Menu

Latest articles

RAC duo busted for stealing and selling crash victims’ data
Keir Starmer hands ex-Darktrace boss investment minister gig

Several security issues were fixed in the Linux kernel.

AI is killing cloud sustainability
FBI created a cryptocurrency so it could watch it being abused
Healthcare attacks spread beyond US – just ask India’s Star Health

The updated packages fix security vulnerabilities References: – https://bugs.mageia.org/show_bug.cgi?id=33614 – https://openssl-library.org/news/vulnerabilities-3.0/

Use-after-free when closing buffers in Vim

HTTP_REDIRECT_STATUS might be controlled via user request FPM log output might be modified by an attacker HTTP POST can be modified by an attacker For other bug fixes consult references

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

Crooks stole personal info of 77k Fidelity Investments customers
TypeScript 5.7 improves error reporting
Secure your AI initiatives
Fore-get about privacy, golf tech biz leaves 32M data records on the fairway
Ransomware attack leaks social security numbers of over 230,000 Comcast customers
CISA adds fresh Ivanti vuln, critical Fortinet bug to hall of shame

Several security issues were fixed in Go.

* bsc#1220826 * bsc#1226145 * bsc#1226666 * bsc#1227487 * bsc#1228466

* bsc#1027519 * bsc#1228574 * bsc#1228575 * bsc#1230366

Mozilla patches critical Firefox vuln that attackers are already exploiting
How to use Java generics to avoid ClassCastExceptions
Drasi: A lightweight approach to event-driven programming
Microsoft previews AI ‘building blocks’ for .NET

Several security issues were fixed in the Linux kernel.

* bsc#1047218 * bsc#1202273 * bsc#1226975 * bsc#1229589 * jsc#PED-10362

* bsc#1047218 * bsc#1225597 * bsc#1226975 * bsc#1229589 * jsc#PED-10362

How to enable secure use of AI
How should CISOs respond to the rise of GenAI?
Dutch cops reveal takedown of ‘world’s largest dark web market’
Internet Archive leaks user info and succumbs to DDoS

https://security-tracker.debian.org/tracker/DSA-5788-1

Moscow-adjacent GoldenJackal gang strikes air-gapped systems with custom malware
Smashing Security podcast #388: Vacuum cleaner voyeur, and pepperoni pact blocks payout
Smart TVs are spying on everyone
Deno 2.0 arrives, ready to battle Node.js
Marriott settles for a piddly $52M after series of breaches affecting millions

https://security-tracker.debian.org/tracker/DSA-5729-2

National Public Data files for bankruptcy, admits ‘hundreds of millions’ potentially affected
Using iPhone Mirroring at work? You might have just overshared to your boss
Gemini Code Assist Enterprise woos enterprise developers
Cyber insurance, human risk, and the potential for cyber-ratings

Could human risk in cybersecurity be managed with a cyber-rating, much like credit scores help assess people’s financial responsibility?

Microsoft cleans up hot mess of Patch Tuesday preview
Ransomware gang Trinity joins pile of scumbags targeting healthcare
Solving the Puzzle of RBAC with Red Hat Customer Portal
Electron vs. Tauri: Which cross-platform framework is for you?
WebSockets under the hood with Node.js

Patch the code to use https instead of http (CVE-2024-45321)

Fixes CVE-2024-45752: A vulnerability that allows users to remap keys arbitrarily. This allows all users on the system to remap a key unexpectedly to a potentially malicious sequence

Patch the code to use https instead of http (CVE-2024-45321)

Update to 0.3.13.3 and fix gresource generation

Patch the code to use https instead of http (CVE-2024-45321)

https://security-tracker.debian.org/tracker/DSA-5787-1

Microsoft issues 117 patches – some for flaws already under attack
Qualcomm urges device makers to push patches after ‘targeted’ exploitation

The fixes for CVE-2024-38474 and CVE-2024-39884 introduced two regressions in mod_rewrite and mod_proxy. For the stable distribution (bookworm), these problems have been fixed in

