news
Security, FUD, and Proprietary Omissions
-
LWN ☛ Security updates for Monday
Security updates have been issued by AlmaLinux (ghostscript, libvirt, and osbuild-composer), Debian (freecad, linux-6.12, node-lodash, pcre2, perl, php8.2, ruby-rack-session, wireshark, and xen), Fedora (assimp, budgie-control-center, budgie-desktop, budgie-desktop-services, budgie-desktop-view, chromium, cri-o1.36, curl, flatpak, lemonldap-ng, libX11, nagios-plugins, nanosvg, noctalia, openssl, pgbouncer, pocillo-gtk-theme, prometheus, python-streamlink, python-urllib3, python-uv-build, python3.12, ruff, rust-libcst, rust-libcst_derive, rust-salsa, rust-salsa-macro-rules, rust-salsa-macros, ty, and uv), Red Hat (rhc-worker-script), SUSE (amazon-ecs-init, binaryen-133, bind, chromium, distribution, firefox, firefox-esr, glib2, gnumeric, helm, jline3, kubevirt-1.6, libparted-fs-resize0, libslirp-devel, libtcnative-1-0, libtcnative-2-0, tomcat, tomcat10, tomcat11, libwireshark19, openai-codex, python313-litellm, rpcbind, rustup, sccache, suseconnect-ng, valkey, wget, and xdg-dbus-proxy), and Ubuntu (ceph).
-
Security Week ☛ Alleged ShinyHunters Leader Arrested in Jordan
Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.
-
Security Week ☛ Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.
-
The Register UK ☛ Debian's latest kernel security update has 1,313 reasons to patch
The DSA-6528-1 Linux security advisory, published on September 29, covers kernel package version 6.12.111-1 for Debian 13, codenamed Trixie. Debian 13.7 was released on September 12, before upstream kernel 6.12.111 arrived nine days later.
-
Fear, Uncertainty, Doubt/Fear-mongering/Dramatisation
-
InfoSecurity Magazine ☛ New Stealthy Linux Backdoors [sic] Target Telecoms, Masquerade as Email Traffic [Ed: It's Not a Linux Back Door If It's an Unpatched Device]
Linux backdoors targeting telecom and network-edge appliances in South Korea and Taiwan have been disguising their traffic as email and their processes as legitimate services on the devices they compromise.
-
HackRead ☛ Hackers Exploit 24 IoT Vulnerabilities to Install ClingSTUN Linux Backdoor
-
-
Proprietary
-
Digital Trends ☛ Kagi is pulling Orion from Windows and Linux, leaving its cross-browser extension dream behind
I’ve been quietly rooting for Orion to escape the Apple bubble for a while, so this one stings a lot.
The bad news is that Kagi just scrapped its Windows and Linux versions. The good news, however, is that the code isn’t headed for the trash. It’s being released for anyone to pick up.
-
West Coast, with penguins: Aaltoverb on Linux; Aalto 2 coming soon
Madrona Labs’ patchable West Coast synth is one of the most playable, exploration-friendly, unique instruments around — a piece of software to last. And it comes with a reverb companion, now on Linux, too as a free demo you can beta-test. The big news: Aalto 2 is coming this fall for macOS, Windows — and Linux, too.
-