news
Security Holes, Breaches, and Windows TCO
-
It's FOSS ☛ Ubuntu's Rust Transition Hits Another Bump as sudo-rs Security Vulnerabilities Show Up [Ed: As expected]
Password exposure and improper authentication validation issues caught early ahead of the LTS release.
-
Tom's Hardware ☛ Intel software fixes stamp down privilege escalation vulnerabilities, while microcode updates clean up CPU messes — chipmaker has its own Patch Tuesday as it stomps down 30 bugs
Intel stomps down 30 bugs including privilege escalation vulnerabilities
-
Security Week ☛ Chipmaker Patch Tuesday: Over 60 Vulnerabilities Patched by Intel
Intel, AMD and Nvidia have published security advisories describing vulnerabilities found recently in their products.
-
Security Week ☛ High-Severity Vulnerabilities Patched by Ivanti and Zoom
Ivanti and Zoom resolved security defects that could lead to arbitrary file writes, elevation of privilege, code execution, and information disclosure.
-
Scoop News Group ☛ Amazon pins Cisco, Citrix zero-day attacks to APT group
The vendors disclosed and patched the defects last summer, but not before advanced attackers exploited the vulnerabilities to likely gain prolonged access for espionage, according to Amazon.
-
Security Week ☛ ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Rockwell, Aveva, Schneider
An Aveva vulnerability also impacts Schneider Electric products and both vendors have published advisories.
-
OMG Ubuntu ☛ Kaspersky Brings Its Antivirus Software to GNU/Linux Desktops [Ed: Russian blob inside GNU/Linux isn't security]
Kaspersky launches GNU/Linux antivirus for Ubuntu and other distros. Features, system requirements and why the banned security firm has come to open-source desktops.
-
Windows TCO / Windows Bot Nets
-
Tom's Hardware ☛ Microsoft patches backdoored Windows 10 issue that accidentally blocked extended security updates from installing — latest update should finally fix all the issues for ESU-eligible devices
Microsoft has published an out-of-band backdoored Windows 10 update that finally addresses all of the glitches surrounding Extended Security Update (ESU) enrollment. Installing this update should finally let you enroll in the ESU program on backdoored Windows 10 if you haven't been able to do so.
-
SANS ☛ SmartApeSG campaign uses ClickFix page to push NetSupport RAT, (Wed, Nov 12th)
-