Menu

Latest articles

Download our NoSQL database enterprise buyer’s guide
The AI Fix #6: AI lobotomies, and bots scam scam bots
Judge dismisses lawsuit over GitHub Copilot AI coding assistant
Ransomware attack on blood-testing service puts lives in danger in South Africa
Elexon’s Insight into UK electricity felled by expired certificate
Evolve Bank & Trust confirms LockBit stole 7.6 million people’s data

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Multiple vulnerabilities have been discovered in LIVE555 Media Server, the worst of which could lead to a denial of service.

Houthi rebels are operating their own GuardZoo spyware
All the brilliance of AI on minimalist platforms
Microsoft China staff can’t log on with an Android, so Redmond buys them iThings
Scammers double-scam victims by offering to help recover from scams
China’s APT40 gang is ready to attack vulns within hours or days of public release
Researchers reveal flaws in AI agent benchmarking
Rust leaps forward in language popularity index
FTC’s non-compete ban almost certainly dead, based on a Texas federal court decision
ChatGPT for Mac app flaw left users’ chat history exposed
Microsoft forgets about SwiftKey’s support site

In recognition of its profound impact, July 16 is celebrated as Artificial Intelligence (AI) Appreciation Day. AI is one of the defining technologies of our era, and its adoption is skyrocketing. People are using AI tools like OpenAI’s ChatGPT and Microsoft Copilot for a wide range of personal applications. Indeed, AI is integrated into various […]

Avast secretly gave DoNex ransomware decryptors to victims before crims vanished

* bsc#1222045 Cross-References: * CVE-2024-29025

* bsc#1223965 Cross-References: * CVE-2024-33394

* bsc#1226469 Cross-References: * CVE-2024-37891

Navigating Europe’s digital identity crossroads
Selfie-based authentication raises eyebrows among infosec experts
Not-so-OpenAI allegedly never bothered to report 2023 data breach
A decade after collapsing, crypto exchange Mt Gox repays some investors

An update that fixes 7 vulnerabilities is now available.

Navigating the Cybersecurity Maze: Advanced Linux Security Practices for Professionals

Update to 2024.07.02

https://security-tracker.debian.org/tracker/DSA-5726-1

A vulnerability has been discovered in Stellarium, which can lead to arbitrary file writes.

Social media and teen mental health – Week in security with Tony Anscombe

Social media sites are designed to make their users come back for more. Do laws restricting children’s exposure to addictive social media feeds have teeth or are they a political gimmick?

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which could arbitrary code execution.

Multiple vulnerabilities have been discovered in the X.Org X11 library, the worst of which could lead to a denial of service.

A vulnerability has been discovered in KDE Plasma Workspaces, which can lead to privilege escalation.

Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.

Devs claim Apple is banning VPNs in Russia ‘more effectively’ than Putin

Two vulnerabilities were discovered in the GSS message token handling in krb5, the MIT implementation of Kerberos. An attacker can take advantage of these flaws to bypass integrity protections or cause a denial of service.

Comprehensive Security Validation and Breach and Attack Simulation for Linux
Cancer patient forced to make terrible decision after Qilin attack on London hospitals
Latest Ghostscript vulnerability haunts experts as the next big breach enabler

Multiple vulnerabilities have been discovered in BusyBox, the worst of which could lead to arbitrary code execution.

A vulnerability has been discovered in Coreutils, which can lead to a heap buffer overflow and possibly aribitrary code execution.

* bsc#1227186 * bsc#1227187 Cross-References: * CVE-2024-37370

Europol says mobile roaming tech is making its job too hard

Multiple vulnerabilities have been discovered in GraphicsMagick, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in TigerVNC, the worst of which could lead to remote code execution.

Multiple vulnerabilities have been discovered in WebKitGTK+, the worst of which could lead to arbitrary code execution

https://security-tracker.debian.org/tracker/DSA-5725-1

Volcano Demon ransomware group rings its victims to extort money
The AI Fix #5: An angry AI girlfriend, and artificial intelligence is stupid
Security vulnerability reporting: Who can you trust?

* bsc#1226642 Cross-References: * CVE-2024-6387

Europol nukes nearly 600 IP addresses in Cobalt Strike crackdown

* bsc#1222050 * bsc#1222052 * bsc#1222053 * bsc#1226957

* bsc#1219217 * bsc#1220266 Cross-References: * CVE-2024-0914

Ransomware scum who hit Indonesian government apologizes, hands over encryption key

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Smashing Security podcast #379: Private nights, evil twins, and crypto home invasions
Traeger security bugs bad news for grillers with neighborly beef

* bsc#1225771 Cross-References: * CVE-2024-5564

* bsc#1227052 Cross-References: * CVE-2024-6104

* bsc#1213720 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5

* bsc#1224282 Cross-References: * CVE-2024-34459

Several security issues were fixed in Firefox.

* bsc#1224282 Cross-References: * CVE-2024-34459

Affirm admits customer info pilfered during ransomware raid at Evolve Bank

USN-6851-1 caused systemctl enable to fail

USN-6844-1 caused the cupsd daemon to never start

How evolving AI regulations impact cybersecurity

* bsc#1226448 Cross-References: * CVE-2024-4032

* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044

* bsc#1224279 * bsc#1224309 Cross-References: * CVE-2024-3044

‘Almost every Apple device’ vulnerable to CocoaPods supply chain attack
Baddies hijack Korean ERP vendor’s update systems to spew malware
Nasty regreSSHion bug in OpenSSH puts around 700K Linux boxes at risk

OpenSSH could be made to bypass authentication and remotely access systems without proper credentials.

Juniper Networks flings out emergency patches for perfect 10 router vuln
Polyfill.io claims reveal new cracks in supply chain, but how deep do they go?
CISA director: US is ‘not afraid’ to shout about Big Tech’s security failings

* bsc#1223965 Cross-References: * CVE-2024-33394

The Qualys Threat Research Unit (TRU) discovered that OpenSSH, an implementation of the SSH protocol suite, is prone to a signal handler race condition. If a client does not authenticate within LoginGraceTime seconds (120 by default), then sshd’s SIGALRM handler is called

* bsc#1224044 Cross-References: * CVE-2024-34397

Several security issues were fixed in eSpeak NG.

Multiple vulnerabilities have been discovered in GNU Emacs and Org Mode, the worst of which could lead to arbitrary code execution.

Police allege ‘evil twin’ of in-flight Wi-Fi used to steal passenger’s credentials
Indonesian government didn’t have backups of ransomwared data, because DR was only an option
Microsoft tells yet more customers their emails have been stolen

https://security-tracker.debian.org/tracker/DSA-5724-1

API security: The importance of rate limiting policies in safeguarding your APIs
Post-quantum cryptography: Code-based cryptography
Embracing automated policy as code in financial services