Language Selection

English French German Italian Portuguese Spanish

Security: Patches, Whonix, IPFire and More

Filed under
Security
  • Security updates for Thursday

    Security updates have been issued by CentOS (kernel, ksh, python-pillow, and thunderbird), Debian (opensmtpd, proftpd-dfsg, and rake), Fedora (NetworkManager-ssh), openSUSE (chromium), and SUSE (libexif, mariadb, ovmf, python3, and squid). 

  • Whonix VirtualBox 15.0.0.8.9 - Point Release! - vanguards; TCP ISN Leak Protection; Extensive Hardening!

    This is a point release.

    Download Whonix for VirtualBox:

  • Build your career in Computer Forensics: List of Digital Forensic Tools - Part I

    Digital devices are present everywhere and considered to be the primary source of evidence in the case of cybercrime. Out of all the devices, phones and laptops are the top weapons used in cybercrimes. Regardless of who the device belonged to, either the victim or suspect, it offers an abundance of data to investigate the crime. But retrieving evidence from these devices in a secure environment can be very challenging. To overcome the time constraint and other complications, cyber forensic professionals use digital forensic tools.  

  • What are Open Source Security Approaches? With Examples

    Open source security approaches enable organizations to secure their applications and networks while avoiding expensive proprietary security offerings. 

    An open source approach allows organizations to secure their applications across cloud providers and other platforms using platform-agnostic APIs. These APIs are written by contributors to the open source software code while cloud providers may use open source code that allows the open APIs to connect to the cloud.

    Open source approaches, for security or not, also bring in collaboration across an industry. It isn’t just one organization that benefits from a program or technology, but everyone who contributes to and uses it.

    The open source projects and programs used as examples in this article come from two major open source entities: The Linux Foundation and the Cloud Native Computing Foundation (CNCF). The two also work closely together to further the projects under their purview.

  • Cloud Snooper: Hackers Using Linux Kernel Driver To Attack Cloud Server [Ed: So, if you install malicious software in Linux, due to recklessness or sabotage, it'll do malicious things. How is that a Linux weakness?]

    Whether you’re a Linux user or not, you must have heard the buzzword about the Linux — “Best OS for security.” Well, it is true, but being a computer program, Linux also has some downside that challenges its security.

    Talking about the security risks, recently, SophosLab published a report about a new malware dubbed Cloud Snooper, that can compromise the security of any Linux or other OS based servers by deploying a kernel driver.

  • IPFire on AWS: Update to IPFire 2.25 - Core Update 141

    Today, we have updated IPFire on AWS to IPFire 2.25 - Core Update 141 - the latest official release of IPFire.

    Since IPFire is available on AWS, we are gaining more and more users who are securing their cloud infrastructure behind an easy to configure, yet fast and secure firewall.

    This update adds the rewritten DNS stack and brings many bug fixes to the cloud.

More FUD

  • The “Cloud Snooper” malware that sneaks into your Linux servers [Ed: Sophos citing itself, hyping up the threat is installing malicious software on one's own server]

    SophosLabs has just published a detailed report about a malware attack dubbed Cloud Snooper.

    The reason for the name is not so much that the attack is cloud-specific (the technique could be used against pretty much any server, wherever it’s hosted), but that it’s a sneaky way for cybercrooks to open up your server to the cloud, in ways you very definitely don’t want, “from the inside out”.

    The Cloud Snooper report covers a whole raft of related malware samples that our researchers found deployed in combination.

OpenSMTPD

  • OpenSMTPD Email Server Vulnerability Threatens Many Linux and BSD Systems [Ed: It is this package, not the operating systems (GNU/Linux rarely uses this)]

    A critical vulnerability has been discovered in the OpenBSD email server OpenSMTPD. Exploiting the flaw could allow remote code execution attacks. The seriousness of the vulnerability poses a threat to the integrity of OpenBSD and Linux systems.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

More in Tux Machines

Raspberry Pi 4: Chronicling the Desktop Experience – Calculators – Week 31

This is a weekly blog about the Raspberry Pi 4 (“RPI4”), the latest product in the popular Raspberry Pi range of computers. The desktop calculator is a small utility that’s shipped with all major operating systems. It’s usually a standard affair, and designed for basic use. They typically include trigonometric functions, logarithms, factorials, parentheses and a memory function. In this article I’m surveying some of the notable calculator software available for the RPI4. I’m not looking at computer algebra systems although they are available from the RPI4. Let’s first look at galculator. Read more

Today in Techrights

Linux Kernel Development and NVIDIA Graphics

  • Micron's HSE Open-Source Storage Engine Ticks Up To v1.7.1

    Announced at the end of April was Micron's HSE as a new open-source storage engine designed for offering speedy performance and lower latency on modern solid-based storage, especially for systems employing 3D XPoint technology. Version 1.7.1 of HSE was released today as their first open-source release since going public with this technology. HSE 1.7.0 was released a week prior to Micron announcing this open-source project in April while has now been succeeded by v1.7.1. This heterogeneous-memory storage engine over the past month has seen a number of fixes throughout, cleaning up code as a result of code review, fixing up some of the examples, and other work.

  • Linux 5.8 Feature Queue Has Multiple Performance Optimizations, Intel Rocket Lake, Other Hardware

    If all goes well Linux 5.7 should reach stable this weekend and that in turn will mark the start of the Linux 5.8 merge window. With our monitoring of the various "-next" branches for weeks already, here is a look at some of what is on the table for this next version of the Linux kernel.

  • NVIDIA 440.66.15 Vulkan Linux Driver Offers Up More Fixes

    NVIDIA has been quite aggressive recently with their new Vulkan beta drivers for Windows and Linux with today marking another such release. NVIDIA over the course of May is now on their third Vulkan beta series after the prior two added new Vulkan extensions and different fixes, including improvements to their KHR ray-tracing support. Today's release is focused squarely on delivering more fixes to users/developers.

"Contributing to KDE is easier than you think" and KIO FUSE Beta (4.95.0) Released

  • Contributing to KDE is easier than you think – Websites from scratch

    This is a series of blog posts explaining different ways to contribute to KDE in an easy-to-digest manner. The purpose of this series originated from how I feel about asking users to contribute back to KDE. I firmly believe that showing users how contributing is easier than they think is more effective than simply calling them out and directing them to the correct resources; especially if, like me, said user suffers from anxiety or does not believe they are up to the task, in spite of their desire to help back. Last time I talked about websites, I taught how to port current KDE websites to Markdown, and this led to a considerable influx of contributors, since it required very little technical knowledge. This blog post however is directed to people who are minimally acquainted with git, html/css, and Markdown. We will be learning a bit of how Jekyll and scss work too.

  • KIO FUSE Beta (4.95.0) Released

    It’s a great pleasure to announce that KIO FUSE has a second Beta release available for testing! We encourage all who are interested to test and report their findings (good or bad) here. Note that, the more people who test (and let us know that they’ve tested), the quicker we’ll be confident to have a 5.0.0 release. You can find the repository here. To compile KIO FUSE, simply run kdesrc-build kio-fuse or follow the README. If your distributor is really nice they may already have KIO FUSE packaged but if they don’t, encourage them to do so!