Security Leftovers
-
Security updates for Tuesday [LWN.net]
Security updates have been issued by Debian (gnutls28 and unzip), Fedora (dovecot and net-snmp), Red Hat (kernel-rt and vim), and Ubuntu (gst-plugins-good1.0).
-
Sandfly Security Expands Leadership Team, Formally Launches Commercial Operations with Release 4.0 of Agentless Linux Security
-
New GwisinLocker ransomware encrypts Windows and Linux ESXi servers [Ed: With Linux you need some way in; with Windows there are back doors, so there's no parity here, just spin from a Microsoft site]
A new ransomware family called 'GwisinLocker' targets South Korean healthcare, industrial, and pharmaceutical companies with Windows and Linux encryptors, including support for encrypting VMware ESXi servers and virtual machines.
-
Cloud-Native Collision: Security and Cloud Center of Excellence [Ed: Lots of "clownwashing"; not much substance]
The migration of enterprise applications and infrastructure to cloud-native architectures is a hot topic—and a very complex one. While we may want to believe digital transformation efforts and cloud migration projects have already pushed large numbers of teams to build new apps and rearchitect existing apps as cloud-native, built using microservices and running on platforms like Kubernetes, the reality is that most organizations are still in the early stages of becoming cloud- and cloud-native-proficient.
-
CISA Adds Two Known Exploited Vulnerabilities to Catalog [Ed: This post is about Microsoft and about Windows. But it does not mention either "Microsoft" or "Windows". Typical CISA.]
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise. Note: to view the newly added vulnerabilities in the catalog, click on the arrow in the "Date Added to Catalog" column, which will sort by descending dates.
-
The Story Behind the Linux Security Quick Reference Guide [Ed: The story behind a site called "Linux Security" that actually promotes anti-Linux FUD in order to make sales. While no platform is perfect (either site or OS), it is wrong to give a platform to Microsoft disinformation against Linux.]
-
Istio / Support for Istio 1.12 has ended
As previously announced, support for Istio 1.12 has now officially ended.
At this point we will no longer back-port fixes for security issues and critical bugs to 1.12, so we heartily encourage you to upgrade to the latest version of Istio (1.14.3) if you haven’t already.
-
Adobe Releases Security Updates for Multiple Products | CISA
Adobe has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected system.
-
VMware Releases Security Updates | CISA
VMware has released security updates to address multiple vulnerabilities in vRealize Automation. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.