Menu

Latest articles

Go language evolving for future hardware, AI workloads
Letting chatbots run robots ends as badly as you’d expect
Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit
Keyboard robbers steal 171K customers’ data from AnnieMac mortgage house
The Dual Edge of Open Source: Examining Key Benefits and Security Challenges
Simplifying endpoint security
Bitfinex burglar bags 5 years behind bars for Bitcoin heist

* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853

* bsc#1232590 Cross-References: * CVE-2024-50602

* bsc#1233282 Cross-References: * CVE-2024-52533

AI meets security: POC to run workloads in confidential containers using NVIDIA accelerated computing

Several security issues were fixed in the Linux kernel.

Microsoft Power Pages misconfigurations exposing sensitive data

Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code

Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code

Fortinet patches VPN app flaw that could give rogue users, malware a privilege boost
Cybercriminal devoid of boundaries gets 10-year prison sentence
ShrinkLocker ransomware: what you need to know
IT specialist Jack Teixeira jailed for 15 years after leaking classified military documents on Discord
Kids’ shoemaker Start-Rite trips over security again, spilling customer card info
OpenSSL in Red Hat Enterprise Linux 10: From engines to providers
NatWest blocks bevy of apps in clampdown on unmonitorable comms
Asda security chief replaced, retailer sheds jobs during Walmart tech divorce
How to use DispatchProxy for AOP in .NET Core
Understanding Hyperlight, Microsoft’s minimal VM manager
Five Eyes infosec agencies list 2024’s most exploited software flaws

Update to 2.46.3

Update to b3561

Backport fix for CVE-2024-50602.

CVE fix for CVE-2024-9632

Reminder: China-backed crews compromised ‘multiple’ US telcos in ‘significant cyber espionage campaign’

Update to 2.46.3

ShrinkLocker ransomware scrambled your files? Free decryption tool to the rescue
Smashing Security podcast #393: Who needs a laptop to hack when you have a Firestick?
Data broker amasses 100M+ records on people – then someone snatches, sells it
Ransomware fiends boast they’ve stolen 1.4TB from US pharmacy network

giflib: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function. (CVE-2023-48161) Array indexing integer overflow. (CVE-2024-21210) HTTP client improper handling of maxHeaderSize. (CVE-2024-21208) Unbounded allocation leads to out-of-memory error. (CVE-2024-21217)

Microsoft slips Task Manager and processor count fixes into Patch Tuesday
Docker tutorial: Get started with Docker volumes
Kotlin for Java developers
The Agile Manifesto was ahead of its time
Visual Studio 17.12 brings C++, Copilot enhancements

Update to 130.0.6723.116

Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch

Update to 130.0.6723.116

Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch

Admins can give thanks this November for dollops of Microsoft patches
China’s Volt Typhoon crew and its botnet surge back with a vengeance
Air National Guardsman gets 15 years after splashing classified docs on Discord

Several security issues were fixed in .NET.

Microsoft’s .NET 9 arrives, emphasizing performance, cloud, and AI
Here’s what we know about the suspected Snowflake data extortionists

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

https://security-tracker.debian.org/tracker/DSA-5811-1

https://security-tracker.debian.org/tracker/DSA-5810-1

Red Hat OpenShift AI unveils model registry, data drift detection
‘Cybersecurity issue’ at Food Lion parent blamed for US grocery mayhem
Go language rises in Tiobe popularity index
The AI Fix #24: Where are the alien AIs, and are we being softened up for superintelligence?
HTTP your way into Citrix’s Virtual Apps and Desktops with fresh exploit code
Managing third-party risks in complex IT environments
Red Hat Developer Hub adds AI templates
Snowflake bares its agentic AI plans by showcasing its Intelligence platform
Amazon confirms employee data exposed in leak linked to MOVEit vulnerability
Winter Fuel Payment scam targets UK citizens via SMS
Why your AI models stumble before the finish line

* bsc#1186511 * bsc#1217826 * bsc#1222121 * bsc#1222815 * bsc#1230551

Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.

Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.

Multiple vulnerabilities have been fixed in libarchive, a multi-format archive and compression library. CVE-2021-36976

New wget packages are available for Slackware 15.0 and -current to fix a security issue.

An out-of-bounds write vulnerability when handling crafted streams was discovered in mpg123, a real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3, which could result in the execution of arbitrary code.

Containerizing WordPress: Best Practices for Robust Security and Management
FBI issues warning as crooks ramp up emergency data request scams
200,000 SelectBlinds customers have their card details skimmed in malware attack
Dark web crypto laundering kingpin sentenced to 12.5 years in prison

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Is your software architecture as clean as your code?
Can Wasm replace containers?
Breaking down digital silos

* bsc#1216423 Cross-References: * CVE-2023-45802

* bsc#1216423 Cross-References: * CVE-2023-45802

Alleged Snowflake attacker gets busted by Canadians – politely, we assume

https://security-tracker.debian.org/tracker/DSA-5809-1

https://security-tracker.debian.org/tracker/DSA-5808-1

https://security-tracker.debian.org/tracker/DSA-5807-1

https://security-tracker.debian.org/tracker/DSA-5805-1

A heap-based out-of-bounds write vulnerability was discovered in libarchive, a multi-format archive and compression library, which may result in the execution of arbitrary code if a specially crafted RAR archive is processed.

Invalid low-level GF(2^m) parameters can lead to an OOB memory access. (CVE-2024-9143) References: – https://bugs.mageia.org/show_bug.cgi?id=33736

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478)

In Libheif, insufficient checks in ImageOverlay::parse() while decoding a HEIF file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. (CVE-2024-41311) References:

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parsing `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A

Permission leak via embed or object elements. (CVE-2024-10458) Use-after-free in layout with accessibility. (CVE-2024-10459) Confusing display of origin for external protocol handler prompt. (CVE-2024-10460) XSS due to Content-Disposition being ignored in

https://security-tracker.debian.org/tracker/DSA-5806-1

https://security-tracker.debian.org/tracker/DSA-5804-1

Scattered Spider, BlackCat claw their way back from criminal underground
Secure cloud bursting: Leveraging confidential computing for peace of mind