news
Security Leftovers
-
Security Week ☛ First Malware Built Specifically for Car Head Units Fuels Botnet
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
-
Security Week ☛ WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
When Android users get a call from a non-contact, they will see more information about the caller, including their country.
-
Scoop News Group ☛ Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further.
-
Federal News Network ☛ CISA wants agencies to maximize ‘insight’ from cyber data logging
CISA's new guide will help agencies meet a November deadline for submitting cyber logging plans that need to prioritize quality, instead of just quantity.
-
Security Week ☛ WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.
-
Security Week ☛ CISA Warns of Exploited Oracle WebLogic Vulnerability
The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.
-
OpenRGB: Remote System Compromise via Custom Network Protocol
OpenRGB is a cross-platform software suite for controlling RGB LED lighting devices on Linux, MacOS and Windows. It caught our attention due to a new systemd service which appeared in the openSUSE Tumbleweed OpenRGB package, containing the following configuration: [...]
-
LWN ☛ Security updates for Tuesday
Security updates have been issued by AlmaLinux (cups-filters, gstreamer1-plugins-base, gstreamer1-plugins-good, kernel, mrtg, NetworkManager, nginx, nginx:1.24, nodejs24, perl-Date-Manip, python-pyasn1, python-urwid, python3.12, python3.14, and qemu-kvm), Debian (erlang, thunderbird, webkit2gtk, and zfs-linux), Fedora (calibre, chromium, freeipa, java-21-openjdk, java-21-openjdk-portable, java-25-openjdk, java-latest-openjdk, jfrog-cli, kernel, libxls, nextcloud, perl-URI, and samba), Gentoo (Incus), Mageia (kernel and kernel-linus), Oracle (ansible-core, cups-filters, curl, firefox, kernel, libcupsfilters, libreoffice, mrtg, NetworkManager, perl-Date-Manip, php:8.2, php:8.3, python-urwid, python3.14, qemu-kvm, and sqlite), Red Hat (assertj-core, httpd, and osbuild-composer), SUSE (buildah, comfyui, dracut, erlang, erlang27, grafana, kernel, libssh2_org, openvswitch, perl-Dancer2-Plugin-Auth-Extensible, postgresql17, python-cryptography, python-sqlparse, python311, python313-hpack, rpm, suseconnect-ng, thunderbird, and vim), and Ubuntu (async-http-client, curl, and ffmpeg).
-
Trail of Bits ☛ State divergence enables unauthorized access
We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK, that lets any user grant themselves admin control over marker accounts without holding a single token. Provenance covers a range of financial services, including on-chain tokenized loans, private equity tokens, bridged assets, and asset registries. Our bug affected 82 markers representing live financial assets on mainnet.