Menu

Latest articles

https://security-tracker.debian.org/tracker/DSA-5760-1

Several security issues were fixed in the Linux kernel.

Microsoft hosts a security summit but no press, public allowed
Microsoft cuts BinaryFormatter from .NET 9
Proof-of-concept code released for zero-click critical IPv6 Windows hole
Microsoft announces Pinecone .NET SDK
Humble UI offers a Clojure-based desktop UI framework
Iran’s Pioneer Kitten hits US networks via buggy Check Point, Palo Alto gear
Dick’s Sporting Goods discloses cyberattack
From Copilot to Copirate: How data thieves could hijack Microsoft’s chatbot
OpenShift Commons Security Special Interest Group (SIG) at Red Hat Summit 2024
AWS’ Amazon Bedrock GenAI service gets cross-region inferencing feature
University criticised for using Ebola outbreak lure in phishing test
The ultimate dual-use tool for cybersecurity
Better than reflection: Using method handles and variable handles in Java
I switched to a vertical mouse and I’m never looking back. Here’s why.

* bsc#1228696 * bsc#1228697 * bsc#1228698 Cross-References:

Woman uses AirTags to nab alleged parcel-pinching scum

CVE-2024-23184: A large number of address headers in email resulted in excessive CPU usage. CVE-2024-23185: Abnormally large email headers are now truncated or discarded, with a limit of 10MB on a single header and 50MB for all the headers of all the parts of an email.

CVE-2024-23184: A large number of address headers in email resulted in excessive CPU usage. CVE-2024-23185: Abnormally large email headers are now truncated or discarded, with a limit of 10MB on a single header and 50MB for all the headers of all the parts of an email.

Chinese broadband satellites may be Beijing’s flying spying censors, think tank warns
Microsoft donates Mono cross-platform .NET to WineHQ

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1225202 * bsc#1225302 Cross-References: * CVE-2021-47378

* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202

Intel’s Software Guard Extensions broken? Don’t panic
Volt Typhoon suspected of exploiting Versa SD-WAN bug since June
The AI Fix #13: ChatGPT runs for mayor, and should we stop killer robots?
Microsoft security tools questioned for treating employees as threats

* bsc#1226463 * bsc#1227138 Cross-References: * CVE-2024-5535

* bsc#1225202 Cross-References: * CVE-2021-47378

* bsc#1225202 * bsc#1225302 Cross-References: * CVE-2021-47378

Multiple security issues were discovered in Python, a high-level, interactive, object-oriented language: CVE-2024-0397

Quantum computing attacks on cloud-based systems

* bsc#1225983 Cross-References: * CVE-2024-21096

* bsc#1225202 Cross-References: * CVE-2021-47378

What AI regulations mean for software developers
Are you the boss of your feed?
Kotlin update shines on garbage collector

https://security-tracker.debian.org/tracker/DSA-5759-1

Deno 1.46 simplifies CLI
Microsoft mistake blows up admins’ inboxes with fake malware alerts
Watchdog warns FBI is sloppy on secure data storage and destruction
Seattle airport ‘possible cyberattack’ snarls travel yet again
AMD internal data reportedly offered for sale
The Future-Proof Server: Antivirus and Beyond for Linux Admins
31.5M invoices, contracts, patient consent forms, and more exposed to the internet

* bsc#1027519 * bsc#1227355 * bsc#1228574 * bsc#1228575

The definitive guide to data pipelines
The slow evolution of enterprise tech
Developing agile ETL flows with Ballerina

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service or request smuggling.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Alleged Karakut ransomware scumbag charged in US

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

https://security-tracker.debian.org/tracker/DSA-5758-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

* bsc#1224188 Cross-References: * CVE-2021-36386

* bsc#1129596 Cross-References: * CVE-2019-9656

PWA phishing on Android and iOS – Week in security with Tony Anscombe

Phishing using PWAs? ESET Research’s latest discovery might just ruin some users’ assumptions about their preferred platform’s security

Method overloading in the JVM
US sues Georgia Tech over alleged cybersecurity failings as a Pentagon contractor

An update that fixes 20 vulnerabilities is now available.

* bsc#1228574 * bsc#1228575 Cross-References: * CVE-2024-31145

* bsc#1226316 * bsc#1228648 Cross-References: * CVE-2024-6600

* bsc#1219559 * bsc#1221563 Cross-References: * CVE-2023-52425

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695 * bsc#1228696

Navigating the AI frontier
JDK 24 preps for restrictions on JNI use
Uniting the brightest minds in security, network and cloud

Bump to version 5.9.4

https://security-tracker.debian.org/tracker/DSA-5757-1

SolarWinds left critical hardcoded credentials in its Web Help Desk product
The reality of AI-centric coding
CrowdStrike deja vu as ‘performance issue’ leaves systems sluggish
How regulatory standards and cyber insurance inform each other

Should the payment of a ransomware demand be illegal? Should it be regulated in some way? These questions are some examples of the legal minefield that cybersecurity teams must deal with

Halliburton probes ‘an issue’ disrupting business ops

* bsc#1224044 Cross-References: * CVE-2024-34397

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Ransomware batters critical industries, but takedowns hint at relief
Hacker leaks upcoming episodes of Netflix shows online following security breach
Authentication and Authorization in Red Hat OpenShift and Microservices Architectures
Deployment considerations for Red Hat OpenShift Confidential Containers solution
Over 100,000 Oregon Zoo visitors warned that their payment card details were stolen in security breach
This uni thought it would be a good idea to do a phishing test with a fake Ebola scare
Why you’ll love dev containers
Kick off early Octoberfest with an EUC-fest
Visual Studio boosts C++ development
How to avoid exceptions in C#

Several security issues were fixed in QEMU.

Cisco calls for United Nations to revisit cyber crime Convention
Foiling bot attacks with AI-powered telemetry

Fix web process cache suspend/resume when sandbox is enabled. Fix accelerated images disappearing after scrolling. Fix video flickering with DMA-BUF sink. Fix pointer lock on X11. Fix movement delta on mouse events in GTK3.

You probably want to patch this critical GitHub Enterprise Server bug now