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The AI Fix #19: AI spy specs, robot dogs with ladders, and is it AI or the climate?
Databricks says with its new Databricks Apps platform, you can build tailored enterprise apps in 5 minutes

* bsc#1222040 * bsc#1222041 * bsc#1222042 Cross-References:

* bsc#1023072 * bsc#1023190 * bsc#1027776 * bsc#1027779 * bsc#1027785

California’s vetoed AI bill: Bullet dodged, but not for long
Embracing your inner on-premises self
SAP Build gains AI capabilities to help build autonomous agents
Happy birthday, Putin – you’ve been pwned
Google brings better bricking to Androids, to curtail crims

Fix login QR code not shown in WhatsApp web. Disable PSON by default again in GTK 3 API versions. Disable DMABuf video sink by default to prevent file descriptor leaks. Fix several crashes and rendering issues. Use Skia instead of cairo for 2D rendering and enable GPU rendering by default.

Fix login QR code not shown in WhatsApp web. Disable PSON by default again in GTK 3 API versions. Disable DMABuf video sink by default to prevent file descriptor leaks. Fix several crashes and rendering issues. Use Skia instead of cairo for 2D rendering and enable GPU rendering by default.

Feds reach for sliver of crypto-cash nicked by North Korea’s notorious Lazarus Group
Oracle touts ‘tip and tail’ release model for Java library development
American Water rinsed in cyberattack, turns off app
Rust resumes rise in popularity
The best new features and fixes in Python 3.13
Cops love facial recognition, and withholding info on its use from the courts

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

Chinese cyberspies reportedly breached Verizon, AT&T, Lumen
Your robot vacuum cleaner might be spying on you

WEBrick could allow a HTTP request smuggling attack.

An update that fixes three vulnerabilities is now available.

* bsc#1231264 * bsc#1231265 * bsc#1231266 Cross-References:

cups-filters could be made to run programs if it received specially crafted network traffic.

CUPS could be made to crash or run programs if it received specially crafted network traffic.

5 ways data scientists can prepare now for genAI transformation
Open source isn’t going to save AI
Embattled users worn down by privacy options? Let them eat code
5 ways companies can use time series forecasting

Several security issues were fixed in Firefox.

ChatGPT o1-preview excels at code generation

https://security-tracker.debian.org/tracker/DSA-5786-1

Dom Walden discovered that the AbuseFilter extension in MediaWiki, a website engine for collaborative work, performed incomplete authorisation checks.

Red Hat Insights provides analytics for the IBM X-Force Cloud Threat Report

update to 129.0.6668.89 High CVE-2024-7025: Integer overflow in Layout High CVE-2024-9369: Insufficient data validation in Mojo High CVE-2024-9370: Inappropriate implementation in V8

Amongst other general bug fixes, this release addresses: CVE-2024-46951 CVE-2024-46952 CVE-2024-46953 CVE-2024-46954

The current versions have reached EOL and several security vulnerabilities were fixed by Mozilla. We are having some issues that are delaying the build for some architectures, so for the moment we are releasing this update just for x86_64

Integer overflows flaws were discovered in the Compound Document Binary File format parser of libgsf, the GNOME Project G Structured File Library, which could result in the execution of arbitrary code if a specially crafted file is processed.

* bsc#1230939 Cross-References: * CVE-2024-47176

The complexities of attack attribution – Week in security with Tony Anscombe

As highlighted by new ESET research this week, attributing a cyberattack to a specific threat actor is a complex affair

Ryanair faces GDPR turbulence over customer ID checks
UK’s Sellafield nuke waste processing plant fined £333K for infosec blunders

update to 129.0.6668.89 High CVE-2024-7025: Integer overflow in Layout High CVE-2024-9369: Insufficient data validation in Mojo High CVE-2024-9370: Inappropriate implementation in V8

Update to new upstream version (closes rhbz#2237124)