Category: security
-

New Bluetooth Flaw Let Hackers Take Over Android, Linux
A critical Bluetooth security flaw could be exploited by threat actors to take control of Android, Linux, macOS and iOS devices. Tracked as CVE-2023-45866, the issue relates to a case of authentication bypass that enables attackers to connect to susceptible devices and inject keystrokes to achieve code execution as the victim. “Multiple Bluetooth stacks have…
-

Kali 2023.4 with GNOME 45 and 15 New Tools
Kali Linux 2023.4, the fourth and final version of 2023, is now available for download, with fifteen new tools and the GNOME 45 desktop environment. Kali Linux is a Linux distribution created for ethical hackers and cybersecurity professionals to perform penetration testing, security audits, and research against networks. With this final release of 2023, the…
-

Crypto Keys Stolen: New Attack
An error as small as a single flipped memory bit is all it takes to expose a private key. For the first time, researchers have demonstrated that a large portion of cryptographic keys used to protect data in computer-to-server SSH traffic are vulnerable to complete compromise when naturally occurring computational errors occur while the connection…
-

JPMorgan Chase Achieves FinOps Certification
SAN FRANCISCO, Nov. 1, 2023 /PRNewswire/ — The FinOps Foundation, a part of The Linux Foundation’s non-profit technology consortium focused on advancing the people and practice of cloud financial management, announced today that JPMorgan Chase has achieved the FinOps Certified Enterprise certification, a key measure of advanced FinOps practices that help guide best practices for…
-

Foundation Warns Risk in 3/4 of a Billion Sites
SAN FRANCISCO, Nov. 1, 2023 /PRNewswire/ — Global web infrastructure is in a precarious position based on new research by the OpenJS Foundation thanks to an Open Source Security Foundation (OpenSSF) grant. The OpenJS Foundation is announcing the results of an end-user audit based on an IDC survey that shows three-quarters of a billion websites…
-

GNOME Linux systems exposed to RCE attacks
A memory corruption vulnerability in the open-source libcue library can let attackers execute arbitrary code on Linux systems running the GNOME desktop environment. “libcue”, a library designed for parsing cue sheet files, is integrated into the Tracker Miners file metadata indexer, which is included by default in the latest GNOME versions. Cue sheets (or CUE…