Pulling the plug on the database would cause "an immediate cascading effect that will impact vulnerability management on a global scale"
#Cybersecurity #Funding #Software #Vulnerabilities #TechNews
Nonprofit That Tracks Software...
Pulling the plug on the database would cause "an immediate cascading effect that will impact vulnerability management on a global scale"
#Cybersecurity #Funding #Software #Vulnerabilities #TechNews
Nonprofit That Tracks Software...
The U.S. Government funding to MITRE, which maintains CVE data, will stop today. New vulnerabilities will no longer be added to the glossary, posing a risk to national security.
Read the full report: https://www.technadu.com/mitre-funding-by-the-u-s-government-to-stop-today-security-teams-left-alarmed/586183/
PHP Core Security Audit Results
For the 4 notable CVEs, one is not published.
CVE-2024-8928: Memory-related vulnerability in PHP’s filter handling, leading to segmentation faults.
#php #vulnerability #vulnerabilities
https://vulnerability.circl.lu/bundle/9bbd91e2-309f-4b35-9b31-fc613b3101d9
AI Vulnerability Finding
Microsoft is reporting that its AI systems are able to find <a href="https://www.bleepingcomputer.com/... https://www.schneier.com/blog/archives/2025/04/ai-vulnerability-finding.html
NEW -
DCG Domain Blocklist available - last updated 2025/04/08
1689244 - Domains blocked with that build !
Supercharging your content blocker to increase privacy and security.
All available lists:
- uBlockOrigin
- Hosts format & Hosts format with wildcards
- dnsmasq with wildcards
Ready to use lists combined from many permissively licensed sources.
https://divested.dev/pages/dnsbl
#divested #DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus #hackernews
#opensource #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #foss #freeyourmind
WhatsApp Vulnerability Could Facilitate Remote Code Execution https://www.securityweek.com/whatsapp-vulnerability-could-facilitate-remote-code-execution/ #Vulnerabilities #vulnerability #WhatsApp #Meta #MIME
WhatsApp Vulnerability Could Facilitate Remote Code Execution https://www.securityweek.com/whatsapp-vulnerability-could-facilitate-remote-code-execution/ #Vulnerabilities #vulnerability #WhatsApp #Meta #MIME
NEW -
DCG real-ucode
Actually provides the latest CPU microcode for AMD and Intel
Version: 2025-04-25
Release: 1
updated ucode for amd and intel with that one !
https://github.com/divestedcg/real-ucode/
#divested
#DivestedComputingGroup
#fsf #FUTO #Fedora #alpinelinux #hardening #linuxtech #cybersec #cybersecurity #infosec #foss
#hackernews #opensource #android #skynet #linuxsecurity #ucode #vulnerabilities #vulnerability #freeyourmind
NEW -
DCG rpm-hardened_malloc available
pkgver = 2025/04/04
pkgrel = 1
Release Note = more coverage
Compatibility:
- Fedora 39/40/etc.
- Arch Linux
Hardened allocator designed for modern systems
https://codeberg.org/divested/rpm-hardened_malloc
#divested #DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #hardened_malloc #hardenedmalloc #linuxtech #cybersec #cybersecurity #antivirus #hackernews
#opensource #android #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #hardening #foss #infosec #freeyourmind
https://www.europesays.com/1970212/ Heritage Foundation documentary highlights aging U.S. nuclear arsenal vulnerabilities #Aging #China #Conflicts #Documentary #HeritageFoundation #IndoPacific #nuclear #U.S.NuclearArsenal #vulnerabilities
NEW -
DCG Brace Build 2025/04/04 - 1
Release Note: Fix bluetooth on F42
Toolkit compatible with multiple Linux distros that allows for installation of handpicked applications, along with corresponding configs that have been tuned for reasonable privacy and security.
Compatibility:
Arch Linux
CentOS 9/Stream
Debian 12
Fedora 39/40/41 (preferred)
openSUSE Tumbleweed
https://codeberg.org/divested/brace
#divested
#DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus
#opensource #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #skynet #foss #freeyourmind
NEW -
DCG Domain Blocklist available - last updated 2025/04/01
1688453 - Domains blocked with that build !
