Security: Patches, Holes, and More
-
Ex Security Head at Twitter Becomes Whistleblower
The Internet as a whole is at the point where you really don’t know who to trust. Malware, spam, and other security and privacy concerns are just so prevalent. That makes this news expected while also surprising. The ex-chief of security at Twitter became a whistleblower on Monday and outed his former company for its lack of security that he describes as “egregious deficiencies.”
[...]
Peiter Zatko, Twitter’s former head of security, claims Twitter violated a Federal Trade Commission settlement with false claims of its security. He filed this claim with the FTC, Security and Exchange Commission, and the United States Department of Justice.
-
Security updates for Wednesday [LWN.net]
Security updates have been issued by Fedora (vim), SUSE (cosign, dpdk, freeciv, gfbgraph, kernel, nim, p11-kit, perl-HTTP-Daemon, python-lxml, and python-treq), and Ubuntu (linux-oem-5.14, open-vm-tools, and twisted).
-
Mozilla Releases Security Updates for Firefox, Firefox ESR, and Thunderbird | CISA
Mozilla has released security updates to address vulnerabilities in Firefox, Firefox ESR, and Thunderbird. An attacker could exploit some of these vulnerabilities to take control of an affected system.
-
Buoyant Updates Linkerd to Simplify Zero-Trust Security
Buoyant today updated the open source Linkerd service mesh to add support for route-based authorization policies that enforce zero-trust policies within microsegmented Kubernetes environments.
In addition, the company is adding support for the Kubernetes Gateway application programming interface (API) and access logging to produce Apache-style request logs.