Latest security news

In case you missed this (I did) - Audacity is now spyware:

https://www.youtube.com/watch?v=2yFpU2rSGGM

Alternatives:

1 Like

Agreed. In fact...

Well guess I missed your post with not being around for a bit. Just checked my Feren OS install and still on 2.2 so good for now in that regard. :wink:

1 Like

Changed from General to Tutorial.

Excellent Tutorial on desktop security.

Latest Linux Security News:

1 Like

SuSE Linux has issued multiple fixes for this issue in 2022:

https://linuxsecurity.com/search?searchword=IO-u r i n g &searchphrase=all

Latest Linux Malware News:

https://linuxsecurity.com/features/must-read-articles/linux-malware-the-truth-about-this-growing-threat-updated

And cross platform weak vectors where Java is running, primarily in Browsers:

https://linuxsecurity.com/news/security-vulnerabilities/openjdk-dos-info-disclosure-vulns-fixed

Ice Cat browser refuses web pages with Java and Stallman urges users to complain to owners of websites to remove Java code.

Chinese Hack attacks:

https://linuxsecurity.com/news/cryptography/chinese-hackers-use-dns-over-https-for-linux-malware-communication

And fake security researchers using stolen ID:

https://linuxsecurity.com/news/hackscracks/fake-zero-day-poc-exploits-on-github-push-windows-linux-malware

Note stupid censorship not allowing "u r i n g" remove spaces when in browser.

Tools for checking exploit vulnerabilities of the Linux kernel:

1 Like

Crosslink:

Reference 10 Aug 23:

Intel Response:

AMD is superior then?

Oh, I wouldn't go that far...

"Zenception":

Interestingly, I notice today that the link I posted yesterday is down. Apparently hackread has been ummm... cough...
hacked...

1 Like

Link is still working here. Maybe they put another 5cents in the meter.

3 Likes
**[Q] Is there any mitigation for Downfall?**

[A] Intel is releasing a microcode update which blocks transient results of gather instructions and prevent attacker code from observing speculative data from *Gather*.

I'd never heard of a "microcode update", some info if anyone's interested.

These Intel updates: will they work on Zorin, or if things like Secure Boot / UEFI are disabled?

Yes. These are not related to Secure Boot.
The microcode and firmware deal with the hardware (motherboard) Operating System, not Windows or Linux operating system.

I ask because, often, the update to fix firmware issues comes as a Windows .exe file only. Not sure what we could do if that's the case here.

sudo apt install linux-firmware

sudo service fwupd start

sudo fwupdmgr refresh

sudo fwupdmgr update

1 Like

Trying on the old HP Pavilion G4:

sudo fwupdmgr refresh

WARNING: UEFI firmware can not be updated in legacy BIOS mode
  See https://github.com/fwupd/fwupd/wiki/PluginFlag:legacy-bios for more information.
Firmware metadata last refresh: 16 hours ago. Use --force to refresh again.

I read the link, but I'm not sure what to do. Just ignore it? ("This warning can be ignored if UEFI firmware updates are not desired.") I don't know how entwined (or not) are firmware, UEFI and microcode.

Update 14 Aug '23:

apt list -u                                                                                    ─╯
Listing... Done
intel-microcode/focal-updates,focal-security 3.20230808.0ubuntu0.20.04.1 amd64 [upgradable from: 3.20230214.0ubuntu0.20.04.1]

Run

sudo apt update && apt list -u

to ensure intel-microcode upgrade is available on your regional server. If so, run

sudo apt upgrade

If not, please try again after a day or so.

1 Like