ShadowSyndicate Investigation Reveals RaaS Ties

Read Time:4 Second

The investigation was conducted by Group-IB, Bridewell and threat researcher Michael Koczwara

Read More

xen-4.17.2-2.fc39

Read Time:17 Second

FEDORA-2023-35d2ad2328

Packages in this update:

xen-4.17.2-2.fc39

Update description:

arm32: The cache may not be properly cleaned/invalidated [XSA-437,
CVE-2023-34321]
top-level shadow reference dropped too early for 64-bit PV guests
[XSA-438, CVE-2023-34322]
x86/AMD: Divide speculative information leak [XSA-439, CVE-2023-20588]

Read More

USN-6396-1: Linux kernel vulnerabilities

Read Time:1 Minute, 18 Second

It was discovered that some AMD x86-64 processors with SMT enabled could
speculatively execute instructions using a return address from a sibling
thread. A local attacker could possibly use this to expose sensitive
information. (CVE-2022-27672)

Daniel Moghimi discovered that some Intel(R) Processors did not properly
clear microarchitectural state after speculative execution of various
instructions. A local unprivileged user could use this to obtain to
sensitive information. (CVE-2022-40982)

Yang Lan discovered that the GFS2 file system implementation in the Linux
kernel could attempt to dereference a null pointer in some situations. An
attacker could use this to construct a malicious GFS2 image that, when
mounted and operated on, could cause a denial of service (system crash).
(CVE-2023-3212)

It was discovered that the NFC implementation in the Linux kernel contained
a use-after-free vulnerability when performing peer-to-peer communication
in certain conditions. A privileged attacker could use this to cause a
denial of service (system crash) or possibly expose sensitive information
(kernel memory). (CVE-2023-3863)

It was discovered that the bluetooth subsystem in the Linux kernel did not
properly handle L2CAP socket release, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2023-40283)

It was discovered that some network classifier implementations in the Linux
kernel contained use-after-free vulnerabilities. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2023-4128)

Read More

Could ChatGPTChat GPT Be The Best Thing That’s Ever Happened To Your Family?

Read Time:5 Minute, 22 Second

I have a confession to make – I so wish ChatGPT was around when my kids were younger. I realise that it’s not perfect but in my opinion, it’s like having a personal digital assistant to help you wade through those super heavy parenting years. Imagine how helpful it would be to have your ‘assistant’ develop a personalised bedtime story for your 6-year-old or, work out what you can cook with just the ingredients in your fridge!! I am so sure I would have been a more relaxed mother if I had ChatGPT working for me!!

How Does ChatGPT Work?

ChatGPT is an amazing website that allows you to have human-like conversations with a chatbot that is driven by Artificial Intelligence (AI) technology. The chatbot can answer your questions, compose emails and essays, translate text, develop code and more. At the time of writing, there is a free version of ChatGPT available which gives the user unlimited access however the paid premium version of $US20 per month gives priority access during peak times, faster response speeds and exclusive access to GPT-4 – a smarter and more capable chatbot!

If you’d like to know more about it, check out my Parents’ ChatGPT Guide which will help fill in the blanks.

How ChatGPT Can Make You A Better Parent

There are so many ways ChatGPT can reduce the stress of parenting and give you some much-needed head space. Here are my top 5:

1. What’s For Dinner?

If I look back at the super intense parenting years when I was working full-time with 4 kids, one of the greatest causes of my stress was dinner. I often wouldn’t have the physical energy to read a recipe book or stop at the shops after an afternoon of school and extra-curricular pickups so I would be scrambling to feed a bunch of ravenous boys. Imagine how good it would be to have your digital assistant, aka ChatGPT, devise a recipe based on what you have in your fridge and pantry? Nothing short of life-changing, in my opinion. And it can even factor in dietary restrictions! So clever!!

2. Can You Tell Me A Bedtime Story

My boys loved bedtime stories – preferably personalised! I know, very demanding!! Now, with 4 separate stories to deliver every night, you can only imagine how much mental energy this required. But if I had ChatGPT working for me, this would take just seconds to solve. Simply enter the name and age of the child (no surnames), the setting, the names of other characters that should be included, and then a theme e.g. hero’s journey, determination, friendship, and wham bam – you’ve got something ready to go!

3. Your Next Holiday – Sorted!

When things are so hectic, it is often the thought of a vacation that can keep you going. However, let’s be honest, successful holidays take quite a bit of planning to get right. Well – that’s where your digital assistant can help. If you ask, ChatGPT can develop itineraries with activity suggestions. It can also recommend hotels – simply ask it for suggestions within a specific location e.g. close to the Eiffel Tower. And it can also tailor its recommendations based on your budget. After planning and managing family holidays for my clan of 6 for well over 20 years, this is a life-changing feature!

