Ubuntu 24.04 LTS is finally released and this week on the #Ubuntu #Security Podcast we've got your back, covering all the new security features it brings, plus we look at security vulnerabilities in, and updates for, FreeRDP, Zabbix, CryptoJS, cpio, less, JSON5 and a heap more https://ubuntusecuritypodcast.org/episode-227/
Ubuntu Security
mastodon 4.7.3We've got your back.
On the #Ubuntu Security Podcast this week we cover some bits from @LinuxSecSummit@social.kernel.org EU including #AppArmor userns restrictions in Ubuntu 24.04 LTS as well as the official announcement of permission prompting in Ubuntu 24.10, a new release of Intel TDX for Ubuntu 24.04 LTS and more https://ubuntusecuritypodcast.org/episode-237/
The #Ubuntu #Security Podcast is back in your ears! The team is back from Madrid and this week we bring you some of our plans for the upcoming Ubuntu 24.10 release, plus we talk about Google’s kernelCTF project and Mozilla’s PDF.js sandbox when covering security updates for the Linux kernel, Firefox, Spreadsheet::ParseExcel, idna and more https://ubuntusecuritypodcast.org/episode-228/
It’s the end of the year for official duties for the #Ubuntu #Security team so on the podcast this week we take a look back on the security highlights of 2024 for Ubuntu and predict what is coming in 2025 https://ubuntusecuritypodcast.org/episode-243/
On the latest episode of the #Ubuntu Security Podcast the long awaited preview of snapd-based AppArmor file prompting is finally seeing the light of day, plus we cover the recent Ubuntu 24.04.1 LTS release and the podcast officially moves to a fortnightly cycle https://ubuntusecuritypodcast.org/episode-236/
The #Ubuntu Security Podcast is back in your ears for the first in a 3-part series for Cybersecurity Awareness month - Luci Stanescu joins @alexmurray@fosstodon.org to discuss the recent CUPS vulnerabilities as well as the evolution of cybersecurity since the origin of the internet https://ubuntusecuritypodcast.org/episode-238/
A recent Microsoft Windows update breaks Linux dual-boot - or does it? This week on the #Ubuntu Security Podcast we look into reports of the recent Windows patch-Tuesday update breaking dual-boot, including a deep-dive into the technical details of Secure Boot, SBAT, grub, shim and more, plus we look at a vulnerability in GNOME Shell and the handling of captive portals as well https://ubuntusecuritypodcast.org/episode-235/
As the #Ubuntu #Security Podcast winds down for a break over the next month, this week we talk about RSA timing side-channel attacks and the recently announced DNSBomb vulnerability as we cover security updates in VLC, OpenSSL, Netatalk, WebKitGTK, amavisd-new, Unbound, Intel Microcode and more https://ubuntusecuritypodcast.org/episode-229/
The #Ubuntu Security Podcast is back in your ears - this week we take a look at the recent Crowdstrike outage and what we can learn from it compared to the testing and release process for security updates in Ubuntu, plus we cover details of vulnerabilities in popper, phpCAS, EDK II, Python, OpenJDK and one package with over 300 CVE fixes in a single update (yes it's the Linux kernel) https://ubuntusecuritypodcast.org/episode-233/
The #Ubuntu Security Podcast is back in your feed and this week we take a deep dive into the latest Linux malware, GoblinRAT to look at how malware is evolving to stay stealthy and evade detection and how malware authors are learning from modern software development along the way https://ubuntusecuritypodcast.org/episode-241/
On the #Ubuntu Security Podcast this week we take a deep dive behind-the-scenes look into how the team handled a recent report from Snyk’s Security Lab of a local privilege escalation vulnerability in wpa_supplicant plus we cover security updates in Prometheus Alertmanager, OpenSSL, Exim, snapd, Gross, curl and more https://ubuntusecuritypodcast.org/episode-234/
This week on the #Ubuntu Security Podcast we deep-dive into one of the best vulnerabilities we’ve seen in a long time regreSSHion - an unauthenticated, remote, root code-execution vulnerability in OpenSSH. Plus we cover updates for Plasma Workspace, Ruby, Netplan, FontForge, OpenVPN and a whole lot more https://ubuntusecuritypodcast.org/episode-232/
The #Ubuntu Security Podcast is back a week early from our scheduled downtime to bring you a special edition, featuring an interview between Ijlal Loutfi and Karen Horovitz who deep-dive into Confidential Computing. Ranging from a high-level discussion of the need for and the features provided by confidential computing, through to the specifics of how this is implemented in Ubuntu and a look at similar future security technologies that are on the horizon. https://ubuntusecuritypodcast.org/episode-230/
On the latest episode of the #Ubuntu Security Podcast we dive into the local privesc vulns discovered by @qualys@bird.makeup in needrestart, covering topics from confused deputies to the inner workings of the /proc filesystem and responsible disclosure as well https://ubuntusecuritypodcast.org/episode-242/
A new episode of the #Ubuntu Security Podcast just dropped! A look into CISA’s Known Exploited Vulnerability Catalogue is on our minds this week, plus we look at vulnerability updates for gdb, Ansible, CUPS, libheif, Roundcube, the Linux kernel and more https://ubuntusecuritypodcast.org/episode-231/