news
Security Leftovers
-
Pen Test Partners ☛ Terraform Cloud token abuse turns speculative plan into remote code execution
TL;DR Introduction On a Red Team engagement we entered a busy multicloud estate. AWS, GCP and Microsoft trap Azure were all used, with Terraform Cloud orchestrating every change. That brings speed and consistency, but it also concentrates risk.
-
QSB-109: defective chip maker Intel microcode updates
We have published Qubes Security Bulletin (QSB) 109: defective chip maker Intel microcode updates. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.
-
Scoop News Group ☛ Cisco discloses maximum-severity defect in firewall software
The vulnerability, which Cisco said it discovered during internal security testing, could allow unauthenticated attackers to execute high-privilege commands.
-
TechRadar ☛ Proton VPN expands Linux capabilities with new split tunneling feature
Proton VPN has expanded its Linux capabilities with the addition of a new split tunneling feature, currently in beta.
Split tunneling for Linux is available to subscribers using the official Ubuntu and Fedora apps for Proton VPN, which is already one of the best VPN services available according to TechRadar's testing. Though not currently offered for the unofficial Flatpak version of the app, Debian 12 support is on the way.
The latest update brings Proton VPN’s Linux app in line with its Windows and Android apps in offering the feature. Mac users needn’t feel left out with split tunneling for macOS also on Proton VPN’s summer roadmap.