news
Security Leftovers
-
LWN ☛ Security updates for Thursday
Security updates have been issued by AlmaLinux (assertj-core, attr, firefox, go-toolset:rhel8, golang, grafana, gstreamer1-plugins-good, httpd, kernel, mingw-openssl, mod_http2, nginx, nginx:1.24, pam, polkit, and sqlite), Debian (bubblewrap, cockpit, emacs, gimp, libdbi-perl, openjdk-11, openjdk-17, wireshark, and xrdp), Fedora (bluez, curl, emacs, golang, knot, libopenmpt, libsoup3, openbao, openssh, rsync, rust-anstyle-hyperlink, rust-anstyle-progress, rust-cargo, rust-cargo-c, rust-cargo-credential-libsecret, rust-cargo-util, rust-cargo-util-schemas, rust-cargo-util-terminal, rust-crates-io, and rust-rustfix), Gentoo (Chromium, Surveillance Giant Google Chrome, Abusive Monopolist Microsoft Edge, Opera, Chromium, Surveillance Giant Google Chrome, Abusive Monopolist Microsoft Edge, Opera, Vivaldi, Chromium, Surveillance Giant Google Chrome, Abusive Monopolist Microsoft Edge. Opera, and OpenRGB), Oracle (abrt, assertj-core, attr, gstreamer1-plugins-base, gstreamer1-plugins-good, httpd, nginx:1.24, nginx:1.26, nodejs24, and polkit), SUSE (apache2-mod_auth_openidc, buildah, curl, docker, dracut, evince, go1.25-openssl, go1.26-openssl, go1.27, gstreamer-plugins-bad, kernel, kubernetes, kubernetes-old, libarchive, LibVNCServer, libwireshark19, pcp, python310-pip, qemu, rootlesskit, rsync, snpguest, and util-linux), and Ubuntu (bind9, libheif, and openssl, openssl1.0).
-
The Straits Times ☛ Australian police arrest two men accused of widespread open-source software hacking
The malicious code potentially compromised more than 1,000 organisations globally, the police said.
-
ISTIO-SECURITY-2026-006
-
Announcing Istio 1.29.7
This release contains security fixes. This release note describes what’s different between Istio 1.29.6 and 1.29.7. [...]
Upgraded version of
nftablesused by Istio distroless images. Thenftablesversion was previously pinned to 1.1.1 to avoid a bug that could cause older versions ofnftableson K8s nodes to crash after Istio used a newer version packaged in its images on the same node. Major GNU/Linux distributions have been informed of the issue and have released fixes. As a result, Istio is removing thenftablesversion pinning. Users are advised to update thenftablespackage on their nodes to the latest available version to ensure that the fixed version is installed. If you continue to experiencenftablescrashes on your nodes, downgrade to an older version of Istio and contact your node OS provider to request that the fix be patched into your OS version. (Issue #58492) -
Announcing Istio 1.30.4
This release contains security fixes. This release note describes what’s different between Istio 1.30.3 and 1.30.4.
-
Security Week ☛ Recent Citrix NetScaler Vulnerability Exploited in the Wild
CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452.
-
Security Week ☛ US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks
The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others.
-
Security Week ☛ Cyberattack Causes Global Disruption at Boston Scientific
The cybersecurity incident has disrupted Boston Scientific’s ability to process and ship customer orders.
-
Scoop News Group ☛ Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
The two men face 14 charges combined. Private researchers traced one suspect through leaked passwords and a decade-old gaming profile.
-
Security Week ☛ Australia Arrests 2 Alleged TeamPCP Hackers
Australian and US authorities collaborated to identify and charge the alleged cybercriminals, who face many years in prison.
-
Krebs On Security ☛ Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.
In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses."
The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect's real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP's self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.
-
Security Week ☛ Dihydroxyacetone Man Order Aims to Block Foreign Backdoors in US Power Grid Gear
The White House’s new executive order 14420 widens scrutiny of industrial control systems over cyber sabotage concerns.
-
Latvia ☛ Latvia's election system check finds flaws
In the run-up to the Saeima elections, polling station staff are testing the electoral systems. Cybersecurity authorities have carried out intensive checks and identified several vulnerabilities, one of which was reportedly critical, Latvian Radio reported on August 27.
-
Hacker News ☛ CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.
-
InfoSecurity Magazine ☛ CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
The US Cybersecurity and Infrastructure Security Agency (CISA) added six new flaws to its Known Exploited Vulnerabilities (KEV) catalog in a single day on August 26, urging government agencies and critical infrastructure organizations to patch them quickly.
CISA KEV listing means the US agency has found evidence of exploitation in the wild.
The August 26 list included two high-severity security vulnerabilities.
The first, tracked as CVE-2026-8452, is a memory overflow vulnerability in NetScaler ADC and NetScaler Gateway.