❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

The White Divide

By: mittens
24 June 2024 at 07:40
"Over the past 30 years, the American political landscape has been characterized by a growing divide between rural and urban voters, almost as if they're on two opposing teams [...] But the divide is confined largely to white Americans, Mettler and collaborators have found in an examination of the racial and ethnic facets of the trend." (The original study is behind a paywall, but the LSE had a write up as well.)

Python Developers Targeted Via Fake Crytic-Compilers Package

21 June 2024 at 03:00

As per recent reports, cybersecurity experts uncovered a troubling development on the Python Package Index (PyPI) – a platform used widely by developers to find and distribute Python packages. A malicious package named β€˜crytic-compilersβ€˜ was discovered, mimicking the legitimate β€˜crytic-compile’ library developed by Trail of Bits. This fraudulent package was designed with sinister intent: to […]

The post Python Developers Targeted Via Fake Crytic-Compilers Package appeared first on TuxCare.

The post Python Developers Targeted Via Fake Crytic-Compilers Package appeared first on Security Boulevard.

A Chemical-Sniffing Van Shows How Heat Amps Up Pollution

21 June 2024 at 10:44
In heat waves, chemicals like formaldehyde and ozone can form more readily in the air, according to researchers driving mobile labs in New York City this week.

Β© Blacki Migliozzi/The New York Times

Mobile labs that measure airborne pollutants drove around New York City and New Jersey during the recent heat wave.

The Unknown Toll Of The AI Takeover

20 June 2024 at 18:16
As artificial intelligence guzzles water supplies and jacks up consumers' electricity rates, why isn't anyone tracking the resources being consumed?

In early May, Google announced it would be adding artificial intelligence to its search engine. When the new feature rolled out, AI Overviews began offering summaries to the top of queries, whether you wanted them or not β€” and they came at an invisible cost. Investigative journalist Lois Parshley explores this topic for The Lever. Archive.org link.

A Tower Struck Down

20 June 2024 at 00:02
Somebody is having a very bad day! Fortunately, gelato has been saved.

Come for the picture of an infrastructure surprise, stay for the heartwarming gelato paragraphs. Transpower are working on it. Meanwhile, have some appropriate music. I'm being flippant but I am in the region affected by this; all is well here. Remember to check in on your neighbours!

"In front is a veranda, inside is the lobby, and upstairs, baby..."

By: box
8 June 2024 at 16:08
The Oklahoma City Council (NPR) voted this week (NYT gift) to clear the way for the 1,907 foot (Popular Science) Legends Tower (Master Design Statement .pdf), which would be the tallest building in the US. It may be 'impropable' (Architectural Record), a 'PR stunt' (NPR station KOSU), or even 'sheer fantasy' (OKC Free Press), especially (The Oklahoman) in a state that has seen 103 tornadoes (National Weather Service) in 2024. It would definitely be expensive--developers (developers' site) say they have $1b in financing lined up.

Cancer Researchers Begin Large Long-Term Study of Black Women

7 June 2024 at 05:06
The American Cancer Society hopes to enroll 100,000 women and follow them for three decades to discover what’s causing higher case and death rates.

Β© Travis Dove for The Washington Post, via Getty Images

Participants in the study will be surveyed about their behaviors, environmental exposures and life experiences.

The Algebra Problem: How Middle School Math Became a National β€˜Flashpoint’

22 May 2024 at 11:35
Top students can benefit greatly by being offered the subject early. But many districts offer few Black and Latino eighth graders a chance to study it.

Β© Andrew Mangum for The New York Times

How to make algebra more equitable is a puzzle districts across the country have struggled to solve.

Ed Dwight Goes to Space 63 Years After Training as 1st Black Astronaut

19 May 2024 at 18:34
Edward Dwight was among the first pilots that the United States was training to send to space in 1961, but he was passed over. On Sunday, he finally made it on a Blue Origin flight.

Β© Blue Origin, via Agence France-Presse β€” Getty Images

Edward Dwight was one of six people who went to space aboard the Mission NS-25 crew capsule from Blue Origin on Sunday. Upon exiting, he raised his arm and said, β€œLong time coming.”

Nancy Neveloff Dubler, Mediator for Life’s Final Moments, Dies at 82

10 May 2024 at 21:45
A bioethicist, she pioneered bedside methods for helping patients, their families and doctors deal with anguishing life-and-death decisions in a high-tech age.

