news
Security Leftovers
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by AlmaLinux (apr-util, corosync, curl, freerdp, gstreamer1-plugins-base, libarchive, libtiff, libxml2, openexr, openssh, rsyslog, sudo, tomcat, unbound, webkit2gtk3, yggdrasil, and yggdrasil-worker-package-manager), Debian (chromium), Fedora (alsa-plugins, amarok, aqualung, atomes, attract-mode, audacious-plugins, audacity, baresip, blender, calibre, cantata, cef, chromaprint, chromium, digikam, doctl, dragon, ffmpeg, ffmpegthumbnailer, ffmpegthumbs, ffms2, fooyin, glaxnimate, goldendict-ng, gpac, gstreamer1-plugin-libav, guacamole-server, guvcview, haruna, hedgewars, icecat, janus, k3b, kdenlive, kf5-kfilemetadata, kf6-kfilemetadata, kpipewire, lazygal, lego, libcamera-apps, libheif, libopenshot, libopenshot-audio, libvncserver, localsearch, mat2, minidlna, mivisionx, mixxx, mlt, monado, mpd, mpv, mpv-mpris, neatvnc, notcurses, nv-codec-headers13.0, obs-studio, obs-studio-plugin-droidcam, obs-studio-plugin-pwvideo, obs-studio-plugin-vaapi, obs-studio-plugin-vkcapture, obs-studio-plugin-webkitgtk, olive, openal-soft, OpenBoard, opencv, openmw, opustags, os-autoinst, patool, Pencil2D, perl-HTML-FormHandler, pianobar, prometheus-podman-exporter, python-audioread, python-torchaudio, python-torchvision, qmmp, qmmp-plugin-pack, qmplay2, qt5-qtwebengine, qt6-qtmultimedia, qt6-qtwebengine, qtox, retroarch, rocdecode, rocdecode7.2, rsgain, siril, squeezelite, swayimg, tigervnc, timg, unpaper, vlc, vtk, waypipe, wf-recorder, wivrn, wxsvg, xine-lib, xmms2, xpra, xscreensaver, yle-dl, znc, and znc-clientbuffer), Mageia (nmap, pcre2, and vim), Oracle (curl, openssl-fips-provider, sudo, tomcat, webkit2gtk3, yggdrasil, and yggdrasil-worker-package-manager), Slackware (util-linux), SUSE (cadvisor, chromium, coredns, fake-gcs-server, freeciv, gh, glibc, google-guest-agent, google-osconfig-agent, hugo, kbd, kbfs, keybase-client, libheif, libpcap, mbedtls, pcre2, python-asteval, python-jwcrypto, python311, python313-ansi2html, shadowsocks-rust, sofia-sip, and trivy), and Ubuntu (clamav, expat, ghostscript, glib2.0, gst-plugins-base1.0, gst-plugins-good1.0, libsoup2.4, libsoup3, libssh2, libxml2, linux-azure-6.8, linux-azure-fde, linux-azure-fde, linux-azure-fde-7.0, linux-azure-fde, linux-intel-iotg, linux-kvm, linux-oracle, linux-xilinx-zynqmp, linux-gcp-6.8, linux-ibm, linux-xilinx, linux-ibm, linux-nvidia-bos, linux-raspi, memcached, openjdk-17, openjdk-21, openjdk-25, openjdk-8, openjdk-lts, rsyslog, and strongswan).
-
FOSS Force ☛ Codenotary Expands Its No-Strings-Attached GNU/Linux Security Deal [Ed: Looks like a press release recycled]
The company’s permanently free security platform for up to 25 machines is now available to organizations running Debian and Ubuntu, as well as AlmaLinux.
-
Business Wire ☛ Codenotary Expands Free Linux Security Program to Debian and Ubuntu
Positive response to Codenotary’s AlmaLinux security offer prompts expansion of free program to additional major Linux distributions
-
Codenotary Expands Free Linux Security Program to Debian and Ubuntu
-
Security Week ☛ Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches.
-
Techstrong Group Inc ☛ Why Kubernetes RBAC Misconfigurations Are the Easiest Privilege Escalation You’ll Ever Find
-
Tom's Hardware ☛ North Korea used job interviews to deploy malware on 30,000 devices during coding tests
Multiple government agencies across the world released a warning that North Korean hackers are posting fake jobs to install malware on unsuspecting applicants' computers. They then steal credentials and cryptocurrency from their victims, with over $10 million reported stolen.
-
Security Week ☛ BigCommerce Data Stolen via Ribon Apps Hack
The attackers used a compromised BigCommerce application key held by Ribon to access customer data.
-
Scoop News Group ☛ Volexity spots another China-aligned threat group exploiting Chrome and Abusive Monopolist Microsoft defects
The threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups.
-
Security Week ☛ Nightmare Eclipse Drops New Abusive Monopolist Microsoft Defender Exploit After Revealing Identity
Abdelhamid Naceri, a former Abusive Monopolist Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse.
-
Microsoft TCO / Windows Bot Nets
-
Security Week ☛ Malicious B-tree NPM Package Accumulates Millions of Downloads [Ed: Microsoft ships malware]
Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method.
-
-
Devices/Embedded
-
Kyle Reddoch ☛ Connected Car Risks: Remote Access, Tracking, and Privacy
A researcher switched off a BYD Shark 6’s headlights while a journalist drove it at night. The same investigation demonstrated remote location tracking and access to the cabin microphone. Those are substantial capabilities to lose control of in something you use to get your family home.
The demonstration, covered by Security Affairs, came from ABC’s Four Corners investigation. Researcher Dan Hreszczuk had the vehicle for two weeks before the test. He said the access he used lacked a password, but he could not access the brakes or cameras.
-
ABC ☛ We got a cybersecurity expert to hack this BYD. It was too easy
His task was to hack the vehicle and find out what could be seen and done remotely by the Shark's Chinese manufacturer.
"It was easier than we were expecting," Hreszczuk says.
-