Security Leftovers
-
Security updates for Monday [LWN.net]
Security updates have been issued by Debian (expat and poppler), Fedora (dokuwiki), Gentoo (fetchmail, grub, harfbuzz, libaacplus, logcheck, mrxvt, oracle jdk/jre, rizin, smarty, and smokeping), Mageia (tcpreplay, thunderbird, and webkit2), SUSE (dpdk, permissions, postgresql14, puppet, and webkit2gtk3), and Ubuntu (linux-gkeop and sosreport).
-
Vultron: A Protocol for Coordinated Vulnerability Disclosure
Coordinated vulnerability disclosure (CVD) begins when at least one individual becomes aware of a vulnerability. It can’t proceed, however, without the cooperation of many. Software supply chains, software libraries, and component vulnerabilities have evolved in complexity and have become as much a part of the CVD process as vulnerabilities in vendors’ proprietary code. Many CVD cases now require coordination across multiple vendors. This post, which is based on a recently published special report, introduces Vultron, a protocol for multi-party coordinated vulnerability disclosure (MPCVD).
-
Google, Microsoft can get your passwords via web browser's spellcheck
Extended spellcheck features in Google Chrome and Microsoft Edge web browsers transmit form data, including personally identifiable information (PII) and in some cases, passwords, to Google and Microsoft respectively.
-
Leaking Passwords through the Spellchecker
The solution is to only use the spellchecker options that keep the data on your computer—and don’t send it into the cloud...
-
iTWire - Optus attacker exposes data of 10k, threatens to reveal more
The individual who claims to have breached Optus has released 10,000 address records and says a similar number will be made public each day for the next four days.
Security researcher Brett Callow of New Zealand-based Emsisoft posted the information in a tweet.
The threat by the attacker comes a day after Home Affairs Minister Clare O'Neil sharply criticised Optus for its inability to stop what she described as "a basic hack".