No Image

USN-5107-1: Firefox vulnerabilities

2021-10-07 KENNETH 0

USN-5107-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof another origin, or execute arbitrary code. Source: USN-5107-1: Firefox vulnerabilities

No Image

Defining a Modern App

2021-10-07 KENNETH 0

Defining a Modern App Developers, architects, and DevOps engineers are no longer satisfied with the status quo when it comes to designing and building applications. We know this because we talk to them all the time. They’re tired of the challenges in porting applications from one cloud to another. They’ve experienced the intense pressure of spinning up additional compute infrastructure quickly to meet unexpected demand. They’ve struggled to put the right assets in place after suffering a major failure or outage. Basically, they are tired of the stress and hassles of legacy application architectures. What we’ve heard over and over again from customers and community members is that they want to build “modern apps.” The term is broad enough to mean different things to different people, so we asked our Dev and DevOps colleagues what a modern app means to [ more… ]

No Image

USN-5106-1: Linux kernel (OEM) vulnerabilities

2021-10-07 KENNETH 0

USN-5106-1: Linux kernel (OEM) vulnerabilities Valentina Palmiotti discovered that the io_uring subsystem in the Linux kernel could be coerced to free adjacent memory. A local attacker could use this to execute arbitrary code. (CVE-2021-41073) It was discovered that the Linux kernel did not properly enforce certain types of entries in the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. An attacker could use this to bypass UEFI Secure Boot restrictions. (CVE-2020-26541) It was discovered that the KVM hypervisor implementation in the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. An attacker who could start and control a VM could possibly use this to expose sensitive information or execute arbitrary code. (CVE-2021-22543) Murray McAllister discovered that the joystick device interface in the Linux kernel did not properly validate data passed via an [ more… ]

No Image

USN-5105-1: Bottle vulnerability

2021-10-07 KENNETH 0

USN-5105-1: Bottle vulnerability It was discovered that Bottle incorrectly handled certain inputs. An attacker could possibly use this issue to cache malicious requests. Source: USN-5105-1: Bottle vulnerability

Windows 11 blossoms with ‘Bloom’ – a new symbol for a new operating system

2021-10-07 KENNETH 0

Windows 11 blossoms with ‘Bloom’ – a new symbol for a new operating system With Windows 11, a fresh perspective starts with the very first image you see on the screen: a desktop wallpaper that’s also a symbolic image of starting anew with this operating system. Inspired by flowers, this new blue beauty is called Bloom. The story of its creation spans a creative and dynamic collaboration between engineering, design and marketing teams at Microsoft, across an ocean during a pandemic and which incorporated a parallel workflow that caught the eye of Windows 11 designers. “It’s the same Windows that you know and love, but this is a new beginning, a new era,” says Christina Koehn, creative director for Windows 11, which became available Oct. 5. This new era comes with intuitive navigation, easy organization, more apps and efficient ways [ more… ]