Security Leftovers
-
Security Week ☛ Google Sees Drop in Memory Safety Bugs in Android as Code Matures
Memory safety bugs in Android have decreased significantly as old code matures and new code uses memory-safe languages.
-
LWN ☛ Eliminating Memory Safety Vulnerabilities at the Source (Google Security Blog)
Here's a
post on the Surveillance Giant Google Security Blog on how switching to a memory-safe
language can quickly reduce vulnerabilities in a project, even if a large
body of older code persists.
-
LWN ☛ Security updates for Thursday
Security updates have been issued by AlmaLinux (container-tools:rhel8, dovecot, emacs, expat, git-lfs, go-toolset:rhel8, golang, grafana, grafana-pcp, gtk3, kernel, kernel-rt, nano, python3, python3.11, python3.12, and virt:rhel and virt-devel:rhel), Debian (mediawiki and puredata), Fedora (chisel), Mageia (glib2.0, gtk+2.0 and gtk+3.0, and python-astropy), Red Hat (git-lfs, grafana, grafana-pcp, kernel, and kernel-rt), SUSE (kubernetes1.24, kubernetes1.25, kubernetes1.26, kubernetes1.27, kubernetes1.28, opensc, and python36), and Ubuntu (apparmor, apr, ca-certificates, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-raspi, openjpeg2, ruby-rack, and tomcat8, tomcat9).
-
Silicon Angle ☛ Critical flaws in Kia’s remote system could have allowed hackers to control vehicles
Connected vehicles continue to increase in popularity with features such as remote access and start, but what if a hacker could access those same features to gain access to a car?
-
Michigan Medicine notifies patients of health information breach
Michigan Medicine is notifying approximately 57,891 individuals about an employee email account that was compromised, potentially exposing some patient health information.
-
Security Week ☛ US Transportation and Logistics Firms Targeted With Infostealers, Backdoors
A malicious campaign is targeting transportation and logistics organizations in North America with various malware families.
-
Pen Test Partners ☛ Direct Memory Access (DMA) attacks. Risks, techniques, and mitigations in hardware hacking
TL;DR Direct Memory Access (DMA) attacks are a powerful class of attack that give read and write access to the memory of a target system [...]
-
Security Week ☛ Israeli Group Claims Lebanon Water Hack as CISA Reiterates Warning on Simple ICS Attacks
Unsophisticated methods can still be used to hack ICS/OT — even so, many cyberattack claims are likely exaggerated.
-
Security Week ☛ Police Are Probing a Cyberattack on Wi-Fi Networks at UK Train Stations
An investigation has been launched into a Wi-Fi service hack that has impacted many train stations in the United Kingdom.
-
Security Week ☛ Cisco Patches High-Severity Vulnerabilities in IOS Software
Cisco has released patches for seven high-severity vulnerabilities affecting products running IOS and IOS XE software.
-
Security Week ☛ X Releases Its First Transparency Report Since Elon Musk’s Takeover
Social media platform X published its first transparency report since the company was purchased by Elon Musk.
-
Security Week ☛ Critical Nvidia Container Flaw Exposes Cloud Hey Hi (AI) Systems to Host Takeover
Nvidia confirms risk of code execution, denial of service, escalation of privileges, information disclosure, and data tampering. CVSS 9/10.
-
Security Week ☛ Remote Code Execution, DoS Vulnerabilities Patched in OpenPLC
Critical and high-severity vulnerabilities that can be exploited for DoS attacks and remote code execution have been patched in OpenPLC.