Menu

Category Archives: All

Everything

OpenSSH could be made to crash or run programs as your login if it received a specially crafted input.

When your cloud strategy is ‘it depends’
9 hacks for a better nightly build
China’s quantum* crypto tech may be unhackable, but it’s hardly a secret
3 common misconceptions around biometrics and authentication
AWS hands OpenSearch to the Linux Foundation
23andMe settles class-action breach lawsuit for $30 million

Update to 1.0.7 CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files. CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser

flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.

flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.

Update to 1.15.10 (CVE-2024-42472)

https://security-tracker.debian.org/tracker/DSA-5769-1

Node.js a JavaScript runtime environment that executes JavaScript code outside a web browser (server side) was vulnerable. CVE-2023-30589

New libarchive packages are available for Slackware 15.0 and -current to fix security issues.

CosmicBeetle joins the ranks of RansomHub affiliates – Week in security with Tony Anscombe

ESET research also finds that CosmicBeetle attempts to exploit the notoriety of the LockBit ransomware gang to advance its own ends

update to 128.0.6613.137 * High CVE-2024-8636: Heap buffer overflow in Skia * High CVE-2024-8637: Use after free in Media Router * High CVE-2024-8638: Type Confusion in V8 * High CVE-2024-8639: Use after free in Autofill

Update to expat-2.6.3.

Update to 1.0.7 CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files. CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser

Update to 115.15.0 https://www.thunderbird.net/en-US/thunderbird/115.15.0esr/releasenotes/

Update to expat-2.6.3.

Update to 3.6.1 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-3.6.1 Update to 3.6.0

Feeld dating app’s security too open-minded as private data swings into public view
Decoding OpenAI’s o1 family of large language models

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

New AI reporting regulations
Life without Python’s ‘dead batteries’

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Cambodian senator sanctioned by US over alleged forced labor cyber-scam camps
Australia’s government spent the week boxing Big Tech
What’s in the cards for MariaDB?
Feds pull plug on domains linked to import of Chinese gun conversion devices
Fortinet admits miscreant got hold of customer data in the cloud
‘Hadooken’ Linux malware targets Oracle WebLogic servers
JFrog Platform adds runtime security for containers
Microsoft moves .NET 9 to release candidate stage
I stole 20 GB of data from Capgemini – and now I’m leaking it, says cybercrook

https://security-tracker.debian.org/tracker/DSA-5768-1

Mastercard splurges $2.65B on another big cyber purchase – Recorded Future
Adobe fixed Acrobat bug, neglected to mention whole zero-day exploit thing
Kong API platform adds service catalog
6 common Geek Squad scams and how to defend against them

Learn about the main tactics used by scammers impersonating Best Buy’s tech support arm and how to avoid falling for their tricks

Google Chrome gets a mind of its own for some security fixes
WordPress plugin and theme developers told they must use 2FA
Transport for London confirms 5,000 users’ bank data exposed, pulls large chunks of IT infra offline

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in libxmltok.

Several security issues were fixed in Expat.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

EU kicks off an inquiry into Google’s AI model
About that Windows Installer ‘make me admin’ security hole. Here’s how it’s exploited
Smashing Security podcast #384: A room with a view, AI music shenanigans, and a cocaine bear
Mind your header! There’s nothing refreshing about phishers’ latest tactic
Using the Pinecone vector database in .NET
NIS2, DORA, and Tiber-EU expanding cybersecurity regulation
Using PostgreSQL as a vector database in RAG
If HDMI screen rips aren’t good enough for you pirates, DeCENC is another way to beat web video DRM
Pokémon GO was an intelligence tool, claims Belarus military official
Healthcare giant to pay $65M settlement after crooks stole and leaked nude patient pics
Cyber crooks shut down UK, US schools, thousands of kids affected
Major sales and ops overhaul leads to much more activity … for Meow ransomware gang
Hunters International claims ransom on Chinese mega-bank’s London HQ
So you paid a ransom demand … and now the decryptor doesn’t work

An update that fixes one vulnerability is now available.

* bsc#1228535 * bsc#1230093 Cross-References: * CVE-2024-7264

* bsc#1230093 Cross-References: * CVE-2024-8096

* bsc#1230093 Cross-References: * CVE-2024-8096

How $20 and a lapsed domain allowed security pros to undermine internet integrity
Mind the talent gap: Infosec vacancies abound, but hiring is flat
Hacker pleads guilty after arriving on plane from Ukraine with a laptop crammed full of stolen credit card details
File handling in server-side JavaScript

* bsc#1225660 * bsc#1227378 * bsc#1227999 * bsc#1228780

Several security issues were fixed in Unbound.

TypeScript 5.6 now generally available
India to train 5,000 ‘Cyber Commandos’
Microsoft says it broke some Windows 10 patching – as it fixes flaws under attack
Oracle Code Assist moves to beta
Crypto scams rake in $5.6B a year for cyberscum lowlifes, FBI says
The AI Fix #15: AI robot butlers and gigawatt banana highways

It was discovered that there were a number of issues in Redis, a popular key-value database: * CVE-2023-45145: On startup, Redis began listening on a Unix

Oracle’s HeatWave data analytics service gets new gen AI features

* bsc#1229823 Cross-References: * CVE-2024-45230

* bsc#1217070 * bsc#1217952 * bsc#1221400 * bsc#1224323 * bsc#1228553

* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629

* bsc#1193629 * bsc#1194111 * bsc#1194765 * bsc#1194869 * bsc#1196261

* bsc#1229013 Cross-References: * CVE-2024-7348

Oracle inks deal with AWS to offer database services
A critical juncture for public cloud providers
Oracle CloudWorld 2024: Latest news and insights
When the PC and Internet were new
Finding the right large language model for your needs
Thanks, Edward Snowden: You propelled China to quantum networking leadership
WhatsApp’s ‘View Once’ could be ‘View Whenever’ due to a flaw
Rust 1.81 stabilizes Error trait
C language slumps in Tiobe popularity index