Security Leftovers
-
SUSE Linux Enterprise and SBOM support
After recent supply chain attacks and with ever increasing security automation especially the software inventory management becomes more and more important. Governments and other regulated industries now require publishing a so called Software Bill Of Materials (SBOM) to software products.
-
SUSE’s Adaptable Linux Platform (ALP) Raises the Bar on Confidential Computing [Ed: This is not about security but about compelling everyone to outsource everything to surveillance giants under the false assumption/premise privacy can be preserved and lack of control is compatible with "confidentiality"]
SUSE has just released the third prototype of ALP, named “Piz Bernina” (the highest mountain in the Swiss Alps). The new prototype has a strong focus on security and demonstrates an innovative concept with confidential computing and a zero-trust approach.
-
UK Runs Fake DDoS-for-Hire Sites
Brian Krebs is reporting that the UK's National Crime Agency is setting up fake DDoS-for-hire sites as part of a sting operation: [...]
-
Elementor Pro Plugin Vulnerability Exploited to Hack WordPress Websites [Ed: Not a problem in WordPress; you can install all sorts of malware on top of it]
A severe vulnerability in the Elementor Pro WordPress plugin is being exploited to inject malware into vulnerable websites.
-
Microsoft OneNote Starts Blocking Dangerous File Extensions [Ed: Microsoft OneNote itself is dangerous]
Microsoft is boosting the security of OneNote users by blocking embedded files with extensions that are considered dangerous.
-
Western Digital Shuts Down Services Due to Cybersecurity Breach
Western Digital shuts down several of its services after discovering a network security breach.
-
4.8 Million Impacted by Data Breach at TMX Finance
Consumer loan provider TMX Finance is informing over 4.8 million individuals that their personal information was stolen in a data breach.
-
Europe, North America Most Impacted by 3CX Supply Chain Hack
Europe, the United States and Australia seem to be the most impacted by the 3CX supply chain hack, according to data from two cybersecurity firms.