Security Leftovers
-
Matthew Garrett: UEFI rootkits and UEFI secure boot [Ed: Microsoft apologists at it again. The person who caused the problems now pretends to be the rescuer offering redemption.]
Kaspersky describes a UEFI-implant used to attack Windows systems. Based on it appearing to require patching of the system firmware image, they hypothesise that it's propagated by manually dumping the contents of the system flash, modifying it, and then reflashing it back to the board. This probably requires physical access to the board, so it's not especially terrifying - if you're in a situation where someone's sufficiently enthusiastic about targeting you that they're reflashing your computer by hand, it's likely that you're going to have a bad time regardless.
-
The History of Kali Linux [Penetration Testing] Distribution
In cybersecurity and digital forensics, penetration testing plays a crucial role in identifying and mitigating exploitable vulnerabilities in a system. A number of tools have been developed to help pentesters efficiently conduct penetrations tests, one of which is Kali Linux.
-
LibreOffice security update fixes macro execution bypass and potential password leaking - gHacks Tech News
The developers of LibreOffice have released updates for the open source Office suite to patch three security issues.