Menu

Category Archives: Security

Articles about security

I tried hard, but didn’t fix all of cybersecurity, admits outgoing US National Cyber Director
GlassFish update fixes restart hangs, random 403 responses
Mitel 0-day, 5-year-old Oracle RCE bug under active exploit
DNA sequencers found running ancient BIOS, posing risk to clinical research
UN’s aviation agency confirms attack on recruitment database
Oracle offers price-performance boost with Exadata X11M update
Building generative AI applications is too hard, developers say

* bsc#1082555 * bsc#1176081 * bsc#1206344 * bsc#1213034 * bsc#1218562

* bsc#1082555 * bsc#1157160 * bsc#1218644 * bsc#1221977 * bsc#1222364

Tinyproxy could be made to crash or run programs if it received specially crafted input.

Crims backdoored the backdoors they supplied to other miscreants. Then the domains lapsed
Intro to Ktor: The HTTP server for Kotlin
Why the C programming language still rules

* bsc#1233435 * bsc#1234663 * bsc#1234664 Cross-References:

Akamai to quit its CDN in China, seemingly not due to trouble from Beijing

Several security issues were fixed in HTMLDOC.

FCC boss urges speedy spectrum auction to fund ‘Rip’n’Replace’ of Chinese kit
Gleam 1.7 brings faster record updates
Almost nothing remains of Software AG
The AI Fix #32: Agentic AI, killer robot fridges, and the robosexual revolution
Turbulence at UN aviation agency as probe into potential data theft begins
DEF CON’s hacker-in-chief faces fortune in medical bills after paralyzing neck injury

* bsc#1234809 Cross-References: * CVE-2024-56326

Cloud providers are running out of ‘next big things’
Agentic AI: The top challenges and how to overcome them
5 ways data teams must lead in AI-driven organizations
US adds web and gaming giant Tencent to list of Chinese military companies

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in the Linux kernel.

Python wins Tiobe language of the year honors

Several security issues were fixed in the Linux kernel.

Charter, Consolidated, Windstream reportedly join China’s Salt Typhoon victim list
FireScam infostealer poses as Telegram Premium app to surveil Android devices

In today’s digital-first world, small and medium-sized businesses (SMBs) face cybersecurity challenges that grow more complex by the day. SMBs are prime targets for attackers hoping to gain a foothold inside any organization that doesn’t have extensive security measures. As threats increase, so does the need for comprehensive, reliable, and accessible protection. This is where […]

MediaTek rings in the new year with a parade of chipset vulns
Demand for AI skills soars, while demand for programming skills falls – O’Reilly report

* bsc#1234809 Cross-References: * CVE-2024-56326

* bsc#1234718 Cross-References: * CVE-2024-11614

* bsc#1202473 * bsc#1205224 * bsc#1211507 Cross-References:

Essential Tips for Updating & Upgrading Your Linux Distro

tinyproxy could be made to expose sensitive information.

After China’s Salt Typhoon, the reconstruction starts now
Someone needs to make AI easy
3 forecasts about time-series forecasting
My robot teacher: The challenge of AI in computer science education
Taiwan reportedly claims China-linked ship damaged one of its submarine cables
Telemetry data from 800K VW Group EVs exposed online

Vulnerabilities were found in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are prior to 7.0.22 and prior to 7.1.2. A difficult to exploit vulnerability allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise an Oracle

The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many ` `. (CVE-2024-39908)

Encryption backdoor debate ‘done and dusted,’ former White House tech advisor says
Securing Linux Environments in AWS: Best Practices and Common Pitfalls
Atos denies Space Bears’ ransomware claims – with a ‘but’

Update to 2.46.5: Fix several crashes and rendering issues. CVE-2024-54479, CVE-2024-54502, CVE-2024-54508, CVE-2024-54505

* bsc#1217826 * bsc#1222815 * bsc#1230551 * bsc#1230552 * bsc#1231345

* bsc#1205224 * bsc#1211507 Cross-References: * CVE-2022-39377

CAPTCHAs now run Doom – on nightmare mode
Boffins carve up C so code can be converted to Rust
The cloud architecture renaissance of 2025
Write Python like it’s 2025
Ruby completes switch to Prism parser

iwd 3.3: Fix issue with handling External Authentication. iwd 3.2: Fix issue with GCC 15 and -std=c23 build errors. Add support for using PMKSA over SAE if available.

iwd 3.3: Fix issue with handling External Authentication. iwd 3.2: Fix issue with GCC 15 and -std=c23 build errors. Add support for using PMKSA over SAE if available.

Linux 6.1 has been packaged for Debian 11 as linux-6.1. This provides a supported upgrade path for systems that currently use kernel packages from the “bullseye-backports” suite.

Chinese cyber-spies reportedly targeted sanctions intel in US Treasury raid
Apple offers to settle ‘snooping Siri’ lawsuit for an utterly incredible $95M
Go teams struggle with coding standards – survey
Fireside chat with Graham Cluley about risks of AI adoption in 2025
Download the Hot IT Certifications Enterprise Spotlight

* bsc#1226162 * bsc#1226468 * bsc#1234292 Cross-References:

* bsc#1234808 * bsc#1234809 Cross-References: * CVE-2024-56201

Fine-tuning Azure OpenAI models in Azure AI Foundry

It was discovered that there was a potential Denial of Service (DoS) vulnerability, in Django, a popular Python-based web development framework.

The AI Fix #31: Replay: AI doesn’t exist
Eight things that should not have happened last year, but did
4 keys for writing cross-platform apps
Intro to VSCode.dev: The IDE in your browser
US Army soldier who allegedly stole Trump’s AT&T call logs arrested

Update to 2.12.9 Fixes CVE-2024-40896

Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2023-28370

* bsc#1234795 Cross-References: * CVE-2024-56378

US Treasury Department outs the blast radius of BeyondTrust’s key leak
China’s cyber intrusions took a sinister turn in 2024
The vital role of red teaming in safeguarding AI systems and data

debootstrap has been updated to avoid pulling in usr-is-merged in testing and unstable. This fixes creating testing/unstable chroots after src:usrmerge is removed from the archive.

More telcos confirm Salt Typhoon breaches as White House weighs in