CVE-2025-31160 Atop 2.11 heap problems
https://openwall.com/lists/oss-security/2025/03/29/1
#HackerNews #CVE-2025-31160 #heap #vulnerabilities #security #issues #OpenWall #OSS #security
Kaspersky analysis of the backdoor in XZ | Securelist
https://securelist.com/xz-backdoor-story-part-1/112354/
"(...) On March 29, 2024, a single message on the #Openwall OSS-security mailing list marked an important discovery for the information security, open source and #Linux communities: the discovery of a malicious #backdoor in #XZ. (...)
Unlike other supply chain attacks (...) in Node.js, PyPI (...), this incident was a multi-stage operation that almost succeeded in compromising #SSH servers on a global scale. (...)"
#Squid games: In February 2021, #security researcher Joshua Rogers performed a security audit of Squid #proxy and said he uncovered 55 flaws in the project's C++ source code.
Fast forward to today, and Rogers asserts only 20 of those flaws have been fixed.
"After two and a half years of waiting, I have decided to release the issues publicly," Rogers wrote in a post to the #Openwall security mailing list.
We'd like to say don't panic … but maybe?
https://www.theregister.com/2023/10/13/squid_proxy_bugs_remain_unfixed/
TONIGHT, 7pm EST join #DEFCON201 Co-Founder GI Jack on the show "Archvile: A Linux Perspective" on the #DC201 LIVE Stream. Get a tour of #OpenWall John The Ripper and #GZDoom Mods!
#Twitch: https://twitch.tv/defcon201live
#DLive: https://dlive.tv/defcon201
#YouTube: https://youtube.com/channel/UCYDQaOHbK5trRU2CDgb0qSg
@torproject : http://axqzx4s6s54s32yentfqojs3x5i7faxza6xo3ehd4bzzsg2ii4fv2iid.onion/channel/UCYDQaOHbK5trRU2CDgb0qSg
OpenWall presenta el proyecto de protección del Kernel http://maslinux.es/openwall-presenta-el-proyecto-de-proteccion-del-kernel/ #protección #Seguridad #openwall #kernel #LKRG