Menu

Category Archives: Security

Articles about security

Firefox ditches Do Not Track because nobody was listening anyway
Citrix goes shopping in Europe and returns with gifts for security-conscious customers
Smashing Security podcast #397: Snowflake hackers, and under the influence

https://security-tracker.debian.org/tracker/DSA-5829-1

Blocking Chinese spies from intercepting calls? There ought to be a law
Google unveils Gemini 2.0 AI model for agentic era

https://security-tracker.debian.org/tracker/DSA-5827-1

Krispy Kreme Doughnut Corporation admits to hole in security
Three more vulns spotted in Ivanti CSA, all critical, one 10/10
The makers and takers of WordPress
OpenSilver 3.1 brings XAML designer for VS Code
Intro to Express.js: Advanced programming with templates, data persistence, and forms
3 takeaways from the Ultralytics AI Python library hack
US names Chinese national it alleges was behind 2020 attack on Sophos firewalls
Go eclipses Node.js in web API requests, Cloudflare reports
Microsoft holds last Patch Tuesday of the year with 72 gifts for admins
“CP3O” pleads guilty to multi-million dollar cryptomining scheme
US military grounds entire Osprey tiltrotor fleet over safety concerns
3AM ransomware: what you need to know
AMD secure VM tech undone by DRAM meddling
The AI Fix #28: Robot dogs with bombs, and who is David Mayer?
Fully patched Cleo products under renewed ‘zero-day-ish’ mass attack
The Critical Role of Open-Source Encryption Apps in Combating Chinese Telecom Hacking
Heart surgery device maker’s security bypassed, data encrypted and stolen
Databricks unveils synthetic data generation API to help evaluate agents faster
Bitfinex heist gets the Netflix treatment after ‘cringey couple’ sentenced
5G never delivered for cloud computing
How to build better AI chatbots
WhatsApp finally fixes View Once flaw that allowed theft of supposedly vanishing pics
Police arrest suspect in murder of UnitedHealthcare CEO, with grainy pics the only tech involved

https://security-tracker.debian.org/tracker/DSA-5826-1

Python a shoo-in for Tiobe language of the year
Configuring SELinux: An In-Depth Guide to Securing Your Linux System
China’s Salt Typhoon recorded top American officials’ calls, says White House

Multiple vulnerabilities have been fixed in the graphics debugger RenderDoc. CVE-2023-33863

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service, authorization bypass, or information disclosure.

It’s an exciting time to be a managed service provider (MSP). More than ever, small and medium businesses (SMBs) are looking to MSPs as trusted advisors to help safeguard them from today’s growing cyber threats. One of the services in high demand right now? Managed detection and response (MDR). When asked about their biggest growth […]

Crooks stole AWS credentials from misconfigured sites then kept them in open S3 bucket
Supply chain compromise of Ultralytics AI library results in trojanized versions
OpenWrt orders router firmware updates after supply chain attack scare
Microsoft dangles $10K for hackers to hijack LLM email service
Why AI coding assistants are best for experienced developers
Surveying the LLM application framework landscape
Why business teams must stay out of application development
Blue Yonder ransomware termites claim credit

Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially among other effects allowing denial of service, information disclosure, use-after-free or remote code inclusion.

How Chinese insiders are stealing data scooped up by President Xi’s national surveillance system

Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in PostgreSQL, the worst of which could lead to arbitrary code execution.

Update to 131.0.6778.108 High CVE-2024-12053: Type Confusion in V8

Buffer overflow when calculating the quantile value has been fixed in the GNU Scientific Library (GSL). For Debian 11 bullseye, this problem has been fixed in version

Salt Typhoon forces FCC’s hand on making telcos secure their networks

A vulnerability has been discovered in OATH Toolkit, which could lead to local root privilege escalation.

Multiple vulnerabilities have been discovered in Dnsmasq, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in Salt, the worst of which can lead to arbitrary code execution.

Confidential cluster: Running Red Hat OpenShift clusters on confidential nodes

Multiple vulnerabilities have been discovered in Icinga2, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in OpenJDK, the worst of which could lead to remote code execution.

Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.

Clarifai previews AI compute orchestration
Micropatchers share 1-instruction fix for NTLM hash leak flaw in Windows 7+
Facing sale or ban, TikTok tossed under national security bus by appeals court
OpenAI releases o1 LLM, unveils ChatGPT Pro
Better together? Why AWS is unifying data analytics and AI services in SageMaker

* bsc#1233420 Cross-References: * CVE-2024-52616

Badass Russian techie outsmarts FSB, flees Putinland all while being tracked with spyware

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1225429 * bsc#1225733 * bsc#1229273 * bsc#1229553

* bsc#1223683 * bsc#1225099 * bsc#1225429 * bsc#1225733 * bsc#1225739

* bsc#1225733 * bsc#1229553 Cross-References: * CVE-2024-36904

* bsc#1223683 * bsc#1225309 * bsc#1225310 * bsc#1225311 * bsc#1225312

Protect your clouds
Public cloud providers are fumbling the AI opportunity
What is TypeScript? Strongly typed JavaScript
PoC exploit chains Mitel MiCollab 0-day, auth-bypass bug to access sensitive files
Microsoft: Another Chinese cyberspy crew targeting US critical orgs ‘as of yesterday’

https://security-tracker.debian.org/tracker/DSA-5824-1

https://security-tracker.debian.org/tracker/DSA-5825-1

Solana blockchain’s popular web3.js npm package backdoored to steal keys, funds
Explore strategies for effective endpoint control
Russian money-laundering network linked to drugs and ransomware disrupted, 84 arrests

* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168

* bsc#1234115 Cross-References: * CVE-2024-53981

British hospitals hit by cyberattacks still battling to get systems back online
Smashing Security podcast #396: Dishy DDoS dramas, and mining our minds for data
BT Group confirms attackers tried to break into Conferencing division
Shape the future of UK cyber security
Get started with Azure AI Content Understanding

* bsc#1225733 * bsc#1229553 Cross-References: * CVE-2024-36904

* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202

Ransomware hangover, Putin grudge blamed for vodka maker’s bankruptcy

Improve memory consumption and performance of Canvas getImageData. Fix preserve-3D intersection rendering. Fix video dimensions since GStreamer 1.24.9. Fix the HTTP-based remote Web Inspector not loading in Chromium. Fix content filters not working on about:blank iframes.

Update to 128.5.0 https://www.thunderbird.net/en-US/thunderbird/128.5.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-68/

T-Mobile US CSO: Spies jumped from one telco to another in a way ‘I’ve not seen in my career’
AI chatbot startup WotNot leaks 346,000 files, including passports and medical records
Cops arrest suspected admin of German-language crime bazaar
Ransomware-hit vodka maker Stoli files for bankruptcy in the United States
Microsoft says premature patch could make Windows Recall forget how to work
AWS amplifies developer tools with new gen AI features

* bsc#1227378 * bsc#1231795 * bsc#1233307 Cross-References: