Menu

Category Archives: Security

Articles about security

* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168

* bsc#1232747 * bsc#1233631 * bsc#1233632 Cross-References:

* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168

Meta quietly leans on rival GPT-4 despite Zuckerberg’s bold Llama claims
Tech support scams leverage Google ads again and again, fleecing unsuspecting internet users
Just say no to JavaScript
Intro to Express.js: Endpoints, parameters, and routes
Cython tutorial: How to speed up Python

* bsc#1027519 * bsc#1230366 * bsc#1232542 * bsc#1232622 * bsc#1232624

* bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553

Eurocops take down ‘secure’ criminal chat system known as Matrix
FTC scolds two data brokers for allegedly selling your location to the meter
Heroku PaaS adds .NET support
Perfect 10 directory traversal vuln hits SailPoint’s IAM solution
Kotlin previews guard conditions in when expressions

https://security-tracker.debian.org/tracker/DSA-5815-2

https://security-tracker.debian.org/tracker/DSA-5823-1

Major energy contractor reports ‘limited’ access to IT after ransomware locks files
The AI Fix #27: Why is AI full of real-life Bond villains?

* bsc#1233773 Cross-References: * CVE-2024-10524

* bsc#1233651 * bsc#1233702 * bsc#1233703 Cross-References:

* bsc#1233650 * bsc#1233695 Cross-References: * CVE-2024-11691

* bsc#1227378 * bsc#1231795 * bsc#1233307 Cross-References:

* bsc#1233815 Cross-References: * CVE-2024-53849

* bsc#1231795 * bsc#1232750 * bsc#1233307 Cross-References:

Severity of the risk facing the UK is widely underestimated, NCSC annual review warns
North Korean hackers masquerade as remote IT workers and venture capitalists to steal crypto and secrets
No guarantees of payday for ransomware gang that claims to have hacked children’s hospital
AWS Database Migration Service gets gen AI-powered schema conversion
Open-washing and the illusion of AI openness
How AI agents will transform the future of work
Understanding unstructured data in the context of AI
Russia gives life sentence to Hydra dark web kingpin after seizing a ton of drugs
Data on 760K workers from Xerox, Nokia, BofA, Morgan Stanley and more dumped online
Rust 1.83 expands const capabilities
AWS unveils cloud security IR service for a mere $7K a month
Red Hat Ansible service comes to AWS Marketplace
AWS PartyRock updated with free daily usage for developers
Download the Cloud Optimization Enterprise Spotlight
Discover the future of Linux security
AWS brings RAG evaluation and LLM-as-a-judge feature to Amazon Bedrock
Russia arrests one of its own – a cybercrime suspect on FBI’s most wanted list
Telco security is a dumpster fire and everyone’s getting burned
The dangers of fashion-driven tech decisions
Refactoring AI code: The good, the bad, and the weird
5 ways AI will change the software development life cycle

https://security-tracker.debian.org/tracker/DSA-5822-1

Interpol nabs thousands, seizes millions in global cybercrime-busting op

An update that fixes two vulnerabilities is now available.

Improve memory consumption and performance of Canvas getImageData. Fix preserve-3D intersection rendering. Fix video dimensions since GStreamer 1.24.9. Fix the HTTP-based remote Web Inspector not loading in Chromium. Fix content filters not working on about:blank iframes.

New version 4.4.2

Update to 5.0.2 fix rhbz#2326888

New version 4.2.9

Multiple vulnerabilities were discovered in Lemonldap::NG, an OpenID-Connect, CAS and SAML compatible Web-SSO system, which could lead to injection of arbitrary scripts or authorization bypass.

Two issues have been found in editorconfig-core, a coding style indenter for all editors. Both issues are related to buffer overflows in different locations.

Brief introduction CVE-2022-0934

An issue has been found in xfpt, a tool to generate XML from plain tex. The issue is about bad handling of input data, which may result in a stack-based buffer overflow and execution of arbitrary code, when

RansomHub claims to net data hat-trick against Bologna FC

An issue has been found in tgt, Linux SCSI target user-space daemon and tools. The issue was related to using rand() without proper seed, resulting in identical sequences of challenges.

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because ‘’ characters at the end of header names are ignored, i.e., a “Transfer-Encoding: chunked” header is treated the same as a “Transfer-Encoding: chunked” header. (CVE-2024-52530) GNOME libsoup before 3.6.1 allows a buffer overflow in applications that

ProFTPD a popular FTP server was affected by multiple vulnerabilities. CVE-2023-48795

Zabbix urges upgrades after critical SQL injection bug disclosure

* bsc#1233447 Cross-References: * CVE-2024-52304

* bsc#1233323 * bsc#1233325 * bsc#1233326 * bsc#1233327

Ransom gang claims attack on NHS Alder Hey Children’s Hospital
UK hospital, hit by cyberattack, resorts to paper and postpones procedures
Fighting cybercrime with actionable knowledge
Python 3.14 is a rational constant
Are we worse at cloud computing than 10 years ago?

Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and

Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and

Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]

Update to 128.5.0 https://www.thunderbird.net/en-US/thunderbird/128.5.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-68/

https://security-tracker.debian.org/tracker/DSA-5821-1

https://security-tracker.debian.org/tracker/DSA-5820-1

Exactly what would an AI-centric OS look like?
Mimic ransomware: what you need to know
Uber branches out into AI data labeling
NHS major ‘cyber incident’ forces hospitals to use pen and paper

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version

Copilot Studio Agents get a major upgrade via Microsoft 365 Copilot
How to use ref structs in C# 13

* bsc#1233695 Cross-References: * CVE-2024-11691 * CVE-2024-11692

* bsc#1225889 Cross-References: * CVE-2024-1298

* bsc#1209401 Affected Products: * Basesystem Module 15-SP6 * Desktop Applications Module 15-SP6

* jsc#PED-11092 Cross-References: * CVE-2023-31489 * CVE-2023-31490

The only thing worse than being fired is scammers fooling you into thinking you’re fired

1.37 – fix parsing of “use if …” Fixes errors in PAR::Packer test t/90-rt59710.t – add test for _parse_libs() 1.36

Smashing Security podcast #395: Gym hacking, disappearing DNA, and a social lockout
Salt Typhoon’s surge extends far beyond US telcos
Uno Platform unveils visual designer for cross-platform .NET development
T-Mobile US takes a victory lap after stopping cyberattacks: ‘Other providers may be seeing different outcomes’

https://security-tracker.debian.org/tracker/DSA-5819-1

Bolster resilience against 2025 cyber threats
Data broker leaves 600K+ sensitive files exposed online
AWS re:Invent 2024: The future of cloud computing (and where AWS fits in it)
First-ever UEFI bootkit for Linux in the works, experts say
Automating endpoint management

* bsc#1233695 Cross-References: * CVE-2024-11691 * CVE-2024-11692

* bsc#1233434 Cross-References: * CVE-2024-52316