Menu

Latest articles

https://security-tracker.debian.org/tracker/DSA-5745-1

Delta: CrowdStrike’s offer to help in Falcon meltdown was too little, too late
US ‘laptop farm’ man accused of outsourcing his IT jobs to North Korea to fund weapons programs
Node.js unveils experimental TypeScript support
Over $40 million recovered and arrests made within days of firm realising it had fallen for Business Email Compromise scam
Using 1Password on Mac? Patch up if you don’t want your Vaults raided
US elections have never been more secure, says CISA chief

A vulnerability was discovered in odoo, a suite of web based open source business apps. It could result in the execution of arbitrary code.

Multiple cross-site scripting vulnerabilities were discovered in RoundCube webmail. For the stable distribution (bookworm), these problems have been fixed in

Report: Tech misconceptions plague the IT world
Microsoft Teams offers more for developers

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Entrust faces years of groveling to regain browsers’ trust, say rival chiefs
How to use FluentValidation in ASP.NET Core

Kerberos could be made to crash if it received specially crafted input.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Update to upstream 2.1-43. 20240531 Addition of 06-aa-04/0xe6 (MTL-H/U C0) microcode at revision 0x1c; Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-02) at revision 0x4121; Addition of 06-ba-08/0xe0 microcode (in intel-ucode/06-ba-03) at revision

Cloud storage lockers from Microsoft and Google used to store and spread state-sponsored malware
Samsung boosts bug bounty to a cool million for cracks of the Knox Vault subsystem

https://security-tracker.debian.org/tracker/DSA-5744-1

https://security-tracker.debian.org/tracker/DSA-5743-1

https://security-tracker.debian.org/tracker/DSA-5742-1

https://security-tracker.debian.org/tracker/DSA-5741-1

Google unveils Flutter GPU API, Dart updates

https://security-tracker.debian.org/tracker/DSA-5739-1

https://security-tracker.debian.org/tracker/DSA-5738-1

Faulty instructions in Alibaba’s T-Head C910 RISC-V CPUs blow away all security
Fighting AI fire with AI fire
Ahead-of-time class loading proposal would speed Java startups
How AI and Machine Learning Are Transforming Cybersecurity Quality Assurance
Small CSS tweaks can help nasty emails slip through Outlook’s anti-phishing net

A vulnerability has been discovered in Bitcoin, which can lead to a denial of service.

* bsc#1228872 Cross-References: * CVE-2024-7383

* bsc#1227296 Cross-References: * CVE-2024-32230

* bsc#1214855 * bsc#1219267 * bsc#1219268 * bsc#1219438 * bsc#1221916

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

Multiple vulnerabilities have been discovered in aiohttp, the worst of which could lead to service compromise.

What is Google Cloud’s generative AI evaluation service?
Police take just 2 days to recover $40M stolen in business email scam
EQT buys majority share in Swiss cybersecurity biz Acronis
Pig-butchering scammer targets BBC journalist
Full-stack development with Java, React, and Spring Boot, Part 3
UK health services call-handling vendor faces $7.7M fine over 2022 ransomware attack
SharpRhino malware targets IT admins – Hunters International gang suspected
Georgia’s voter portal gets a crash course in client versus backend input validation
Microsoft punches back at Delta Air Lines and its legal threats
CrowdStrike hires outside security outfits to review troubled Falcon code

https://security-tracker.debian.org/tracker/DSA-5740-1

JetBrains updates IDEs, improves AI assistant
Google splats device-hijacking exploited-in-the-wild Android kernel bug among others
Sonic Automotive says ransomware-linked CDK software outage cost it $30M
FTC warns consumers of scammers offering to remove all negative information from credit reports
The AI Fix #10: An AI cookery dumpster fire, the ARC prize, and a creepy new AI friend
Bad apps bypass Windows security alerts for six years using newly unveiled trick

Artificial intelligence (AI) and chatbots like ChatGPT are transforming the way educators and students approach education. It’s not just college students leveraging AI to get ahead; high school and even grade school students are using AI resources for their projects and homework. Students can write essays, get math tutoring help, and even create study plans […]

* bsc#1220356 * bsc#1227525 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5

* bsc#1227052 Cross-References: * CVE-2024-6104

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1221302 * bsc#1223059

Users call on Microsoft to update Outlook’s friendly name feature
Extending Red Hat Unified Kernel Images More Securely By Using Addons
Is efficiency on your cloud architect’s radar?

* bsc#1228549 * bsc#1228552 Cross-References: * CVE-2024-41671

* bsc#1227147 Cross-References: * CVE-2024-5535

GitHub Copilot: Productivity boost or DORA metrics disaster?
Visual Studio Code 1.92 improves debugging experience
Billion-dollar bust as international op shutters Cryptonator wallet
MDM vendor Mobile Guardian attacked, leading to remote wiping of 13,000 devices
Illinois relaxes biometric privacy law so snafus won’t cost businesses billions
NFL to begin using face scanning tech across all of its stadiums
Python scores its highest rating in Tiobe index
That cyber-heist of 2.9B personal records? There’s a class-action lawsuit looming for that
Your copilot for improved cyber protection
Sneaky SnakeKeylogger slithers into Windows inboxes to steal sensitive secrets

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of Java sandbox restrictions.

CrowdStrike unhappy about Delta’s ‘litigation threat,’ claims airline refused ‘free on-site help’
11 reasons the new JavaScript isn’t like the old JavaScript
Turning AI hype into reality
A developer’s guide to the headless data architecture

Several security issues were fixed in the Linux kernel.

Backport fix for CVE-2023-49528

China starts testing national cyber-ID before consultation on the idea closes
Google gamed into advertising a malicious version of Authenticator

https://security-tracker.debian.org/tracker/DSA-5737-1

https://security-tracker.debian.org/tracker/DSA-5736-1

AI and automation reducing breach costs – Week in security with Tony Anscombe

Organizations that leveraged AI and automation in security prevention cut the cost of a data breach by US$2.22 million compared to those that didn’t deploy these technologies, according to IBM

DARPA suggests turning old C code automatically into Rust – using AI, of course

update to 127.0.6533.88 Critical CVE-2024-6990: Uninitialized Use in Dawn High CVE-2024-7255: Out of bounds read in WebTransport High CVE-2024-7256: Insufficient data validation in Dawn

update to 127.0.6533.88 Critical CVE-2024-6990: Uninitialized Use in Dawn High CVE-2024-7255: Out of bounds read in WebTransport High CVE-2024-7256: Insufficient data validation in Dawn update to 127.0.6533.72

Update to upstream version 2.11.

Update to upstream version 2.11.

* bsc#1225013 * bsc#1225310 Cross-References: * CVE-2024-27398

* bsc#1219296 * bsc#1220145 * bsc#1220211 * bsc#1220828 * bsc#1220832

Israeli hacktivist group brags it took down Iran’s internet
Respect your data, and protect it

* bsc#1214855 * bsc#1221916 * bsc#1228324 Cross-References:

Fortune 50 biz coughed up record-breaking $75M ransom to halt leak of stolen data
UK plans to revamp national cyber defense tools are already in motion

Gross could be made to crash or to allow arbitrary code execution.

Small language models and open source are transforming AI