Menu

Category Archives: Security

Articles about security

Several security issues were fixed in EDK II.

Several security issues were fixed in Lua.

China ponders creating a national ‘cyberspace ID’
Secure Boot useless on hundreds of PCs from major vendors after key leak

https://security-tracker.debian.org/tracker/DSA-5734-2

The security update announced as DSA 5734-1 caused a regression on configurations using the Samba DLZ module. Updated packages are now available to correct this issue.

Telegram for Android hit by a zero-day exploit – Week in security with Tony Anscombe

Attackers abusing the “EvilVideo” vulnerability could share malicious Android payloads via Telegram channels, groups, and chats, all while making them appear as legitimate multimedia files

Update to 1.16 fixes rhbz#2259096

Update to 2.11.2

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Update to 1.16 fixes rhbz#2259096

Update to 2.11.2

TypeScript takes aim at truthy and nullish bugs

https://security-tracker.debian.org/tracker/DSA-5734-1

CrowdStrike meets Murphy’s Law: Anything that can go wrong will
Progress discloses second critical flaw in Telerik Report Server in as many months
The case for multicloud: Lessons from the CrowdStrike outage
Python pick: Shiny for Python—now with chat

* bsc#1222693 Cross-References: * CVE-2023-29483

* bsc#1198880 * bsc#1214678 Cross-References: * CVE-2022-28506

BMC report examines DataOps practices

Update to 115.13.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-31/ https://www.thunderbird.net/en-US/thunderbird/115.13.0/releasenotes/

Backport upstream patch for CVE-2023-49606.

North Korean chap charged for attacks on US hospitals, military, NASA – and even China
Malware crew Stargazers Goblin used 3,000 GitHub accounts to make bank

Update to v1.29.7 for FC40. Resolves CVE-2024-5321: Incorrect permissions on Windows containers logs. Additional bug and regression fixes from upstream.

Update to version 1.11.2 to fix CVE-2023-49606.

CrowdStrike update blunder may cost world billions – and insurance ain’t covering it all
Beware of fake CrowdStrike domains pumping out Lumma infostealing malware
FYI: Data from deleted GitHub repos may not actually be deleted
Rust 1.80 adds lazy types
OpenAI announces free fine-tuning for GPT-4o mini model
Robot dog trained to jam wireless devices during police raids
Uncle Sam accuses telco IT pro of decade-long spying campaign for China
Building cyber-resilience: Lessons learned from the CrowdStrike incident

Organizations, including those that weren’t struck by the CrowdStrike incident, should resist the temptation to attribute the IT meltdown to exceptional circumstances

SEXi / APT Inc ransomware – what you need to know
You should probably fix this 5-year-old critical Docker vuln fairly sharpish

An update that fixes one vulnerability is now available.

Kaspersky says Uncle Sam snubbed proposal to open up its code for third-party review
Mistral AI unveils Mistral Large 2 amid rising AI competition
Build and manage LLM prompts with Prompty
Patch management still seemingly abysmal because no one wants the job

Security fix for CVE-2024-5569 (rhbz#2297117)

New libxml2 packages are available for Slackware XXX 15.0 and -current to fix a security issue.

New htdig packages are available for Slackware 15.0 and -current to fix a security issue.

How a cheap barcode scanner helped fix CrowdStrike’d Windows PCs in a flash

Update to 1.3.3 https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3

Security fix for CVE-2024-5569 (rhbz#2297118)

The months and days before and after CrowdStrike’s fatal Friday
Smashing Security podcast #382: CrowdStrike, Dark Wire, and the Paris Olympics
Visual Studio Code Java extension backs JDK 23
Oops. Apple relied on bad code while flaming Google Chrome’s Topics ad tech
Why Meta’s Llama 3.1 is a boon for enterprises and a bane for other LLM vendors
Uncle Sam opens probe into CrowdStrike turbulence at Delta Air Lines
Windows Patch Tuesday update might send a user to the BitLocker recovery screen
Data pilfered from Pentagon IT supplier Leidos

Security fix for CVE-2024-33869 Security fixes for CVE-2024-29509, CVE-2024-29508, CVE-2024-29507, CVE-2024-29506

update xmedcon to 0.24.0 fixes: Bug 2283157 – xmedcon-0.24.0 is available Bug 2283100 – CVE-2024-29421 xmedcon: Heap overview when parsing DICOM medical files [fedora-all]

provd could be made to run programs as an administrator.

What is GraphQL? Better APIs by design
How to create an operational data store with TiDB
School gets an F for using facial recognition on kids in canteen
Forget security – Google’s reCAPTCHA v2 is exploiting users for profit

A vulnerability has been discovered in Freenet, which can lead to deanonymization due to path folding.

Multiple vulnerabilities have been discovered in ExifTool, the worst of which could lead to arbitrary code execution.

A vulnerability has been discovered in Dmidecode, which can lead to privilege escalation.

CrowdStrike blames a test software bug for that giant global mess it made
Security biz KnowBe4 hired fake North Korean techie, who got straight to work … on evil
Philippines wipes out its legit online gambling industry to take down scammers
Microsoft .NET Aspire automates Dockerfile builds
How did a CrowdStrike config file crash millions of Windows computers? We take a closer look at the code
Shiny for Python adds chat component for generative AI chatbots
Administrators have update lessons to learn from the CrowdStrike outage
Protecting AI systems from cyber threats
Google Cloud Spanner gets dual-region configuration option
Agentic AI drives enterprises away from public clouds
Cybercrooks spell trouble with typosquatting domains amid CrowdStrike crisis
British teen arrested in connection with MGM Resorts ransomware attack
Alphabet’s reported $23B bet on Wiz fizzles out
DDoS-for-hire site DigitalStress taken down by police, suspected owner arrested
The AI Fix #8: Emergence, a rancid donkey, and the world’s funniest joke

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Deciding and iterating with Java statements

* bsc#1227268 * bsc#1227269 * bsc#1227272 Cross-References:

* bsc#1219660 Cross-References: * CVE-2024-24577

* bsc#1219660 Cross-References: * CVE-2024-24577

* bsc#1214980 * bsc#1222804 * bsc#1222807 * bsc#1222811 * bsc#1222813

Retrieval-augmented generation refined and reinforced
Securing AI around the world
Google’s plan to drop third-party cookies in Chrome crumbles
IBM adds Mistral Large language model to watsonx.ai
Global cops power down world’s ‘most prolific’ DDoS dealership
LA County Superior Court closes doors to reboot justice after ransomware attack
Cybercrooks crafting solo careers in wake of ransomware takedowns
Oracle coughs up $115M to make privacy case go away

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.