Menu

Latest articles

* bsc#1167721 Cross-References: * CVE-2019-20633

UK crimebusters shut down global call-spoofing outfit that claimed 170K-plus victims
Japan mandates app to ensure national ID cards aren’t forged

update to 127.0.6533.72 * CVE-2024-6988: Use after free in Downloads * CVE-2024-6989: Use after free in Loader * CVE-2024-6991: Use after free in Dawn * CVE-2024-6992: Out of bounds memory access in ANGLE

India contemplates compulsory dynamic 2FA for digital payments
US sends cybercriminals back to Russia in prisoner swap that freed WSJ journo, others

Several security issues were fixed in Tomcat.

https://security-tracker.debian.org/tracker/DSA-5735-1

Several security issues were fixed in Bind.

Too late now for canary test updates, says pension fund suing CrowdStrike
Google adds Gemini to BigQuery, Looker to help with data engineering
The cyberthreat that drives businesses towards cyber risk insurance

Many smaller organizations are turning to cyber risk insurance, both to protect against the cost of a cyber incident and to use the extensive post-incident services that insurers provide

$75 million record-breaking ransom paid to cybercriminals, say researchers
FBI, CISA remind US voters that DDoS attacks can’t touch election systems
How to counter adversarial AI

Several security issues were fixed in the Linux kernel.

Firefox’s Mozilla follows Google in losing trust in Entrust’s TLS certificates
Google Cloud adds graph processing to Spanner, SQL support to Bigtable

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

How Dapr improves cloud-native development

* bsc#1224788 Cross-References: * CVE-2024-35195

* bsc#1211674 Cross-References: * CVE-2023-32681

The best new features in C# 13
Germany names China as source of attack on government geospatial agency
Ransomware infection cuts off blood supply to 250+ hospitals
More than 83K certs from nearly 7K DigiCert customers must be swapped out now
Russia takes aim at Sitting Ducks domains, bags 30,000+

Several security issues were fixed in Python.

Chrome adopts app-bound encryption to stymie cookie-stealing malware
Embedding AI security from the get go
‘Error’ in Microsoft’s DDoS defenses amplified 8-hour Azure outage
How to get started with MySQL
Full-stack development with Java, React, and Spring Boot, Part 2
UK Electoral Commission slapped for basic cybersecurity fails
Why Apache Iceberg is on fire right now

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 17.

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

Update to 1.3.3 https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3

DigiCert gives unlucky folks 24 hours to replace doomed certificates after code blunder
White House opts to not add regulatory restrictions on AI development – for now
Delta Air Lines dials up Microsoft’s legal nemesis over CrowdStrike losses
‘LockBit of phishing’ EvilProxy used in more than a million attacks every month
The AI Fix #9: When AI detectors fail (spectacularly), and OpenAI’s five steps to Skynet

* bsc#1228184 Cross-References: * CVE-2024-40897

* bsc#916845 Cross-References: * CVE-2013-4235

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Ransomware gangs are loving this dumb but deadly make-me-admin ESXi vulnerability

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Who should own cloud costs?
The rise and fall of Stack Overflow
How AI will transform data analytics
Proofpoint phishing palaver plagues millions with ‘perfectly spoofed’ emails from IBM, Nike, Disney, others
Malaysia is working on an internet ‘kill switch’, says minister
Meta’s AI safety system defeated by the space bar
US border cops really must get a warrant in NY before searching your phones, devices
Hacking gang leaks documents stolen from Pentagon IT provider
Intruders at HealthEquity rifled through storage, stole 4.3M people’s data

Several security issues were fixed in the Linux kernel.

Google apologizes for breaking password manager for millions of Windows users with iffy Chrome update

Affected Products: * openSUSE Leap 15.5

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

How to choose the right low-code, no-code, or process automation platform
Qdrant review: A highly flexible option for vector search
The other shoe drops on generative AI
Get ready for more Java licensing changes
NIST releases new tool to check AI models’ security
Microsoft admits 8.5M CrowdStruck machines estimate was lowballed

Several security issues were fixed in EDK II.

Several security issues were fixed in Lua.

China ponders creating a national ‘cyberspace ID’
Secure Boot useless on hundreds of PCs from major vendors after key leak

https://security-tracker.debian.org/tracker/DSA-5734-2

The security update announced as DSA 5734-1 caused a regression on configurations using the Samba DLZ module. Updated packages are now available to correct this issue.

Telegram for Android hit by a zero-day exploit – Week in security with Tony Anscombe

Attackers abusing the “EvilVideo” vulnerability could share malicious Android payloads via Telegram channels, groups, and chats, all while making them appear as legitimate multimedia files

Update to 1.16 fixes rhbz#2259096

Update to 2.11.2

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

Update to 1.16 fixes rhbz#2259096

Update to 2.11.2

TypeScript takes aim at truthy and nullish bugs

https://security-tracker.debian.org/tracker/DSA-5734-1

CrowdStrike meets Murphy’s Law: Anything that can go wrong will
Progress discloses second critical flaw in Telerik Report Server in as many months
The case for multicloud: Lessons from the CrowdStrike outage
Python pick: Shiny for Python—now with chat

* bsc#1222693 Cross-References: * CVE-2023-29483

* bsc#1198880 * bsc#1214678 Cross-References: * CVE-2022-28506

BMC report examines DataOps practices

Update to 115.13.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-31/ https://www.thunderbird.net/en-US/thunderbird/115.13.0/releasenotes/

Backport upstream patch for CVE-2023-49606.

North Korean chap charged for attacks on US hospitals, military, NASA – and even China
Malware crew Stargazers Goblin used 3,000 GitHub accounts to make bank