Menu

Category Archives: Security

Articles about security

CUPS could be made to crash or run programs if it received specially crafted network traffic.

Open source isn’t going to save AI
5 ways data scientists can prepare now for genAI transformation
Embattled users worn down by privacy options? Let them eat code
5 ways companies can use time series forecasting

Several security issues were fixed in Firefox.

ChatGPT o1-preview excels at code generation

https://security-tracker.debian.org/tracker/DSA-5786-1

Dom Walden discovered that the AbuseFilter extension in MediaWiki, a website engine for collaborative work, performed incomplete authorisation checks.

Red Hat Insights provides analytics for the IBM X-Force Cloud Threat Report

update to 129.0.6668.89 High CVE-2024-7025: Integer overflow in Layout High CVE-2024-9369: Insufficient data validation in Mojo High CVE-2024-9370: Inappropriate implementation in V8

Amongst other general bug fixes, this release addresses: CVE-2024-46951 CVE-2024-46952 CVE-2024-46953 CVE-2024-46954

The current versions have reached EOL and several security vulnerabilities were fixed by Mozilla. We are having some issues that are delaying the build for some architectures, so for the moment we are releasing this update just for x86_64

Integer overflows flaws were discovered in the Compound Document Binary File format parser of libgsf, the GNOME Project G Structured File Library, which could result in the execution of arbitrary code if a specially crafted file is processed.

* bsc#1230939 Cross-References: * CVE-2024-47176

The complexities of attack attribution – Week in security with Tony Anscombe

As highlighted by new ESET research this week, attributing a cyberattack to a specific threat actor is a complex affair

Ryanair faces GDPR turbulence over customer ID checks
UK’s Sellafield nuke waste processing plant fined £333K for infosec blunders

update to 129.0.6668.89 High CVE-2024-7025: Integer overflow in Layout High CVE-2024-9369: Insufficient data validation in Mojo High CVE-2024-9370: Inappropriate implementation in V8

Update to new upstream version (closes rhbz#2237124)

Fix CVE-2024-39844 https://wiki.znc.in/ChangeLog/1.9.0

https://security-tracker.debian.org/tracker/DSA-5785-1

Node.js previews network inspection support
Google ships Gemini 1.5 Flash-8B AI model
About a quarter million Comcast subscribers had their data stolen from debt collector

Fabian Vogt reported that the PAM module in oath-toolkit, a collection of components to build one-time password authentication systems, does not safely perform file operations in users’s home directories when using the usersfile feature (allowing to place the OTP state in the home

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.

Unfortunately, when your devices are infected with a virus, it’s not as easy as a little bed rest for them to recover, and the damage can be long-lasting. A cyberattack can compromise your computers, phones and tablets, and open the door for cyber thieves to steal your sensitive personal information. According to a study by […]

Why cloud security outranks cost and scalability
Sellafield nuclear site hit with £332,500 fine after “significant cybersecurity shortfalls”
Visit CyberThreat 2024 to hone your cybersecurity skills
Harvard duo hacks Meta Ray-Bans to dox strangers on sight in seconds

cJSON was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c. (CVE-2024-31755) References:

Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal. (CVE-2023-39327) References:

The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an “SSID Confusion” issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, […]

Use after free in Downloads. (CVE-2024-6988) Use after free in Loader. (CVE-2024-6989) Use after free in Dawn. (CVE-2024-6991) Heap buffer overflow in Layout. (CVE-2024-6994) Inappropriate implementation in Fullscreen. (CVE-2024-6995)

Big names among thousands infected by payment-card-stealing CosmicSting crooks

PHP version 8.2.24 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable

Fix CVE-2024-9014.

https://security-tracker.debian.org/tracker/DSA-5783-1

https://security-tracker.debian.org/tracker/DSA-5784-1

Visual Studio Code 1.94 improves file search

https://security-tracker.debian.org/tracker/DSA-5780-1

SingleStore acquires BryteFlow to boost data ingestion capabilities
Average North American CISO salary now $565K, mainly thanks to one weird trick
Tick tock.. Operation Cronos arrests more LockBit ransomware gang suspects

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Generative AI has taken the world by storm, transforming how individuals and businesses interact with and trust this new technology. With tools like ChatGPT, Grok, DALL-E, and Microsoft Copilot, everyday users are finding new ways to enhance productivity, creativity, and efficiency. However, as the integration of AI into daily life accelerates, so do the concerns […]

Two British-Nigerian men sentenced over multimillion-dollar business email scam

* bsc#1229930 * bsc#1229931 * bsc#1229932 Cross-References:

* bsc#1230020 * bsc#1230034 Cross-References: * CVE-2023-7256

A smarter way to manage malware with Red Hat Insights

Several security issues were fixed in the Linux kernel.

