news
Security Leftovers
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by Debian (corosync and kernel), Fedora (checkpointctl, chromium, curl, and perl-Catalyst-Authentication-Credential-HTTP), SUSE (firefox, frr, kernel, rustup, vim, and wireshark), and Ubuntu (glibc and pam).
-
APNIC ☛ APNIC / FIRST Security 2 at APNIC 60
At #APNIC60, APNIC and FIRST brought together experts from across the region to share real-world responses to cybersecurity threats—from RCE vulnerabilities and lateral movement risks to scalable training models for cyber resilience.
-
Silicon Angle ☛ Darktrace reveals ShadowV2 botnet exploiting Docker misconfigurations in AWS
A new report out today from Darktrace Ltd. reveals a sophisticated cybercrime campaign that blends traditional malware with cloud-native design principles, exposing how threat actors are evolving distributed denial-of-service operations into fully fledged “as-a-service” platforms. The campaign detailed in the report, dubbed “ShadowV2,” is a Python-based command-and-control framework hosted on Microsoft's proprietary prison GitHub CodeSpaces.
-
Supply Chain to SSH Keys: The Expanding Arsenal of Linux Ransomware Threats [Ed: A lot of these exploits come from Microsoft (GitHub, npm etc.)]
Let’s break down how these evolving threats penetrate your environment—and why deterministic prevention, like memory shielding and zero-trust execution, is the only reliable way to stop stealthy payloads before they execute.
-
Security Week ☛ SonicWall Updates SMA 100 Appliances to Remove Overstep Malware
The software update includes additional file checks and helps users remove the known rootkit deployed in a recent campaign.
-
Security Week ☛ Jaguar Land Rover Says Shutdown Will Continue Until at Least Oct 1 After Cyberattack
JLR extended the pause in production “to give clarity for the coming week as we build the timeline for the phased restart of our operations and continue our investigation.”
-
Security Week ☛ Patch Bypassed for Supermicro Vulnerability Allowing BMC Hack
Binarly researchers have found a way to bypass a patch for a previously disclosed vulnerability.
-
Security Week ☛ SolarWinds Makes Third Attempt at Patching Exploited Vulnerability
CVE-2025-26399 is a patch bypass of CVE-2024-28988, which is a patch bypass of the exploited CVE-2024-28986.