Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

Security updates for Thursday

Security updates have been issued by AlmaLinux (bind9.18, glib2, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, kernel-rt, libcupsfilters, mysql8.4, mysql:8.4, pcp, perl-Date-Manip, php8.4, php:7.4, php:8.2, php:8.3, python3, and yggdrasil), Debian (designate, firefox-esr, and swift), Gentoo (acl, attr, Emacs, libssh2, and quickjs-ng), Oracle (.NET 10.0, .NET 9.0, attr, bind9.18, curl,…

We haven't written up this one. LWN has the full story — the link below goes straight to it.

Read the original at lwn.net →

More in Tech

The antivirus said 'no malware detected'. It was sitting right there on the disk.

A real incident, and a lesson about green lights. Every command output, version number and CVE ID below is from the actual investigation. Nothing was invented for the narrative.

  • Malware hidden on Synology NAS despite no threats detected by antivirus scan
  • Packers and shell scripts used to evade signature-based malware detection
  • Unpatched vulnerability and exposed remote access feature allowed remote code execution

[$] The beginning of the 7.3 merge window

As of this writing, 2,346 non-merge changesets have been pulled into the mainline repository for the 7.3 kernel release. That, clearly, is a mere down payment on the flood that is to come.

More from Thursday 20 August →