Below the Surface episode 82 was recorded on September 10, 2026, with host Paul Asadoorian joined by Vlad Babkin and Chase Snyder. The conversation moves across several current security stories, but…
TLDR: Exploit. This is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions, having unprivileged user…
Le support de la délégation Kerberos côté Linux a été étendu afin de pouvoir emprunter une identité arbitraire au sein d'une même forêt. Cette identité peut être ensuite utilisée pour accéder à une…
Maintenant que l'IA aide à la recherche de vulnérabilités et au patch diffing de kernel, faisant sauter les embargos de responsible disclosure, la période est pour le moins intense pour les…
Dans cet article, nous allons présenter Pike, un agent LLM expérimental capable de générer et d'analyser des traces d'exécution de programmes Linux. Nous montrerons qu'avec une architecture simple…
Une connaissance fine des protocoles utilisés par les applications s’avère être un prérequis nécessaire pour étudier la sécurité des applications. Lors de ces dernières, nous avons été amenés à…
VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than…
Posted by SOFIA ETCHEPARE DARONCO on Sep 18 FWIW PPPoE is quite ubiquitous, though normally for gateway ISP communication rather than anything in end user machines.
The Chrome team is excited to announce the promotion of Chrome 155 to the Beta channel for Windows, Mac and Linux. Chrome 155.0.8059.5 contains our usual under-the-hood performance and stability…
The Stable channel has been updated to 153.0.8010.47/.48 for Windows and Mac and 153.0.8010.47 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is…
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally…
A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - IPv6 networking; -…
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally…
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for…
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - OCFS2 file…
The Dev channel has been updated to 156.0.8063.3 for Windows, Mac and Linux. A partial list of changes is available in the Git log. Interested in switching release channels?