news
Security Leftovers
-
LWN ☛ Security updates for Friday
Security updates have been issued by AlmaLinux (.NET 10.0, coreutils, kernel, libevent, libsoup3, microcode_ctl, perl-Net-DNS, postgresql18, postgresql:16, postgresql:18, tomcat, and unbound), Debian (bind9, chromium, libapache2-mod-auth-openidc, nginx, xz-utils, and zip), Fedora (chromium, freeipmi, GitPython, gnatcoll, nodejs-undici, parted, python-django5, and sblim-cmpi-base), Mageia (imagemagick and python-starlette), Oracle (.NET 10.0, .NET 8.0, .NET 9.0, coreutils, corosync, firewalld, kernel, libevent, libsoup, microcode_ctl, nginx:1.24, perl, perl:5.32, postgresql:16, postgresql:18, redis, rsync, rsyslog, tesseract, and unbound), Red Hat (vim), SUSE (alsa, chirp, chromium, cjose, cups, discount, firefox, gh, glibc, gvfs, jq, kernel, libcjose-devel, libmbedcrypto7, libpcap, mbedtls-2, netcdf, nodejs18, openai-codex, openvpn, pcre2, perl-net-dns, sngrep, tiff, and znc), and Ubuntu (bison, bubblewrap, and gst-plugins-good1.0).
-
SANS ☛ HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
-
Security Week ☛ Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Hackers used a compromised API key to deploy a Clownflare worker that injected malicious scripts.
-
Security Week ☛ In Other News: Ransomware Developer Sentenced, Plugin4Shell Hey Hi (AI) Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 Hey Hi (AI) risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited.
-
Security Week ☛ Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
-
Security Week ☛ Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
-
Security Week ☛ NightmareStresser DDoS Service Disrupted in International Operation
Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.
-
Security Week ☛ 23 Million User Records Compromised in Gyazo Data Breach
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.
-
Bruce Schneier ☛ Are AIs Still Struggling with CAPTCHAs?
Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.
-
Cybersecurity Threat Advisory: KATARU IoT malware
KATARU is a newly identified IoT malware family that targets internet-facing Linux devices and recruits them into Mirai-style DDoS botnets. It commonly gains access through exposed Telnet services protected by weak or default credentials.
-
Cybersecurity Threat Advisory: Linux kernel RDS vulnerability
-
Hacker News ☛ Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
The flaws are called DirtyAH6, TUNderflow, PPPoEject, and DiagSpill. Researcher Asim Manizada found them and reported them to the Linux kernel security team in mid-July.