Security Leftovers
-
Critical Windows code-execution vulnerability went undetected until now | Ars Technica
Microsoft elevates security rating for vulnerability resembling EternalBlue.
-
SFP#18: IT-Security from a cryptographer's point of view with Cryptie
A cryptographer and privacy specialist Amandine Jambert, a.k.a. Cryptie, is our guest in the 18th Software Freedom Podcast episode. With her experience, Cryptie is the perfect person to tackle some basics about Security in Free Software.
Cryptie has been involved with Free Software for around 20 years now and has been a volunteer for the FSFE for 10 years. Together Cryptie and Bonnie Mehring discuss the basics of cryptography and discover what a privacy specialist is. They then move on to the basics of IT-Security and talk about prejudices against the security of Free Software. If you have wondered what is needed to make Software more secure this is the perfect episode for you to start with this topic and learn about the basics of IT-Security.
-
Running in Place: Staying Afloat With Language-Level Vulnerability Management - CPO Magazine
The patch management process can be painful, tedious, and time and labor intensive. Often, all this effort is for no other purpose than to maintain the operational status quo. And for devs or sysadmins, patch management has to happen on top of handling every-day activities as well as any other additional challenges that occur during service interruptions or system reboots.
-
New DDoS Botnet Malware Infecting Windows, Linux, and IoT Devices [Ed: Citing Microsoft as authority on security while it puts back doors in its very own products is ludicrous; this is Microsoft badmouthing "Linux" or concern-trolling for PR]
A cross-platform botnet, ‘MCCrash’ that starts out from malicious software downloads on Windows devices and spreads to a range of Linux-based devices was recently examined by the Microsoft Defender for IoT research team.
-
Changes/XServerProhibitsByteSwappedClients - Fedora Project Wiki
X server implementations (e.g. Xorg and Xwayland) will (by default) no longer allow clients with different endianess to connect.