news
Security Leftovers
-
LWN ☛ Security updates for Thursday
Security updates have been issued by Debian (7zip, kernel, libde265, and p7zip), Mageia (tomcat), Oracle (fence-agents, frr10, kernel, ldns, libgcrypt, mingw-glib2, nodejs24, osbuild-composer, p11-kit, php8.4, sg3_utils, and thunderbird), Red Hat (libXfont2), and SUSE (containerd, evince, libXfont2, nginx, openssl-3, pcp, php7, php8, python-Django, python-httplib2, python-nltk, rrdtool, vifm, and wireshark).
-
Security Affairs ☛ OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root
Security researcher Asim Manizada disclosed OVSwrap (CVE-2026-64531, CVSS score of 7.8), a local privilege escalation vulnerability in the Linux kernel’s Open vSwitch datapath that lets an ordinary user become root on a wide range of default-configured distributions.
-
Scoop News Group ☛ Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
A scan of internet-connected industrial equipment found 4,400 exposed PLCs, including 22 in cities recently targeted by water system attacks.
-
OpenSSF (Linux Foundation) ☛ Announcing OpenBao v2.6!
We are thrilled to announce the availability of OpenBao v2.6, adding per-namespace sealing and the new workflow engine for cross-plugin communication!
-
Security Week ☛ Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution.
-
Security Week ☛ Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code.
-
Security Week ☛ Critical Paperclip Flaw Allowed Admin Access, Code Execution
An attacker could self-register, sign in for board-level API access, and import a new company for code execution.
-
Security Week ☛ Snowflake Hacker Pleads Guilty in US Court
Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada.
-
Krebs On Security ☛ Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the clown data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.
-
Security Week ☛ Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison
Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.
-
Bleeping Computer ☛ New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines.
-
Hacker News ☛ New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests.
-
Windows TCO / Windows Bot Nets
-
Tom's Hardware ☛ VPN provider built a script to block Microsoft's hidden GDID tracking on backdoored Windows — Windscribe's "deGDID" erases existing identifiers and blocks new ones from being created
You can run the deGDID script on your computer to delete cached GDID keys and prevent Microsoft's servers from minting new ones in the background. The firewall you put up with this script will break certain Abusive Monopolist Microsoft services and features, however, but you can always reverse it.
-