news
Security Leftovers
-
LWN ☛ Security updates for Wednesday
Security updates have been issued by AlmaLinux (expat, glib2, microcode_ctl, mrtg, pam, redis, thunderbird, and valkey), Debian (fort-validator, gst-plugins-base1.0, kernel, and slurm-wlm), Fedora (complyctl, libevent, openvpn, and tar), Mageia (dovecot and spice-vdagent), Red Hat (ignition, opentelemetry-collector, and osbuild-composer), SUSE (amazon-ssm-agent, aws-nitro-enclaves-cli, bzip2, cadvisor, chromium, curl, distribution-registry, emacs, freeciv, fuse-overlayfs, gh, google-guest-agent, GraphicsMagick, hauler, insighttoolkit-devel, java-17-openjdk, libidn, libusb-1_0, libvirt, libvncserver, libzypp, zypper, lkl, lxd, multipath-tools, NetworkManager, perl-Net-DNS, perl-URI, python, python-authlib, python-sqlparse, python-tornado, python3, rpcbind, supergfxctl, systemd, terraform-provider-null, ucode-intel, wget, wireshark, and xen), and Ubuntu (curl, ffmpeg, glibc, hsqldb1.8.0, imagemagick, perl, and vim).
-
Qubes Canary 048 [Ed: Using NSA platform for a "Canary" is misguided]
We have published Qubes Canary 048. The text of this canary and its accompanying cryptographic signatures are reproduced below. For an explanation of this announcement and instructions for authenticating this canary, please see the end of this announcement.
-
Bleeping Computer ☛ Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.
The malware shows signs of being a second-stage payload that was likely deployed after exploiting CVE-2025-53521, a critical remote code execution (RCE) flaw that F5 Networks reclassified from a DoS problem in March.
-
Help Net Security ☛ Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos.
F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarily used by enterprises, financial institutions, government agencies, and public sector organizations.
-
Security Affairs ☛ PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts.
SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Policy Manager environments. Sophos tracks it as Linux/Agnt-IC. F5 has confirmed exploitation of the underlying vulnerability and links the activity to a cluster it tracks internally as c05d5254.
-
Scoop News Group ☛ FTC rescinds policy requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization.
-
Scoop News Group ☛ Chinese espionage groups swarm to exploit triple-link chain of zero-days
Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen.
-
SANS ☛ Scans for Proxmox Servers, (Wed, Sep 9th)
About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.
-
Security Week ☛ Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic.
-
Security Week ☛ ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.
-
Security Week ☛ Android’s September 2026 Updates Patch 180 Vulnerabilities
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.
-
A Tailored Approach to Meet National Security Objectives: How the FCC Can Protect Innovation and Supply Chains
-
Pen Test Partners ☛ Passing the bucks $$$: Passback attacks explained
Default printer configurations are common to find in internal infrastructure engagements. These configurations are usually insecure, exposing outdated protocols like SNMPv1 and web interfaces without requiring authentication.
-
Security Week ☛ This Key Will Self-Destruct: An Open Standard for Revocable API Keys
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default.
-
Security Week ☛ Ivanti Patches Critical Flaws Across Enterprise Security Products
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.
-
Security Week ☛ Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
Major chipmakers announced patches for vulnerabilities recently discovered in their products.
-
Windows TCO / Windows Bot Nets
-
Tom's Hardware ☛ Researcher reverse-engineers infamous Stuxnet malware source code, publishes it on Microsoft's proprietary prison Microsoft's proprietary prison GitHub for all — attack targeted Iranian nuclear facilities and was the first software of its type to cause physical damage
An anonymous security researcher has reconstructed the source code of the infamous Stuxnet worm, which was built to subtly interfere with Iranian uranium enrichment during the Bush and Obama administrations.
-