Menu

Category Archives: Security

Articles about security

https://security-tracker.debian.org/tracker/DSA-5744-1

Google unveils Flutter GPU API, Dart updates

https://security-tracker.debian.org/tracker/DSA-5739-1

https://security-tracker.debian.org/tracker/DSA-5738-1

Faulty instructions in Alibaba’s T-Head C910 RISC-V CPUs blow away all security
Fighting AI fire with AI fire
Ahead-of-time class loading proposal would speed Java startups
How AI and Machine Learning Are Transforming Cybersecurity Quality Assurance
Small CSS tweaks can help nasty emails slip through Outlook’s anti-phishing net

A vulnerability has been discovered in Bitcoin, which can lead to a denial of service.

* bsc#1228872 Cross-References: * CVE-2024-7383

* bsc#1227296 Cross-References: * CVE-2024-32230

* bsc#1214855 * bsc#1219267 * bsc#1219268 * bsc#1219438 * bsc#1221916

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

Multiple vulnerabilities have been discovered in aiohttp, the worst of which could lead to service compromise.

What is Google Cloud’s generative AI evaluation service?
Police take just 2 days to recover $40M stolen in business email scam
EQT buys majority share in Swiss cybersecurity biz Acronis
Pig-butchering scammer targets BBC journalist
Full-stack development with Java, React, and Spring Boot, Part 3
UK health services call-handling vendor faces $7.7M fine over 2022 ransomware attack
SharpRhino malware targets IT admins – Hunters International gang suspected
Georgia’s voter portal gets a crash course in client versus backend input validation
Microsoft punches back at Delta Air Lines and its legal threats
CrowdStrike hires outside security outfits to review troubled Falcon code

https://security-tracker.debian.org/tracker/DSA-5740-1

JetBrains updates IDEs, improves AI assistant
Google splats device-hijacking exploited-in-the-wild Android kernel bug among others
Sonic Automotive says ransomware-linked CDK software outage cost it $30M
FTC warns consumers of scammers offering to remove all negative information from credit reports
The AI Fix #10: An AI cookery dumpster fire, the ARC prize, and a creepy new AI friend
Bad apps bypass Windows security alerts for six years using newly unveiled trick

Artificial intelligence (AI) and chatbots like ChatGPT are transforming the way educators and students approach education. It’s not just college students leveraging AI to get ahead; high school and even grade school students are using AI resources for their projects and homework. Students can write essays, get math tutoring help, and even create study plans […]

* bsc#1220356 * bsc#1227525 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5

* bsc#1227052 Cross-References: * CVE-2024-6104

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1221302 * bsc#1223059

Users call on Microsoft to update Outlook’s friendly name feature
Extending Red Hat Unified Kernel Images More Securely By Using Addons
Is efficiency on your cloud architect’s radar?

* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671

* bsc#1227147 Cross-References: * CVE-2024-5535

GitHub Copilot: Productivity boost or DORA metrics disaster?
Visual Studio Code 1.92 improves debugging experience
Billion-dollar bust as international op shutters Cryptonator wallet
MDM vendor Mobile Guardian attacked, leading to remote wiping of 13,000 devices
Illinois relaxes biometric privacy law so snafus won’t cost businesses billions
NFL to begin using face scanning tech across all of its stadiums
Python scores its highest rating in Tiobe index
That cyber-heist of 2.9B personal records? There’s a class-action lawsuit looming for that
Your copilot for improved cyber protection
Sneaky SnakeKeylogger slithers into Windows inboxes to steal sensitive secrets

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of Java sandbox restrictions.

CrowdStrike unhappy about Delta’s ‘litigation threat,’ claims airline refused ‘free on-site help’
11 reasons the new JavaScript isn’t like the old JavaScript
Turning AI hype into reality
A developer’s guide to the headless data architecture

Several security issues were fixed in the Linux kernel.

Backport fix for CVE-2023-49528

China starts testing national cyber-ID before consultation on the idea closes
Google gamed into advertising a malicious version of Authenticator

https://security-tracker.debian.org/tracker/DSA-5736-1

https://security-tracker.debian.org/tracker/DSA-5737-1

AI and automation reducing breach costs – Week in security with Tony Anscombe

Organizations that leveraged AI and automation in security prevention cut the cost of a data breach by US$2.22 million compared to those that didn’t deploy these technologies, according to IBM

DARPA suggests turning old C code automatically into Rust – using AI, of course

update to 127.0.6533.88 Critical CVE-2024-6990: Uninitialized Use in Dawn High CVE-2024-7255: Out of bounds read in WebTransport High CVE-2024-7256: Insufficient data validation in Dawn

update to 127.0.6533.88 Critical CVE-2024-6990: Uninitialized Use in Dawn High CVE-2024-7255: Out of bounds read in WebTransport High CVE-2024-7256: Insufficient data validation in Dawn update to 127.0.6533.72

Update to upstream version 2.11.

Update to upstream version 2.11.

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

* bsc#1219296 * bsc#1220145 * bsc#1220211 * bsc#1220828 * bsc#1220832

Israeli hacktivist group brags it took down Iran’s internet
Respect your data, and protect it

* bsc#1214855 * bsc#1221916 * bsc#1228324 Cross-References:

Fortune 50 biz coughed up record-breaking $75M ransom to halt leak of stolen data
UK plans to revamp national cyber defense tools are already in motion

Gross could be made to crash or to allow arbitrary code execution.

Small language models and open source are transforming AI

* bsc#1167721 Cross-References: * CVE-2019-20633

UK crimebusters shut down global call-spoofing outfit that claimed 170K-plus victims
Japan mandates app to ensure national ID cards aren’t forged

update to 127.0.6533.72 * CVE-2024-6988: Use after free in Downloads * CVE-2024-6989: Use after free in Loader * CVE-2024-6991: Use after free in Dawn * CVE-2024-6992: Out of bounds memory access in ANGLE

India contemplates compulsory dynamic 2FA for digital payments
US sends cybercriminals back to Russia in prisoner swap that freed WSJ journo, others

Several security issues were fixed in Tomcat.

https://security-tracker.debian.org/tracker/DSA-5735-1

Several security issues were fixed in Bind.

Too late now for canary test updates, says pension fund suing CrowdStrike
Google adds Gemini to BigQuery, Looker to help with data engineering
The cyberthreat that drives businesses towards cyber risk insurance

Many smaller organizations are turning to cyber risk insurance, both to protect against the cost of a cyber incident and to use the extensive post-incident services that insurers provide

$75 million record-breaking ransom paid to cybercriminals, say researchers
FBI, CISA remind US voters that DDoS attacks can’t touch election systems
How to counter adversarial AI

Several security issues were fixed in the Linux kernel.

Firefox’s Mozilla follows Google in losing trust in Entrust’s TLS certificates
Google Cloud adds graph processing to Spanner, SQL support to Bigtable

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

How Dapr improves cloud-native development