news
Security Leftovers
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by AlmaLinux (cockpit-image-builder, expat, ipa, kernel, kernel-rt, resteasy, ruby, ruby4.0, ruby:3.3, and ruby:4.0), Debian (dovecot, flatpak, glance, kernel, libdbi-perl, lxml, rsync, swift, and wordpress), Fedora (chromium, freeipa, freerdp, grub2, NetworkManager-iodine, NetworkManager-l2tp, perl-Catalyst-Plugin-Static-Simple, perl-Dancer2, perl-HTML-FormFu, python-quart-trio, python-streamlink, python-urllib3, and vlc), Mageia (libxml2, p11-kit, pam, and php), Slackware (groff and pcre2), SUSE (389-ds, amazon-ssm-agent, erlang27, exiv2, glib2, gnome-shell, hplip, ImageMagick, kernel, libheif, libsodium, libtpms, nodejs16, perl-DBI, python-soupsieve, redis, redis7, swtpm, and wireshark), and Ubuntu (curl, libevent, linux-aws, linux-aws-6.8, linux-aws-5.15, linux-azure-5.15, linux-azure-fde-5.15, linux-intel-iotg-5.15, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-7.0, linux-oem-7.0, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, and linux-oracle-7.0).
-
SANS ☛ Scans for Wordfence Protected Websites, (Tue, Sep 29th)
-
TechXplore ☛ File-notification systems leave Windows, Linux, Android and macOS vulnerable [Ed: Microsoft said it did this intentionally]
-
Linux containers - When isolation no longer holds
Indeed, a container like the ones run by Docker or Kubernetes gives a program the impression of having its own machine. Except that in reality, it doesn't ship its own operating system. All the containers on a server go through the same Linux kernel, that of the host, whose job is to manage memory, CPU, and networking on their behalf.
-
Hacker News ☛ New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses [Ed: This is not a Linux issue, it's a stupid, greedy, cheating hardware companies issue]
-
Windows TCO / Windows Bot Nets
-
Security Week ☛ Hackers Use Abusive Monopolist Microsoft Chaffbot Custom GPTs in ClickFix Attacks
The personalized versions of Abusive Monopolist Microsoft Chaffbot were used to impersonate legitimate products and trick users into executing PowerShell commands.
-