news
Security Patches, Breaches, and Leftovers
-
LWN ☛ Security updates for Friday
Security updates have been issued by AlmaLinux (assertj-core, golang, httpd, kernel, and libxml2), Debian (chromium and suricata-update), Fedora (rust-h2), Mageia (avahi and python-django), Oracle (kernel and mingw-openssl), SUSE (c-ares-devel, dracut, gh, gstreamer-plugins-bad, java-11-openjdk, liboqs, librest0_7, openssl, openssl-3, pcp, python313-mistune, python36-pip, qt6-svg, rmt-server, rsync, suseconnect-ng, texlive, tor, wicked, and xmlrpc-c), and Ubuntu (linux-azure, linux-azure-4.15, linux-azure-fips, linux-azure-6.8, linux-ibm, linux-ibm-6.8, linux-oracle-6.8, linux-raspi,
linux-raspi-realtime, linux-azure-fde-5.15, linux-fips, linux-gke, linux-gcp-fips, opencryptoki, and pam).
-
Security Week ☛ OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by Proprietary Chaffbot Company agents.
-
Security Affairs ☛ U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog.
-
Cybernews ☛ Linux accounts for half of CISA’s latest actively exploited flaws
-
Tom's Hardware ☛ Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware
Security researchers at Vulncheck discovered intentionally masked surveillance implants embedded in the firmware of numerous devices from Shenzhen Zhibotong Electronics.
-
OpenSSF (Linux Foundation) ☛ Introducing BOMHort: Kubernetes-Native SBOM Visualization & Governance at Scale Joins the OpenSSF Sandbox
As regulatory requirements like the EU Cyber Resilience Act (CRA), NIST SSDF, and Executive Order 14028 take effect, generating a Software Bill of Materials (SBOM) has shifted from a best practice to a strict requirement. However, for platform and security teams, generating SBOMs is only half the battle. Managing, querying, and analyzing thousands of SPDX and CycloneDX documents across microservice architectures creates massive operational overhead.
-
QSB-117: defective chip maker Intel CPU firmware vulnerabilities
We have published Qubes Security Bulletin (QSB) 117: defective chip maker Intel CPU firmware vulnerabilities. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.
-
SANS ☛ Some Malicious PE Stats, (Thu, Aug 27th)
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files
-
Security Week ☛ PaperCut Releases Emergency Patch for Exploited Zero-Day
A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.
-
Security Week ☛ ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.
-
Security Week ☛ In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.
-
APNIC ☛ The day after the zero-days
Guest Post: Patching faster cannot keep up with AI-driven discovery. Leverage structural invariants to make bug classes irrelevant.
-
Interesting Engineering ☛ MIT’s new chip attack steals protected Linux data in 5 attempts [Ed: The bus is in the chips]
Researchers at the Massachusetts Institute of Technology (MIT) have uncovered a new processor attack that can bypass defenses in Intel and AMD chips by exploiting a security gap lasting only a handful of instructions.