news
Security Leftovers
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by AlmaLinux (gpsd), Debian (caddy, libyaml-syck-perl, nss, and wordpress), Fedora (chezmoi, chromium, emacs, kernel, knot, libcupsfilters, mingw-gstreamer1-plugins-good, mingw-libidn, mingw-python-pip, nghttp2, p11-kit, python-webob, suricata, and xen), Mageia (bind, openslide, php8.4, and php8.5), Oracle (gpsd-minimal, kernel, libarchive, libpng12, nodejs-nodemon, php:8.3, ruby:3.3, and ruby:4.0), SUSE (agama-web-ui, bind, bouncycastle, dhcpcd, ffmpeg, ffmpeg-4, freerdp, gd, gitoxide, kak-lsp, kernel-devel, librest-1_0-0, libsdb2_5_0, libssh2_org, nodejs22, PackageKit, perl, perl-Date-Manip, python-ujson, python3-sqlparse, python311, python312, python313-pymongo, ruby2.5, runc, suseconnect-ng, thunderbird, vlang, webkit2gtk3, and weechat), and Ubuntu (imagemagick and systemd).
-
OpenSSF (Linux Foundation) ☛ CRA Readiness: A Practitioner’s Guide to Compliance
The EU Cyber Resilience Act (CRA) is no longer a future regulatory discussion; it is an immediate operational reality.
-
Scoop News Group ☛ NIST wants to overhaul its vulnerability database for the Hey Hi (AI) age
NIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data.
-
Security Week ☛ US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers.
-
Scoop News Group ☛ Kimwolf botnet rebuilt to survive takedowns, researchers say
Months after police seized its servers and arrested an alleged operator, the Kimwolf botnet is running code that disguises attacks as Chrome traffic and fetches its orders from the Ethereum blockchain.
-
Security Week ☛ SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs.
-
Security Week ☛ Zoom Patches Zero-Click Code Execution Vulnerability
Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.
-
Security Week ☛ Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
The security defects could be exploited for arbitrary code execution and denial-of-service.
-
Tech Times ☛ Six Agencies Warn Gunra Ransomware Hacked MFA at Server Level; Linux Victims May Recover Files Free
A joint advisory published Monday by six government agencies — the FBI, the Cybersecurity and Infrastructure Security Agency, the Department of Defense Cyber Crime Center, the National Security Agency, the U.S. Secret Service, and South Korea's National Police Agency — confirmed that a ransomware operation called Gunra has been defeating enterprise multi-factor authentication not by tricking users into approving fraudulent login attempts, but by directly modifying the authentication server itself, so that a code chosen by the attackers always works. For organizations that detected a Gunra attack on Linux systems, the CISA advisory AA26-222A disclosed a second finding with immediate financial stakes: a flaw in the way the Linux variant generates its encryption keys means that victims who preserved their encrypted files may be able to reconstruct the decryption keys from timestamps alone — without paying a ransom that the FBI observed starting at tens of millions of dollars.
-
Tech Times ☛ Gunra Ransomware Hit Hospitals and Governments; Linux Victims Should Not Pay Ransom
Six US and South Korean government agencies jointly warned Monday that Gunra, a ransomware-as-a-service operation built on leaked code from the notorious Conti gang, has struck at least 51 organizations across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific — breaching hospitals, government agencies, and financial institutions by exploiting unpatched Fortinet firewall products and demanding ransoms that in most documented cases exceeded $10 million. The advisory, designated CISA advisory AA26-222A under CISA's ongoing #StopRansomware initiative, carries an unusual second piece of intelligence that network defenders should act on immediately: researchers at Breakglass Intelligence confirmed in March 2026 that Gunra's Linux-specific ransomware builds contain a fatal cryptographic error that allows victims whose Linux systems were encrypted to recover their files without paying the ransom — a finding detailed in Breakglass Intelligence's March 2026 analysis.