news
Security Leftovers
-
Security Week ☛ 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor.
-
OpenSSF (Linux Foundation) ☛ OpenSSF at Hacker Summer Camp 2026: Black Hat & DEF CON Highlights and Recap
Las Vegas was once again the center of the cybersecurity universe from August 1–9 for Black Hat and DEF CON 2026. The Open Source Security Foundation (OpenSSF) had a major presence throughout the week, engaging with security leaders, project maintainers, and the broader community to advance open source security.
-
Security Week ☛ In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
Noteworthy stories that might have slipped under the radar: Abusive Monopolist Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion.
-
LWN ☛ Security updates for Friday
Security updates have been issued by Debian (chromium, firefox-esr, and pcre2), Fedora (cockpit, expat, freeipa, kbd, kernel, mrtg, python-pip, and valkey), Mageia (libopenmpt and python-gitpython), Oracle (dbus-broker, freerdp, gegl, gegl04, gimp:2.8, go-fdo-client, go-fdo-server, golang-github-openprinting-ipp-usb, grafana, gzip, image-builder, iperf3, kernel, libssh, libxml2, microcode_ctl, nodejs:22, nodejs:24, openssl-fips-provider, pam, php:7.4, php:8.2, tar, and wget), SUSE (apache2-mod_auth_openidc, apptainer, busybox, cpio, cups-filters, curl, dracut, ffmpeg, file-roller, glibc, grafana, kubevirt, virt-pr-helper-container, lcms2, libtree-sitter0_26, libvirt, postgresql14, postgresql15, postgresql16, postgresql18, suseconnect-ng, terraform-provider-susepubliccloud, and yast2-users), and Ubuntu (FFmpeg, gnupg2, librabbitmq, libssh2, openssh, and spice-vdagent).
-
Federal News Network ☛ Water utilities are a cybersecurity challenge that’s national in scope but local in responsibility
"They are trying cause chaos, they are trying to cause disturbances in our daily lives. And water is a great target to achieve that," Ozgur Ozmen.
-
Security Week ☛ Google Patches 6th Chrome Zero-Day of 2026
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine.
-
Federal News Network ☛ As Washington races ahead, are existing national security technology systems at risk?
"You will get ransomware, it's just you have to be prepared how to deal with it, and this is how you deal with these devices being attacked," said Rob Smith.
-
Security Week ☛ Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution.
-
Security Week ☛ HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates.
-
Security Week ☛ VMware Workstation and Fusion Updates Patch Critical Vulnerability
The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system.
-
Hacker News ☛ New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.
The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and the ability to replace the running binary.