news
Security Leftovers
-
Diffoscope ☛ Reproducible Builds (diffoscope): diffoscope 327 released
The diffoscope maintainers are pleased to announce the release of diffoscope version
327. This version includes the following changes: [...] -
Security Week ☛ In Other News: Hey Hi (AI) Slop Limits Fashion Company Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
Noteworthy stories that might have slipped under the radar: ban on Chinese data center tech, QuickFox VPN supply chain attack, IEH Corporation mailbox breached via phishing.
-
Security Week ☛ Microsoft, Fashion Company Apple Release Fresh Security Updates
Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Fashion Company Apple patched a high-severity authentication bypass.
-
LWN ☛ Security updates for Friday
Security updates have been issued by AlmaLinux (compat-libtiff3, fence-agents, firefox, freerdp, frr, gimp, gstreamer1-plugins-bad-free, java-25-openjdk, kernel, kernel-rt, ldns, libgcrypt, libXfont2, nodejs:22, nodejs:24, p11-kit, pipewire, resource-agents, sg3_utils, thunderbird, and yelp), Debian (async-http-client, jq, kernel, linux-6.1, linux-6.12, redis, and udisks2), Fedora (abrt, chromium, coreutils, curl, freeipa, gst-devtools, gst-editing-services, gstreamer1, gstreamer1-doc, gstreamer1-plugin-libav, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, gstreamer1-rtsp-server, ImageMagick, kernel, libXfont2, php, python-gstreamer1, samba, tcpreplay, and trafficserver), Mageia (firefox, nss, rootcerts, python-django, and thunderbird), Oracle (freerdp, gimp, gpsd, kernel, kernel-uek, and osbuild-composer), Red Hat (buildah and container-tools:rhel8), Slackware (libXfont2 and p11-kit), and SUSE (amazon-ecs-init, azure-storage-azcopy, bind, bouncycastle, cockpit-repos, cockpit-subscriptions, dnsdist, ffmpeg-4, hawk-apiserver, nodejs22, nodejs24, OpenImageIO, openssl-1_1, openssl-3, perl-Mojo-JWT, php8, rsyslog, sssd, and wireshark).
-
Pen Test Partners ☛ Breaking the attack chain created by exposed cloud secrets
A secret is only as safe as the route it takes Secrets are supposed to let systems authenticate without leaving credentials sitting in plain view. However, a secret still has to be created, stored, retrieved by a workload, used and eventually replaced.
-
Scoop News Group ☛ More than half of AI-generated patches are broken
Research finds your Hey Hi (AI) generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way.
-
Security Week ☛ Critical Vulnerabilities Patched With Chrome 151 Update
The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws.
-
Security Week ☛ Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix
NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities.
-
Security Week ☛ Vishing Extortion Group UNC6671 Rebrands After Making Millions
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands.
-
Security Week ☛ 3.8 Million Impacted by Unlimited Technology Systems Data Breach
Hackers stole personal, medical, and health insurance information from a company’s data center.
-
Hacker News ☛ 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath.
The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.
Tracked as CVE-2026-64564 and named SCTPhantom by its finders, the flaw was disclosed publicly on August 6, two days after the kernel CVE team assigned it. No public exploit code had surfaced at the time of writing, and The Hacker News found no entry for the flaw in CISA's Known Exploited Vulnerabilities catalog as of August 7.
-
Wiz Inc ☛ Wiz Brings Automated DISA STIG Assessment to Amazon Linux 2023 and Windows Server 2025
Automating DISA STIG Compliance for Amazon Linux 2023 and Windows Server 2025, giving defense and federal teams immediate and continuous hardening validation.