Security Leftovers

-
Ben Hutchings: Debian LTS work, April 2022
I spent most of my time triaging security issues for Linux, working out which of them were fixed upstream and which actually applied to the versions provided in Debian 9 "stretch". I also rebased the Linux 4.9 (linux) package on the latest stable update, but did not make an upload this month.
-
Microsoft Releases Security Advisory for Azure Data Factory and Azure Synapse Pipelines [Ed: Microsoft's true TCO]
Microsoft has released a security advisory to address a remote code execution vulnerability affecting Azure Data Factory and Azure Synapse Pipelines. A remote attacker could exploit this vulnerability to take control of an affected system.
-
CISA Adds One Known Exploited Vulnerability to Catalog [Ed: F5/proprietary software]
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise. Note: to view the newly added vulnerability in the catalog, click on the arrow on the of the "Date Added to Catalog" column, which will sort by descending dates.
-
U.S. Government Attributes Cyberattacks on SATCOM Networks to Russian State-Sponsored Malicious Cyber Actors
-
Release of Technical Report into the AMD Security Processor [Ed: It is not Security Processor but Security Theatre Processor with user-hostile lock-down, i.e. something to be avoided]
-
The latest security information on Intel® products. 2022.1 IPU - Intel® Processor Advisory [Ed: Intel products are critically defective]
Description: Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
-
Adminer in Industrial Products [Ed: Microsoft Windows TCO]
-
AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere [Ed: Microsoft Windows TCO]
-
The Rust Programming Language Blog: Security advisory: malicious crate rustdecimal [Ed: Rust: migrating things to Rust is all about security. Also Rust: Oh, maybe not, but look at all those other perceived benefits (like having to create a Microsoft account to participate, and then get censored heavily)]
The Rust Security Response WG and the crates.io team were notified on 2022-05-02 of the existence of the malicious crate rustdecimal, which contained malware. The crate name was intentionally similar to the name of the popular rust_decimal crate, hoping that potential victims would misspell its name (an attack called "typosquatting").
To protect the security of the ecosystem, the crates.io team permanently removed the crate from the registry as soon as it was made aware of the malware. An analysis of all the crates on crates.io was also performed, and no other crate with similar code patterns was found.
-
OpenSSF Introduces Package Analysis Project [Ed: OpenSSF has been outsourced to Microsoft proprietary software in the NSA's bag; so you know it cannot be taken seriously for real security, it is in bed with the biggest culprit]
The OpenSSF has announced a prototype version of the Package Analysis project, aimed at identifying malicious packages in popular open source repositories in order to better secure critical projects.
-

- Login or register to post comments
Printer-friendly version- 1649 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
digiKam 7.7.0 is released
After three months of active maintenance and another bug triage, the digiKam team is proud to present version 7.7.0 of its open source digital photo manager. See below the list of most important features coming with this release.
|
Dilution and Misuse of the "Linux" Brand
|
Samsung, Red Hat to Work on Linux Drivers for Future Tech
The metaverse is expected to uproot system design as we know it, and Samsung is one of many hardware vendors re-imagining data center infrastructure in preparation for a parallel 3D world.
Samsung is working on new memory technologies that provide faster bandwidth inside hardware for data to travel between CPUs, storage and other computing resources. The company also announced it was partnering with Red Hat to ensure these technologies have Linux compatibility.
|
today's howtos
|








.svg_.png)
Content (where original) is available under CC-BY-SA, copyrighted by original author/s.

Recent comments
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago
1 year 11 weeks ago