Menu

Category Archives: Security

Articles about security

Now US government agencies can use OpenAI’s ChatGPT too
The curious story of Uncle Sam’s HR dept, a hastily set up email server, and fears of another cyber disaster
Stable values API would speed Java startups
SLAP, Apple, and FLOP: Safari, Chrome at risk of data theft on iPhone, Mac, iPad Silicon
New tweak to Linux kernel could cut data center power usage by up to 30%
Baguette bandits strike again with ransomware and a side of mockery

https://security-tracker.debian.org/tracker/DSA-5851-1

The AI Fix #35: Project Stargate, the AI emergency, and batsh*t AI cryonics
Protecting AWS environments from cyberthreats
Security pros more confident about fending off ransomware, despite being battered by attacks
Most Java-based organizations use Java for AI development – report
Endor Labs’ new tool helps enterprises track the AI models they use

* bsc#1214612 * bsc#1215807 * bsc#1215926 * bsc#1217828 * bsc#1221677

Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2024-50349

The crisis of AI’s hidden costs
A distributed state of mind: Event-driven multi-agent systems
Apple plugs security hole in its iThings that’s already been exploited in iOS

FRR could be made to crash or exhibit degraded performance if it received specially crafted network traffic.

Quagga could be made to crash if it received specially crafted network traffic.

US freezes foreign aid, halting cybersecurity defense and policy funds for allies

* bsc#1225819 * bsc#1227369 * bsc#1227781 * bsc#1227784 * bsc#1228349

Prompt Security adds code sanitization, data leak prevention for GitHub Copilot
DeepSeek limits new accounts amid cyberattack
Google takes action after coder reports ‘most sophisticated attack I’ve ever seen’
Hacked buses blare out patriotic pro-European anthems in Tbilisi, attack government
Sweden seizes cargo ship after another undersea cable hit in suspected sabotage

* bsc#1226324 Cross-References: * CVE-2024-36971

* bsc#1226324 * bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553

CDNs: Great for speeding up the internet, bad for location privacy

An update that fixes two vulnerabilities is now available.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

British Museum says ex-contractor ‘shut down’ IT systems, wreaked havoc
Is ChatGPT making us stupid?
How to pick the right SAST tool
11 cutting-edge programming languages to learn now

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size. (CVE-2025-0395)

Timing side-channel in ECDSA signature computation. (CVE-2024-13176) References: – https://bugs.mageia.org/show_bug.cgi?id=33942 – https://openssl-library.org/news/secadv/20250120.txt

Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8

https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/

Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8

https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/

https://security-tracker.debian.org/tracker/DSA-5850-1

Puppet open source fork OpenVox arrives
Someone is slipping a hidden backdoor into Juniper routers across the globe, activated by a magic packet
UK telco TalkTalk confirms probe into alleged data grab underway

pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.

New version 3.4.1, a couple of fixes for the 3.4.0 release.

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Includes security fixes to the crypto/x509 and net/http packages

Bun 1.2 squashes Node.js compatibility bugs
AI chatbot startup founder, lawyer wife accused of ripping off investors in $60M fraud
Don’t want your Kubernetes Windows nodes hijacked? Patch this hole now
North Korean dev who renamed himself ‘Bane’ accused of IT worker fraud scheme
Be careful what you say about data leaks in Turkey, new law could mean prison for reporting hacks
JetBrains launches AI coding agent
Is cloud-based AI becoming a monopoly?
Ready or not, here it comes: GenAI in 2025
China and friends claim success in push to stamp out tech support cyber-scam slave camps
Court rules FISA Section 702 surveillance of US resident was unconstitutional

Update to latest version Fix CVE-2024-53263

pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.

Update to latest version Fix CVE-2024-53263

PCL could be made to crash if it received specially crafted input.

https://security-tracker.debian.org/tracker/DSA-5849-1

One of Salt Typhoon’s favorite flaws still wide open on 91% of at-risk Exchange Servers

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Palo Alto Networks releases QRNG API framework
Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management

https://security-tracker.debian.org/tracker/DSA-5847-1

The OpenJDK’s plans for Java in 2025
SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix
Meta’s pay-or-consent model under fire from EU consumer group
FortiGate config leaks: Victims’ email addresses published online
Google BigQuery gets metadata service with Iceberg support

OpenJPEG could be made to crash or run programs if it opened a specially crafted file.

Django could be made to cause a denial of service if it received a specially crafted IPv6 string.

In FRR, the internet routing protocol suite software, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket’s buffer size, default 4K on most OSes.

Who is DDoSing you? Rivals, probably, or cheesed-off users
Biz tax rises, inflation and high interest. Why fewer UK tech firms started in 2024
Stratoshark analyzes cloud applications at a syscall level
How to use resource-based authorization in ASP.NET Core

Multiple vulnerabilities have been discovered in PHP, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to arbitrary code execution.

Asus lets processor security fix slip out early, AMD confirms patch in progress
Kazakhstan’s SOS 102: Redefining Public Safety Through Innovation
Oracle emits 603 patches, names one it wants you to worry about soon
Smashing Security podcast #401: Hacks on the high seas, and how your home can be stolen under your nose

https://security-tracker.debian.org/tracker/DSA-5848-1

Trump ‘waved a white flag to Chinese hackers’ as Homeland Security axed cyber advisory boards
Supply chain attack hits Chrome extensions, could expose millions
Give users confidence in your digital infrastructure
Microsoft issues out-of-band fix for Windows Server 2022 NUMA glitch
Stargate Project launched for OpenAI AI infrastructure