OpenAI updates API with model distillation, prompt caching abilities
Ransomware crew infects 100+ orgs monthly with new MedusaLocker variant
Brits hate how big tech handles their data, but can’t be bothered to do much about it
Understanding VBS Enclaves, Windows’ new security technology
How to use extension methods in C#

https://security-tracker.debian.org/tracker/DSA-5781-1

https://security-tracker.debian.org/tracker/DSA-5782-1

Smashing Security podcast #387: Breaches in your genes, and Kaspersky switcheroo raises a red flag
OpenAI previews Realtime API for speech-to-speech apps
700K+ DrayTek routers are sitting ducks on the internet, open to remote hijacking
Two simple give-me-control security bugs found in Optigo network switches used in critical manufacturing
Why system resilience should mainly be the job of the OS, not just third-party applications

Building efficient recovery options will drive ecosystem resilience

NIST’s security flaw database still backlogged with 17K+ unprocessed bugs. Not great

* bsc#1230986 Cross-References: * CVE-2024-38286

‘Patch yesterday’: Zimbra mail servers under siege through RCE vuln

A protocol flaw was fixed in AsyncSSH.

Spring AI: An AI framework for Java developers
Docker tutorial: Get started with Docker
Microsoft releases official OpenAI library for .NET
The fix for BGP’s weaknesses has big, scary, issues of its own, boffins find

PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable

Update to new upstream version (closes rhbz#2237124)

PHP version 8.3.12 (26 Sep 2024) CGI: Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable

Several packages have been updated for Slackware 15.0 and -current to fix rpath security issues.

* bsc#1230698 Cross-References: * CVE-2024-41996

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Euro cops arrest 4 including suspected LockBit dev chilling on holiday
The AI Fix #18: ChatGPT’s false memories, and would an inner critic stop AI hallucinations?
JDK 24: The new features in Java 24
Evil Corp’s deep ties with Russia and NATO member attacks exposed
NCA unmasks man it suspects is both ‘Evil Corp kingpin’ and LockBit affiliate

From the apps on our smartphones to chatbot assistant services, artificial intelligence (AI) is transforming our lives in both big and small ways. But as exciting as AI can be, it’s also important to understand its potential risks. October is Cybersecurity Awareness Month, making it the perfect time to become more cyber-savvy about AI. Let’s […]

As October rolls around, it’s time to focus on cybersecurity. After all, it’s Cybersecurity Awareness Month—a perfect reminder to check in on the safety of your identity. If you’ve ever had your identity stolen or know someone who has, you understand how serious the problem is. From text scams to stolen passwords, criminals are finding […]

October is the month for pumpkin spice and all things spooky. But protecting your personal information online doesn’t need to be scary. For more than 20 years now, October has also been recognized as Cybersecurity Awareness Month. In our digitally connected world, apps and online accounts can make our lives much more convenient. Sadly, they […]

Two good Visual Studio Code alternatives

Python could be made to bypass some restrictions if it received specially crafted input.

The battle cry of 2025: Do cloud local!
Breaking through AI data bottlenecks
The worst programmer I know
JRuby 10 due to arrive in early-2025
Australian e-tailer digiDirect customers’ info allegedly stolen and dumped online

debian-security-support, the Debian security support coverage checker, has been updated in bullseye-security to mark the end of life of the following packages: * pdns-recursor: See https://bugs.debian.org/1070176

Rackspace internal monitoring web servers hit by zero-day
Ransomware forces hospital to turn away ambulances
T-Mobile US to cough up $31.5M after that long string of security SNAFUs