news
Security Leftovers and Windows TCO
-
LWN ☛ Security updates for Wednesday
Security updates have been issued by AlmaLinux (dbus-broker, freerdp, gegl, gegl04, gimp, gimp:2.8, glib2, grafana, gzip, iperf3, libssh, nodejs22, nodejs24, nodejs:22, nodejs:24, php:7.4, php:8.2, pipewire, ruby:3.3, ruby:4.0, tar, wget, and xmlrpc-c), Debian (cyrus-imapd, keystone, and lemonldap-ng), Fedora (bubblewrap, cockpit, emacs, gdk-pixbuf2, openssl, openvkl, python-linkify-it-py, python-llm, and rkcommon), Gentoo (Chromium, Surveillance Giant Google Chrome, Abusive Monopolist Microsoft Edge, Opera, Vivaldi), Oracle (glib2, gzip, mingw-sqlite, nodejs22, xorg-x11-server, and xorg-x11-server-Xwayland), Red Hat (go-toolset:rhel8, golang, and grafana), Slackware (pcre2), SUSE (apache2-mod_auth_openidc, busybox, cups-filters, java-17-openj9, java-1_8_0-openj9, libapr-util1, libgcrypt, python-sqlparse, python3-sqlparse, python313-uv, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, ucode-intel, wicked, and yast2-auth-client), and Ubuntu (libevent, libgcrypt20, ncurses, opencryptoki, pam, pyasn1, rust-sudo-rs, and ubuntu-advantage-tools).
-
RedHat Linux Kernel Multiple Vulnerabilities
Multiple vulnerabilities were identified in RedHat Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger data manipulation, denial of service condition, elevation of privilege, sensitive information disclosure and remote code execution on the targeted system.
-
Security Week ☛ 23-Year-Old Sality P2P Botnet Disrupted
The shutdown operation involved peer list manipulation and Sality payload URL takedown.
-
Security Week ☛ Malicious Virtualizor Update Served via BGP Hijacking
Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates.
-
Security Week ☛ Exploit Published for Fresh Cleo Harmony Vulnerability
The security defect allows remote attackers to bypass authentication through argument bearer manipulation.
-
Security Week ☛ Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.
-
Security Week ☛ UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.
-
Echo Acquires Minimus Assets As Hardened Open-Source Security Platform Expands Across Linux Distributions
Echo Software has acquired key assets from Minimus after Minimus decided to wind down operations, expanding Echo’s hardened open-source software platform while giving existing Minimus customers a path to keep using related technology.
-
ZDNet ☛ OpenAI’s agents exploited a patched Linux bug in Hugging Face incident: 6 steps to take ASAP [Ed: Slop hype from LF funded site and LF funded writer (LF is bribed by these slop companies to promote them)]
-
Windows TCO / Windows Bot Nets
-
Tom's Hardware ☛ Russian hacker faces up to 20 years in prison, following extradition and indictment over US phishing campaign that allegedly infected 80,000 PCs — hacker stole victims' data via remote access
Russian national faces US charges over a phishing campaign that allegedly infected 80,000 PCs and stole credentials and personal data
-
Scoop News Group ☛ Dogged Russia-based botnet dismantled after 23-year run
Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down.
-