news
Security Leftovers
-
LWN ☛ Security updates for Thursday
Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, corosync, firewalld, kernel, kernel-rt, libevent, libsoup, microcode_ctl, nginx:1.26, python-lxml, rsyslog, tesseract, and unbound), Debian (firefox-esr, mkvtoolnix, thunderbird, and tor), Fedora (open62541, php-pecl-mongodb2, python-django6, python-jwcrypto, and roundcubemail), Mageia (aom, cockpit, libgd, packagekit, and python-h2), Red Hat (corosync, delve, git-lfs, grafana-pcp, gstreamer1-plugins-base, libvirt, opentelemetry-collector, and rhc-worker-playbook), Slackware (mozilla-firefox and mozilla-thunderbird), SUSE (acl, attr, alloy, ansible-core, clamav, containerized-data-importer, corosync, cups, distribution, glibc, google-cloud-sap-agent, govulncheck-vulndb, gvfs, helm, jq, kbd, kubernetes1.34-apiserver, kubernetes1.35-apiserver, lcms2, libcupsfilters, liblzmasdk26, libzypp, zypper, mistral-vibe, opensc, openvpn, pcre2, python-jwcrypto, tomcat, tomcat10, and tomcat11), and Ubuntu (guix, libheif, perl, python-cryptography, sqlite3, and valkey).
-
Security Week ☛ CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.
> -
Security Week ☛ Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.
-
Security Week ☛ ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.
-
Security Week ☛ Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.
-
Security Week ☛ CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
-
Security Week ☛ Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.
-
WhichUK ☛ Scamwatch: 'My Fashion Company Apple account has been compromised'
This sneaky scam could allow criminals to take over your account