Security Leftovers
-
Security updates for Monday [LWN.net]
Security updates have been issued by Debian (graphicsmagick and krb5), Fedora (dotnet6.0, js-jquery-ui, kubernetes, and xterm), Gentoo (php and postgresql), Mageia (php-pear-CAS, sysstat, varnish, vim, and x11-server), Red Hat (thunderbird), SUSE (389-ds, binutils, dpkg, firefox, frr, grub2, java-11-openjdk, java-17-openjdk, kernel, kubevirt stack, libpano, nodejs16, openjpeg, php7, php74, pixman, python-Twisted, python39, rubygem-loofah, sccache, sudo, thunderbird, tor, and tumbler), and Ubuntu (flac, git, linux-azure-fde, linux-gke, linux-gkeop, linux-raspi-5.4, linux-gcp, linux-gcp-4.15, and linux-gcp-5.15, linux-gke-5.15, linux-intel-iotg, linux-raspi).
-
The US Securing Open Source Software Act of 2022 is a step in the right direction - TechCrunch [Ed: False. Perforce seems to be promoting Microsoft's agenda here.]
Cybersecurity continues to be a hot topic. More and more organizations are getting hit by ransomware attacks, critical open software vulnerabilities are making news, and we’re seeing industries and governments coming together to discuss initiatives to improve software security.
-
Breaking the Zeppelin Ransomware Encryption Scheme [Ed: Microsoft Windows TCO]
A company offered recovery services based on this break, but was reluctant to advertise because it didn’t want Zeppelin’s creators to fix their encryption flaw.
-
Criminals 'follow the money' by commercialising cybercrime, launching more 'innovative' ransomware attacks and doubling down on credential theft: Sophos [iophk: Windows TCO]
According to Sophos the evolving economics of the underground has not only incentivised the growth of ransomware and the “as-a-service" industry, but also increased the demand for credential theft-andwith the expansion of web services, various types of credentials, especially cookies, can be used in numerous ways to gain a deeper foothold in networks, even bypassing MFA. Credential theft also remains one of the easiest ways for novice criminals to gain access to underground marketplaces and begin their “career.”