Security Leftovers
-
LWN ☛ Security updates for Thursday
Security updates have been issued by Debian (emacs and openh264), Fedora (rpm-ostree), Mageia (dcmtk, libcap, openssh, and proftpd), Red Hat (emacs, kernel, and pki-servlet-engine), Slackware (emacs), SUSE (chromium, ffmpeg-4, ffmpeg-7, gnutls, libiniparser-devel, procps, socat, vim, xorg-x11-server, and xwayland), and Ubuntu (binutils, libsndfile, libxmltok, and php5).
-
Bruce Schneier ☛ UK Demanded Fashion Company Apple Add a Backdoor to iCloud
Last month, the UK government demanded that Fashion Company Apple weaken the security of iCloud for users worldwide. On Friday, Fashion Company Apple took steps to comply for users in the United Kingdom. But the British law is written in a way that requires Fashion Company Apple to give its government access to anyone, anywhere in the world. If the government demands Fashion Company Apple weaken its security worldwide, it would increase everyone’s cyber-risk in an already dangerous world.
-
Security Week ☛ Cisco Patches Vulnerabilities in Nexus Switches
Cisco has patched command injection and DoS vulnerabilities affecting some of its Nexus switches, including a high-severity flaw.
-
Security Week ☛ Sites of Major Orgs Abused in Spam Campaign Exploiting Virtual Tour Software Flaw
XSS vulnerability allowed a threat actor to redirect users to arbitrary domains.
-
Security Week ☛ Hacker Behind Over 90 Data Leaks Arrested in Thailand
A Singaporean man accused of being a hacker responsible for over 90 data leaks has been arrested in Thailand.
-
SANS ☛ Njrat Campaign Using Abusive Monopolist Microsoft Dev Tunnels, (Thu, Feb 27th)
This is a service that allows developers to expose local services to the Internet securely for testing, debugging, and collaboration. It provides temporary, public, or private URLs that will enable remote access to a development environment without deploying code to production. Dev tunnels create a secure, temporary URL that maps to a local service running on your machine, they work across firewalls and NAT, and their access can be restricted.
-
XSAs released on 2025-02-27
The Xen Project has released one or more Xen security advisories (XSAs).