Supercharging your content blocker to increase privacy and security.
All available lists:
- uBlockOrigin
- Hosts format & Hosts format with wildcards
- dnsmasq with wildcards
Ready to use lists combined from many permissively licensed sources.
https://divested.dev/pages/dnsbl
#divested #DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus #hackernews
#opensource #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #foss #freeyourmind
NEW -
DCG rpm-hardened_malloc available
last updated:
2025/03/24
pkgver = 2025/01/27
pkgrel = 19
Compatibility:
- Fedora 39/40/etc.
- Arch Linux
Hardened allocator designed for modern systems
https://codeberg.org/divested/rpm-hardened_malloc
#divested #DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #hardened_malloc #hardenedmalloc #linuxtech #cybersec #cybersecurity #antivirus #hackernews
#opensource #android #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #hardening #foss #infosec #freeyourmind
#Microsoft - Analyzing #opensource bootloaders: Finding #vulnerabilities faster with #AI - By leveraging Microsoft #Security #Copilot to expedite the vulnerability discovery process, Microsoft Threat Intelligence uncovered several vulnerabilities in multiple open-source bootloaders, impacting all operating systems relying on Unified Extensible Firmware Interface (UEFI) Secure Boot as well as IoT devices. The vulnerabilities found in the GRUB2 bootloader (commonly used as a Linux bootloader) and U-boot and Barebox bootloaders (commonly used for embedded systems), could allow threat actors to gain and execute arbitrary code. https://www.microsoft.com/en-us/security/blog/2025/03/31/analyzing-open-source-bootloaders-finding-vulnerabilities-faster-with-ai/
The “CVE and AI-related Vulnerabilities” blog series is documenting the journey the CVE Program is on determining how to address #CVE assignments for #vulnerabilities in an #AI-enabled world.
Read article #2 in the series here: https://medium.com/@cve_program/cve-id-assignment-and-cve-record-publication-for-ai-related-vulnerabilities-78a649bda815
The Signal Chat Leak and the NSA
US National Security Advisor Mike Waltz, who started the now-infamous group chat coordinating a US attack against the Yemen-based Houthis on March 15, is seemingly now suggesting that the secure messaging service Signal has security vulnerabilitie... https://www.schneier.com/blog/archives/2025/03/the-signal-chat-leak-and-the-nsa.html
Latest issue of my curated #cybersecurity and #infosec list of resources for week #13/2025 is out!
It includes the following and much more:
➝ DNA of 15 Million People for Sale in #23andMe Bankruptcy,
➝ #Trump administration accidentally texted a journalist its war plans,
➝ Critical Ingress #NGINX controller vulnerability allows RCE without authentication,
➝ #Cyberattack hits Ukraine's state railway,
➝ Troy Hunt's Mailchimp account was successfully phished,
➝ #OpenAI Offering $100K Bounties for Critical #Vulnerabilities,
➝ #Meta AI is now available in #WhatsApp for users in 41 European countries... and cannot be turned off
Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end
https://infosec-mashup.santolaria.net/p/infosec-mashup-13-2025
NEW -
D-WRT builds available: 2025-03-26
update to kernel 6.6.84
https://divested.dev/unofficial-openwrt-builds/mvebu-linksys
https://codeberg.org/divested/Divested-WRT
#divested
#DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus #hackernews
#opensource #android #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #foss #freeyourmind
NEW -
DCG real-ucode
Actually provides the latest CPU microcode for AMD and Intel
Version: 2025-03-24
updated ucode for amd and intel with that one !
https://github.com/divestedcg/real-ucode/
#divested
#DivestedComputingGroup
#fsf #FUTO #Fedora #alpinelinux #hardening #linuxtech #cybersec #cybersecurity #infosec #foss
#hackernews #opensource #android #skynet #linuxsecurity #ucode #vulnerabilities #vulnerability #freeyourmimd
The “CVE and AI-related Vulnerabilities” blog series is documenting the journey the CVE Program is on determining how to address #CVE assignments for #vulnerabilities in an #AI-enabled world.
Interested? Start here: https://medium.com/@cve_program/cve-and-ai-related-vulnerabilities-3ae6ad8ae81b