Menu

Latest articles

Simone Margaritelli reported that cups, the Common UNIX Printing System, does not properly sanitize IPP attributes when creating PPD files, which may result in the execution of arbitrary code.

Red team hacker on how she ‘breaks into buildings and pretends to be the bad guy’

Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted input could cause a heap-buffer-overflow leading to memory corruption and potentially causing the application to crash or allowing arbitrary code execution

Update to new upstream version (closes rhbz#2237124)

https://security-tracker.debian.org/tracker/DSA-5779-1

https://security-tracker.debian.org/tracker/DSA-5778-1

Multiple vulnerabilities have been fixed in ruby-rails-html-sanitizer, a Ruby library for sanitizing HTML fragments in Rails applications. CVE-2022-23517

Multiple vulnerabilities have been fixed in ruby-loofah, a Ruby library for manipulating and transforming HTML/XML documents and fragments. CVE-2022-23514

Gamaredon’s operations under the microscope – Week in security with Tony Anscombe

ESET research examines the group’s malicious wares as used to spy on targets in Ukraine in the past two years

Red Hat’s response to OpenPrinting CUPS vulnerabilities: CVE-2024-47076, CVE-2024-47175, CVE-2024-47176 and CVE-2024-47177
When LLMs day dream: Hallucinations and how to prevent them

multipart/form-data request tampering has been fixed in ruby-httparty, a Ruby library for using Web-based APIs and related services. For Debian 11 bullseye, this problem has been fixed in version

Multiple vulnerabilities have been discovered in nginx, the worst of which could result in denial of service.

Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in denial of service.

Multiple vulnerabilities have been found in yt-dlp, the worst of which could result in arbitrary code execution.

Multiple vulnerabilities have been discovered in Docker, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.

Feds charge 3 Iranians with ‘hack-and-leak’ of Trump 2024 campaign
Recall the Recall recall? Microsoft thinks it can make that Windows feature palatable
That doomsday critical Linux bug: It’s CUPS. May lead to remote hijacking of devices
Microsoft adds safety tools to Azure AI Studio
Kobiton preps AI-enabled testing tools for mobile apps
Don’t panic and other tips for staying safe from scareware

Keep your cool, arm yourself with the right knowledge, and other tips for staying unshaken by fraudsters’ scare tactics

Deepfake Ukrainian diplomat targeted US senator on Zoom call
Ransomware gang using stolen Microsoft Entra ID creds to bust into the cloud

An update that fixes four vulnerabilities is now available.

* bsc#1202346 * bsc#1227985 * bsc#1228002 * bsc#1228938 * bsc#1228959

* bsc#1225099 * bsc#1228349 Cross-References: * CVE-2023-52846

Is it possible to save money and run on a public cloud?
Python in VS Code gets even better

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

In today’s world, both small businesses and everyday consumers face a growing number of cyber threats. From ransomware attacks to phishing scams, hackers are becoming more sophisticated. OpenText’s 2024 Threat Hunter Perspective sheds light on what’s coming next and how to protect yourself. Whether you’re running a small business or managing personal data at home, […]

https://security-tracker.debian.org/tracker/DSA-5777-1

https://security-tracker.debian.org/tracker/DSA-5776-1

Meta introduces Llama Stack distributions for building LLM apps
Patch now: Critical Nvidia bug allows container escape, complete host takeover
HPE patches three critical security holes in Aruba PAPI
Doomsday ‘9.9 RCE bug’ could hit every Linux system
Tabnine AI agents generate, validate code for Jira issues
Securing intellectual property in AI-powered enterprises
When UK rail stations’ Wi-Fi was defaced by hackers the only casualty was the truth
Victims lose $70k to one single wallet-draining app on Google’s Play Store
CISA warns hackers targeting industrial systems with “unsophisticated methods” as claims made of Lebanon water hack

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

The CA certificates in the ca-certificates package were updated.

Public Wi-Fi operator investigating cyberattack at UK’s busiest train stations

Several security issues were fixed in the Linux kernel.

OpenJPEG could be made to crash if it opened a specially crafted file.

The system could be made to expose sensitive information.

How to use generics in your Java programs
What’s next for Azure API Management?
3 great new features in Postgres 17
Smashing Security podcast #386: The $230 million crypto handbag heist, and misinformation on social media
UK government’s bank data sharing plan slammed as ‘financial snoopers’ charter’
How to get LLM-driven applications into production
WordPress.org denies service to WP Engine, potentially putting sites at risk

https://security-tracker.debian.org/tracker/DSA-5775-1

China’s Salt Typhoon cyber spies are deep inside US ISPs
Eclipse working group to address cybersecurity, AI regulations
RansomHub genius tries to put the squeeze on Delaware Libraries

* bsc#1230366 Cross-References: * CVE-2024-45817

* bsc#1202023 * bsc#1229438 * bsc#1230866 Cross-References:

Intro to Node’s built-in SQLite module

Several security issues were fixed in the Linux kernel.

Multiple vulnerabilities have been found in Xpdf, the worst of which could result in denial of service.

Several security issues were fixed in Intel Microcode.

China claims Taiwan, not civilians, behind web vandalism
CrowdStrike apologizes to Congress for ‘perfect storm’ that caused global IT outage

* bsc#1069468 * bsc#1079798 * bsc#1079799 * bsc#1079800 * bsc#1079801

Who’s watching you the closest online? Google, duh
US proposes ban on Chinese, Russian connected car tech over security fears
Russia’s digital warfare on Ukraine shows no signs of slowing: Malware hits surge
Warnings after new Valencia ransomware group strikes businesses and leaks data
10 nasty software bugs put thousands of fuel storage tanks at risk of cyberattacks
The AI Fix #17: Why AI is an AWFUL writer and LinkedIn’s outrageous land grab
Cybersecurity and compliance: The dynamic duo of 2024

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

How to spot a North Korean agent before they get comfy inside payroll
Citing security fears, Ukraine bans Telegram on government and military devices
Two men arrested one month after $230 million of cryptocurrency stolen from a single victim
OpenAI Academy to help train developers, offer free credits
A data leak and a data breach
The challenge of cloud computing forensics
Java 23 highlights crypto performance and security
Gleam language reaches 1.5 release

* bsc#1193629 * bsc#1194111 * bsc#1194765 * bsc#1194869 * bsc#1196261

* bsc#1229596 * bsc#1229704 * bsc#1230227 Cross-References:

py7zr could be made to create arbitrary files when extracting the contents of a specially crafted 7z archive.

Multiple vulnerabilities have been found in Tor, the worst of which could result in denial of service.

Some US Kaspersky customers find their security software replaced by ‘UltraAV’
Telegram will now hand over IP addresses, phone numbers of suspects to cops
‘Cybersecurity issue’ takes MoneyGram offline for three days – and counting
Necro malware continues to haunt side-loaders of dodgy Android mods
So how’s Microsoft’s Secure Future Initiative going?

* bsc#1012628 * bsc#1193454 * bsc#1194869 * bsc#1205462 * bsc#1208783

* bsc#1229596 * bsc#1230227 Cross-References: * CVE-2024-6232