Quotidien Hebdomadaire Mensuel

Hebdomadaire Shaarli

Tous les liens d'un semaine sur une page.

Semaine 30 (July 24, 2023)

TETRA Radio Code Encryption Has a Flaw: A Backdoor

A secret encryption cipher baked into radio systems used by critical infrastructure workers, police, and others around the world is finally seeing sunlight. Researchers say it isn’t pretty.

Critical Infrastructure Companies Warned to Watch for Ongoing Cyberattack

Hackers exploited a ‘zero-day’ flaw in Ivanti software to breach 12 ministries in Norway
Norway’s security officials warned around 20 critical infrastructure companies, other businesses and public agencies in the country they might also be vulnerable to a cyberattack disclosed Monday that hit 12 government ministries.

Ivanti warns of second vulnerability used in attacks on Norway gov’t

A second vulnerability affecting mobile endpoint management software from IT giant Ivanti has been discovered, according to a new advisory from the company.

U.S. Hunts Chinese Malware That Could Disrupt American Military Operations

American intelligence officials believe the malware could give China the power to disrupt or slow American deployments or resupply operations, including during a Chinese move against Taiwan.

Two privilege escalation flaws affect 40% of Ubuntu workloads in OverlayFS

Ubuntu patched the high-severity vulnerabilities on July 24 and recommends that users update their Ubuntu kernels.

Almost 40% of Ubuntu users vulnerable to new privilege elevation flaws

Two Linux vulnerabilities introduced recently into the Ubuntu kernel create the potential for unprivileged local users to gain elevated privileges on a massive number of devices.

Zenbleed

It turns out that with precise scheduling, you can cause some processors to recover from a mispredicted vzeroupper incorrectly!

This technique is CVE-2023-20593 and it works on all Zen 2 class processors, which includes at least the following products

Cryptojacking: Understanding and defending against cloud compute resource abuse

Cloud cryptojacking, a type of cyberattack that uses computing power to mine cryptocurrency, could result in financial loss to targeted organizations due to the compute fees that can be incurred from the abuse.

Apple issues third mobile OS update after zero-click spyware campaign

The patch is the latest to address issues associated with what cybersecurity firm Kaspersky called Operation Triangulation.