news
Security Leftovers
-
LWN ☛ Security updates for Monday
Security updates have been issued by AlmaLinux (firefox, gpsd-minimal, kernel, libarchive, libgcrypt, and LibRaw), Debian (bind9, ca-certificates, chromium, dnsdist, icinga2, kitty, libheif, openjdk-21, pdns, pdns-recursor, thunderbird, and xen), Fedora (bird, erlang, kernel, mingw-glib2, nghttp2, p11-kit, perl, perl-Devel-Cover, perl-PAR-Packer, pgadmin4, polymake, python-nh3, python-wsgidav, python3.12, rabbitmq-server, rust-ammonia, seamonkey, and udisks2), Mageia (python-starlette), Oracle (gnutls, kernel, and LibRaw), Red Hat (container-tools:rhel8), Slackware (wpa_supplicant), and SUSE (azure-storage-azcopy, bouncycastle, ffmpeg-4, fuse-overlayfs, gleam, gstreamer-plugins-bad, libssh2-1, libssh2_org, libwireshark19, libXfont2-2, perl-Mojo-JWT, perl-Mojolicious, podman, python310, python313-Django4, and tekton-cli).
-
Hacker Noon ☛ sos-vault Earns a 50.6 Proof of Usefulness Score by Building a Secure, AI-Assisted Platform for Analyzing sosreport Archives
In this interview, we sit down with Jorge Rueda, the creator of sos-vault. This open-source, self-hosted platform provides a secure environment for Linux support engineers and SRE teams to upload, decrypt, unpack, and analyze sosreport archives. By integrating an AI-assisted analysis pipeline, sos-vault enhances collaborative troubleshooting and diagnostic workflows.
-
The Register UK ☛ Feds warn Gunra ransomware is exploiting known bugs to hit critical infrastructure
The attackers have exploited CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in Fortinet's FortiOS and FortiProxy, to gain administrative access through internet-facing appliances.
-
Scoop News Group ☛ U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
The ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe.
-
APNIC ☛ Finding zero-days with any model
Guest Post: Vulnerability discovery is an orchestration problem, not a frontier-model problem.
-
Security Week ☛ Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition.
-
Security Week ☛ CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.
-
Security Week ☛ Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.
-
Security Week ☛ Metabase Patches Vulnerability Exploited as Zero-Day
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.
-
Security Week ☛ New Jersey, Alabama Join States Targeted in Water Cyberattacks
Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.