news
Security Leftovers
-
LWN ☛ Security updates for Monday
Security updates have been issued by AlmaLinux (kernel, perl-Net-DNS, sudo, tomcat, and tomcat9), Debian (chromium, gimp, libde265, libevent, linux-6.12, ruby-jwt, and unbound), Fedora (asterisk, chromium, doctl, dovecot, evolution, firefox, forgejo, freeciv, freeipa, gegl04, gimp, libheif, nss, opkssh, parted, ruby, stb, thunderbird, unbound, and webkitgtk), Mageia (bind, gawk, gdk-pixbuf2.0, graphicsmagick, gstreamer1.0-plugins-base, libde265, libpcap, libssh, mpg123, ntfs-3g, ntpsec, patch, perl-YAML, postfix, python-configargparse, and python-httplib2), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, firefox, image-builder, kernel, libevent, libsoup, libsoup3, perl-Net-DNS, python-lxml, sudo, tomcat, tomcat9, and unbound), Slackware (stunnel), SUSE (alloy, dovecot22, ffmpeg-8, firefox, firefox-esr, freeipmi, glibc, google-guest-agent, google-osconfig-agent, helm, ImageMagick, jq, kbd, kernel-devel, libpcap, libsoup, libzypp, zypper, NetworkManager-applet-l2tp, nginx, openCryptoki, pcre2, python311, python313-aiosmtplib, python313-litellm, rpm, and thunderbird), and Ubuntu (linux-aws, linux-aws-fips, linux-azure-5.15, linux-azure-fde-5.15, linux-azure-fips, linux-azure-5.4, linux-gcp-fips, linux-azure-fips, linux-nvidia-tegra, linux-raspi, linux-raspi-realtime, and rclone).
-
APNIC ☛ Latest BGP hijack targets hosting software vendor
Guest Post: An analysis of the BGP hijack against Softaculous that enabled an attacker to obtain a fraudulent TLS certificate and distribute a malicious Virtualizor update.
-
SANS ☛ TerminalFix: PNG Steganography, (Mon, Sep 21st)
Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.
-
Security Week ☛ Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.
-
Security Week ☛ RatHat Android Trojan Uses Hey Hi (AI) for Automation
The malware relies on Hey Hi (AI) for real-time device navigation and control, increasing adaptability and evasion.
-
Security Week ☛ Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
The Cybersecurity and Infrastructure Security Agency has expanded its Known Exploited Vulnerabilities (KEV) catalog with three Linux kernel flaws, urging federal agencies to immediately patch them.
-
Diffoscope ☛ Reproducible Builds (diffoscope): diffoscope 330 released
The diffoscope maintainers are pleased to announce the release of diffoscope version
330. This version includes the following changes:* Don't Build-Depend on apksigcopier as it has been removed from testing.
(Closes: #1146852)
-
Security Week ☛ Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said.
-
Security Week ☛ CrowdSec Confirms Source Code Stolen in Supply Chain Attack
The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.
-
Standards/Consortia
-
Trail of Bits ☛ SAML: A fractal of bad design
Born out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies in the late aughts, IT departments needed a way for users to authenticate to many new web services. SAML and the burgeoning single sign-on (SSO) industry fulfilled this need. However, SAML is being crushed under the weight of its own complexity. It’s time to deprecate it and move on to modern alternatives like OpenID Connect (OIDC). In this post, I will explore the design-by-committee origin of SAML, its progression through the ranks in academic and corporate environments, its slow disintegration at the hands of the security research community, and its (hopeful) deprecation in favor of newer protocols.
-