Security Leftovers
-
Dolphin Publications B V ☛ Small security tweak Torvalds improves Linux performance
Linux guru and founder Linus Torvalds has implemented a small security tweak in the OS’s source code that boosts performance just a bit more. His efforts increase Linux’s multithreaded performance in particular.
The security tweak implemented by Torvalds, which is designated x86/uaccess:Avoid barrier_nospec() in 64-bit copy_from_user(), focuses on improving the source code against the well-known Meltdown and Spectre attacks that have been known since 2018. The tweak (or patch) is a rewrite of an adjustment made by Red Hat specialist Josh Poimboeuf and is now faster. The speed gain is 2.6 percent, to be exact.
-
LWN ☛ Security updates for Thursday
Security updates have been issued by AlmaLinux (bcc, bpftrace, bzip2, container-tools:rhel8, grafana-pcp, haproxy, kernel, kernel-rt, krb5, libtiff, python-gevent, python3.11, python3.11-urllib3, python3.12, python3.12-urllib3, xmlrpc-c, and xorg-x11-server and xorg-x11-server-Xwayland), Debian (puma and pypy3), Fedora (firefox), Gentoo (libgit2), Mageia (libarchive), SUSE (ghostscript, go1.22-openssl, go1.23-openssl, htmldoc, kmail-account-wizard, libarchive, libgsf, libmozjs-128-0, openssl-3, python-jupyterlab, python-mysql-connector-python, python36, and ruby2.1), and Ubuntu (cinder, linux-aws, linux-aws-6.8, linux-oracle, linux-oracle-6.8, linux-aws, linux-azure-5.4, linux-kvm, linux-oracle, linux-xilinx-zynqmp, and linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency).
-
SANS ☛ Steam Account Checker Poisoned with Infostealer, (Thu, Nov 7th)
I found an interesting script targeting Steam users. Steam[1] is a popular digital distribution platform for purchasing, downloading, and playing video games on personal computers.
-
Scoop News Group ☛ China’s elite hackers expand target list to European Union
Beijing's hackers are also using an open-source VPN tool for persistence.
-
Cyber Security News ☛ ANY.RUN Launched an Upgraded Linux Sandbox for Effective Malware Analysis
October 2024 has been a productive month for Interactive malware analysis platform ANY.RUN, bringing a series of improvements aimed at enhancing threat detection and malware analysis capabilities.