Security Leftovers
-
iTWire - Medibank data linked off same forum on which Optus data was leaked
Ransomware generally attacks only systems running Microsoft's Windows operating system.
-
CISA Has Added One Known Exploited Vulnerability to Catalog [Ed: Such a generic headline. This is 100% about Microsoft and 100% about Windows.]
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. This type of vulnerability is a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise. Note: To view the newly added vulnerabilities in the catalog, click on the arrow in the "Date Added to Catalog" column, which will sort by descending dates.
-
Critical Local Privilege Escalation Vulnerability in Linux kernel. Patch immediately
The local privilege escalation vulnerability in the Linux Kernel was reported by Redhat, and its CVE code is 2022-3977. The problem is that the most recent Linux kernel upstream contains a use-after-free vulnerability called mctp sk unhash that may be exploited to elevate privileges to root. When a program tries to utilize memory that has been released or no longer assigned to it after it has been given to another application, it is known as a use-after-free vulnerability. In cyber attack situations, this might result in arbitrary code execution or provide an attacker access to remote code execution capabilities. It can also cause crashes and unintentional data overwriting.