news
Security Leftovers
-
LWN ☛ Security updates for Friday
Security updates have been issued by AlmaLinux (dogtag-pki, expat, freerdp, gawk, gdb, ghostscript, gvfs, kernel, kernel-rt, libpcap, openssh, pki-core, rsync, thunderbird, and webkit2gtk3), Debian (chromium, firefox-esr, libio-compress-perl, libpng1.6, nodejs, open-iscsi, redis, thunderbird, and webkit2gtk), Fedora (sos), Mageia (libgcrypt, python-tornado, python-urwid, python-wcwidth, and wireshark), Oracle (corosync, dogtag-pki, expat, firefox, freerdp, gawk, glib2, ipa, kernel, libXfont2, nodejs:24, openssh, osbuild-composer, perl-DBI, pki-core, postgresql:12, python-cryptography, resteasy, ruby, ruby4.0, ruby:3.3, ruby:4.0, thunderbird, and xmlrpc-c), Red Hat (skopeo), SUSE (chromium, emacs, glib2, glibc, gnome-shell, helm3, ImageMagick, imagemagick, kernel-devel, libtcnative-1-0, libtcnative-1-0, libtcnative-2-0, tomcat, tomcat10,, libtcnative-2-0, libX11, libX11-6, libXi-devel, libXpm-devel, libXtst-devel, mistral-vibe, openssl-3, perl-DBI, perl-Protocol-HTTP2, php-composer2, php8, python, rpcbind, sccache, and valkey), and Ubuntu (kf6-kcoreaddons, libxpm, linux, linux-aws, linux-fips, linux-kvm, linux-lts-xenial, linux-fips, linux-gke, linux-raspi-5.4, and openssl).
-
Security Week ☛ Crypto Scammers Hijack Microsoft’s Official X Account [Ed: A Crypto Scammer already hijacked it in 2022. His name is MElon.]
Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account.
-
The Straits Times ☛ AI tools suspected in South Korea’s Shinhan Bank hack, Yonhap says
Information exposed in the breach included names, phone numbers, annual income and borrowing limits.
-
Trail of Bits ☛ SequenceHash: multihashing for the rest of us
Multihashing is one of those cryptographic tasks that’s easy not to think about too much. This is unfortunate, because multihashing is a common stumbling point when cryptographers try to use hashes.
-
Security Week ☛ Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system.
-
Security Week ☛ Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.
-
Security Week ☛ In Rare Move, Alleged Iranian State Hacker Extradited to US
Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad.
-
Security Week ☛ macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
-
Dark Reading ☛ Malicious Linux Implants Mimic Asian Mail Security Products
It's common enough for malicious software to imitate legitimate software, superficially. An unwelcome program might name itself after something it expects in its target environment, so that if a passerby spots it, they might not think much of it. A few new Linux backdoors go further than this, though, by imitating the filenames, firewall-allowed traffic, and other specific operating habits of the popular Asian email security appliances they infect.
-
RedHat Linux Kernel Multiple Vulnerabilities
Multiple vulnerabilities were identified in Red Hat Enterprise Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure and data manipulation on the targeted system.
-
SUSE Linux Kernel Multiple Vulnerabilities
Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, security restriction bypass and sensitive information disclosure on the targeted system.