news
Security Leftovers
-
OpenSSF (Linux Foundation) ☛ Security Slam 2026 – Fall Edition
The Open Source Security Foundation (OpenSSF) is partnering with the Cloud Native Computing Foundation (CNCF) Security Technical Advisory Group (TAG Security) to support the 2026 Security Slam at KubeCon + CloudNativeCon America.
-
LWN ☛ Security updates for Wednesday
Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10.0, dotnet8.0, dotnet9.0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5.15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7.0, linux-azure-fde-6.8, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-oracle, linux-oracle-6.8, linux-raspi, openssh, and sudo).
-
The Straits Times ☛ New Zealand says China is its most persistent state-backed cyber threat
New Zealand's cyber security agency said China was the country's most persistent and capable state-backed cyber threat, as foreign actors targeted government agencies and organisations in sectors including health, education and information technology.
-
Security Week ☛ Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws.
-
Scoop News Group ☛ Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
The DHS inspector general said CISA lacks the power to compel agencies to implement its Binding Operational Directives.
-
Security Week ☛ Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.
-
Security Week ☛ Arista Urges Immediate Patching of Exploited VCO Zero-Day
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.
-
Security Week ☛ Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.
-
Federal News Network ☛ FBI investigates hackers’ claim to have stolen sensitive employee data, compromised jobs website
The bureau said in a statement Wednesday that it was aware of the claims, but didn't know the “point of breach.”
-
LWN ☛ Critical security vulnerabilities in the Radicle network protocol
The Radicle peer-to-peer code-collaboration project has disclosed two critical vulnerabilities in the network protocol used by Radicle nodes. The first flaw is that the network protocol used by Radicle "
does not give the confidentiality it was expected to give
", which allows anyone who can observe the network between two nodes to read the data exchanged.