Menu

Category Archives: Security

Articles about security

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of Java sandbox restrictions.

CrowdStrike unhappy about Delta’s ‘litigation threat,’ claims airline refused ‘free on-site help’
11 reasons the new JavaScript isn’t like the old JavaScript
Turning AI hype into reality
A developer’s guide to the headless data architecture

Several security issues were fixed in the Linux kernel.

Backport fix for CVE-2023-49528

China starts testing national cyber-ID before consultation on the idea closes
Google gamed into advertising a malicious version of Authenticator

https://security-tracker.debian.org/tracker/DSA-5736-1

https://security-tracker.debian.org/tracker/DSA-5737-1

AI and automation reducing breach costs – Week in security with Tony Anscombe

Organizations that leveraged AI and automation in security prevention cut the cost of a data breach by US$2.22 million compared to those that didn’t deploy these technologies, according to IBM

DARPA suggests turning old C code automatically into Rust – using AI, of course

update to 127.0.6533.88 Critical CVE-2024-6990: Uninitialized Use in Dawn High CVE-2024-7255: Out of bounds read in WebTransport High CVE-2024-7256: Insufficient data validation in Dawn

update to 127.0.6533.88 Critical CVE-2024-6990: Uninitialized Use in Dawn High CVE-2024-7255: Out of bounds read in WebTransport High CVE-2024-7256: Insufficient data validation in Dawn update to 127.0.6533.72

Update to upstream version 2.11.

Update to upstream version 2.11.

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

* bsc#1219296 * bsc#1220145 * bsc#1220211 * bsc#1220828 * bsc#1220832

Israeli hacktivist group brags it took down Iran’s internet
Respect your data, and protect it

* bsc#1214855 * bsc#1221916 * bsc#1228324 Cross-References:

Fortune 50 biz coughed up record-breaking $75M ransom to halt leak of stolen data
UK plans to revamp national cyber defense tools are already in motion

Gross could be made to crash or to allow arbitrary code execution.

Small language models and open source are transforming AI

* bsc#1167721 Cross-References: * CVE-2019-20633

UK crimebusters shut down global call-spoofing outfit that claimed 170K-plus victims
Japan mandates app to ensure national ID cards aren’t forged

update to 127.0.6533.72 * CVE-2024-6988: Use after free in Downloads * CVE-2024-6989: Use after free in Loader * CVE-2024-6991: Use after free in Dawn * CVE-2024-6992: Out of bounds memory access in ANGLE

India contemplates compulsory dynamic 2FA for digital payments
US sends cybercriminals back to Russia in prisoner swap that freed WSJ journo, others

Several security issues were fixed in Tomcat.

https://security-tracker.debian.org/tracker/DSA-5735-1

Several security issues were fixed in Bind.

Too late now for canary test updates, says pension fund suing CrowdStrike
Google adds Gemini to BigQuery, Looker to help with data engineering
The cyberthreat that drives businesses towards cyber risk insurance

Many smaller organizations are turning to cyber risk insurance, both to protect against the cost of a cyber incident and to use the extensive post-incident services that insurers provide

$75 million record-breaking ransom paid to cybercriminals, say researchers
FBI, CISA remind US voters that DDoS attacks can’t touch election systems
How to counter adversarial AI

Several security issues were fixed in the Linux kernel.

Firefox’s Mozilla follows Google in losing trust in Entrust’s TLS certificates
Google Cloud adds graph processing to Spanner, SQL support to Bigtable

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

How Dapr improves cloud-native development

* bsc#1224788 Cross-References: * CVE-2024-35195

* bsc#1211674 Cross-References: * CVE-2023-32681

The best new features in C# 13
Germany names China as source of attack on government geospatial agency
Ransomware infection cuts off blood supply to 250+ hospitals
More than 83K certs from nearly 7K DigiCert customers must be swapped out now
Russia takes aim at Sitting Ducks domains, bags 30,000+

Several security issues were fixed in Python.

Chrome adopts app-bound encryption to stymie cookie-stealing malware
Embedding AI security from the get go
‘Error’ in Microsoft’s DDoS defenses amplified 8-hour Azure outage
Full-stack development with Java, React, and Spring Boot, Part 2
How to get started with MySQL
UK Electoral Commission slapped for basic cybersecurity fails
Why Apache Iceberg is on fire right now

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 17.

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

Update to 1.3.3 https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3

DigiCert gives unlucky folks 24 hours to replace doomed certificates after code blunder
White House opts to not add regulatory restrictions on AI development – for now
Delta Air Lines dials up Microsoft’s legal nemesis over CrowdStrike losses
‘LockBit of phishing’ EvilProxy used in more than a million attacks every month
The AI Fix #9: When AI detectors fail (spectacularly), and OpenAI’s five steps to Skynet

* bsc#1228184 Cross-References: * CVE-2024-40897

* bsc#916845 Cross-References: * CVE-2013-4235

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Ransomware gangs are loving this dumb but deadly make-me-admin ESXi vulnerability

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Who should own cloud costs?
The rise and fall of Stack Overflow
How AI will transform data analytics
Proofpoint phishing palaver plagues millions with ‘perfectly spoofed’ emails from IBM, Nike, Disney, others
Malaysia is working on an internet ‘kill switch’, says minister
Meta’s AI safety system defeated by the space bar
US border cops really must get a warrant in NY before searching your phones, devices
Hacking gang leaks documents stolen from Pentagon IT provider
Intruders at HealthEquity rifled through storage, stole 4.3M people’s data

Several security issues were fixed in the Linux kernel.

Google apologizes for breaking password manager for millions of Windows users with iffy Chrome update

Affected Products: * openSUSE Leap 15.5

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

How to choose the right low-code, no-code, or process automation platform
The other shoe drops on generative AI
Qdrant review: A highly flexible option for vector search
Get ready for more Java licensing changes
NIST releases new tool to check AI models’ security
Microsoft admits 8.5M CrowdStruck machines estimate was lowballed