Menu

Category Archives: Security

Articles about security

AMD processors may allow a privileged local attacker to further escalate their privileged and execute arbitrary code within the processor’s firmware layer.

https://security-tracker.debian.org/tracker/DSA-5794-1

Two issues have been found in asterisk, an Open Source Private Branch Exchange.

Open source LLM tool primed to sniff out Python zero-days

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Update to 130.0.6723.58 * High CVE-2024-9954: Use after free in AI * Medium CVE-2024-9955: Use after free in Web Authentication * Medium CVE-2024-9956: Inappropriate implementation in Web Authentication * Medium CVE-2024-9957: Use after free in UI

Fixes possible denial of service attack on untrusted input

https://security-tracker.debian.org/tracker/DSA-5793-1

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

True multithreading in Python at last!
Threat actors exploiting zero-days faster than ever – Week in security with Tony Anscombe

The average time it takes attackers to weaponize a vulnerability, either before or after a patch is released, shrank from 63 days in 2018-2019 to just five days last year

Update to 130.0.6723.58 * High CVE-2024-9954: Use after free in AI * Medium CVE-2024-9955: Use after free in Web Authentication * Medium CVE-2024-9956: Inappropriate implementation in Web Authentication * Medium CVE-2024-9957: Use after free in UI

Fix for CVE-2024-48957 Automatic update for libarchive-3.7.2-6.fc40.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Jetpack fixes 8-year-old flaw affecting millions of WordPress sites

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Protecting children from grooming | Unlocked 403 cybersecurity podcast (ep. 7)

“Hey, wanna chat?” This innocent phrase can take on a sinister meaning when it comes from an adult to a child online – and even be the start of a predatory relationship

Alleged Bitcoin crook faces 5 years after SEC’s X account pwned
ESET denies it was compromised as Israeli orgs targeted with ‘ESET-branded’ wipers
Free-threaded programming in Python 3.13
AI stagnation: The gap between AI investment and AI adoption

* bsc#1229910 Cross-References: * CVE-2024-42934

* bsc#1231689 Cross-References: * CVE-2024-47874

* bsc#1231651 Cross-References: * CVE-2024-8184

Intel hits back at China’s accusations it bakes in NSA backdoors
Biz hired, and fired, a fake North Korean IT worker – then the ransom demands began
Uncle Sam puts $10M bounty on Russian troll farm Rybar
Troubled US insurance giant hit by extortion after data leak

The fixes for CVE-2024-38474 and CVE-2024-39884 introduced two regressions in mod_rewrite and mod_proxy. For Debian 11 bullseye, these problems have been fixed in version

A glimmer of good news on the ransomware front, as encryption rates plummet

The more devices, digital apps and online accounts you use, the more efficient and convenient your life becomes. But all that ease of use comes with a price. Your devices are constantly collecting your personal data to fine-tune your user experience. At the same time, hackers, and other cyber criminals are working round the clock […]

Hackers breach Pokémon game developer, source code and personal information leaks online
Brazilian police claim they’ve cuffed serial cybercrook behind FBI and Airbus attacks
Secure Azure Kubernetes with Advanced Container Networking Services
How to use Task.WhenEach in .NET 9

* bsc#1228349 * bsc#1228786 Cross-References: * CVE-2024-40909

WeChat devs introduced security flaws when they modded TLS, say researchers

* bsc#1227651 * bsc#1228573 Cross-References: * CVE-2021-47291

* bsc#1225312 * bsc#1225739 * bsc#1226325 * bsc#1228573 * bsc#1228786

* bsc#1228573 * bsc#1228786 Cross-References: * CVE-2024-40954

* bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225099 * bsc#1225312

Anonymous Sudan isn’t any more: Two alleged operators named, charged

Prevent command injection by quoting template strings in activation scripts

US contractor pays $300K to settle accusation it didn’t properly look after Medicare users’ data
Smashing Security podcast #389: WordPress vs WP Engine, and the Internet Archive is down
Critical default credential bug in Kubernetes Image Builder allows SSH root access
Volkswagen monitoring data dump threat from 8Base ransomware crew
Critical hardcoded SolarWinds credential now exploited in the wild
China’s infosec leads accuse Intel of NSA backdoor, cite chip security flaws

* bsc#1231284 Cross-References: * CVE-2024-8508

* bsc#1231284 Cross-References: * CVE-2024-8508

* bsc#1095184 * bsc#1118897 * bsc#1118898 * bsc#1118899 * bsc#1121850

* bsc#1225312 * bsc#1226325 * bsc#1227651 * bsc#1228573

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1223059 * bsc#1223363

* bsc#1210619 * bsc#1218487 * bsc#1220145 * bsc#1220537 * bsc#1221302

Get started with the free-threaded build of Python 3.13
WasmGC and the future of front-end Java development
Strengthen your cybersecurity with automation
Internet Archive wobbles back online, with limited functionality
IBM acquires Indian SaaS startup Prescinto to shine a light on renewable energy assets
WhatsApp may expose the OS you use to run it – which could expose you to crooks
Cisco confirms ‘ongoing investigation’ after crims brag about selling tons of data

https://security-tracker.debian.org/tracker/DSA-5792-1

Microsoft says more ransomware stopped before reaching encryption
The AI Fix #20: Elon’s androids, emotional support chickens, and an AI Fix super fan

* bsc#1228123 Cross-References: * CVE-2024-41184

* bsc#1228123 Cross-References: * CVE-2024-41184

* bsc#1225312 * bsc#1225739 * bsc#1226325 * bsc#1228573 * bsc#1228786

* bsc#1219296 * bsc#1220145 * bsc#1220211 * bsc#1220828 * bsc#1220832

* bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225099 * bsc#1225312

* bsc#1223683 * bsc#1225099 * bsc#1225739 * bsc#1228349 * bsc#1228573

At the mercy of social media
How to manage generative AI programs – governance, education, regulation
Why are we still confused about cloud security?
AI amplifies systemic risk to financial sector, says India’s Reserve Bank boss
China again claims Volt Typhoon cyber-attack crew was invented by the US to discredit it
US healthcare org admits up to 400,000 people’s personal info was snatched
Open source package entry points could be used for command jacking
Leveraging AI/ML for next-gen SOC environments
Trump campaign arms up with ‘unhackable’ phones after Iranian intrusion

An update that fixes two vulnerabilities is now available.

Python could me made to bypass some restrictions if it received specially crafted input.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Thousands of Fortinet instances vulnerable to actively exploited flaw
How to head off data breaches with CIAM
Making generative AI work for you
How do we fund open source?
How to leverage APIs for IT-enabled information capability
Crypto-apocalypse soon? Chinese researchers find a potential quantum attack on classical encryption
Schools bombarded by nation-state attacks, ransomware gangs, and everyone in between

Update to 129.0.6668.100 * CVE-2024-9602: Type Confusion in V8 * CVE-2024-9603: Type Confusion in V