Menu

Category Archives: Security

Articles about security

https://security-tracker.debian.org/tracker/DSA-5799-1

Senator accuses sloppy domain registrars of aiding Russian disinfo campaigns
FIPS 140-3 changes for PKCS #12
ESET Research Podcast: CosmicBeetle

Learn how a rather clumsy cybercrime group wielding buggy malicious tools managed to compromise a number of SMBs in various parts of the world

Worker surveillance must comply with credit reporting rules

https://security-tracker.debian.org/tracker/DSA-5798-1

Google expands Responsible GenAI Toolkit

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The updated package provides Firefox 128 for all mandatory arches of Mageia (x86_64, i586 and aarch64), fixing several bugs, including security vulnerabilities, for i586 and aarch64: Fullscreen notification dialog can be obscured by document content. (CVE-2024-7518)

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

US offers $10 million bounty for members of Iranian hacking gang
Just how private is Apple’s Private Cloud Compute? You can test it to find out
Hugging Face pitches HUGS as an alternative to Nvidia’s NIM for open models

* bsc#1220262 Cross-References: * CVE-2023-50782

Strengthen DevSecOps with Red Hat Trusted Software Supply Chain
Secure design principles in the age of artificial intelligence
Confidential Containers with IBM Secure Execution for Linux
A look at risk, regulation, and lock-in in the cloud
What is .NET? Microsoft’s answer to Java is now free and open source

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink. (CVE-2024-47191)

fix CVE-2024-7006 (rhbz#2302997) fix CVE-2023-52356 (rhbz#2260112) fix CVE-2023-6228 (rhbz#2251863)

Putin’s pro-Trump trolls accuse Harris of poaching rhinos

https://security-tracker.debian.org/tracker/DSA-5796-1

https://security-tracker.debian.org/tracker/DSA-5797-1

JetBrains offers free use of WebStorm and Rider IDEs
AWS Cloud Development Kit flaw exposed accounts to full takeover
Next.js 15 arrives with faster bundler
Emergency patch: Cisco fixes bug under exploit in brute-force attacks
NotLockBit: ransomware discovery serves as wake-up call for Mac users

* bsc#1231294 Cross-References: * CVE-2024-47850

* bsc#1224038 * bsc#1224051 * bsc#1229013 Cross-References:

Bitwarden’s FOSS halo slips as new SDK requirement locks down freedoms
Ransomware’s ripple effect felt across ERs as patient care suffers
Enter the Neoverse with Azure’s Cobalt servers

* bsc#1231039 Cross-References: * CVE-2024-23213 * CVE-2024-23271

* bsc#1231039 Cross-References: * CVE-2024-23206 * CVE-2024-23213

* bsc#1231698 Cross-References: * CVE-2024-9676

* bsc#1231698 Cross-References: * CVE-2024-9676

Voice-enabled AI agents can automate everything, even your phone scams
China’s top messaging app WeChat banned from Hong Kong government computers
Anthropic’s latest Claude model can interact with computers – what could go wrong?
Perfctl malware strikes again as crypto-crooks target Docker Remote API servers
Samsung phone users under attack, Google warns
Penn State pays DoJ $1.25M to settle cybersecurity compliance case
Smashing Security podcast #390: When security firms get hacked, and your new North Korean remote worker
FortiManager critical vulnerability under active attack
‘Satanic’ data thief claims to have slipped into 350M Hot Topic shoppers info
Microsoft SharePoint RCE flaw exploits in the wild – you’ve had 3 months to patch
Syncfusion open-sources UI controls for .NET MAUI
How developers can automate ‘computer use’ with Anthropic’s new LLM

* bsc#1230683 Cross-References: * CVE-2024-45405

The power of prime numbers in computing
Why we get buggy software
The best Python libraries for parallel processing

libheif could be made to crash or read sensitive data if it opened a specially crafted file

Several security issues were fixed in Go.

Various security, performance, accuracy, and stability issues have been fixed.

New version 4.2.8 Fix for CVE-2024-9781

Millions of Android and iOS users at risk from hardcoded creds in popular apps
Developers embracing API-first development, survey says

It was discovered that there was a potential out-of-bounds read vulnerability in libheif, a decoder and encoder for the HEIF and AVIF image formats.

US lawmakers push DoJ to prosecute tax prep firms for leaking taxpayer data to big tech

https://security-tracker.debian.org/tracker/DSA-5795-1

TSMC blows whistle on potential sanctions-busting shenanigans from Huawei
VMware fixes critical RCE, make-me-root bugs in vCenter – for the second time
Tech firms to pay millions in SEC penalties for misleading SolarWinds disclosures
AI chatbots can be tricked by hackers into helping them steal your private data
Akira ransomware is encrypting victims again following pure extortion fling
The AI Fix #21: Virtual Trump, barking mad AI, and a robot dog with a flamethrower

Unbound could be made to stop responding if it received specially crafted DNS traffic.

Understanding Linux Persistence Mechanisms and Detection Tools
Musk’s xAI unveils a new API service for Grok models
Is data gravity no longer centered in the cloud?
Why Python is the language of choice for AI
Agile and devops for SaaS and low-code development

A heap-based pointer disclosure problem was found in Ghostscript, an interpreter for the PostScript language and for PDF. This could lead to information disclosure.

Firefox could be made to crash or run programs as your login

Multiple vulnerabilities were discovered in libsepol, a set of userspace utilities and libraries for manipulating SELinux policies. CVE-2021-36084, CVE-2021-36085, CVE-2021-36086

Pixel perfect Ghostpulse malware loader hides inside PNG image files
China’s Spamouflage cranks up trolling of US Senator Rubio as election day looms

New openssl packages are available for Slackware 15.0 to fix a security issue.

Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The billionaire behind Trump’s ‘unhackable’ phone is on a mission to fight Tesla’s FSD
macOS HM Surf vuln might already be under exploit by major malware family
IBM works to address the developer skills gap with AI
Boost Your Linux Server Security with SSH Mastery
Stopping the rot in AI spending
How Kubecost shines a light on GPU efficiency
11 open source AI projects that developers will love
Tesla, Intel, deny they’re the foreign company China just accused of making maps that threaten national security
Internet Archive exposed again – this time through Zendesk

AMD processors may allow a privileged local attacker to further escalate their privileged and execute arbitrary code within the processor’s firmware layer.

https://security-tracker.debian.org/tracker/DSA-5794-1