Β© James Estrin/The New York Times

Nancy Dubler, director of the bioethics division at Montefiore Medical Center in the Bronx, spoke in 2005 with Fred Haber, who was at his wife’s bedside after a mediation session.

Herbert Pardes, Who Steered the Growth of a Giant Hospital, Dies at 89

9 May 2024 at 14:56
A psychiatrist, he ran New York-Presbyterian after a landmark merger, improving its patient care and finances and raising money to expand its footprint across the region.

Β© Marilynn K. Yee/The New York Times

Dr. Herbert Pardes in 2003 as president and chief executive of NewYork-Presbyterian Hospital. He ran its sprawling domain for 11 years.

Widening Racial Disparities Underlie Rise in Child Deaths in the U.S.

4 May 2024 at 15:30
New research finds that the death rate among Black youths soared by 37 percent, and among Native American youths by 22 percent, between 2014 and 2020, compared with less than 5 percent for white youths.

Β© Carolyn Kaster/Associated Press

Flowers for Karon Blake, 13, who was shot and killed in Washington, D.C., in January 2023. Gun-related deaths were two to four times higher among Black and Native American youth than among white youth.

Racist AI Deepfake of Baltimore Principal Leads to Arrest

26 April 2024 at 14:41
A high school athletic director in the Baltimore area was arrested after he used A.I., the police said, to make a racist and antisemitic audio clip.

Β© Kim Hairston/The Baltimore Sun

Myriam Rogers, superintendent of Baltimore County Public Schools, speaking about the arrest of Dazhon Darien, the athletic director of Pikesville High.

Update now! JetBrains TeamCity vulnerability abused at scale

8 March 2024 at 07:08

JetBrains issued a warning on March 4, 2024 about two serious vulnerabilities in TeamCity server. The flaws can be used by a remote, unauthenticated attacker with HTTP(S) access to a TeamCity on-premises server to bypass authentication checks and gain administrative control of the TeamCity server.

TeamCity is a build management and continuous integration and deployment server from JetBrains that allows developers to commit code changes into a shared repository several times a day. Each commit is followed by an automated build to ensure that the new changes integrate well into the existing code base and as such can be used to detect problems early.

Compromising a TeamCity server allows an attacker full control over all TeamCity projects, builds, agents and artifacts. Which, depending on the use-case of your projects, could make for a suitable attack vector leading to a supply chain attack.

The two vulnerabilities are CVE-2024-27198, an authentication bypass vulnerability with a CVSS score of 9.8, and CVE-2024-27199, a path traversal issue with a CVSS score of 7.3. The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-27198 to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. This means that Federal Civilian Executive Branch (FCEB) agencies need to remediate this vulnerability by March 28, 2024 in order to protect their devices against active threats.

These two vulnerabilities allow an attacker to create new administrator accounts on the TeamCity server which have full control over all TeamCity projects, builds, agents and artifacts.

Exploitation code is readily available online and has already been integrated in offensive security tools like the MetaSploit framework.

So, it doesn’t come as a surprise that researchers are now reporting abuse of the vulnerabilities.

Bleeping Computer reports that attackers have already compromised more than 1,440 instances, while a scan for vulnerable instances by Shadowserver showed that the US and Germany are the most affected countries.

If running JetBrains TeamCity on-prem – make sure to patch for latest CVE-2024-27198 (remote auth bypass) & CVE-2024-27199 vulns NOW!

We started seeing exploitation activity for CVE-2024-27198 around Mar 4th 22:00 UTC. 16 IPs seen scanning so far.https://t.co/zZ0iU5MD8S

β€” Shadowserver (@Shadowserver) March 5, 2024

The vulnerabilities affect all TeamCity on-premises versions through 2023.11.3 and were fixed in version 2023.11.4. Customers of TeamCity Cloud have already had their servers patched, and according to JetBrains they weren’t attacked.

To update your server,Β download the latest versionΒ (2023.11.4) or use theΒ automatic updateΒ option within TeamCity.Β 

JetBrains has also made a security patch plugin available for customers who are unable to upgrade to version 2023.11.4. There are two security patch plugins, one forΒ TeamCity 2018.2 and newerΒ and one forΒ TeamCity 2018.1 and older. See theΒ TeamCity plugin installation instructionsΒ for information on installing the plugin.

If your server is publicly accessible over the internet, and you are unable to immediately mitigate the issue you should probably make your server inaccessible until you can.


We don’t just report on vulnerabilitiesβ€”we identify them, and prioritize action.

Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in tow by usingΒ ThreatDown Vulnerability and Patch Management.

❌
❌