news
Security Leftovers
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by Debian (network-manager-l2tp and urwid), Fedora (perl-Dancer2, perl-Data-Entropy, perl-DBI, perl-Protocol-HTTP2, podman-tui, rust-lru, and rust-lru0.16), Mageia (bzip2, cups-filters, libcupsfilters, libssh2, perl-Authen-SASL, perl-HTML-FormFu, tar, unzip, and zip), Red Hat (grafana and image-builder), SUSE (389-ds, acl, attr, apache2-mod_auth_openidc, apr-util, aws-nitro-enclaves-cli, bzip2, c-ares, clamav, cpio, curl, dhcpcd, dovecot23, dovecot24, dracut, emacs, fuse-overlayfs, go1.25-openssl, go1.26-openssl, google-cloud-sap-agent, google-osconfig-agent, govulncheck-vulndb, gstreamer-devtools, gzip, helm, java-17-openjdk, java-21-openjdk, java-25-openjdk, jq, libBasicUsageEnvironment2, libgpg-error, libidn, librest, libusb-1_0, libvirt, LibVNCServer, libzypp, zypper, lkl, mcphost, MozillaFirefox, mozilla-nspr, mozilla-nss, rust-cbindgen, MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen, MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen, msgpack-c, multipath-tools, NetworkManager, openexr, openssl-3, perl-Protocol-HTTP2, perl-URI, php-composer2, postgresql14, postgresql15, postgresql16, postgresql17, postgresql18, python-aiohttp, python-cryptography, python-h2, python-ruff, python-sqlparse, python311, python312, python39.SUSE_SLE-15-SP3_Update, rav1e, rpcbind, sssd, systemd, tomcat, tomcat11, ucode-intel, udisks2, vim, and wicked2nm), and Ubuntu (cgit, dracut, freeciv, konsole, libinput, linux-azure, linux-nvidia-7.0, nginx, vips, and yelp).
-
Security Week ☛ $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage.
-
GNOME ☛ Michael Catanzaro: Privilege Escalation Vulnerabilities in NetworkManager Plugins
Andreas Gabriel Berbescu has reported several root privilege escalation vulnerabilities in various NetworkManager VPN plugins. If the VPN plugin is installed, then an unprivileged user can escalate to root by loading a malicious VPN configuration file: [...]
-
OpenSSF (Linux Foundation) ☛ Grow CRA Readiness: Find Your Path Through the European Union Cyber Resilience Act
Discover how the EU Cyber Resilience Act (CRA) impacts your open source work. OpenSSF’s new community garden user journey helps maintainers, software stewards, and manufacturers navigate legal requirements and find essential tools for CRA readiness.
-
Security Week ☛ Thai Broadband Provider Hacked via Fortinet Vulnerability
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.
-
Security Week ☛ Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data
A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.
-
Security Week ☛ Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks.
-
Security Week ☛ ClosedSlop Investigates Report Linking Hey Hi (AI) Agents to RubyGems Attack
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.
-
QSB-119: Potential attacker-controlled format string in qvm-open-in-vm
We have published Qubes Security Bulletin (QSB) 119: Potential attacker-controlled format string in qvm-open-in-vm. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.
-
Hacker News ☛ BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems.
-
Bleeping Computer ☛ BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems.
-
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit
Acronis Threat Research Unit (TRU) uncovered a multinational campaign in which a Chinese-speaking threat actor, tracked as Red Heron, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management platform. The activity progressed from source-code theft to persistent access, credential collection, and lateral movement, including root-level access to a three-node Proxmox cluster.