Security and Windows TCO Leftovers
-
Trail of Bits ☛ A few notes on proprietary trap AWS Nitro Enclaves: Attack surface
In the race to secure cloud applications, proprietary trap AWS Nitro Enclaves have emerged as a powerful tool for isolating sensitive workloads. But with great power comes great responsibility—and potential security pitfalls.
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by Gentoo (GCC, Hunspell, Tor, and ZNC), SUSE (apr-devel, cargo-c, chromedriver, firefox, kernel, libecpg6, libmfx, onefetch, postgresql12, postgresql13, postgresql14, postgresql15, postgresql16, python310-azure-identity, python39, qemu, rage-encryption, stgit, and system-user-zabbix), and Ubuntu (kernel, linux-ibm-5.15, linux-oracle-5.15, linux-xilinx-zynqmp, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-raspi, and py7zr).
-
Security Week ☛ AI-Generated Malware Found in the Wild
HP has intercepted an email campaign comprising a standard malware payload delivered by an AI-generated dropper.
-
XSAs released on 2024-09-24
The Xen Project has released one or more Xen security advisories (XSAs).
-
SANS ☛ Exploitation of RAISECOM Gateway Devices Vulnerability CVE-2024-7120, (Tue, Sep 24th)
Late in July, a researcher using the alias "NETSECFISH" published a blog post revealing a vulnerability in RASIECOM gateway devices.
-
Windows TCO
-
Security Week ☛ CrowdStrike Overhauls Testing and Rollout Procedures to Avoid System Crashes
CrowdStrike says it has revamped several testing, validation, and update rollout processes to prevent a repeat of the July BSOD incident.
-
Scoop News Group ☛ CrowdStrike exec apologizes in front of Congress over huge global IT outage
House lawmakers struck a sympathetic tone toward the company at a hearing where they nevertheless said nothing like that could happen again.
-