Menu

Category Archives: Security

Articles about security

EU gave CrowdStrike the keys to the Windows kernel, claims Microsoft
Two Russians sanctioned over cyberattacks on US critical infrastructure
Focusing open source on security, not ideology
10 more big devops gotchas to watch out for

* bsc#1205628 Cross-References: * CVE-2022-4065

Semantic Kernel: Diving into Microsoft’s AI orchestration SDK

Several security issues were fixed in Thunderbird.

Cellebrite got into Trump shooter’s Samsung device in just 40 minutes

Update to 115.13.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-31/ https://www.thunderbird.net/en-US/thunderbird/115.13.0/releasenotes/

CrowdStrike’s Falcon Sensor also linked to Linux kernel panics and crashes
The Risks Inherent in Including Security Modules At Kernel Level: Lessons From CrowdStrike Incident

Memory corruption in WebGL API. (CVE-2024-6600) Race condition in permission assignment. (CVE-2024-6601) Memory corruption in thread creation. (CVE-2024-6603) Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13. (CVE-2024-6604)

Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features:

Backport fix for CVE-2023-49528 and backport fixes for compatibility with Mesa 24.0.6+ / 24.1.4+ for VA-API

update to 126.0.6478.182 High CVE-2024-6772: Inappropriate implementation in V8 High CVE-2024-6773: Type Confusion in V8 High CVE-2024-6774: Use after free in Screen Capture High CVE-2024-6775: Use after free in Media Stream

Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features:

An update that fixes 22 vulnerabilities is now available.

Beyond the blue screen of death: Why software updates matter

The widespread IT outages triggered by a faulty CrowdStrike update have put software updates in the spotlight. Here’s why you shouldn’t dread them.

The complexities of cybersecurity update processes

If a software update process fails, it can lead to catastrophic consequences, as seen today with widespread blue screens of death blamed on a bad update by CrowdStrike

update to 126.0.6478.182 High CVE-2024-6772: Inappropriate implementation in V8 High CVE-2024-6773: Type Confusion in V8 High CVE-2024-6774: Use after free in Screen Capture High CVE-2024-6775: Use after free in Media Stream

Update to 3.0.4

New bugfix and security update

Rebase to v2.19.5

Update to 3.24.43

Update to 3.0.4

UK cops arrest teen suspect in MGM Resorts cyberattack probe

https://security-tracker.debian.org/tracker/DSA-5733-1

CrowdStrike Windows patchpocalypse could take weeks to fix, IT admins fear

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Messy data is holding enterprises back from AI
CrowdStrike file update bricks Windows machines around the world
North Korea likely behind takedown of Indian crypto exchange WazirX
Beijing’s attack gang Volt Typhoon was a false flag inside job conspiracy: China

This is the July 2024 security update for .NET 6. Release Notes SDK: https://github.com/dotnet/core/blob/main/release- notes/6.0/6.0.32/6.0.132.md Runtime: https://github.com/dotnet/core/blob/main/release-

Fix for CVE-2024-38517.

Security fixes for https://nvd.nist.gov/vuln/detail/CVE-2024-38875 https://nvd.nist.gov/vuln/detail/CVE-2024-39329 https://nvd.nist.gov/vuln/detail/CVE-2024-3930 https://nvd.nist.gov/vuln/detail/CVE-2024-39614

Developer productivity poorly understood, report says
Judge mostly drags SEC’s lawsuit against SolarWinds into the recycling bin
Kaspersky challenges US government to put up or shut up about Kremlin ties
Russia’s FIN7 is peddling its EDR-nerfing malware to ransomware gangs

* bsc#1220145 * bsc#1223363 * bsc#1223681 * bsc#1223683 * bsc#1225211

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1210619 * bsc#1220537 * bsc#1223363 * bsc#1223683 * bsc#1225211

Red Hat Enterprise Linux and Secure Boot in the cloud
Red Hat Advanced Cluster Security Cloud Service is now Generally Available
Red Hat’s path to post-quantum cryptography
Maximum-severity Cisco vulnerability allows attackers to change admin passwords
Talk of GitLab sale highlights growing importance of DevSecOps platforms

stunnel could allow unintended access to network services.

Building next-generation applications with the Windows Application SDK

* bsc#1224122 Cross-References: * CVE-2024-3727

How to use HybridCache in ASP.NET Core
Firms skip security reviews of major app updates about half the time

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Release the hounds! Securing datacenters may soon need sniffer dogs

https://security-tracker.debian.org/tracker/DSA-5732-1

Google’s Genkit for Go brings AI app development to Go language
Merged Exabeam and LogRhythm cut jobs, face lawsuit
Smashing Security podcast #381: Trump shooting conspiracy, Squarespace account hijack, and the butt stops here

https://security-tracker.debian.org/tracker/DSA-5731-1

Google rolls out new dev tools focusing on open source and GenAI
Kaspersky gives US customers six months of free updates as a parting gift
Deno adds workspaces for managing monorepos
HardBit ransomware – what you need to know
Ransomware continues to pile on costs for critical infrastructure victims
Salesforce previews Einstein-powered service agent
London council accuses watchdog of ‘exaggerating’ danger of 2020 raid on residents’ data
Mistral’s new Codestral Mamba to aid longer code generation
Exim 4.98 Addresses Critical Vulnerabilities, Bolsters Email Server Security
Frequently sought solutions for JavaScript

* bsc#1227399 Cross-References: * CVE-2024-34750

* bsc#1225771 Cross-References: * CVE-2024-5564

* bsc#1222665 * bsc#1227554 * bsc#1227560 Cross-References:

* bsc#1227554 * bsc#1227560 * bsc#1227561 * bsc#1227562 * bsc#1227563

Theia IDE: Eclipse’s answer to Visual Studio Code
Craig Wright admits he isn’t the inventor of Bitcoin after High Court judgment in UK

This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732

This update fixes CVE-2024-24791

Iran’s MuddyWater phishes Israeli orgs with custom BugSleep backdoor
Microsoft pushes .NET 9 Preview 6 with a range of improvements

https://security-tracker.debian.org/tracker/DSA-5730-1

OpenJDK plan calls for restricting JNI usage
Scattered Spider’s fave new ransomware tools are RansomHub and Qilin
Hello, is it me you’re looking for? How scammers get your phone number

Your humble phone number is more valuable than you may think. Here’s how it could fall into the wrong hands – and how you can help keep it out of the reach of fraudsters.

Exploring Linux 6.10: Guide to Key Security Enhancements & Updates for Admins
The AI Fix #7: Can AI speak dolphin and do robots lick toads?
Don’t be complacent on cybersecurity resilience
Securing IT Assets: Practical Strategies for Linux Admins & IT Teams

Several security issues were fixed in the Linux kernel.

* bsc#1220145 * bsc#1223363 * bsc#1223681 * bsc#1223683

How to Secure Your Data Warehouse in a Linux System
Privacy group complains to UK regulator about Meta scraping user data to train AI

Several security issues were fixed in the Linux kernel.

An update that fixes three vulnerabilities is now available.

Several security issues were fixed in the Linux kernel.

Learning cloud cost management the hard way
What senior developers do

* bsc#1215420 * bsc#1220833 * bsc#1221656 * bsc#1221659 * bsc#1222005