Security Leftovers
-
NVISO Labs ☛ TLPT & ME: Everything you need to know about Threat-Led Penetration Testing (TLPT) in a TIBER world.
-
Pen Test Partners ☛ BEC-ware the Phish (part 2): Respond and Remediate Incidents in M365
TL;DR Ensure you can reliably take initial containment actions such as disabling accounts, resetting passwords, and revoking tokens.
-
Diffoscope ☛ Reproducible Builds (diffoscope): diffoscope 283 released
The diffoscope maintainers are pleased to announce the release of diffoscope version
283
. This version includes the following changes: [...] -
Debian Family
-
Freexian Collaborators: Debian Contributions: October’s report (by Anupa Ann Joseph)
rebootstrap, by Helmut Grohne
After significant changes earlier this year, the state of architecture cross bootstrap is normalizing again. More and more architectures manage to complete rebootstrap testing successfully again. Here are two examples of what kind of issues the bootstrap testing identifies.
At some point,
libpng1.6
would fail to cross build onmusl
architectures whereas it would succeed on other ones failing to locatezlib
. Adding--debug-find
to thecmake
invocation eventually revealed that it would fail to search in/usr/lib/<triplet>
, which is the default library path. This turned out to be a bug in cmake assuming that all linux systems use glibc.libpng1.6
also gained a baseline violation forpowerpc
andppc64
by enabling the use of AltiVec there.
-
-
Kernel Space
-
Tom's Hardware ☛ Intel engineer's Linux patch would alert users of outdated microcode — Flagging the system as vulnerable
Your Linux system will inform you if your CPU is using an old microcode.
-