Menu

Latest articles

Several security issues were fixed in libxmltok.

How Red Hat is integrating post-quantum cryptography into our products

Several security issues were fixed in ClamAV.

Several security issues were fixed in DCMTK.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Ticketmaster boss who repeatedly hacked rival firm sentenced
China claims Starlink signals can reveal stealth aircraft – and what that really means
Chinese national accused by Feds of spear-phishing for NASA, military source code
Microsoft confirms IE bug squashed in Patch Tuesday was exploited zero-day
The empire of C++ strikes back with Safe C++ blueprint
Snowflake slams ‘more MFA’ button again – months after Ticketmaster, Santander breaches
Germany’s CDU still struggling to restore data months after June cyberattack

An update that fixes four vulnerabilities is now available.

* bsc#1176447 * bsc#1195668 * bsc#1195928 * bsc#1195957 * bsc#1196018

* bsc#1229907 * bsc#1230372 Cross-References: * CVE-2024-8250

* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629

* bsc#1082555 * bsc#1190317 * bsc#1196516 * bsc#1205462 * bsc#1210629

Prison just got rougher as band of heinously violent cybercrims sentenced to lengthy stints

OpenSSH could be made to crash or run programs as your login if it received a specially crafted input.

9 hacks for a better nightly build
When your cloud strategy is ‘it depends’
China’s quantum* crypto tech may be unhackable, but it’s hardly a secret
3 common misconceptions around biometrics and authentication
AWS hands OpenSearch to the Linux Foundation
23andMe settles class-action breach lawsuit for $30 million

Update to 1.0.7 CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files. CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser

flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.

flatpak 1.15.10 and bubblewrap 0.10.0 updates, which together fix CVE-2024-42472 in Flatpak.

Update to 1.15.10 (CVE-2024-42472)

https://security-tracker.debian.org/tracker/DSA-5769-1

Node.js a JavaScript runtime environment that executes JavaScript code outside a web browser (server side) was vulnerable. CVE-2023-30589

New libarchive packages are available for Slackware 15.0 and -current to fix security issues.

CosmicBeetle joins the ranks of RansomHub affiliates – Week in security with Tony Anscombe

ESET research also finds that CosmicBeetle attempts to exploit the notoriety of the LockBit ransomware gang to advance its own ends

update to 128.0.6613.137 * High CVE-2024-8636: Heap buffer overflow in Skia * High CVE-2024-8637: Use after free in Media Router * High CVE-2024-8638: Type Confusion in V8 * High CVE-2024-8639: Use after free in Autofill

Update to expat-2.6.3.

Update to 1.0.7 CVE-2024-20506: Changed the logging module to disable following symlinks on Linux and Unix systems so as to prevent an attacker with existing access to the ‘clamd’ or ‘freshclam’ services from using a symlink to corrupt system files. CVE-2024-20505: Fixed a possible out-of-bounds read bug in the PDF file parser

Update to 115.15.0 https://www.thunderbird.net/en-US/thunderbird/115.15.0esr/releasenotes/

Update to expat-2.6.3.

Update to 3.6.1 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/mbedtls-3.6.1 Update to 3.6.0

Feeld dating app’s security too open-minded as private data swings into public view
Decoding OpenAI’s o1 family of large language models

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Life without Python’s ‘dead batteries’
New AI reporting regulations

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Cambodian senator sanctioned by US over alleged forced labor cyber-scam camps
Australia’s government spent the week boxing Big Tech
What’s in the cards for MariaDB?
Feds pull plug on domains linked to import of Chinese gun conversion devices
Fortinet admits miscreant got hold of customer data in the cloud
‘Hadooken’ Linux malware targets Oracle WebLogic servers
JFrog Platform adds runtime security for containers
Microsoft moves .NET 9 to release candidate stage
I stole 20 GB of data from Capgemini – and now I’m leaking it, says cybercrook

https://security-tracker.debian.org/tracker/DSA-5768-1

Mastercard splurges $2.65B on another big cyber purchase – Recorded Future
Adobe fixed Acrobat bug, neglected to mention whole zero-day exploit thing
Kong API platform adds service catalog
6 common Geek Squad scams and how to defend against them

Learn about the main tactics used by scammers impersonating Best Buy’s tech support arm and how to avoid falling for their tricks

Google Chrome gets a mind of its own for some security fixes
WordPress plugin and theme developers told they must use 2FA
Transport for London confirms 5,000 users’ bank data exposed, pulls large chunks of IT infra offline

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in libxmltok.

Several security issues were fixed in Expat.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

EU kicks off an inquiry into Google’s AI model
About that Windows Installer ‘make me admin’ security hole. Here’s how it’s exploited
Smashing Security podcast #384: A room with a view, AI music shenanigans, and a cocaine bear
Mind your header! There’s nothing refreshing about phishers’ latest tactic
Using the Pinecone vector database in .NET
NIS2, DORA, and Tiber-EU expanding cybersecurity regulation
Using PostgreSQL as a vector database in RAG
If HDMI screen rips aren’t good enough for you pirates, DeCENC is another way to beat web video DRM
Pokémon GO was an intelligence tool, claims Belarus military official
Healthcare giant to pay $65M settlement after crooks stole and leaked nude patient pics
Cyber crooks shut down UK, US schools, thousands of kids affected
Major sales and ops overhaul leads to much more activity … for Meow ransomware gang
Hunters International claims ransom on Chinese mega-bank’s London HQ
So you paid a ransom demand … and now the decryptor doesn’t work

An update that fixes one vulnerability is now available.

* bsc#1228535 * bsc#1230093 Cross-References: * CVE-2024-7264

* bsc#1230093 Cross-References: * CVE-2024-8096

* bsc#1230093 Cross-References: * CVE-2024-8096

How $20 and a lapsed domain allowed security pros to undermine internet integrity
Mind the talent gap: Infosec vacancies abound, but hiring is flat
Hacker pleads guilty after arriving on plane from Ukraine with a laptop crammed full of stolen credit card details
File handling in server-side JavaScript

* bsc#1225660 * bsc#1227378 * bsc#1227999 * bsc#1228780

Several security issues were fixed in Unbound.

TypeScript 5.6 now generally available
India to train 5,000 ‘Cyber Commandos’
Microsoft says it broke some Windows 10 patching – as it fixes flaws under attack
Oracle Code Assist moves to beta