Security Leftovers
-
Security Week ☛ In Other News: Critical Chrome Bug, Capital One Hacker Resententencing, Story of Expat Flaw
Noteworthy stories that might have slipped under the radar: Capital One hacker’s sentence reversed, Surveillance Giant Google patches critical Chrome vulnerability, the story of an Expat flaw.
-
Diffoscope ☛ Reproducible Builds (diffoscope): diffoscope 290 released
The diffoscope maintainers are pleased to announce the release of diffoscope version
290
. -
Diffoscope ☛ Reproducible Builds (diffoscope): diffoscope 291 released
The diffoscope maintainers are pleased to announce the release of diffoscope version
291
. This version includes the following changes: [...] -
Security Week ☛ Ransomware Group Claims Attack on Virginia Attorney General’s Office
The Cloak ransomware group has claimed responsibility for a February cyberattack on Virginia Attorney General’s Office.
-
Security Week ☛ New Jailbreak Technique Uses Fictional World to Manipulate AI
Cato Networks discovers a new LLM jailbreak technique that relies on creating a fictional world to bypass a model’s security controls.
-
Security Week ☛ Chinese I-Soon Hackers Hit 7 Organizations in Operation FishMedley
The FishMonger APT group, a subdivision of Chinese cybersecurity firm I-Soon, compromised seven organizations in a 2022 campaign.
-
LWN ☛ Julien Malka proposes method for detecting XZ-like backdoors [Ed: For starters, do not use GitHub, it's a hub for social engineering]
Julien Malka has called for the NixOS project to use build-reproducibility to detect when a program has a maintainer-generated tarball that results in a different artifact than building from source.
-
LWN ☛ Security updates for Friday
Security updates have been issued by Debian (chromium), Fedora (fluent-bit, openssh, php, and webkitgtk), Mageia (freerdp), Oracle (libreoffice and webkit2gtk3), Red Hat (kernel-rt), Slackware (libarchive), SUSE (apptainer, gitea-tea, libxml2, tomcat, webkit2gtk3, and wpa_supplicant), and Ubuntu (libxslt and pam-pkcs11).
-
Bruce Schneier ☛ NCSC Releases Post-Quantum Cryptography Timeline
The UK’s National Computer Security Center (part of GCHQ) released a timeline—also see their blog post—for migration to quantum-computer-resistant cryptography.
It even made The Guardian.
-
Silicon Angle ☛ FCC opens probe into nine Chinese tech firms over US presence
The U.S. Federal Communications Commission today opened a probe into more than a half-dozen Chinese electronics suppliers and internet providers. The companies in question were previously ordered either to scale back or to shut down their U.S. operations.
-
InfoSecurity Magazine ☛ Albabat Ransomware Evolves to Target Linux and macOS
This use of [Microsoft] GitHub is designed to streamline operations.