Security Leftovers

-
Security updates for Tuesday [LWN.net]
Security updates have been issued by Debian (nodejs and squid), Fedora (uboot-tools), Red Hat (kernel-rt, kpatch-patch, and python), SUSE (drbd, openssl-1_0_0, oracleasm, and rubygem-rack), and Ubuntu (curl).
-
2022 CWE Top 25 Most Dangerous Software Weaknesses | CISA
The Homeland Security Systems Engineering and Development Institute, sponsored by CISA and operated by MITRE, has released the 2022 Common Weakness Enumeration (CWE) Top 25 Most Dangerous Software Weaknesses list. The list uses data from the National Vulnerability Database to compile the most frequent and critical errors that can lead to serious vulnerabilities in software. An attacker can often exploit these vulnerabilities to take control of an affected system, obtain sensitive information, or cause a denial-of-service condition. This year’s list also incorporates updated weakness data for recent Common Vulnerabilities and Exposure records in the dataset that are part of CISA’s Known Exploited Vulnerabilities Catalog.
-
When Security Locks You Out of Everything
Thought experiment story of someone of someone who lost everything in a house fire, and now can’t log into anything
[...]
Those risks are in the order of most common to least common, but that doesn’t necessarily mean that they are in risk order. They probably are, but then we’re left with no good way to handle someone who has lost all their digital credentials—computer, phone, backup, hardware token, wallet with ID cards—in a catastrophic house fire.
I want to remind readers that this isn’t a true story. It didn’t actually happen. It’s a thought experiment.
-
Codenotary introduces Software Bill of Materials service for Kubernetes
Software Bill of Materials (SBOM)s aren't optional anymore. If we really want the applications we're running in containers to be secure, we must know what's what within them. To make that easier, Codenotary, a leading software supply chain security company, is launching its new SBOM Operator for Kubernetes in both its open-source Community Attestation Service and its flagship service, Codenotary's Trustcenter.
-
Delaying the inevitable: Implementation of CERT-In’s Cybersecurity Directions gets a piecemeal extension
On June 27, 2022, the Indian Computer Emergency Response Team (“CERT-In”) issued a notification (No. 20(3)/2022-CERT-In) in relation to the extension of timelines for partial enforcement of Cyber Security Directions of April 28, 2022 (“Directions”) issued under sub-section (6) of section 70B of the Information Technology (“IT”) Act, 2000. The Directions were scheduled to go into effect 60 days from the date of their notification. While the timelines for enforcement of the entire Directions have been extended for Micro, Small and Medium Enterprises (“MSMEs”), for Data Centres, Virtual Private Server (“VPS”) providers, Cloud Service providers and Virtual Private Network (“VPN”) service providers only specific requirements relating to the validation of subscribers/customers details have received a timeline extension. The new date for enforcement of the Directions for such entities and specific requirements is September 25, 2022.
-
CMC Electronics EFB breakout vulnerability | Pen Test Partners
We’ve been finding vulnerabilities in electronic flight bags for a few years now. Disclosure response from the vendors involved has varied from excellent to radio silence.
In every case we have tried extremely hard to engage with the vendors involved, even where we were ignored. We asked friendly OEMs and others in the supply chain to help encourage those who wouldn’t respond to us, but their efforts were ignored too.
In some circumstances, it would be possible to affect take-off performance and landing calculations, resulting in significant safety events such as those here.
-

- Login or register to post comments
Printer-friendly version- 1120 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
today's howtos
|
Open Hardware: XON/XOFF and Raspberry Pi Pico
|
Security Leftovers
|
How to Apply Accent Colour in Ubuntu Desktop
A step-by-step tutorial on how to apply accent colour in Ubuntu desktop (GNOME) with tips for Kubuntu and others.
|





This section of TuxMachines will no longer have new stories in it (with some caveats, including this post). To see the latest stories go to 

.svg_.png)
Content (where original) is available under CC-BY-SA, copyrighted by original author/s.

Recent comments
1 day 23 hours ago
2 days 3 hours ago
2 days 3 hours ago
3 days 10 hours ago
3 days 11 hours ago
3 days 12 hours ago
3 days 12 hours ago
3 days 13 hours ago
3 days 15 hours ago
3 days 17 hours ago