news
Security and FUD Leftovers
-
LWN ☛ Security updates for Wednesday
Security updates have been issued by AlmaLinux (bind, dovecot, freerdp, kernel, mariadb-connector-c, mod_auth_openidc, nodejs22, nodejs:22, sudo, and vim), Debian (node-shell-quote, puma, rails, ruby-jwt, and suricata-update), Fedora (chromium, cockpit, flocq, freerdp, gappalib-coq, golang-x-mod, httpd, janus, libical, musescore, python3-docs, python3.14, python3.15, rocq, rocq-stdlib, tesseract, why3, and zenon), Mageia (srt and tor), Oracle (freerdp, kernel, libpcap, mariadb-connector-c, nodejs22, sudo, and vim), Red Hat (expat and grafana), Slackware (openssh), SUSE (chromium, docker-stable, firefox, jupyter-jupyterlab, libtcnative-1-0, tomcat, tomcat10, libtcnative-1-0, tomcat11, openexr, python310, python313-azure-storage-queue, python313-langchain-anthropic, python313-sglang, python313-Werkzeug, and valkey), and Ubuntu (fluidsynth, freerdp3, freetype, golang-1.18, golang-1.21, golang-1.24, gst-plugins-good1.0, libsoup2.4, libsoup3, libwebsockets, linux, linux-aws, linux-gcp, linux-gke, linux-ibm, linux-oracle, linux-realtime, linux-azure, linux-azure-fde, linux-nvidia-tegra, linux-oem-7.0, redis, sg3-utils, tesseract, and u-boot).
-
Krebs On Security ☛ ShinyHunters Extorted Boeing Spin-off Prior to Arrests
A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle "Rey," was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey's father -- Royal Jordanian Airlines.
-
Security Week ☛ Advantest Discloses Data Breach Months After Ransomware Attack
The Japanese chip testing giant said hackers stole personal information from its servers in the February 2026 cyberattack.
-
QSB-120: Two CTAP proxy vulnerabilities
We have published Qubes Security Bulletin (QSB) 120: Two CTAP proxy vulnerabilities. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.
-
Tom's Hardware ☛ Florida sues TP-Link for ‘lying about the safety of its routers’
Florida and three other states have sued the company on the grounds that it's misleading their citizens about the security of its products and its ties with China.
-
Digital Music News ☛ Live Nation Is Battling Multiple Class Action Lawsuits Following Its Latest Data Breach. DMN Has Already Discovered Three Separate Suits.
Live Nation recently disclosed a data breach that exposed sensitive customer information. Now, multiple class action lawsuits have emerged. On October 1, Live Nation disclosed to the Vermont Attorney General a data breach that exposed highly sensitive customer information, including social security numbers and government ID numbers.
-
Scoop News Group ☛ Major rules for federal contractors handling sensitive data are nearing the finish line
The regulations on “controlled unclassified information” include security rules and requirements for reporting when they’re breached, including by cyberattacks.
-
The Straits Times ☛ Suspect behind South Korea bank hacks may be 26-year-old in China: Crowdstrike
CrowdStrike said the attacker used ARTEX, a recently released Chinese-developed open-source penetration testing tool.
-
Security Week ☛ Atlassian Patches Critical Vulnerability Affecting 8 Products
Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory.
-
SANS ☛ Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)
-
Security Week ☛ ASOS Confirms Cyberattack, Data Breach
Hackers compromised a third-party communication platform and sent rogue notifications to ASOS users.
-
Security Week ☛ Android’s October 2026 Updates Patch 25 Vulnerabilities
The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.
-
It's FOSS ☛ Google Has Shut Down Part of its Open Source Bounty Program [Ed: Proving Wrong Those Slop Maximalists and Boosters, GAFAM Says Slop is a Nuisance and Bans/Hides the Slop Submissions]
Submitting product vulnerability reports is no longer possible. You can thank Hey Hi (AI) for that.
-
Security Week ☛ Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany
The individual was detained in May and has been extradited to Germany to face hacking charges.
-
Security Week ☛ Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
Southern Company is notifying customers that their utility account information was accessed by hackers.
-
Fear, Uncertainty, Doubt/Fear-mongering/Dramatisation
-
Hacker News ☛ Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan [Ed: It's Not a Linux Back Door If It's an Unpatched Device]
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection.
-
Security Boulevard ☛ AWS Uses AI to Tame Linux CVEs
So far in 2026, there have been, deep breath, 7,178 Linux kernel Common Vulnerabilities and Exposures (CVE) reports with 526 rated Critical and 2,754 rated High severity. Debian Linux alone has 1,313 reasons to patch in its latest kernel security update. What’s a company to do?
-
Researcher finds full VM escape zero-day in Linux KVM
Vercel has confirmed a zero-day vulnerability in Linux KVM that security researcher Paulos Yibelo described as allowing a full virtual machine escape, CEO Guillermo Rauch said.
Yibelo said on X that the flaw could allow a user inside a guest virtual machine to gain root access on its host. He shared a screenshot showing a bug-bounty award for the discovery, which he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!”
-