news
Security Leftovers
-
LWN ☛ Security updates for Monday
Security updates have been issued by AlmaLinux (.NET 8.0, .NET 9.0, bind, dracut, freerdp, gnome-remote-desktop, kernel, and nghttp2), Debian (apr-util, docker.io, ironic, neutron, postgresql-15, unzip, and util-linux), Fedora (chromium, jfrog-cli, jrnl, libgsasl, libsoup3, pdns, pdns-recursor, perl-Archive-Tar, php-pear-PHP-CodeSniffer, rust-bat, rust-git-delta, rust-git-interactive-rebase-tool, rust-lsd, rust-pretty-git-prompt, rust-tokei, and stunnel), Gentoo (haveged, HTTP-Daemon, nginx, NTFS-3G, Portage, PostgreSQL, and X.Org X server, XWayland), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, bind, dhcpcd, dracut, grafana, iscsi-initiator-utils, kernel, nodejs:24, openssh, osbuild-composer, python-idna, ruby, and ruby4.0), Slackware (proftpd), and SUSE (7zip, afterburn, ansible-lint, bouncycastle, cargo-audit, cargo-c, chromedriver, chromium, containerized-data-importer, dnsdist, dracut-112, ffmpeg-9-libavcodec-devel, firefox, freetype2, git-cliff, glib2, go1.25, go1.26, google-guest-agent, google-osconfig-agent, gzip, himmelblau, java-1_8_0-openjdk, kernel, kernel-devel, kubeshark-cli, kubevirt1.9-continer-disk, libkrun, libXfont2, molecule, net-tools, nginx, nodejs22, nodejs24, open-iscsi, perl, pgadmin4, php-composer2, php8, python-httplib2, python-sh, python-ujson, python3-ansible-compat, python313-nltk, rrdtool, rsyslog, samba, spice-vdagent, sssd, webkit2gtk3, wireshark, and wpa_supplicant).
-
Dolphin Publications B V ☛ New Linux botnet turns routers into proxy servers [Ed: Does it infect via bad passwords? Does not specify.]
Once installed, the malware attempts to persist via various Linux mechanisms, including systemd, SysV init, and rc.local. A cron job also attempts to re-download the malware every five minutes. This means that simply removing the active process is insufficient to permanently clean an infected device.
-
Hacker News ☛ Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies [Ed: This says they exploit CVEs]
Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture. The script subsequently clears Bash history to erase traces of the attack.
-
Security Week ☛ Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components.
-
Security Week ☛ Recent macOS Screen Sharing Vulnerability Exploited in Attacks
Threat actors gained root access to the vulnerable systems and deployed a Monero miner.
-
Security Week ☛ 40,000 Impacted by SafePal Data Breach
Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.
-
Security Week ☛ Irregular Details How a Naming Error Let Hey Hi (AI) Models Attack a Real Company
The Hey Hi (AI) security testing firm has shared information on a recently disclosed incident involving Anthropic Hey Hi (AI) models.
-
Scoop News Group ☛ Details emerge on BlackFile’s recent attacks on financial companies
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google.
-
Security Week ☛ Fortune 500 Companies Hit in Microsoft trap Azure Data Theft Campaign
A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations.
-
SANS ☛ Apple Screen Sharing Security, (Mon, Aug 17th)
About 20 years ago, with macOS 10.5 (Leopard), Fashion Company Apple introduced screen sharing. Fashion Company Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP port 5900. Historically, the protocol used a simple global password for authentication. Fashion Company Apple adapted the protocol for its own use, but overall, left the VNC protocol itself alone.
-
SANS ☛ Apple Patches iOS and macOS, (Mon, Aug 17th)
Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS.
-
Security Week ☛ Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware
Anthropic has been conducting tests to identify issues in how Hey Hi (AI) agents interact with each other.