Security Leftovers
-
Apple Patches Another Kernel Flaw Exploited in ‘Operation Triangulation’ Attacks
Apple patched another zero-day flaw used in the 'Operation Triangulation' exploit chain. iOS and macOS-powered devices are affected.
-
Apple issues slew of fixes for macOS Ventura, iPadOS and iOS [Ed: Apple works for the NSA. Security is not the goal, remote access is.]
"Apple has also issued fixes for CVE-2023-37450, a separate zero-day vulnerability that was first patched as part of Apple's Rapid Security Response update process.
-
Ivanti blocks access to zero-day advisory, then reverses policy
US-based endpoint software management firm Ivanti initially blocked access to a security advisory about an exploitable zero-day in its Endpoint Manager Mobile software, formerly known as MobileIron Core.
-
XSAs released on 2023-07-24
The Xen Project has released one or more Xen security advisories (XSAs).
-
Who and What is Behind the Malware Proxy Service SocksEscort?
Researchers this month uncovered a two-year-old Linux-based remote access trojan dubbed AVrecon that enslaves Internet routers into botnet that bilks online advertisers and performs password-spraying attacks. Now new findings reveal that AVrecon is the malware engine behind a 12-year-old service called SocksEscort, which rents hacked residential and small business devices to cybercriminals looking to hide their true location online.