Language Selection

English French German Italian Portuguese Spanish

Security Leftovers

Filed under
Security
  • Cisco kills leaked CIA 0-day that let attackers commandeer 318 switch models

    As previously reported, the zero-day exploit allowed attackers to issue commands that remotely execute malicious code on 318 models of Cisco switches. The attack code was published in early March by WikiLeaks as part of its Vault7 series of leaks, which the site is billing as the largest publication of intelligence documents ever.

    The bug resides in the Cisco Cluster Management Protocol (CMP), which uses the telnet protocol to deliver signals and commands on internal networks. It stems from a failure to restrict telnet options to local communications and the incorrect processing of malformed CMP-only telnet options.

  • Open source password strength meter could help boost account security

    It's no secret that most people are rubbish at choosing passwords -- it's something that's proved time and time again when the annual list of common passwords is released. To help overcome the problem, and hopefully increase the security of people's accounts, a team of researchers from the Carnegie Mellon University and the University of Chicago have created an open source password meter that provides advice about how to strengthen a password.

  • Apache OpenOffice: Not dead yet, you'll just have to wait until mid-May for mystery security fixes
  • NIST to security admins: You've made passwords too hard

    Despite the fact that cybercriminals stole more than 3 billion user credentials in 2016, users don't seem to be getting savvier about their password usage. The good news is that how we think about password security is changing as other authentication methods become more popular.

  • Google Docs Phishing Scam a Game Changer

More in Tux Machines

CentOS Linux 7 and 6 Users Receive New Microcode Updates for Intel and AMD CPUs

CentOS Linux is an open-source, free, enterprise-class, and community-supported operating system based on and compatible with Red Hat Enterprise Linux. As such, it regularly receives new important security updates as soon as they are released upstream by Red Hat. About two weeks ago, CentOS Linux 7 and 6 users received kernel and microcode updates that mitigated the Meltdown and Spectre security vulnerabilities unearthed earlier this month. However, after some thorough testing, Red Hat discovered that these updated microcode firmware developed by Intel and AMD caused hardware issues. Read more

Google moves to Debian for in-house Linux desktop

Google has officially confirmed the company is shifting its in-house Linux desktop from the Ubuntu-based Goobuntu to a new Linux distro, the DebianTesting-based gLinux. Margarita Manterola, a Google Engineer, quietly announced Google would move from Ubuntu to Debian-testing for its desktop Linux at DebConf17 in a lightning talk. Manterola explained that Google was moving to gLinux, a rolling release based on Debian Testing. Read more

Android Support Removed from Intel Graphics Driver Debugging Tool for Linux

For those unfamiliar with intel-gpu-tools, it's a collection of tools for GNU/Linux distribution that allows the debugging the official Intel graphics driver for Intel GPUs. Tools include a GPU hang dumping program, performance microbenchmarks for regression testing the DRM, as well as a performance monitor. The latest release, intel-gpu-tools 1.21, adds quite a bunch of changes, including automatic loading of DRM modules when opening a DRM device, much-improved GPU quiescing code to more thoroughly flush pending work and old data, as well as production support for the Meson build system while automake is still kept around. Read more

Educational-Oriented Escuelas Linux 5.6 Distro Released with LibreOffice 6.0

Based on the latest release of the Ubuntu-based and Enlightenment-focused Bodhi Linux operating system, Escuelas Linux 5.6 is powered by the Linux 4.14.13 kernel, which includes patches against the Meltdown and Spectre security vulnerabilities, and comes with a bunch of up-to-date educational apps. These include the OnlyOffice 4.8.6 office suite (only for the 64-bit edition), Vivaldi 1.13, Chromium 63, Google Chrome 63, and Mozilla Firefox 57 "Quantum" web browsers, Geogebra 5.0.414 geometry, algebra, statistics, and calculus app, latest Adobe Flash Player 28 plugin, and the upcoming LibreOffice 6.0 open-source office suite. Read more