Menu

Latest articles

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Python to C: What’s new in Cython 3.1
Kotlin for Java developers: Concurrency with coroutines
A software developer gives thanks
The workplace has become a surveillance state

* bsc#1230366 * bsc#1232542 * bsc#1232622 * bsc#1232624

CrowdStrike still doesn’t know how much its Falcon flame-out will cost
Telco engineer who spied on US employer for Beijing gets four years in the clink

Several security issues were fixed in libsoup.

Kotlin to lose scripting features
Man accused of hilariously bad opsec as alleged cybercrime spree detailed
Anthropic introduces the Model Context Protocol
The AI Fix #26: Would AI kill sentient robots, and is water wet?
US senators propose law to require bare minimum security standards
Data leaks from websites built on Microsoft Power Pages, including 1.1 million NHS records
Fortify your data
Bing Wallpaper app, now in Windows Store, accused of cookie shenanigans

* bsc#1219340 * bsc#1230423 * bsc#1233323 * bsc#1233325 * bsc#1233326

Another ‘major cyber incident’ at a UK hospital, outpatients asked to stay away

USN-7117-1 caused some regression in needrestart.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

QNAP and Veritas dump 30-plus vulns over the weekend

Multiple vulnerabilities have been fixed in pypy3, an alternative implementation of the Python 3.x language. CVE-2020-10735

Build generative AI pipelines without the infrastructure headache
Are cloud units a good measure of cloud value?

* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853

Britain Putin up stronger AI defences to counter growing cyber threats
USPTO petitioned to cancel Oracle’s JavaScript trademark
Supply chain management vendor Blue Yonder succumbs to ransomware
PHP updates DOM API
Security? We’ve heard of it: How Microsoft plans to better defend Windows
FlipaClip animation app data breach exposes details of almost 900,000 users

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

A microcode update has been released for Intel processors, addressing multiple vulnerabilties which potentially could cause information disclosue or local DoS.

China has utterly pwned ‘thousands and thousands’ of devices at US telcos
3 data engineering trends riding Kafka, Flink, and Iceberg
GitHub Copilot: Everything you need to know
Speed is the killer app
Google blocked 1,000-plus pro-China fake news websites from its search results
Imagine a land in which Big Tech can’t send you down online rabbit holes or use algorithms to overcharge you
Russian spies may have moved in next door to target your network

Several security issues were fixed in OpenJDK 23.

Multiple vulnerabilities have been fixed in the PostScript/PDF interpreter Ghostscript. CVE-2024-46951

Volunteer DEF CON hackers dive into America’s leaky water infrastructure

Ansible is a command-line IT automation software application. It can configure systems, deploy software, and orchestrate advanced workflows to support application deployment, system updates, …

https://security-tracker.debian.org/tracker/DSA-5818-1

A buffer overflow with long SOCKS4a proxy hostname and username has been fixed in the GNOME Input/Output library (GIO). For Debian 11 bullseye, this problem has been fixed in version

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Trump taps border hawk to head DHS. Will Noem’s ‘enthusiasm’ extend to digital domain?

PHP version 8.3.14 (21 Nov 2024) CLI: Fixed bug GH-16373 (Shebang is not skipped for router script in cli-server started through shebang). (ilutov) Fixed bug GHSA-4w77-75f9-2c8w (Heap-Use-After-Free in sapi_read_post_data

This is the .NET 9.0 GA release. It contains security fixes for CVE-2024-43498 and CVE-2024-43499 Announcement: https://devblogs.microsoft.com/dotnet/announcing-dotnet-9/ Release Notes: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.0/9.0.0.md

https://security-tracker.debian.org/tracker/DSA-5817-1

New php packages are available for Slackware 15.0 and -current to fix security issues.

Andrew Tate’s site ransacked, subscriber data stolen
1000s of Palo Alto Networks firewalls hijacked as miscreants exploit critical hole

https://security-tracker.debian.org/tracker/DSA-5812-2

An update that fixes 8 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

TypeScript 5.7 arrives with improved error reporting
Examining the Significance of the Recent Real-time Linux Kernel v6.12 Release
How to master endpoint security

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-40866

AWS prepares to command an army of AI agents
SafePay ransomware gang claims Microlise attack that disrupted prison van tracking

Fix null pointer dereference in opendmarc_policy.c. (CVE-2024-25768) References: – https://bugs.mageia.org/show_bug.cgi?id=33756

Upstream kernel version 6.6.61 fixes bugs and vulnerabilities. The bluez, kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.

Vanilla upstream kernel version 6.6.61 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33776

An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function. (CVE-2024-48241) References: – https://bugs.mageia.org/show_bug.cgi?id=33755

In versions prior to 1.2.31 an authenticated user is able to perform a SQL injection, leading to a privilege escalation or loss of confidentiality. It appears that in some insert and update operations the code improperly uses the PicoDB library to update/insert new information.

Helpline for Yakuza victims fears it leaked their personal info
Here’s what happens if you don’t layer network security – or remove unused web shells
Angular 19 bolsters server-side rendering with incremental hydration
Red Hat Linux to be official WSL distro
DARPA-backed voting system for soldiers abroad savaged
Mastering Business Intelligence with Open-Source Tools: A Guide for Secure and Cost-Effective Linux Solutions
Low-Code, High Security: Integrating Open Source Tools for Robust Application Development

Potential disclosure of plaintext in OpenPGP encrypted message. (CVE-2024-11159) References: – https://bugs.mageia.org/show_bug.cgi?id=33763

Remove ClamAV subdirectory because of viruses in input files: These were the findings: MultiSource/Applications/ClamAV/inputs/rtf-test/rtf1.rtf: Eicar-Signature MultiSource/Applications/ClamAV/inputs/clam.zip: Clamav.Test.File-6 MultiSource/Applications/ClamAV/inputs/rtf-test/docCLAMexe.rtf:

Remove ClamAV subdirectory because of viruses in input files: These were the findings: MultiSource/Applications/ClamAV/inputs/rtf-test/rtf1.rtf: Eicar-Signature MultiSource/Applications/ClamAV/inputs/clam.zip: Clamav.Test.File-6 MultiSource/Applications/ClamAV/inputs/rtf-test/docCLAMexe.rtf:

Update to 130.0.6723.116

Several security issues were fixed in the Linux kernel.

750,000 patients’ medical records exposed after data breach at French hospital
Chinese ship casts shadow over Baltic subsea cable snipfest
‘Alarming’ security bugs lay low in Linux’s needrestart server utility for 10 years

With the rise of online scams and privacy risks, virtual private networks (VPNs) are becoming more popular for day-to-day use. Or at least I feel like they are based on the number of ads I hear for them on my favorite podcasts. So maybe you’ve heard of VPNs but aren’t actually sure what they are. […]

Embracing the Future of Linux: Understanding NVMe Enhancements in the 6.13 Kernel
Managed Identity and Workload Identity support in Azure Red Hat OpenShift
Security of LLMs and LLM systems: Key risks and safeguards
Now Online Safety Act is law, UK has ‘priorities’ – but still won’t explain ‘spy clause’
Advanced programming with Java generics
Put your usernames and passwords in your will, advises Japan’s government

Several security issues were fixed in Ruby.

RHEL AI, JBoss EAP 8 coming to Azure cloud
Five Scattered Spider suspects indicted for phishing spree and crypto heists
Smashing Security podcast #394: Digital arrest scams and stream-jacking
Chinese cyberspies, Musk’s Beijing ties, labelled ‘real risk’ to US security by senator
Azure Container Apps launches Python, JavaScript interpreters
Mega US healthcare payments network restores system 9 months after ransomware attack