Security Leftovers
-
Notorious Downfall & Inception Microcode Info Disclosure Vulns Fixed
Multiple significant microcode security issues have been discovered. An information exposure bug known as Downfall ( CVE-2022-40982 ) has been found in some Intel(R) Processors, as well as a side channel vulnerability in some AMD CPUs known as Inception ( CVE-2023-20569 ) that may allow an attacker to influence the return address prediction, potentially resulting in speculative execution at an attacker-controlled address.
-
Freexian Collaborators: Monthly report about Debian Long Term Support, July 2023 (by Santiago Ruano Rincón)
Like each month, have a look at the work funded by Freexian’s Debian LTS offering.
-
Bank of Ireland glitch led to police being sent to some ATMs - BBC News
The glitch allowed people with withdraw large sums despite having little or no money in their accounts.
-
New reports show phishing is on the rise – and getting more sophisticated
Two new reports on phishing trends show a rise in attacks, and they’re taking more complex paths through the internet to connect victims with malware-laced websites.
-
Hacker Forum Credentials Found on 120,000 PCs Infected With Info-Stealer Malware
Hudson Rock security researchers have identified credentials for hacker forums on roughly 120,000 computers infected with information stealers.
-
Discord.io suffers data breach with 760,000+ users’ info stolen
Discord.io, a third-party site that allows users to create custom server invites for the instant messaging and voice app Discord Inc., has been taken offline after a data breach led to the exposure of the information of more than 760,000 users. The breach took place Monday night and Discord.io was taken offline shortly thereafter.
-
The Cyber Resilience Act. What's so bad about it
We need to start talking about the Cyber Resilience Act, because according to all major Open Source organizations the CRA is a threat to Free Software itself, and it has been approved by the European Committee that was working on it.
This, is going to be a complex story of laws and burocracy, and even though it might seem like Europe accidentally hurted Open Source whilst doing an otherwise great bill... this is very much intentional.
-
2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability
A threat actor has exploited a recent Citrix vulnerability (CVE-2023-3519) to infect roughly 2,000 NetScaler instances with a backdoor.
-
Hackers target Citrix NetScaler vulnerabilities to gain persistent access
A new report released today by Fox-IT, part of NCC Group PLC, has detailed how about 2,000 Citrix NetScalers have been exploited by a threat actor to gain persistent access. Citrix NetScaler is an application delivery controller and load-balancing solution offered by Citrix Systems Inc.
-
1.5 Million Impacted by Ransomware Attack at Canadian Dental Service
The personal information of 1.5 million individuals was compromised in a ransomware attack at Alberta Dental Service Corporation (ADSC).
-
MOVEit Vulnerability Yields Another 4 Million Breached Records [Ed: Windows TCO]
A zero-day security vulnerability in the MOVEit file transfer software discovered in late spring has been wreaking havoc across American companies this summer. The latest victims are people signed up for Colorado’s version of Medicaid, who had their data compromised when cybercriminals used the flaw to access their data in the IBM Cloud.