Security Leftovers
-
GamingOnLinux ☛ X.Org X server and Xwayland have 8 more security vulnerabilities revealed
You should probably keep an eye on your software updater, as the X.Org X server and Xwayland have more security vulnerabilities that have been announced.
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by AlmaLinux (libpq, postgresql:13, postgresql:15, and postgresql:16), Debian (nodejs and php-nesbot-carbon), Mageia (neomutt), Red Hat (python3.11-urllib3 and tuned), SUSE (crun, ovmf, pam_pkcs11, qemu, and webkit2gtk3), and Ubuntu (iniparser, libcap2, linux, linux-hwe, linux, linux-hwe-5.4, linux, linux-lowlatency, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-ibm-5.4, linux-azure, linux-azure-fde, linux-gkeop, linux-nvidia, linux-oracle, linux-azure-5.15, linux-azure-fde-5.15, linux-oracle-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-kvm, linux-lowlatency-hwe-5.15, and linux-xilinx-zynqmp).
-
OpenSSF (Linux Foundation) ☛ OpenSSF Announces Initial Release of the Open Source Project Security Baseline [Ed: Not real security]
-
Bruce Schneier ☛ North Korean Hackers Steal $1.5B in Cryptocurrency
It looks like a very sophisticated attack against the Dubai-based exchange Bybit:
Bybit officials disclosed the theft of more than 400,000 ethereum and staked ethereum coins just hours after it occurred. The notification said the digital loot had been stored in a “Multisig Cold Wallet” when, somehow, it was transferred to one of the exchange’s hot wallets. From there, the cryptocurrency was transferred out of Bybit altogether and into wallets controlled by the unknown attackers.
-
Scoop News Group ☛ Crypto analysts stunned by Lazarus Group’s capabilities in $1.46B Bybit theft
The amount stolen last week surpasses what the group was able to steal in all of 2024.
-
Security Week ☛ CISA Warns of Attacks Exploiting Oracle Agile PLM Vulnerability
CISA has added CVE-2024-20953, an Oracle Agile PLM vulnerability patched in January 2024, to its KEV catalog.
-
Security Week ☛ Skybox Security Shuts Down, Lays Off Entire Workforce
The sudden shutdown follows the sale of Skybox Security’s business and technology assets to rival Israeli cybersecurity firm Tufin.