news
Security Holes and Patches, OpenSSF Tech Talk
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by Debian (libwebsockets), Fedora (chromium and fvwm3), Mageia (apache, firefox, and postgresql13, postgresql15), Oracle (idm:DL1), Red Hat (bind, bind9.18, firefox, and openssl), SUSE (alloy, ghostscript, and openssl-1_0_0), and Ubuntu (ffmpeg and freeglut).
-
Security Week ☛ Chrome 142 Update Patches Exploited Zero-Day
The flaw was reported by Google's Threat Analysis Group and was likely exploited by a commercial spyware vendor.
-
OpenSSF (Linux Foundation) ☛ Tech Talk Recap: Simplifying DevSecOps in Air-Gapped Environments with Zarf
In the latest OpenSSF Tech Talk, we focused on a significant hurdle in software supply chain security: managing software delivery and upkeep within air-gapped and restricted network environments. You can now view the recording on the OpenSSF YouTube channel, and the presentation slides are accessible here.