Menu

Latest articles

Google’s AI bug hunters sniff out two dozen-plus code gremlins that humans missed
D-Link tells users to trash old VPN routers over bug too dangerous to identify
What is Rust? Safe, fast, and easy software development
Kotlin for Java developers: Classes and coroutines
Azure AI Foundry tools for changes in AI applications

A security issue was discovered in Thunderbird, which could result in the disclosure of OpenPGP encrypted messages. For Debian 11 bullseye, this problem has been fixed in version

Data is the new uranium – incredibly powerful and amazingly dangerous
Microsoft unveils imaging APIs for Windows Copilot Runtime
Healthcare org Equinox notifies 21K patients and staff of data theft

The system could be made to crash under certain conditions.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer
Russian suspected Phobos ransomware admin extradited to US over $16M extortion
Microsoft extends Entra ID to WSL, WinGet
America’s drinking water systems have a hard-to-swallow cybersecurity problem
The AI Fix #25: Beware of the superintelligence, and a spam-eating AI super gran
Palo Alto Networks tackles firewall-busting zero-days with critical patches
Navigating third-party risks
Microsoft rebrands Azure AI Studio to Azure AI Foundry
Crook breaks into AI biz, points $250K wire payment at their own account
Malware delivered via malicious QR codes sent in the post
Join in the festive cybersecurity fun
A GRC framework for securing generative AI
How to transform your architecture review board
Succeeding with observability in the cloud
iOS 18 added secret and smart security feature that reboots iThings after three days

Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid

Update to 2.6.4. Backport fix for CVE-2024-50602.

Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid

Update to lemonldap-ng 2.20.1: [Security] Adaptative Authentication Rules triggered by “Refresh my rights” [Security] XSS in upgradeSession / forceUpgrade pages downloadSamlMetadata missing from packages in 2.20.0 CDA request for id is not valid

Update to 2.6.4. Backport fix for CVE-2024-50602.

F# 9 adds nullable reference types

https://security-tracker.debian.org/tracker/DSA-5816-1

https://security-tracker.debian.org/tracker/DSA-5815-1

Ford ‘actively investigating’ after employee data allegedly parked on leak site
Akka distributed computing platform adds Java SDK
Critical 9.8-rated VMware vCenter RCE bug exploited after patch fumble
T-Mobile US ‘monitoring’ China’s ‘industry-wide attack’ amid fresh security breach fears

GLib could be made to crash or other undefined behavior if it received a specially crafted input.

Sweden’s ‘Doomsday Prep for Dummies’ guide hits mailboxes today
Deepen your knowledge of Linux security
Hardening your operating system? Red Hat Enterprise Linux to the rescue!

Several issues were fixed in AsyncSSH.

14 great preprocessors for developers who love to code
Designing the APIs that accidentally power businesses
Spin 3.0 supports polyglot development using Wasm components
The dirty little secret of open source contributions

This is the .NET 9.0 GA release. It contains security fixes for CVE-2024-43498 and CVE-2024-43499 Announcement: https://devblogs.microsoft.com/dotnet/announcing-dotnet-9/ Release Notes: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.0/9.0.0.md

Several security issues were fixed in Tomcat.

Teen serial swatter-for-hire busted, pleads guilty, could face 20 years

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Will passkeys ever replace passwords? Can they?

Multiple vulnerabilties were discovered for smarty3, a widely-used PHP templating engine, which potentially allows an attacker to perform an XSS (e.g JavaScript or PHP code injection).

A vulnerability has been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation.

A vulnerability has been discovered in Pillow, which may lead to arbitrary code execution.

CVE-2024-46951 ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space (fedora#2325238) 2325241 – CVE-2024-46952 CVE-2024-46953 CVE-2024-46954 CVE-2024-46955 CVE-2024-46956 ghostscript: various flaws [fedora-41]

DoS due to resource exhaustion has been fixed in waitress, a Python Web Server Gateway Interface. For Debian 11 bullseye, this problem has been fixed in version

https://security-tracker.debian.org/tracker/DSA-5814-1

https://security-tracker.debian.org/tracker/DSA-5813-1

https://security-tracker.debian.org/tracker/DSA-5812-1

Multiple security issues were discovered in PostgreSQL, which may result in the execution of arbitrary code, privilege escalation or log manipulation. For Debian 11 bullseye, these problems have been fixed in version

Rust haters, unite! Fil-C aims to Make C Great Again
Swiss cheesed off as postal service used to spread malware

Update to upstream 2.1-47. 20241112 Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in intel-ucode/06-8f-05) from revision 0x2b0005c0 up to 0x2b000603; Update of 06-8f-05/0x87 (SPR-SP E2) microcode from revision 0x2b0005c0 up to 0x2b000603;

bartlett/php-compatinfo-db 6.12.0 – 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support

Update to version 3.0.1, which resolves CVE-2024-49768 and CVE-2024-49769.

CVE-2024-46951 ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space (fedora#2325237) 2325240 – CVE-2024-46952 CVE-2024-46953 CVE-2024-46954 CVE-2024-46955 CVE-2024-46956 ghostscript: various flaws

bartlett/php-compatinfo-db 6.12.0 – 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support

Bloke behind Helix Bitcoin launderette jailed for three years, hands over $400M
Go language evolving for future hardware, AI workloads
Letting chatbots run robots ends as badly as you’d expect
Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit
Keyboard robbers steal 171K customers’ data from AnnieMac mortgage house
The Dual Edge of Open Source: Examining Key Benefits and Security Challenges
Simplifying endpoint security
Bitfinex burglar bags 5 years behind bars for Bitcoin heist

* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853

* bsc#1232590 Cross-References: * CVE-2024-50602

* bsc#1233282 Cross-References: * CVE-2024-52533

AI meets security: POC to run workloads in confidential containers using NVIDIA accelerated computing

Several security issues were fixed in the Linux kernel.

Microsoft Power Pages misconfigurations exposing sensitive data

Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code

Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code

Fortinet patches VPN app flaw that could give rogue users, malware a privilege boost
Cybercriminal devoid of boundaries gets 10-year prison sentence
ShrinkLocker ransomware: what you need to know
IT specialist Jack Teixeira jailed for 15 years after leaking classified military documents on Discord
Kids’ shoemaker Start-Rite trips over security again, spilling customer card info
OpenSSL in Red Hat Enterprise Linux 10: From engines to providers
NatWest blocks bevy of apps in clampdown on unmonitorable comms
Asda security chief replaced, retailer sheds jobs during Walmart tech divorce
How to use DispatchProxy for AOP in .NET Core
Understanding Hyperlight, Microsoft’s minimal VM manager
Five Eyes infosec agencies list 2024’s most exploited software flaws