news
Security Leftovers
-
LWN ☛ Security updates for Monday
Security updates have been issued by AlmaLinux (firefox, ipa, kernel, libxml2, perl-DBI, python-cryptography, thunderbird, and unbound), Debian (chromium, evolution-data-server, exim4, ghostscript, incus, lemonldap-ng, libheif, nodejs, php8.4, ruby-oj, swift, and vlc), Fedora (chromium, cinnamon, cinnamon-desktop, cinnamon-session, cinnamon-settings-daemon, ckermit, dnf5, forgejo, goose, gssntlmssp, libheif, libpcap, librsvg2, mingw-gstreamer1, mingw-gstreamer1-plugins-bad-free, mingw-gstreamer1-plugins-base, mingw-gstreamer1-plugins-good, mingw-python3, mongo-c-driver, muffin, nemo, nemo-extensions, nextcloud, pgadmin4, postgresql16-postgis, postgresql17-postgis, postgresql18-postgis, rust-librsvg, rust-xml5ever, sipp, suricata, tesseract, and xreader), Mageia (erlang, gpsd, libreswan, python3 & python-pip, and udisks2), Oracle (abrt, buildah, cockpit-image-builder, corosync, ipa, kernel, libxml2, openexr, perl-DBI, perl-DBI:1.641, postgresql, thunderbird, unbound, and yelp), SUSE (389-ds, ansible-lint, cups, firefox, flatpak-builder, forgejo-longterm, gdb, gimp, gitoxide, glib2, gnome-shell, google-guest-agent, google-osconfig-agent, haveged, helm, ImageMagick, kbd, libsoup, libtpms, obs-service-cargo, openai-codex, opensuse-signkey-cert, osmo-iuh, perl-mojolicious, poppler, python-WebOb, python-WebOb-doc, python313-vllm, python314, sdbootutil, suseconnect-ng, and swtpm), and Ubuntu (exim4, freerdp3, libvirt, libvirt-hwe, libwebsockets, lxc, pyjwt, and requests).
-
Security Week ☛ Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.
-
Diffoscope ☛ Reproducible Builds (diffoscope): diffoscope 332 released
The diffoscope maintainers are pleased to announce the release of diffoscope version
332. This version includes the following changes: [...] -
Tom's Hardware ☛ Teenager hacks open Abusive Monopolist Microsoft database with 17 trillion total rows and 25,000 user accounts
Teenager cracks open Abusive Monopolist Microsoft database with 17 trillion total rows and 25,000 user accounts — lack of JWT token validation yields a fruitful trove
-
Tom's Hardware ☛ North Korea named as primary suspect in $387 million Bitget crypto hack
Bitget says $387.5 million hack may be linked to North Korean state-backed actors, citing suspicious IP addresses tied to VPN infrastructure previously used by North Korean hacker groups.
-
Security Week ☛ Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.
-
Security Week ☛ DC Health Agency Exposes 400,000 Beneficiary Records
The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.
-
Security Week ☛ Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers.
-
Federal News Network ☛ More than 3 million people affected by military data breach
It revealed the names, dates of birth, Social Security numbers, job specialties and other records of nearly 2.8 million living and 294,000 deceased individuals.
-
PR Newswire ☛ Civil Infrastructure Platform Achieves Significant Cybersecurity Milestone with IEC 62443 Compliance
The Civil Infrastructure Platform (CIP), a collaborative, open source project hosted by the Linux Foundation, today announced that it has achieved compliance with IEC 62443-4-1 and IEC 62443-4-2. This milestone strengthens the security foundation available to manufacturers and operators building long-lived industrial and critical infrastructure systems. With this achievement, CIP became one of the first open source initiatives to achieve this level of IEC 62443 alignment, demonstrating that open collaboration can deliver enterprise-grade cybersecurity.
-
Help Net Security ☛ Other users can watch your browsing and time your keystrokes through OS file notifications [Ed: Microsoft says this is intentional and by design]
On Windows, a standard unprivileged account detected 95.7 percent of another user’s visits to popular websites in Firefox, and every site it flagged was one the victim’s browser had loaded. On Linux, a separate weakness exposed keystroke timing, both at the local keyboard and in SSH sessions.
-
File-Notification Systems Leave Windows, Linux, Android and macOS Vulnerable