8250

* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629

* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629

Prison just got rougher as band of heinously violent cybercrims sentenced to lengthy stints