Latest security news

A good site to sign up to, https://linuxsecurity.com

1 Like

https://kali.training/downloads/Kali-Linux-Revealed-1st-edition.pdf

BackTrack was the old name of Kali Linux. These people and the 'mooshoo' clan found a major error in an HP Server, they sent their findings and never got a response from HP!

The video below is not what you think - it's a response to a redditt post!

1 Like

Anyone running Linux on Windows 10 using WSL need to think again:

Polkit vulnerability. Ubuntu 20.04 but not Ubuntu 18.04 according to this:

@AZorin any comment re Z15, Z16 being vulnerable?

1 Like

Zorin OS 15 is not vulnerable as the code in question is not present in its version of polkit.

The issue has been fixed in Zorin OS 16 with version 0.105-26ubuntu1.1 of the polkit package, which was created on 26 May (a week before the vulnerability was publicly announced). Simply install the latest updates in the Software Updater to stay safe.

7 Likes

Just seen this reported on another forum:

1 Like

I wonder if this news is related to these issues?:

In case you missed this (I did) - Audacity is now spyware:

https://www.youtube.com/watch?v=2yFpU2rSGGM

Alternatives:

1 Like

Agreed. In fact...

Well guess I missed your post with not being around for a bit. Just checked my Feren OS install and still on 2.2 so good for now in that regard. :wink:

1 Like

Changed from General to Tutorial.

Excellent Tutorial on desktop security.

Latest Linux Security News:

1 Like

SuSE Linux has issued multiple fixes for this issue in 2022:

https://linuxsecurity.com/search?searchword=IO-u r i n g &searchphrase=all

Latest Linux Malware News:

https://linuxsecurity.com/features/must-read-articles/linux-malware-the-truth-about-this-growing-threat-updated

And cross platform weak vectors where Java is running, primarily in Browsers:

https://linuxsecurity.com/news/security-vulnerabilities/openjdk-dos-info-disclosure-vulns-fixed

Ice Cat browser refuses web pages with Java and Stallman urges users to complain to owners of websites to remove Java code.

Chinese Hack attacks:

https://linuxsecurity.com/news/cryptography/chinese-hackers-use-dns-over-https-for-linux-malware-communication

And fake security researchers using stolen ID:

https://linuxsecurity.com/news/hackscracks/fake-zero-day-poc-exploits-on-github-push-windows-linux-malware

Note stupid censorship not allowing "u r i n g" remove spaces when in browser.

Tools for checking exploit vulnerabilities of the Linux kernel:

1 Like

Crosslink:

Reference 10 Aug 23:

Intel Response:

AMD is superior then?

Oh, I wouldn't go that far...

"Zenception":

Interestingly, I notice today that the link I posted yesterday is down. Apparently hackread has been ummm... cough...
hacked...

1 Like