news
Security and Microsoft TCO
-
LWN ☛ Security updates for Wednesday
Security updates have been issued by AlmaLinux (fence-agents, gstreamer1-plugins-good, kernel, kernel-rt, p11-kit, perl-Archive-Tar, perl-DBI, and thunderbird), Debian (aom, botan3, and kernel), Fedora (abrt, coreutils, doctl, kernel, open62541, perl, perl-Devel-Cover, perl-PAR-Packer, and polymake), Mageia (acl and php), Oracle (firefox, frr, kernel, libreswan, nodejs-nodemon, nodejs22, perl-Archive-Tar, php:7.4, php:8.2, rsync, and thunderbird), Red Hat (compat-libtiff3, libpq, libtiff, postgresql, postgresql16, postgresql18, postgresql:12, postgresql:13, postgresql:15, postgresql:16, and postgresql:18), Slackware (stunnel), and SUSE (alloy, alsa, bind, chromedriver, corepack24, ffmpeg-4, golang-github-prometheus-prometheus, google-guest-agent, google-osconfig-agent, kubevirt, libgcrypt, libpng16, multipath-tools, netty, netty-tcnative, nodejs26, openssl-1_1, openssl-3, perl-HTTP-Tiny, perl-YAML-Syck, podman, python-sh, python-ujson, rsyslog, spice-vdagent, thrift, valkey, wpa_supplicant, and xen).
-
Security Week ☛ New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.
-
Security Week ☛ CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
-
Security Week ☛ How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications.
-
OSTechNix ☛ Do You Really Need Antivirus on Linux? Here’s What New Users Should Know
Do you really need antivirus on Linux? Learn when antivirus helps, when it doesn't, and how to secure your GNU/Linux system with practical security best practices.
-
Security Week ☛ 311,000 Impacted by Brown Health Medical Group-MA Data Breach
Hackers stole personal information, medical records, and financial information from the organization’s server.
-
Bruce Schneier ☛ Vulnerabilities in Car Anti-Theft Device
This is disturbing:
…a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.
-
Cybernews ☛ Tails Linux critical vulnerability allows websites to deanonymize users: emergency patch available
Tails, a security and anonymity-focused portable Linux distribution that keeps no records of user activity, has fixed a critical kernel vulnerability. Simply visiting a malicious website could deanonymize the user.
-
Hacker News ☛ New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.
The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim Manizada on July 28, 2026.
The bug sits in the kernel datapath, not the userspace ovs-vswitchd daemon. In a technical write-up, Manizada said an attacker needs "no existing OVS bridge, no running ovs-vswitchd, no host-level CAP_NET_ADMIN."
-
Microsoft TCO
-
Security Week ☛ Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and Microsoft's proprietary prison GitHub credentials.
-
SANS ☛ Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the Microsoft's proprietary prison GitHub PAT, cycle the clown keys. That reflex has been correct in almost every supply-chain incident I have worked. In the
keyv/cacheablecompromise that has been unfolding since yesterday, it is the one thing you should not do first - because revoking the stolen token is exactly what arms the payload.
-