Language Selection

English French German Italian Portuguese Spanish

Security Leftovers and Proprietary Software

Filed under
Security
  • 700,000 WordPress Sites Affected By Zero-day Vulnerability in File Manager Plugin

    Yesterday a zero-day vulnerability was discovered in a popular WordPress plugin, File Manager. The vulnerability allows arbitrary file upload and remote code execution.

    File Manager plugin is a useful plugin that allows users to browse site files in an easy way. The plugin has over 700,000 active installations that make it a desired target for attackers.

    Yesterday the vulnerability was discovered by Seravo as part of their WordPress upkeep service. They noticed unusual activity on several of their customers’ websites and further investigation revealed the severe vulnerability in the File Manager plugin.

  • Kees Cook: security things in Linux v5.6

    Linux v5.6 was released back in March. Here’s my quick summary of various features that caught my attention:

  • Australian firm Tandem Corp hit by Windows NetWalker ransomware [iophk: Windows TCO]

    "We continue to work with our external data security providers and, if any personally identifiable information has been accessed, we will notify those who may have been impacted as well as the appropriate authorities as required, including the Office of the Australian Information Commissioner.

  • Zoom's market value surges past General Motors and Boeing

    Zoom projected a total revenue of $2.4 billion dollars ( for its fiscal year ending in January. This is up from the 1.8 billion dollars (1.5 billion euros) it forecast back in June, and takes into account the users that will not renew the monthly subscriptions they signed up for in the first quarter.

  • Cisco says it will issue patch ‘as soon as possible’ for bugs [attackers] are trying to exploit

    Justin Elze, a principal security consultant at security company TrustedSec, pointed out that in order for the vulnerability to be exploited, a protocol known as IGMP needs to be enabled. That protocol is less common in enterprise networks and tends to be used by cable TV networks to do video streaming, he said.

  • Audible Unveils 'Sesame Street' Podcast

    Last year, the beloved children's series announced a move to HBO Max for its 51st season, a deal that includes five new seasons of the show.

  • Animal Crossing Continues To Be An Innovative Playground As Biden Campaign Begins Advertising On It

    For nearly half a year now, especially when this damned pandemic really took off, we've been bringing you the occasional story of how Nintendo's Animal Crossing keeps popping up with folks finding innovative ways to use the game as a platform. Protesters advocating for freedom in Hong Kong gathered in the game. Sidelined reality show stars took to the game to ply their trade. Very real people enduring very real layoffs used the game's currency as a method for making very real money. As someone who has never played the game, the picture I'm left with is of a game that is both inherently malleable to what you want to do within it and immensely social in nature.

More in Tux Machines

digiKam 7.7.0 is released

After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release. Read more

Dilution and Misuse of the "Linux" Brand

Samsung, Red Hat to Work on Linux Drivers for Future Tech

The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world. Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility. Read more

today's howtos

  • How to install go1.19beta on Ubuntu 22.04 – NextGenTips

    In this tutorial, we are going to explore how to install go on Ubuntu 22.04 Golang is an open-source programming language that is easy to learn and use. It is built-in concurrency and has a robust standard library. It is reliable, builds fast, and efficient software that scales fast. Its concurrency mechanisms make it easy to write programs that get the most out of multicore and networked machines, while its novel-type systems enable flexible and modular program constructions. Go compiles quickly to machine code and has the convenience of garbage collection and the power of run-time reflection. In this guide, we are going to learn how to install golang 1.19beta on Ubuntu 22.04. Go 1.19beta1 is not yet released. There is so much work in progress with all the documentation.

  • molecule test: failed to connect to bus in systemd container - openQA bites

    Ansible Molecule is a project to help you test your ansible roles. I’m using molecule for automatically testing the ansible roles of geekoops.

  • How To Install MongoDB on AlmaLinux 9 - idroot

    In this tutorial, we will show you how to install MongoDB on AlmaLinux 9. For those of you who didn’t know, MongoDB is a high-performance, highly scalable document-oriented NoSQL database. Unlike in SQL databases where data is stored in rows and columns inside tables, in MongoDB, data is structured in JSON-like format inside records which are referred to as documents. The open-source attribute of MongoDB as a database software makes it an ideal candidate for almost any database-related project. This article assumes you have at least basic knowledge of Linux, know how to use the shell, and most importantly, you host your site on your own VPS. The installation is quite simple and assumes you are running in the root account, if not you may need to add ‘sudo‘ to the commands to get root privileges. I will show you the step-by-step installation of the MongoDB NoSQL database on AlmaLinux 9. You can follow the same instructions for CentOS and Rocky Linux.

  • An introduction (and how-to) to Plugin Loader for the Steam Deck. - Invidious
  • Self-host a Ghost Blog With Traefik

    Ghost is a very popular open-source content management system. Started as an alternative to WordPress and it went on to become an alternative to Substack by focusing on membership and newsletter. The creators of Ghost offer managed Pro hosting but it may not fit everyone's budget. Alternatively, you can self-host it on your own cloud servers. On Linux handbook, we already have a guide on deploying Ghost with Docker in a reverse proxy setup. Instead of Ngnix reverse proxy, you can also use another software called Traefik with Docker. It is a popular open-source cloud-native application proxy, API Gateway, Edge-router, and more. I use Traefik to secure my websites using an SSL certificate obtained from Let's Encrypt. Once deployed, Traefik can automatically manage your certificates and their renewals. In this tutorial, I'll share the necessary steps for deploying a Ghost blog with Docker and Traefik.