Menu

Latest articles

https://security-tracker.debian.org/tracker/DSA-5733-1

CrowdStrike Windows patchpocalypse could take weeks to fix, IT admins fear

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Messy data is holding enterprises back from AI
CrowdStrike file update bricks Windows machines around the world
North Korea likely behind takedown of Indian crypto exchange WazirX
Beijing’s attack gang Volt Typhoon was a false flag inside job conspiracy: China

This is the July 2024 security update for .NET 6. Release Notes SDK: https://github.com/dotnet/core/blob/main/release- notes/6.0/6.0.32/6.0.132.md Runtime: https://github.com/dotnet/core/blob/main/release-

Security fixes for https://nvd.nist.gov/vuln/detail/CVE-2024-38875 https://nvd.nist.gov/vuln/detail/CVE-2024-39329 https://nvd.nist.gov/vuln/detail/CVE-2024-3930 https://nvd.nist.gov/vuln/detail/CVE-2024-39614

Fix for CVE-2024-38517.

Developer productivity poorly understood, report says
Judge mostly drags SEC’s lawsuit against SolarWinds into the recycling bin
Kaspersky challenges US government to put up or shut up about Kremlin ties
Russia’s FIN7 is peddling its EDR-nerfing malware to ransomware gangs

* bsc#1220145 * bsc#1223363 * bsc#1223681 * bsc#1223683 * bsc#1225211

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1210619 * bsc#1220537 * bsc#1223363 * bsc#1223683 * bsc#1225211

Red Hat Enterprise Linux and Secure Boot in the cloud
Red Hat Advanced Cluster Security Cloud Service is now Generally Available
Red Hat’s path to post-quantum cryptography
Maximum-severity Cisco vulnerability allows attackers to change admin passwords
Talk of GitLab sale highlights growing importance of DevSecOps platforms

stunnel could allow unintended access to network services.

Building next-generation applications with the Windows Application SDK

* bsc#1224122 Cross-References: * CVE-2024-3727

How to use HybridCache in ASP.NET Core
Firms skip security reviews of major app updates about half the time

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Release the hounds! Securing datacenters may soon need sniffer dogs

https://security-tracker.debian.org/tracker/DSA-5732-1

Google’s Genkit for Go brings AI app development to Go language
Merged Exabeam and LogRhythm cut jobs, face lawsuit
Smashing Security podcast #381: Trump shooting conspiracy, Squarespace account hijack, and the butt stops here

https://security-tracker.debian.org/tracker/DSA-5731-1

Google rolls out new dev tools focusing on open source and GenAI
Kaspersky gives US customers six months of free updates as a parting gift
Deno adds workspaces for managing monorepos
HardBit ransomware – what you need to know
Ransomware continues to pile on costs for critical infrastructure victims
Salesforce previews Einstein-powered service agent
London council accuses watchdog of ‘exaggerating’ danger of 2020 raid on residents’ data
Mistral’s new Codestral Mamba to aid longer code generation
Exim 4.98 Addresses Critical Vulnerabilities, Bolsters Email Server Security
Frequently sought solutions for JavaScript

* bsc#1227399 Cross-References: * CVE-2024-34750

* bsc#1225771 Cross-References: * CVE-2024-5564

* bsc#1222665 * bsc#1227554 * bsc#1227560 Cross-References:

* bsc#1227554 * bsc#1227560 * bsc#1227561 * bsc#1227562 * bsc#1227563

Theia IDE: Eclipse’s answer to Visual Studio Code
Craig Wright admits he isn’t the inventor of Bitcoin after High Court judgment in UK

This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732

This update fixes CVE-2024-24791

Iran’s MuddyWater phishes Israeli orgs with custom BugSleep backdoor
Microsoft pushes .NET 9 Preview 6 with a range of improvements

https://security-tracker.debian.org/tracker/DSA-5730-1

OpenJDK plan calls for restricting JNI usage
Scattered Spider’s fave new ransomware tools are RansomHub and Qilin
Hello, is it me you’re looking for? How scammers get your phone number

Your humble phone number is more valuable than you may think. Here’s how it could fall into the wrong hands – and how you can help keep it out of the reach of fraudsters.

Exploring Linux 6.10: Guide to Key Security Enhancements & Updates for Admins
The AI Fix #7: Can AI speak dolphin and do robots lick toads?
Don’t be complacent on cybersecurity resilience
Securing IT Assets: Practical Strategies for Linux Admins & IT Teams

Several security issues were fixed in the Linux kernel.

* bsc#1220145 * bsc#1223363 * bsc#1223681 * bsc#1223683

How to Secure Your Data Warehouse in a Linux System
Privacy group complains to UK regulator about Meta scraping user data to train AI

Several security issues were fixed in the Linux kernel.

An update that fixes three vulnerabilities is now available.

Several security issues were fixed in the Linux kernel.

What senior developers do
Learning cloud cost management the hard way

* bsc#1215420 * bsc#1220833 * bsc#1221656 * bsc#1221659 * bsc#1222005

How to master multi-tenant data management
DarkGate, the Swiss Army knife of malware, sees boom after rival Qbot crushed
Kaspersky culls staff, closes doors in US amid Biden’s ban
Disney hacked? NullBulge claims to have stolen 1.1 TB of data from internal Slack channels
ZDI shames Microsoft for – yet another – coordinated vulnerability disclosure snafu
Infoseccers claim Squarespace migration linked to DNS hijackings at Web3 firms

* bsc#1221530 Cross-References: * CVE-2024-21503

* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828

7 reasons analytics and ML fail to meet business objectives

* bsc#1224122 * bsc#1226136 Cross-References: * CVE-2024-24786

Are we thinking too small about generative AI?
How to choose the right database for your application
Google reportedly in talks to buy infosec outfit Wiz for $23 billion
I spy another mSpy breach: Millions more stalkerware buyers exposed
UK cyber-boss slams China’s bug-hoarding laws
Should ransomware payments be banned? – Week in security with Tony Anscombe

The issue of whether to ban ransomware payments is a hotly debated topic in cybersecurity and policy circles. What are the implications of outlawing these payments, and would the ban be effective?

Vanilla upstream kernel version 6.6.37 fix bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33374

Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack. (CVE-2024-37894) References:

This vulnerability allows an attacker performing a meddler-in-the-middle attack between Palo Alto Networks PAN-OS firewall and a RADIUS server to bypass authentication and escalate privileges to ¢”superuser¢” when RADIUS authentication is in use and either CHAP or PAP is selected in the RADIUS server profile.

Beyond the usual suspects: 5 fresh data science tools to try today

* bsc#1216377 Cross-References: * CVE-2023-45803

* bsc#1189936 * bsc#1190531 * bsc#935380 Cross-References:

Three words to send a chill down your spine: Snowflake. Intrusion. Alert
Red Hat VEX files for CVEs are now generally available

Upstream kernel version 6.6.37 fix bugs and vulnerabilities. The dwarves, kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.

This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732