Security Leftovers
-
LinuxSecurity ☛ RunC Container Escape Flaws Grant Attackers Host Access
A series of severe security vulnerabilities have been discovered in the popular runC command line tool. These vulnerabilities, collectively known as Leaky Vessels, allow threat actors to break out of containers and gain unauthorized access to the host operating system.
-
Data Breaches ☛ Updating: Prince George’s County Public Schools breach affected almost 100,000
In August 2023, Prince George’s County Public Schools disclosed a cyberattack. At the time, they reported that “an estimated 4,500 user accounts out of 180,000 were impacted, primarily staff accounts. The school system is still assessing the full scope of this incident, but as of this time, the main business and student information systems – Oracle and SchoolMAX – do not appear to be impacted by this event.”
In November, the Rhysida ransomware group claimed responsibility for the attack and put the data up for sale. They would later update the listing to leak data that they did not sell (whether they ever really sold any of the data is unknown to DataBreaches).
-
Open Source Security (Audio Show) ☛ Josh Bressers: Episode 416 – Thomas Depierre on open source in Europe
Josh and Kurt talk to Thomas Depierre about some of the European efforts to secure software. We touch on the CRA, MDA, FOSDEM, and more. As expected Thomas drops a huge amount of knowledge on what’s happening in open source. We close the show with a lot of ideas around how to move the needle for open source. It’s not easy, but it is possible.