Menu

Latest articles

Russian spies use remote desktop protocol files in unusual mass phishing drive
Beijing claims it’s found ‘underwater lighthouses’ that its foes use for espionage
Uncle Sam outs a Russian accused of developing Redline infostealing malware
Cast a hex on ChatGPT to trick the AI into writing exploit code
Tony Fadell: Innovating to save our planet | Starmus highlights

As methane emissions come under heightened global scrutiny, learn how a state-of-the-art satellite can pinpoint their sources and deliver the insights needed for targeted mitigation efforts

Belgian cops cuff 2 suspected cybercrooks in Redline, Meta infostealer sting
GitHub Copilot expands AI model support
The story behind the Health Infrastructure Security and Accountability Act
The AI Fix #22: Probing AI tongues and ASCII smuggling attacks
Admins better Spring into action over latest critical open source vuln
Tabnine previews AI code review agent
Merde! Macron’s bodyguards reveal his location by sharing Strava data
AI is transforming the developer experience. Embrace the change
Rise of the cloud computing opposition
Five Eyes nations tell tech startups to take infosec seriously. Again
Wanted. Top infosec pros willing to defend Britain on shabby salaries
OSI unveils Open Source AI Definition 1.0
JPMorgan Chase sues scammers following viral ‘infinite money glitch’
Feds investigate China’s Salt Typhoon amid campaign phone hacks
French ISP Free confirms data breach after hacker puts customer data up for auction
Brazen crims selling stolen credit cards on Meta’s Threads
Delta officially launches lawyers at $500M CrowdStrike problem
Dutch cops pwn the Redline and Meta infostealers, leak ‘VIP’ aliases
Visual Studio Code vs. Sublime Text: Which code editor should you use?
Bridging the performance gap in data infrastructure for AI
Open source gets complicated
WordPress forces user conf organizers to share social media credentials, arousing suspicions

https://security-tracker.debian.org/tracker/DSA-5799-1

Senator accuses sloppy domain registrars of aiding Russian disinfo campaigns
FIPS 140-3 changes for PKCS #12
ESET Research Podcast: CosmicBeetle

Learn how a rather clumsy cybercrime group wielding buggy malicious tools managed to compromise a number of SMBs in various parts of the world

Worker surveillance must comply with credit reporting rules

https://security-tracker.debian.org/tracker/DSA-5798-1

Google expands Responsible GenAI Toolkit

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The updated package provides Firefox 128 for all mandatory arches of Mageia (x86_64, i586 and aarch64), fixing several bugs, including security vulnerabilities, for i586 and aarch64: Fullscreen notification dialog can be obscured by document content. (CVE-2024-7518)

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

US offers $10 million bounty for members of Iranian hacking gang
Just how private is Apple’s Private Cloud Compute? You can test it to find out
Hugging Face pitches HUGS as an alternative to Nvidia’s NIM for open models

* bsc#1220262 Cross-References: * CVE-2023-50782

Strengthen DevSecOps with Red Hat Trusted Software Supply Chain
Secure design principles in the age of artificial intelligence
Confidential Containers with IBM Secure Execution for Linux
What is .NET? Microsoft’s answer to Java is now free and open source
A look at risk, regulation, and lock-in in the cloud

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink. (CVE-2024-47191)

fix CVE-2024-7006 (rhbz#2302997) fix CVE-2023-52356 (rhbz#2260112) fix CVE-2023-6228 (rhbz#2251863)

Putin’s pro-Trump trolls accuse Harris of poaching rhinos

https://security-tracker.debian.org/tracker/DSA-5797-1

https://security-tracker.debian.org/tracker/DSA-5796-1

JetBrains offers free use of WebStorm and Rider IDEs
AWS Cloud Development Kit flaw exposed accounts to full takeover
Next.js 15 arrives with faster bundler
Emergency patch: Cisco fixes bug under exploit in brute-force attacks
NotLockBit: ransomware discovery serves as wake-up call for Mac users

* bsc#1231294 Cross-References: * CVE-2024-47850

* bsc#1224038 * bsc#1224051 * bsc#1229013 Cross-References:

Bitwarden’s FOSS halo slips as new SDK requirement locks down freedoms
Ransomware’s ripple effect felt across ERs as patient care suffers
Enter the Neoverse with Azure’s Cobalt servers

* bsc#1231039 Cross-References: * CVE-2024-23213 * CVE-2024-23271

* bsc#1231039 Cross-References: * CVE-2024-23206 * CVE-2024-23213

* bsc#1231698 Cross-References: * CVE-2024-9676

* bsc#1231698 Cross-References: * CVE-2024-9676

Voice-enabled AI agents can automate everything, even your phone scams
China’s top messaging app WeChat banned from Hong Kong government computers
Anthropic’s latest Claude model can interact with computers – what could go wrong?
Perfctl malware strikes again as crypto-crooks target Docker Remote API servers
Samsung phone users under attack, Google warns
Penn State pays DoJ $1.25M to settle cybersecurity compliance case
Smashing Security podcast #390: When security firms get hacked, and your new North Korean remote worker
FortiManager critical vulnerability under active attack
‘Satanic’ data thief claims to have slipped into 350M Hot Topic shoppers info
Microsoft SharePoint RCE flaw exploits in the wild – you’ve had 3 months to patch
Syncfusion open-sources UI controls for .NET MAUI
How developers can automate ‘computer use’ with Anthropic’s new LLM

* bsc#1230683 Cross-References: * CVE-2024-45405

The best Python libraries for parallel processing
Why we get buggy software
The power of prime numbers in computing

libheif could be made to crash or read sensitive data if it opened a specially crafted file

Several security issues were fixed in Go.

Various security, performance, accuracy, and stability issues have been fixed.

New version 4.2.8 Fix for CVE-2024-9781

Millions of Android and iOS users at risk from hardcoded creds in popular apps
Developers embracing API-first development, survey says

It was discovered that there was a potential out-of-bounds read vulnerability in libheif, a decoder and encoder for the HEIF and AVIF image formats.

US lawmakers push DoJ to prosecute tax prep firms for leaking taxpayer data to big tech

https://security-tracker.debian.org/tracker/DSA-5795-1

TSMC blows whistle on potential sanctions-busting shenanigans from Huawei
VMware fixes critical RCE, make-me-root bugs in vCenter – for the second time
Tech firms to pay millions in SEC penalties for misleading SolarWinds disclosures
AI chatbots can be tricked by hackers into helping them steal your private data