Menu

Category Archives: All

Everything

* bsc#1227178 Cross-References: * CVE-2024-39134

* bsc#1227178 Cross-References: * CVE-2024-39134

Over 40 million Kakao Pay users’ data somehow ended up with Alipay
China-linked cyber-spies infect Russian govt, IT sector

https://security-tracker.debian.org/tracker/DSA-5743-2

Russian cyber snoops linked to massive credential-stealing campaign
Texas sues GM for selling driver data to analytics, insurance companies
Enzo Biochem ordered to cough up $4.5 million over lousy security that led to ransomware disaster
Ransomware kingpin who called himself “J P Morgan” extradited to United States
Palo Alto Networks execs apologize for ‘hostesses’ dressed as lamps at Black Hat booth

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1065729 * bsc#1088701 * bsc#1149446 * bsc#1179610 * bsc#1186463

* bsc#1156395 * bsc#1190336 * bsc#1191958 * bsc#1193454 * bsc#1193554

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695

Improved vulnerability reporting on Quay.io
Is Lenovo a blind spot in US anti-China security measures?
Functional programming with Java collections
UK Prime Minister Keir Starmer and Prince William deepfaked in investment scam campaign
The magic of RAG is in the retrieval
Indian telcos to cut off scammy, spammy, telemarketers for two whole years
NIST finalizes trio of post-quantum encryption standards
Patch Tuesday brings 90 new Microsoft CVEs, six already under exploit
Go 1.23 arrives with faster PGO build times

https://security-tracker.debian.org/tracker/DSA-5748-1

Six ransomware gangs behind over 50% of 2024 attacks
US accuses man of being ‘elite’ ransomware pioneer they’ve hunted for years
Linux Foundation’s adoption of OMI could pave way for ethical LLMs, analysts say
The great location leak: Privacy risks in dating apps

Convenience may come at a cost – such as when your favorite app reveals your exact coordinates to someone you’d rather keep at a distance

The AI Fix #11: AI gods, a robot dentist, and an angry human
Feds bust minor league Radar/Dispossessor ransomware gang
JDK 23: The new features in Java 23

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Orion SA says scammers conned company out of $60 million
BlackHat USA 2024: Key Takeaways for Linux Admins & InfoSec Pros
Staying a Step Ahead of Adversaries: Mitigating Chromium’s Security Flaws on Linux
Who uses LLM prompt injection attacks IRL? Mostly unscrupulous job seekers, jokesters and trolls
Remember quantum computing in the cloud?
Why I don’t buy Apple products
iPaaS in an AI-driven world
‘Digital arrest’ scams are big in India and may be spreading
AMD won’t patch Sinkclose security bug on older Zen CPUs
Tauri 2.0 moves core functionality to plugins
Attacker steals personal data of 200k+ people with links to Arizona tech school
5 Key Benefits Of Code Signing Solutions
Mega money, unfathomable violence pervade thriving underground doxxing scene
5 Open-Source Blockchain Technologies That Linux Users Need to Know About
Google Cloud adds 3 new Apache Airflow operators to Vertex AI
The BlackSuit ransomware gang has demanded over $500 million since 2022

Multiple vulnerabilities have been discovered in protobuf-c, the worst of which could result in denial of service.

5 things great data science product managers do
Evolve your cloud security knowledge
Most AI software will stay proprietary
Tabnine AI coding assistant flexes its models
Practical strategies for mitigating API security risks

Multiple vulnerabilities have been discovered in PHP, the worst of which can lead to a denial of service.

A vulnerability has been discovered in protobuf and protobuf-python, which can lead to a denial of service.

A vulnerability has been discovered in dpkg, which allows for directory traversal.

Multiple vulnerabilities have been discovered in MuPDF, the worst of which could lead to arbitrary code execution.

Trump campaign cites Iran election phish claim as evidence leaked docs were stolen

Update NSS to 3.103.0 Update to Firefox 129.0

The UN unanimously agrees that cybercrime is bad, mkay?

https://security-tracker.debian.org/tracker/DSA-5747-1

Black Hat USA 2024 recap – Week in security with Tony Anscombe

Unsurprisingly, many discussions focused on the implications of the recent CrowdStrike outage, including the lessons it may have offered for bad actors

Black Hat USA 2024: All eyes on election security

In this high-stakes year for democracy, the importance of robust election safeguards and national cybersecurity strategies cannot be understated

Multiple vulnerabilities have been discovered in runc, the worst of which could lead to privilege escalation.

A vulnerability has been discovered in Ruby on Rails, which can lead to remote code execution via serialization of data.

New version 8.5.5

* bsc#1228256 * bsc#1228257 Cross-References: * CVE-2024-1737

* bsc#1220356 * bsc#1227525 Affected Products: * Basesystem Module 15-SP5

Black Hat USA 2024: How cyber insurance is shaping cybersecurity strategies

Cyber insurance is not only a safety net, but it can also be a catalyst for advancing security practices and standards

Multiple vulnerabilities have been discovered in GnuPG, the worst of which could lead to signature spoofing.

Multiple vulnerabilities have been discovered in Bundler, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in GPAC, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in libde265, the worst of which could lead to arbitrary code execution.

Raptor Lake microcode limits Intel chips to a mere 1.55 volts to prevent CPU destruction
Why tech-savvy leadership is key to cyber insurance readiness

Having knowledgeable leaders at the helm is crucial for protecting the organization and securing the best possible cyber insurance coverage

Understanding escalating cyber threats
Pro-Iran groups lay groundwork for ‘chaos and violence’ as US election meddling intensifies

Multiple vulnerabilities have been discovered in ncurses, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in QEMU, the worst of which could lead to a denial of service.

A vulnerability has been discovered in Nautilus, which can lead to a denial of service.

A strategic road map for navigating the cloud skills shortage

Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation. For the oldstable distribution (bullseye), this problem has been fixed

Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation. For the stable distribution (bookworm), this problem has been fixed in

* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671

It’s 2024 and we’re just getting round to stopping browsers insecurely accessing 0.0.0.0
Hello? Are you talking on a Cisco SPA300 or SPA500 IP phone? Now’s the time to junk ’em
AWS closes several cloud services to new customers

https://security-tracker.debian.org/tracker/DSA-5745-1

https://security-tracker.debian.org/tracker/DSA-5746-1

Delta: CrowdStrike’s offer to help in Falcon meltdown was too little, too late
US ‘laptop farm’ man accused of outsourcing his IT jobs to North Korea to fund weapons programs
Node.js unveils experimental TypeScript support