Menu

Category Archives: Security

Articles about security

How to master multi-tenant data management
DarkGate, the Swiss Army knife of malware, sees boom after rival Qbot crushed
Kaspersky culls staff, closes doors in US amid Biden’s ban
Disney hacked? NullBulge claims to have stolen 1.1 TB of data from internal Slack channels
ZDI shames Microsoft for – yet another – coordinated vulnerability disclosure snafu
Infoseccers claim Squarespace migration linked to DNS hijackings at Web3 firms

* bsc#1221530 Cross-References: * CVE-2024-21503

* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828

7 reasons analytics and ML fail to meet business objectives

* bsc#1224122 * bsc#1226136 Cross-References: * CVE-2024-24786

Are we thinking too small about generative AI?
How to choose the right database for your application
Google reportedly in talks to buy infosec outfit Wiz for $23 billion
I spy another mSpy breach: Millions more stalkerware buyers exposed
UK cyber-boss slams China’s bug-hoarding laws
Should ransomware payments be banned? – Week in security with Tony Anscombe

The issue of whether to ban ransomware payments is a hotly debated topic in cybersecurity and policy circles. What are the implications of outlawing these payments, and would the ban be effective?

Vanilla upstream kernel version 6.6.37 fix bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33374

Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack. (CVE-2024-37894) References:

This vulnerability allows an attacker performing a meddler-in-the-middle attack between Palo Alto Networks PAN-OS firewall and a RADIUS server to bypass authentication and escalate privileges to ¢”superuser¢” when RADIUS authentication is in use and either CHAP or PAP is selected in the RADIUS server profile.

Beyond the usual suspects: 5 fresh data science tools to try today

* bsc#1216377 Cross-References: * CVE-2023-45803

* bsc#1189936 * bsc#1190531 * bsc#935380 Cross-References:

Three words to send a chill down your spine: Snowflake. Intrusion. Alert
Red Hat VEX files for CVEs are now generally available

Upstream kernel version 6.6.37 fix bugs and vulnerabilities. The dwarves, kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.

This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732

Backport fix for CVE-2024-4067.

Backport security fixes for CVE-2024-4216, CVE-2024-4068, CVE-2024-4067.

Car dealer software slinger CDK Global said to have paid $25M ransom after cyberattack

https://security-tracker.debian.org/tracker/DSA-5729-1

White House urged to double check Microsoft isn’t funneling AI to China via G42 deal
CISA broke into a US federal agency, and no one noticed for a full 5 months
Understanding IoT security risks and how to mitigate them | Cybersecurity podcast

As security challenges loom large on the IoT landscape, how can we effectively counter the risks of integrating our physical and digital worlds?

Identity: the new security perimeter
Break-in at ‘third-party cloud platform’ leaked 110M customer records, says AT&T

* bsc#1226448 Cross-References: * CVE-2024-4032

* bsc#1226495 * bsc#1227239 Cross-References: * CVE-2024-34703

Several security issues were fixed in the Linux kernel.

RansomHub ransomware – what you need to know
Generative AI won’t fix cloud migration

Backport fix for CVE-2024-4032.

Backport fix for CVE-2024-4032.

Singapore’s banks to ditch texted one-time passwords
China’s APT41 crew adds a stealthy malware loader and fresh backdoor to its toolbox
‘Gay furry hackers’ say they’ve disbanded after raiding Project 2025’s Heritage Foundation
HR professionals trust AI recommendations

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5728-1

https://security-tracker.debian.org/tracker/DSA-5727-1

OpenSSH bug leaves RHEL 9 and the RHELatives vulnerable
Amazon Bedrock updated with contextual grounding, RAG connectors
Safety off: Programming in Rust with `unsafe`
OpenSilver 3.0 previews AI-powered UI designer for .NET
Exposed! The AI-enhanced social media bot farm that pumped out Kremlin propaganda on Twitter
Smashing Security podcast #380: Teachers TikTok targeted, and fraud in the doctors’ waiting room
Advance Auto Parts: 2.3M people’s data accessed when crims broke into our Snowflake account

* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828

Privacy expert put away for 9 years after ‘grotesque’ cyberstalking campaign
Microsoft updates its serverless Azure Functions
How to use FastEndpoints in ASP.NET Core

* bsc#1220145 * bsc#1223363 * bsc#1223683 * bsc#1225211

You had a year to patch this Veeam flaw and now it’s going to hurt
Japanese space agency spotted zero-day attacks while cleaning up attack on M365

Updated to latest upstream (128.0)

Fix CVE-2024-39936.

Security fix for CVE-2024-5187

This is the May 2024 release for .NET 8. This is a security update for .NET 8. Release notes: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.5/8.0.5.md

Microsoft moves forward with C# 13, offering overload resolution
Snowflake lets admins make MFA mandatory across all user accounts
Enhancing your cyber defense with Wazuh threat intelligence integrations
Malware that is ‘not ransomware’ wormed its way through Fujitsu Japan’s systems

* bsc#1224123 Cross-References: * CVE-2024-3727

* bsc#1220145 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223059

Ransomware crews investing in custom data stealing malware
Progressive web app essentials: Service worker background sync
How platform teams lead to better, faster, stronger enterprises

* bsc#1119113 * bsc#1191958 * bsc#1195065 * bsc#1195254 * bsc#1195775

Several security issues were fixed in Firefox.

Big Tech’s eventual response to my LLM-crasher bug report was dire

Multiple vulnerabilities have been discovered in Buildah, the worst of which could lead to privilege escalation.

ViperSoftX variant spotted abusing .NET runtime to disguise data theft

Several security issues were fixed in dotnet6, dotnet8.

RADIUS networking protocol blasted into submission through MD5-based flaw
Critical Windows licensing bugs – plus two others under attack – top Patch Tuesday
FBI, cyber-cops zap ~1K Russian AI disinfo Twitter bots
Google, Udacity offer free course on Gemini API
8 reasons developers love Go—and 8 reasons they don’t
AI’s moment of disillusionment
The next 10 years for cloud computing
What’s new in MySQL 9.0
Understanding DiskANN, a foundation of the Copilot Runtime
How to use Refit to consume APIs in ASP.NET Core
Visual Studio Code previews incoming/outgoing changes graph
ECMAScript 2024 JavaScript standard approved
JetBrains launches Qodana Self-Hosted
AWS approach to RAG evaluation could help enterprises reduce AI spending
How to get started with GraphQL
Intro to multithreaded JavaScript
Rust types team moves forward on next-gen trait solver
Qdrant unveils vector-based hybrid search for RAG