Security Leftovers
-
The Register UK ☛ OpenSSH bugs threaten enterprise security, uptime
OpenSSH today released version 9.9p2, which addresses both vulnerabilities and thanked Qualys for the report.
-
Security Week ☛ Golang Backdoor Abuses Telegram for C&C Communication
A newly discovered Golang backdoor is abusing Telegram for communication with its command-and-control (C&C) server.
-
SANS ☛ https://SecTemplates.com - simplified, free open-source templates to enable engineering and smaller security teams to bootstrap security capabilities for their organizations, (Tue, Feb 18th)
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by Debian (gnutls28, openssh, and pam-pkcs11), Mageia (microcode and python-cryptography), Oracle (nodejs:18, nodejs:20, and rsync), Red Hat (gcc, nodejs:20, and nodejs:22), SUSE (emacs, kernel, openvswitch, and ucode-intel), and Ubuntu (Docker).
-
Security Week ☛ Microsoft Warns of Improved XCSSET macOS Malware [Ed: Microsoft is not a security expert but culprit; the media should quit playing along with this phony narrative of Microsoft as authority in this area; it gives the NSA back doors to everything.]
Microsoft has observed a new variant of the XCSSET malware being used in limited attacks against macOS users.