🦞🌯 Lobster Roll

Stories by lattera

backdoor in upstream xz/liblzma leading to ssh server compromise (openwall.com)
Heap-based buffer overflow in Sudo (CVE-2021-3156) (openwall.com)
OpenBSD 7.3 (openbsd.org)
Not-a-Linux distro review: SerenityOS is a Unix-y love letter to the ’90s (arstechnica.com)
Password Managers (lock.cmpxchg8b.com)
Memory Safe Languages in Android 13 (security.googleblog.com)
Are all BSDs created equally? A survey of BSD kernel vulnerabilities (media.defcon.org)
Phrack 72 (phrack.org)
Signal Becomes a 501(c)(3) Foundation (signal.org)
FreeBSD 13.0-RELEASE Now Available (lists.freebsd.org)
Is It Time to Rewrite the Operating System in Rust? (infoq.com)
RSYNC: 6 vulnerabilities (openwall.com)
System Down: A systemd-journald exploit (qualys.com)
Sovereign Tech Fund to Invest €686,400 in FreeBSD Infrastructure Modernization (freebsdfoundation.org)
Firefox 64.0 Release Available Today (blog.mozilla.org)
Ghidra - A software reverse engineering (SRE) suite of tools developed by NSA's Research Directorate (ghidra-sre.org)
FreeBSD 14.1-RELEASE Announcement (freebsd.org)
Local Privilege Escalation in OpenBSD's dynamic loader (CVE-2019-19726) (openwall.com)
A libc in LLVM (lists.llvm.org)
Vulnerabilities in OpenBSD's hypervisor (marc.info)
The RIPE NCC has run out of IPv4 Addresses (ripe.net)
NSA's Ghidra source code released (github.com)
Private contact discovery for Signal (signal.org)
I'm posting here due to its interesting use of Intel SGX.
Future of 32-bit platform support in FreeBSD (lists.freebsd.org)
More than you really wanted to know about patch (lists.landley.net)
Panama Papers (panamapapers.sueddeutsche.de)
Massive security breach at US universities (dorper.me)
OpenSSH 8.2 released (openssh.com)
Phrack 69 Released (phrack.org)
Retbleed: Arbitrary Speculative Code Execution with Return Instructions (comsec.ethz.ch)