Explore top 10 tips to secure your open-source projects now. Read More
×The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added half a dozen vulnerabilities to its catalog of Known Exploited Vulnerabilities and is ordering federal agencies to follow vendor’s instructions to fix them. . Of the six security flaws, only one was disclosed this year. It impacts Trend Micro’s Apex One platform for automated threat detection and response. CISA is giving federal agencies until October 6th to patch security vulnerabilities that have been reported between 2010 and 2022. . NIST mandates that government departments tackle critical weaknesses, impacting applications like Symantec's Endpoint Protection. Take immediate action!. CISA Mandate, Trend Micro Apex One, Vulnerability Management. . Brittany Day
Red Hat has used RPM for software package distribution for decades, but thanks to CloudLinux developer Dmitry Antipov we now know that RPM contained a nasty hidden security bug since Day One. A repair patch for this major security hole has been submitted, but Antipov fears that it may be months before the fix is released. . In 1995, when Linux 1.x was the hot new Linux kernel, early Red Hat founding programmers Marc Ewing and Erik Troan created RPM . This software package management system became the default way to distribute software for Red Hat Linux-based distributions such as Red Hat Enterprise Linux (RHEL) , CentOS Stream , AlmaLinux OS , and Rocky Linux . Unfortunately, hidden within its heart is a major security hole. Dmitry Antipov, a Linux developer at CloudLinux , AlmaLinux OS's parent company, first spotted the problem in March 2021. Antipov found that RPM would work with unauthorized RPM packages . This meant that unsigned packages or packages signed with revoked keys could silently be patched or updated without a word of warning that they might not be kosher. . An important vulnerability in RPM identified by Dmitry Antipov poses risks for Red Hat and related distributions.. Red Hat Package Management, RPM Security Flaw, Linux Issues, CloudLinux. . Brittany Day
In early December, Facebook’s developer team declared the discovery of a security bug that gave developers access to photos users hadn’t shared on their timeline, including photos they had posted in Facebook Marketplace or Stories.. More worryingly, apps could find access to images users might have uploaded to Facebook but didn’t post anywhere. For example, this could be pictures you uploaded to a profile update you abandoned and did not complete. These are pictures that users haven’t shared with anyone. The link for this article located at The Next Web is no longer available. . Applications were able to view photos that users had uploaded without publicly sharing them on Facebook. This raised serious issues regarding privacy and safety.. Facebook Privacy Breach, Security Bug, Data Exposure, Image Access, Software Flaw. . LinuxSecurity.com Team
Singapore Airlines (SIA) says a software glitch was the cause of a data breach that affected 284 members of its frequent flyer programme, compromising various personal information including passport and flight details. . The "software bug" surfaced after changes were made to the Singapore carrier's website on January 4 and enabled some of its Krisflyer members to view information belonging to other travellers, SIA told ZDNet in an email. The link for this article located at ZDNet is no longer available. . The 'software bug' surfaced after changes were made to the Singapore carrier's website on January 4 . singapore, airlines, (sia), software, glitch, cause, breach, affected. . LinuxSecurity.com Team
A spat between two security companies shows just how sensitive reporting software vulnerabilities can be, particularly when it involves a popular product. The kerfuffle between FireEye and ERNW, a consultancy in Germany, started after an ERNW researcher found five software flaws in FireEye's Malware Protection System (MPS) earlier this year. . One of the flaws, found by researcher Felix Wilhelm, could be exploited to gain access to the host system, according to an advisory published by ERNW. As is customary in the industry, ERNW contacted FireEye in early April with details of the problems. . Concerns emerge regarding the disclosure of weaknesses in the Malware Defense System between CrowdStrike and CERT over issues in threat assessment.. Malware Protection System, FireEye, Ethical Disclosure, Software Flaws, Cybersecurity. . LinuxSecurity.com Team
A number of TLS software implementations contain vulnerabilities that allow hackers with minimal computational expense to learn RSA keys. Florian Weimer, a researcher with Red Hat, last week published a paper called . The TLS implementations in these products, Weimer said, lack proper hardening to defend against what is known as the Lenstra attack against the Chinese Remainder Theorem, also known as RSA-CRT. . Multiple susceptible TLS versions threaten RSA key integrity, as highlighted in Veimer's findings showcasing insufficient protections.. TLS Improvements, RSA Key Protection, Cryptography Security. . LinuxSecurity.com Team
A senior Linux kernel developer has pointed to an instance of what he calls a lax approach to security in the Linux kernel, citing the case of a serious vulnerability that is now more than a month old and is yet to be fixed.. Jonathan Corbet (pictured above), who is also the editor of the Linux Weekly News website, described in an article how a flaw in the kernel, which was initially discussed on a private mailing list, had been made public with a posting by a developer named Oleg Nesterov. The link for this article located at IT Wire is no longer available. . Jonathan Corbet (pictured above), who is also the editor of the Linux Weekly News website, described. senior, linux, kernel, developer, pointed, instance, calls, approach, securi. . LinuxSecurity.com Team
Serial Java fault-finder Adam Gowdiak has embarrassed Oracle yet again. Gowdiak hit the headlines last year when he reported a vulnerability, waited for Oracle's response, and then upped the ante with a comeback vuln.. It's d The link for this article located at Sophos is no longer available. . Java specialist Emma Carson reveals additional unrectified vulnerabilities in Oracle systems, raising the ante once more.. Java Security Risks, Oracle Software Issues, Gowdiak Findings, Java Flaws. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.