Happy #PatchTuesday from Palo Alto Networks (LIKELY ZERO-DAYS):
(Note: PAN likes to downplay by showing the base + threat metrics CVSSv4 score)
Palo Alto Networks is not aware of any malicious exploitation of this issue.
My new concern is whether I should say #zeroday for CVE-2025-0110 and 0109. Based on the First criteria for Exploit Maturity:
```Based on threat intelligence sources each of the following must apply:
#paloaltonetworks #infosec #vulnerability #cve #cybersecurity #poc #proofofconcept
An international team of scientists announced Wed the detection of an extraordinary, elusive #neutrino ā a tiny, subatomic particle that flitted at close to the speed of light toward an undersea detector off the coast of Sicily carrying about 30k times the #energy generated by the largest particle accelerator on #earth.
ā©The observation, unveiled in the journal #Nature, revealed the highest-energy neutrino ever detected.
#astrophysics #science #cool
https://www.nature.com/articles/s41586-024-08543-1
From Convenience to Contagion: The Half-Day Threat and Libarchive Vulnerabilities Lurking in Windows 11 https://devco.re/blog/2025/02/12/from-convenience-to-contagion-the-half-day-threat-and-libarchive-vulnerabilities-lurking-in-windows-11-en/
Happy #PatchTuesday with GitLab: GitLab Patch Release: 17.8.2, 17.7.4, 17.6.5
8 CVEs (1 high severity, 7 medium). At a glance, no mention of exploitation.
As JD Vance delivered his speech about āEuropean overregulationā and criticized āendless compliance costs imposed on the US companies by GDPRā I have seen some voices from Europe who said something to the effect āI donāt know a single EU company happy about #GDPR eitherā.
Well, itās kind of obvious companies arenāt happy because GDPR was not made to make companies happy but to protect the privacy of consumers š
This regulation is based on fundamental differences between US and EU legal systems. In EU, you own and control your personal data. In US itās owned by whoever managed to extort it from you, and then aggregate, personalise and resell to any other entity anywhere.
For example, if you want to pay higher insurance premium because you have genetic tendencies to diabetes or obesity - well, thatās the US way of doing business, but itās not the only one, nor itās somehow axiomatically ābetterā. And yes, high insurance premiums also have the effect of increasing overall countryās GDP, just as a house burnt and rebuilt also does this magic, yet somehow few people celebrate it š
Then someone asked me if I really āfeel that my data is better protected thanks to GDPRā. And yes, as a matter of fact the most invasive behavioural profiling arenāt being rolled out by companies like Twitter or Facebook to EU specifically because of GDPR, while in US they just roll them out without asking anyone.
Anyone⦠of course except for the states which have regulations very similar or even more restrictive than GDPR, such as California. Yet, because California is ātheirā, these companies and their CEOs with high media presence simply shut up and make their apps compliant with CCPA without all this barking about āhow GDPR kills out businessā.
Itās the same with EU VAT, about which Vance also whined, whereas US sales tax accounting rules are not even harmonized across states. But hey, you know what? An US business that has to emply a tax consulting company to get multi-state accounting right also increases overall GDP! š
So effectively what in US is perceived as each stateās fundamental right, sign of their diversity and key part of their autonomy, in the EU is portrayed as something equivalent to Soviet Union style central planning. And when they post all the memes about ābottle capsā in EU, they of course never mention a gazillion of state-level archaic or absurd regulations which are nonetheless binding, especially if someone likes to build a class lawsuit around them.
And now as Tesla opened a new factory in #China, Iāve never seen Musk make a single critical remark about the overregulation in China, even though itās even more complex than EU and US taken together due to its vast geographic and administrative diversity.
The #MADWeb '25 program is live!
We've got 9 full papers, 3 work-in-progress papers, and 2 exciting keynotes lined up. Huge thanks to all the authors and the program committee!
Check out the details and get ready for a great event! š„
š https://madweb.work/#program
See you in San Diego!
Thanks @bagder for providing the Firefox ca bundle publicly in an accessible way here: https://curl.se/docs/caextract.html
Extra kudos for the appropriate curl command-line to automatically download the latest version!