4. The Best Birthday Party Checklist Ever

Far out, birthday parties can be stressful experiences. Invitations, themes, venue, entertainment, kids’ food, lolly bags, parents’ food, parents’ drinks, the list goes on and on. But if you haven’t already put ChatGPT to work as a party planner – then you’re missing out. Simply type in the age of the child and it can give you an entire plan. It will also give you 20-25 top tips that I guarantee will ensure you have everything covered!

5. Homework Help

If you’ve got a tribe of kids who are all at various levels and need homework help, then staying up to date with maths and science can be quite exhausting – particularly after a long day at work! Simply entering ‘explain’ or ‘explain so a 10-year-old can understand’ into ChatGPT will provide you with enough smarts to get that homework done. Of course, fact-checking ChatGPT is essential but what it will provide is some momentum in the right direction.

But A Word of Caution

ChatGPT can absolutely make your life easier as a parent but there are a few things to remember before you start typing into that chat box.

1. It Doesn’t Always Get Everything Right

It’s important to double-check everything. Ensure your kids also appreciate that everything online needs to be double-checked.

2. Be Mindful of Your Privacy When Using It

For a full explanation of its impact on privacy and how you can protect yourself, check out my recent blog post about . But to summarise: be careful what you share in the chat box, stay anonymous, and consider deleting your chat history.

3. Consider How You Use It With Your Kids

One of the biggest negatives of ChatGPT is its potential impact on creativity and thinking skills. Some schools and universities have banned its use while others have specialised programs that supposedly can detect whether a student has used it. While it does sadden me that our kids won’t need to struggle over complex maths questions or English essays like we did, I am a realist and believe that whether we like it or not – it is here to stay. My prediction is that the school and university systems will adapt because generative AI will be a part of our kids’ world. Our role as parents and educators is to teach them how to use it safely and with a critical-thinking mindset.

So, if you’ve dreamed about hiring a personal assistant (I do regularly!) then you so need to check out ChatGPT. It will help you get through your ‘to-do’ list, save you so much time and energy which means you’ve got more time to spend with your kids – or by yourself under a tree. You choose!!

Till Next Time

Stay Safe Online

Alex

The post Could ChatGPTChat GPT Be The Best Thing That’s Ever Happened To Your Family? appeared first on McAfee Blog.

Read More

USN-6361-2: CUPS vulnerability

Read Time:15 Second

USN-6361-1 fixed a vulnerability in CUPS. This update provides the
corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.

Original advisory details:

It was discovered that CUPS incorrectly authenticated certain remote
requests. A remote attacker could possibly use this issue to obtain
recently printed documents.

Read More

golang-github-cncf-xds-0-0.10.20230912gite9ce688.fc38 golang-github-envoyproxy-control-plane-0.11.1-1.fc38 golang-github-hashicorp-msgpack-2.1.0-1.fc38 golang-github-minio-highwayhash-1.0.2-2.fc38 golang-github-nats-io-1.30.1-3.fc38 golang-github-nats-io-jwt-2-2.5.2-1.fc38 golang-github-nats-io-nkeys-0.4.5-2.fc38 golang-github-nats-io-streaming-server-0.25.5-1.fc38 golang-github-protobuf-1.5.3-3.fc38 golang-google-protobuf-1.31.0-4.fc38 nats-server-2.10.1-4.fc38

Read Time:36 Second

FEDORA-2023-f122ea1b3e

Packages in this update:

golang-github-cncf-xds-0-0.10.20230912gite9ce688.fc38
golang-github-envoyproxy-control-plane-0.11.1-1.fc38
golang-github-hashicorp-msgpack-2.1.0-1.fc38
golang-github-minio-highwayhash-1.0.2-2.fc38
golang-github-nats-io-1.30.1-3.fc38
golang-github-nats-io-jwt-2-2.5.2-1.fc38
golang-github-nats-io-nkeys-0.4.5-2.fc38
golang-github-nats-io-streaming-server-0.25.5-1.fc38
golang-github-protobuf-1.5.3-3.fc38
golang-google-protobuf-1.31.0-4.fc38
nats-server-2.10.1-4.fc38

Update description:

Contains updates to address CVE-2022-{28357,41717}

Read More

Signal Will Leave the UK Rather Than Add a Backdoor

Read Time:29 Second

Totally expected, but still good to hear:

Onstage at TechCrunch Disrupt 2023, Meredith Whittaker, the president of the Signal Foundation, which maintains the nonprofit Signal messaging app, reaffirmed that Signal would leave the U.K. if the country’s recently passed Online Safety Bill forced Signal to build “backdoors” into its end-to-end encryption.

“We would leave the U.K. or any jurisdiction if it came down to the choice between backdooring our encryption and betraying the people who count on us for privacy, or leaving,” Whittaker said. “And that’s never not true.”

Read More