Security Leftovers

-
Security updates for Friday
Security updates have been issued by Debian (squashfs-tools, tomcat9, and wordpress), Fedora (openssh), openSUSE (kernel, mbedtls, and rpm), Oracle (httpd, kernel, and kernel-container), SUSE (firefox, kernel, and rpm), and Ubuntu (linux-azure, linux-azure-5.4).
-
Apache Releases Security Advisory for Tomcat | CISA
The Apache Software Foundation has released a security advisory to address a vulnerability in multiple versions of Tomcat. An attacker could exploit this vulnerability to cause a denial of service condition.
-
Security Risks of Client-Side Scanning
Even before Apple made their announcement, law enforcement shifted their battle for back doors to client-side scanning. The idea is that they wouldn’t touch the cryptography, but instead eavesdrop on communications and systems before encryption or after decryption. It’s not a cryptographic back door, but it still a back door — and brings with it all the insecurities of a back door.
I’m part of a group of cryptographers that has just published a paper discussing the security risks of such a system. (It’s substantially the same group that wrote a similar paper about key escrow in 1997, and other “exceptional access” proposals in 2015. We seem to have to do this every decade or so.) In our paper, we examine both the efficacy of such a system and its potential security failures, and conclude that it’s a really bad idea.
-
The Open Source Security Foundation receives $ 10 million in funding - itsfoss.net
The Linux Foundation has announced a $ 10 million commitment to the OpenSSF (Open Source Security Foundation), an effort to improve the security of open source software. Funds raised through royalties from parent companies of OpenSSF, including Amazon, Cisco, Dell Technologies, Ericsson, Facebook, Fidelity, GitHub, Google, IBM, Intel, JPMorgan Chase, Microsoft, Morgan Stanley, Oracle, Red Hat, Snyk, and VMware …
-
- Login or register to post comments
Printer-friendly version
- 2535 reads
PDF version
More in Tux Machines
- Highlights
- Front Page
- Latest Headlines
- Archive
- Recent comments
- All-Time Popular Stories
- Hot Topics
- New Members
- Stable Kernels: 5.18.8, 5.15.51, 5.10.127, and 5.4.202
- Microsofters Deflecting (From Microsoft's Security Woes to "Linux")
- How to install latest GNU Image Manipulation Program (GIMP) on Linux
- EndeavourOS Artemis 22.6 released
- Ubuntu Touch OTA-23 Rolls Out to All Supported Ubuntu Phones, This is What’s New
- Today in Techrights
- today's leftovers
- today's howtos
- Hardware leftovers
- Programming Leftovers
- Security Leftovers
- HP Linux Imaging and Printing Drivers Now Support Ubuntu 22.04 LTS and Fedora 36
- Russians are searching for pirated Microsoft products and switching to Linux as the Western corporate exodus hits software updates and services: report
- Android Leftovers
- Best Free and Open Source Alternatives to Autodesk 3ds Max
- Games: Monkey Island, Elementallis, and More
- Video: Qt, Choice, and Destination Linux
- today's howtos
- RHEL / Red Hat / IBM Leftovers
- How to Exclude Packages from Transactions using DNF in RHEL Linux
Another roundup
This Week In Security: The Apache Fix Miss, Github (Malicious) Actions, And Shooting The Messenger | Hackaday
KubeCon + CloudNativeCon
KubeCon + CloudNativeCon Highlights Security for Open Source