news
Security Leftovers
-
LWN ☛ Security updates for Friday
Security updates have been issued by AlmaLinux (bind, bind9.16, freerdp, glibc, kbd, mod_auth_openidc, openssl, perl-DBI, python3.12, python3.14, and tftp), Debian (rails and twitter-bootstrap3), Fedora (barman, cockpit, hcloud, libmodsecurity, nginx-mod-modsecurity, perl-DBI, sudo, and xorg-x11-server-Xwayland), Mageia (libxfont2), Oracle (bind9.18, firefox, kernel, nodejs24, perl-DBI, and vim), Red Hat (kernel, libreswan, opentelemetry-collector, osbuild-composer, rhc, and runc), SUSE (alloy, amazon-ecs-init, bind, busybox, distribution, emacs, ghostscript, glibc, GraphicsMagick, hauler, helm, helm3, jackson-annotations, jackson-core, jackson-databind, kernel, libpoppler-cpp3, libxtst, logback, nvidia-open-driver-G07-signed, perl-DBI, php-composer2, pi-coding-agent, portprotonqt, pvetui, python-hpack, python313-GitPython, and wpa_supplicant), and Ubuntu (apache2, bluez, libarchive, libde265, libgit2, libpng1.6, libxml2, linux, linux-aws, linux-aws-6.8, linux-aws-fips, linux-fips, linux-realtime, linux-realtime-6.8, linux-aws-7.0, linux-azure, linux-azure-6.8, linux-azure-fde, linux-azure-fde-6.8, linux-azure-fips, linux-azure-7.0, linux-azure-fde-7.0, linux-gcp, linux-gcp-6.8, linux-gcp-fips, linux-gcp-7.0, linux-hwe-7.0, linux-oracle-7.0, linux-gke, linux-gkeop, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oracle, linux-ibm-6.8, linux-nvidia, and linux-oem-6.17).
-
Hacker News ☛ Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection.
AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security advisory.
-
Diffoscope ☛ Reproducible Builds (diffoscope): diffoscope 333 released
The diffoscope maintainers are pleased to announce the release of diffoscope version
333. This version includes the following changes: [...] -
Security Week ☛ Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries
Midnight Mimosa is the name given to a malware campaign primarily running preinstalled on low-cost Android devices.
-
XSAs released on 2026-10-09
The Xen Project has released one or more Xen security advisories (XSAs).
-
Security Week ☛ Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.
-
Security Week ☛ Google Domains Impacted by Recent ccTLD Hijacks
Hackers hijacked the .gh, .sl, and .as ccTLDs and obtained HTTPS certificates for several Surveillance Giant Google domains.
-
Krebs On Security ☛ FBI Arrests Founder of Ransomware Negotiation Firm
Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity.
-
Security Week ☛ US Disrupts Chinese State-Sponsored Hacking Tools
Flax Typhoon and other APTs used MicroScan and FishHub to scan and hack US and foreign critical infrastructure.
-
Security Week ☛ Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.
-
Security Week ☛ Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own
$1.2 million was paid out at Pwn2Own Ireland 2026 for exploits targeting phones, printers, smart speakers, smart home hubs, and Hey Hi (AI) infrastructure and coding tools.