TLDR

TLDR Information Security 2024-04-01

Backdoor in xz leads to SSH Compromise 💀, AT&T Confirms massive data breach ⚠️, EU Election security guidance 🇪🇺

Datadog research finds widespread use of long-lived credentials, other risks (Sponsor)

🔓
Attacks & Vulnerabilities

Backdoor in xz/liblzma leading to SSH Compromise (4 minute read)

AT&T confirms data breach and resets millions of customer passcodes (2 minute read)

Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching (4 minute read)

🧠
Strategies & Tactics

Why small B2B SaaS companies should focus on presales information security (4 minute read)

Vulnerability Management Lifecycle in DevSecOps (10 minute read)

Mind the Patch Gap: Exploiting an io_uring Vulnerability in Ubuntu (16 minute read)

🧑‍💻
Launches & Tools

NetExec (GitHub Repo)

cleanowners (GitHub Repo)

Root (Product Launch)

🎁
Miscellaneous

Ubuntu Will Manually Review Snap Store After Crypto Wallet Scams (3 minute read)

EU publishes election security guidance for social media giants and others in scope of DSA (3 minute read)

DinodasRAT Linux variant targets users worldwide (3 minute read)

⚡️
Quick Links

Thread Hijacking: Phishes That Prey on Your Curiosity (4 minute read)

A Year in Review of Zero-Days Exploited In-the-Wild in 2023 (20 minute read)

OpenAI deems its voice cloning tool too risky for general release (3 minute read)

Curated news 📰, research 🧑‍🔬, and tools 🔒 for information security professionals
Join 300,000 readers for one daily email