Menu

Category Archives: All

Everything

Russia’s top-secret military unit reportedly plots undersea cable ‘sabotage’
Linux in the Cloud: Exploring Linux-based Cloud Computing Solutions
Avis alerts nearly 300k car renters that crooks stole their info
1.7M potentially pwned after payment services provider takes a year to notice break-in
Strengthening enterprise storage against cyber threats
Kremlin-linked COLDRIVER crooks take pro-democracy NGOs for phishy ride

* bsc#1207666 * bsc#1211708 * bsc#1211709 * bsc#1213318 * bsc#1215959

* bsc#1229013 Cross-References: * CVE-2024-7348

* bsc#1229013 Cross-References: * CVE-2024-7348

* bsc#1229013 Cross-References: * CVE-2024-7348

* bsc#1229013 Cross-References: * CVE-2024-7348

* bsc#1227276 * bsc#1227278 * bsc#1227353 Cross-References:

Deploying Red Hat OpenShift Operators in a disconnected environment
Cybersecurity regulation stepping up
Does your organization need a data fabric?
Junior developers and AI
Haystack review: A flexible LLM app builder
How to implement a headless data architecture
Predator spyware updated with dangerous new features, also now harder to track

Multiple vulnerabilities have been fixed in the Amanda backup system. CVE-2022-37703

Multiple vulnerabilities have been fixed in bluez library, tools and daemons for using Bluetooth devices. CVE-2021-3658

https://security-tracker.debian.org/tracker/DSA-5767-1

Integer overflows have been fixed in aom, an AV1 Codec Library. For Debian 11 bullseye, this problem has been fixed in version 1.0.0.errata1-3+deb11u2.

Bitcoin ATM scams skyrocket – Week in security with Tony Anscombe

The schemes disproportionately victimize senior citizens, as those aged 60 or over were more than three times as likely as younger adults to fall prey to the scams

ESET Research Podcast: HotPage

ESET researchers discuss HotPage, a recently discovered adware armed with a highest-privilege, yet vulnerable, Microsoft-signed driver

Despite cyberattacks, water security standards remain a pipe dream
Google says replacing C/C++ in firmware with Rust is easy
Cisco merch shoppers stung in Magecart attack

* bsc#1221243 * bsc#1221677 * bsc#1224117 Cross-References:

* bsc#1229821 Cross-References: * CVE-2024-8381 * CVE-2024-8382

* bsc#1229013 Cross-References: * CVE-2024-7348

* bsc#1229013 Cross-References: * CVE-2024-7348

* bsc#1229869 Cross-References: * CVE-2023-45288

* bsc#1217353 Cross-References: * CVE-2023-5752

Salesforce previews new XGen-Sales model, releases xLAM family of LLMs
Are you ready for data hyperaggregation?
What is GitHub? More than Git version control in the cloud
Visual Studio Code 1.93 shines on profiles
To patch this server, we need to get someone drunk
Homeland security hopes to scuttle maritime cyber-threats with port infosec testbed
White House’s new fix for cyber job gaps: Serve the nation in infosec
Vue JavaScript framework boosts reactivity system
Uncle Sam charges Russian GRU cyber-spies behind ‘WhisperGate intrusions’
Cisco’s Smart Licensing Utility flaws suggest it’s pretty dumb on security
Cicada ransomware – what you need to know
Quantum computing is coming – are you ready?
Security boom is over, with over a third of CISOs reporting flat or falling budgets

Sinatra is an open source web framework for Ruby programming language. CVE-2022-29970

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Managing Automatic Certificate Management Environment (ACME) in Identity Management (IdM)
The fingerpointing starts as cyber incident at London transport body continues
DirectML on Arm is here at last, almost
Packages and static imports in Java
What software supply chain security really means
Generative AI and coding: Time to rethink software development
Security biz Verkada to pay $3M penalty under deal that also enforces infosec upgrade
White House seizes 32 domains, issues criminal charges in massive election-meddling crackdown
North Korean scammers plan wave of stealth attacks on crypto companies, FBI warns

https://security-tracker.debian.org/tracker/DSA-5766-1

Smashing Security podcast #383: The Godfather club, and AirTags to the rescue
Palo Alto takes a big $500M bite out of IBM QRadar
Copilot for Microsoft 365 might boost productivity if you survive the compliance minefield
Planned Parenthood confirms cyber-attack as RansomHub threatens to leak data
Angular 19 to make standalone the default for components
InfluxData makes performance, storage improvements to InfluxDB 3.0
Cicada ransomware may be a BlackCat/ALPHV rebrand and upgrade

* bsc#1229823 * bsc#1229824 Cross-References: * CVE-2024-45230

* bsc#1228046 * bsc#1228047 * bsc#1228048 * bsc#1228050 * bsc#1228051

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Several security issues were fixed in Twisted.

Qt moves forward on toolkit for .NET-C++ interoperability
What is HTTP/3? The next-generation web protocol
PostgreSQL tutorial: Get started with PostgreSQL 16

* bsc#1176492 Cross-References: * CVE-2014-10401 * CVE-2014-10402

The open source community strikes back

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Telegram apologizes to South Korea and takes down smutty deepfakes
Ex-senior New York State staffer charged in cash-for-favors scandal with China

https://security-tracker.debian.org/tracker/DSA-5765-1

White House thinks it’s time to fix the insecure glue of the internet: Yup, BGP
UK trio pleads guilty to operating $10M MFA bypass biz
The AI Fix #14: There are two Rs in “strawberry”, and an AI makes unsmellable smells
Spamouflage trolls pretend to be American patriots on X, TikTok ahead of US presidential election
Data watchdog fines Clearview AI $33M for ‘illegal’ data collection

It was discovered that there was a series of integer overflow vulnerabilities in LibTomMath, a multiple-precision mathematics library.

A vulnerability was discovered in Nokogiri, an open source XML and HTML library for Ruby. An inefficient regular expression was susceptible to excessive backtracking when attempting to detect encoding in HTML documents. This could lead to denial-of-service.

Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2019-1387

Transport for London confirms cyberattack, assures us all is well
Application builders get ready

* bsc#1224044 Cross-References: * CVE-2024-34397

Path traversal that allowed TZInfo::Timezone.get to load arbitrary files has been fixed in ruby-tzinfo, a Ruby library for working with time zone information.

Fix buffer overrun when giving an offset to Session:receive

https://security-tracker.debian.org/tracker/DSA-5764-1

Telegram CEO was ‘too free’ on content moderation, says Russian minister
Exploring the OpenShift confidential containers solution
The future of Kubernetes and cloud infrastructure