< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

Cybersecurity report identifies critical Linux flaws and industrial risks

A weekly review of 16 critical cybersecurity vulnerabilities highlights significant risks across multiple sectors. In the Linux ecosystem, an 18-year-old flaw was identified that could allow local users to obtain root rights and escape containers. Additionally, vulnerabilities in SCTP and Open vSwitch emphasize the ongoing necessity for system updates.

In the realm of hardware security, a firmware vulnerability in COLDCARD wallets, caused by a faulty random number generator, reportedly enabled an estimated theft of $88.6 million in Bitcoin. Industrial security is also under scrutiny, as scans revealed over 4,000 American industrial controllers used in water systems remain exposed online, coinciding with confirmed attacks on U.S. water networks.

The integrity of the vulnerability reporting ecosystem is being challenged. Researchers noted the appearance of fake critical CVEs, and JFrog discovered that out of 55 vulnerabilities submitted by a single GitHub account, 54 were entirely fabricated. Furthermore, artificial intelligence is expanding the attack surface through tools such as Diffusers and various AI meeting agents.

Entities

Allen-Bradley · Coldcard · GitHub · JFrog · Linux