news
Security and Microsoft TCO
-
LWN ☛ Research into file-notification attacks on Linux
Sudheendra Raghav Neela, a member of a group of researchers from Graz University of Technology, has announced the release of research into file-notification attacks that would allow spying on user activity on Android, Linux, macOS, and Windows.
-
LWN ☛ Security updates for Thursday
Security updates have been issued by AlmaLinux (buildah, containernetworking-plugins, firefox, kernel, kernel-rt, openexr, perl-DBI, podman, postgresql, postgresql16, postgresql:15, runc, skopeo, and tar), Debian (libdatetime-timezone-perl, tzdata, xdg-dbus-proxy, and znc), Fedora (chromium, evolution, evolution-data-server, evolution-ews, kernel, libheif, mingw-pcre2, nginx-mod-modsecurity, unbound, and webkitgtk), Mageia (borgbackup, coreutils, firefox, nss, kbd, libnfs, libwebsockets, perl-URI, pipewire, and xdg-dbus-proxy), Oracle (apr-util, containernetworking-plugins, coreutils, curl, firefox, freerdp, gstreamer1-plugins-base, host-metering, libarchive, libtiff, libxml2, openexr, openssh, perl-DBI, podman, postgresql16, postgresql18-postgis, postgresql:15, rsyslog, runc, tar, and unbound), SUSE (apptainer, gimp, librepods, libX11-6, perl-Authen-SASL, podofo, python-WebOb, and python313-graphifyy), and Ubuntu (imagemagick, libgit2, moodle, network-manager, Open-iSNS, python-urllib3, sqlparse, and xdg-desktop-portal).
-
Scoop News Group ☛ How tax policy can stop threat actors from breaching US water systems [Ed: Deleting Windows works better]
New federal programs take years to launch and fund. State and local governments need cybersecurity software now. The One Big Beautiful Bill already enables tax incentives. Congress should clarify and deploy them.
-
Scoop News Group ☛ Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks [Ed: Back doors that were put there intentionally]
The legislation from Senate Intelligence Vice-Chairman. Mark Warner, D-Va., and Senate Commerce Chairman Ted Cruz, R-Tex., would create a government-industry group to write voluntary best practices.
-
Scoop News Group ☛ House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it.
-
OpenSSF (Linux Foundation) ☛ Inside the OpenSSF Summer Mentorship Showcase: How Emerging Developers Are Strengthening Supply Chain Security
At OpenSSF, securing the open source software supply chain isn’t just about writing code or establishing policies. It is about growing the community of developers who build, maintain, and innovate these tools.
-
Security Week ☛ SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.
-
Security Week ☛ Astrana Health Data Breach Impacts Private, Confidential Information
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.
-
Federal News Network ☛ IG report finds government cyber directives lack teeth
Most agencies missed a deadline to adopt cloud security standards. The DHS IG found CISA lacks the authority to enforce its "binding operational directives."
-
TechRadar ☛ Obscura VPN finally arrives on Linux — with a GUI, a CLI, and a new open-source license
The privacy-first VPN now covers every major desktop and mobile platform, and it's now fully open source, too
-
The Register UK ☛ Decades-old file security flaws found in Android, Linux, macOS, and Windows
Security researchers affiliated with Austria's Graz University of Technology have found flaws in the implementation of file notification systems on Android, Linux, macOS, and Windows that leak potentially compromising system information.
"We found decades-old bugs on [these operating systems], all rooted in the file-notification subsystems that every modern OS ships to inform applications when files change," said Sudheendra Raghav Neela, a doctoral student at TU Graz, in an email to The Register.
-
Microsoft TCO
-
Bruce Schneier ☛ Malicious npm Packages That Evade Defenses [Ed: Microsoft is still transmitting malware, nobody blames it for that]
This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.
-