Menu

Latest articles

Functional programming with Java collections
UK Prime Minister Keir Starmer and Prince William deepfaked in investment scam campaign
The magic of RAG is in the retrieval
Indian telcos to cut off scammy, spammy, telemarketers for two whole years
NIST finalizes trio of post-quantum encryption standards
Patch Tuesday brings 90 new Microsoft CVEs, six already under exploit
Go 1.23 arrives with faster PGO build times

https://security-tracker.debian.org/tracker/DSA-5748-1

Six ransomware gangs behind over 50% of 2024 attacks
US accuses man of being ‘elite’ ransomware pioneer they’ve hunted for years
Linux Foundation’s adoption of OMI could pave way for ethical LLMs, analysts say
The great location leak: Privacy risks in dating apps

Convenience may come at a cost – such as when your favorite app reveals your exact coordinates to someone you’d rather keep at a distance

The AI Fix #11: AI gods, a robot dentist, and an angry human
Feds bust minor league Radar/Dispossessor ransomware gang
JDK 23: The new features in Java 23

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Orion SA says scammers conned company out of $60 million
BlackHat USA 2024: Key Takeaways for Linux Admins & InfoSec Pros
Staying a Step Ahead of Adversaries: Mitigating Chromium’s Security Flaws on Linux
Who uses LLM prompt injection attacks IRL? Mostly unscrupulous job seekers, jokesters and trolls
Remember quantum computing in the cloud?
Why I don’t buy Apple products
iPaaS in an AI-driven world
‘Digital arrest’ scams are big in India and may be spreading
AMD won’t patch Sinkclose security bug on older Zen CPUs
Tauri 2.0 moves core functionality to plugins
Attacker steals personal data of 200k+ people with links to Arizona tech school
5 Key Benefits Of Code Signing Solutions
Mega money, unfathomable violence pervade thriving underground doxxing scene
5 Open-Source Blockchain Technologies That Linux Users Need to Know About
Google Cloud adds 3 new Apache Airflow operators to Vertex AI
The BlackSuit ransomware gang has demanded over $500 million since 2022

Multiple vulnerabilities have been discovered in protobuf-c, the worst of which could result in denial of service.

5 things great data science product managers do
Evolve your cloud security knowledge
Practical strategies for mitigating API security risks
Tabnine AI coding assistant flexes its models
Most AI software will stay proprietary

Multiple vulnerabilities have been discovered in PHP, the worst of which can lead to a denial of service.

A vulnerability has been discovered in protobuf and protobuf-python, which can lead to a denial of service.

A vulnerability has been discovered in dpkg, which allows for directory traversal.

Multiple vulnerabilities have been discovered in MuPDF, the worst of which could lead to arbitrary code execution.

Trump campaign cites Iran election phish claim as evidence leaked docs were stolen

Update NSS to 3.103.0 Update to Firefox 129.0

The UN unanimously agrees that cybercrime is bad, mkay?

https://security-tracker.debian.org/tracker/DSA-5747-1

Black Hat USA 2024 recap – Week in security with Tony Anscombe

Unsurprisingly, many discussions focused on the implications of the recent CrowdStrike outage, including the lessons it may have offered for bad actors

Black Hat USA 2024: All eyes on election security

In this high-stakes year for democracy, the importance of robust election safeguards and national cybersecurity strategies cannot be understated

Multiple vulnerabilities have been discovered in runc, the worst of which could lead to privilege escalation.

A vulnerability has been discovered in Ruby on Rails, which can lead to remote code execution via serialization of data.

New version 8.5.5

* bsc#1228256 * bsc#1228257 Cross-References: * CVE-2024-1737

* bsc#1220356 * bsc#1227525 Affected Products: * Basesystem Module 15-SP5

Black Hat USA 2024: How cyber insurance is shaping cybersecurity strategies

Cyber insurance is not only a safety net, but it can also be a catalyst for advancing security practices and standards

Multiple vulnerabilities have been discovered in GnuPG, the worst of which could lead to signature spoofing.

Multiple vulnerabilities have been discovered in Bundler, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in GPAC, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in libde265, the worst of which could lead to arbitrary code execution.

Raptor Lake microcode limits Intel chips to a mere 1.55 volts to prevent CPU destruction
Why tech-savvy leadership is key to cyber insurance readiness

Having knowledgeable leaders at the helm is crucial for protecting the organization and securing the best possible cyber insurance coverage

Understanding escalating cyber threats
Pro-Iran groups lay groundwork for ‘chaos and violence’ as US election meddling intensifies

Multiple vulnerabilities have been discovered in ncurses, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in QEMU, the worst of which could lead to a denial of service.

A vulnerability has been discovered in Nautilus, which can lead to a denial of service.

A strategic road map for navigating the cloud skills shortage

Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation. For the oldstable distribution (bullseye), this problem has been fixed

Noah Misch discovered a race condition in the pg_dump tool included in PostgreSQL, which may result in privilege escalation. For the stable distribution (bookworm), this problem has been fixed in

* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671

It’s 2024 and we’re just getting round to stopping browsers insecurely accessing 0.0.0.0
Hello? Are you talking on a Cisco SPA300 or SPA500 IP phone? Now’s the time to junk ’em
AWS closes several cloud services to new customers

https://security-tracker.debian.org/tracker/DSA-5746-1

https://security-tracker.debian.org/tracker/DSA-5745-1

Delta: CrowdStrike’s offer to help in Falcon meltdown was too little, too late
US ‘laptop farm’ man accused of outsourcing his IT jobs to North Korea to fund weapons programs
Node.js unveils experimental TypeScript support
Over $40 million recovered and arrests made within days of firm realising it had fallen for Business Email Compromise scam
Using 1Password on Mac? Patch up if you don’t want your Vaults raided
US elections have never been more secure, says CISA chief

A vulnerability was discovered in odoo, a suite of web based open source business apps. It could result in the execution of arbitrary code.

Multiple cross-site scripting vulnerabilities were discovered in RoundCube webmail. For the stable distribution (bookworm), these problems have been fixed in

Report: Tech misconceptions plague the IT world
Microsoft Teams offers more for developers

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Entrust faces years of groveling to regain browsers’ trust, say rival chiefs
How to use FluentValidation in ASP.NET Core

Kerberos could be made to crash if it received specially crafted input.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Update to upstream 2.1-43. 20240531 Addition of 06-aa-04/0xe6 (MTL-H/U C0) microcode at revision 0x1c; Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-02) at revision 0x4121; Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-03) at revision

Cloud storage lockers from Microsoft and Google used to store and spread state-sponsored malware
Samsung boosts bug bounty to a cool million for cracks of the Knox Vault subsystem

https://security-tracker.debian.org/tracker/DSA-5744-1

https://security-tracker.debian.org/tracker/DSA-5743-1

https://security-tracker.debian.org/tracker/DSA-5742-1