Security Leftovers
-
LWN ☛ Security updates for Thursday
Security updates have been issued by Debian (asterisk and chromium), Fedora (FlightGear, java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk, java-latest-openjdk, and SimGear), Mageia (bind, chromium-browser-stable, python-django, and vim), Oracle (buildah, bzip2, firefox, keepalived, mariadb:10.11, and podman), Slackware (curl, mariadb, and mozilla), SUSE (cargo-audit-advisory-db-20250204 and python311-scikit-learn), and Ubuntu (ckeditor, krb5, and ruby2.7).
-
Security Week ☛ 1,000 Apps Used in Malicious Campaign Targeting Android Users in India
Zimperium warns that threat actors have stolen the information of tens of thousands of Android users in India using over 1,000 malicious applications.
-
The Strategist ☛ Spyware is spreading far beyond its national-security role
Spyware is increasingly exploited by criminals or used to suppress civil liberties, and this proliferation is in part due to weak regulation.
-
Bleeping Computer ☛ CISA tags Abusive Monopolist Microsoft .NET and Apache OFBiz bugs as exploited in attacks
The US Cybersecurity & Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies and large organizations to apply the available security updates as soon as possible.
-
Scoop News Group ☛ Hugging Face platform continues to be plagued by vulnerable ‘pickles’
A widely used python module for machine-learning developers can be loaded with malware and bypass detection measures.
-
Help Net Security ☛ Attackers compromise IIS servers by leveraging exposed ASP.NET machine keys - Help Net Security
A ViewState code injection attack leveraging exposed ASP.NET machine keys could be easily replicated by other attackers.
-
Top 7 Most Secure Linux Distro for Privacy in 2025
In 2025, rising digital threats make secure Linux OS for privacy essential. Our list of the 7 most secure Linux distros highlights top choices for protection.