#update

anonymiss@despora.de

#BLUFFS: #Bluetooth Forward and Future Secrecy Attacks and Defenses

Source: https://francozappa.github.io/post/2023/bluffs-ccs23/

TL;DR: If you are within range of a Bluetooth connection, you can force both devices into an insecure #encryption which can be cracked using brute force. The #workaround is to reject weak encryption via #software. Since there are never #updates for devices that have already been sold, any Bluetooth #connection with an old device must be considered insecure. Bluetooth can be monitored up to 100 meters with special antennas.

#bug #fail #security #hack #warning #danger #problem #update #news #CVE-2023-24023 #smartphone #vulnerability

anonymiss@despora.de

#Apple is planing a feature to #update an #iPhone without interaction of the owner. So it is a forced update with which you can bring everything on the iPhone. This is exactly what the #FBI, #NSA and #TSA dream about at night.

Apple is planning a new system for its retail stores that will update the software on iPhones prior to sale. The company has developed a proprietary pad-like device that the store can place boxes of iPhones on top of. That system can then wirelessly turn on the iPhone, update its #software and then power it back down — all without the phone’s packaging ever being opened. The company aims to begin rolling this out to its stores before the end of the year.

Source: https://www.bloomberg.com/news/newsletters/2023-10-15/apple-october-2023-executive-promotions-new-vps-of-retail-software-operations-lnrh4t94

#news #technology #conspiracy #Fnord #security #smartphone #problem #trust

tekaevl@diasp.org

If all goes to plan, Nautilus’ new two-panel look will roll out to all when GNOME 45 is released in September.

The new design extends Nautilus’ sidebar to the full height of the window, gains the title “Places”, and becomes the new home for the file manager’s hamburger menu:
https://www.omglinux.com/nautilus-split-pane-gnome-45/
#gnome #linux #nautilus
#update
#exposed #aEvl_us

anonymiss@despora.de

Easy-to-exploit local privilege escalation vulnerabilities in #Ubuntu #Linux affect 40% of Ubuntu cloud workloads

source: https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability

CVE-2023-2640 and CVE-2023-32629 were found in the #OverlayFS module in Ubuntu, which is a widely used Linux #filesystem that became highly popular with the rise of containers as its features enable the deployment of dynamic filesystems based on pre-built images. OverlayFS serves as an attractive attack surface as it has a history of numerous logical vulnerabilities that were easy to exploit. This makes the new discovered vulnerabilities especially risky given the exploits for the past OverlayFS vulnerabilities work out of the box without any changes.

#security #os #software #update #bug #problem #news #exploit #hack #hacker #server #vulnerability

faab64@diasp.org

Latest reports at 23:30 CET

  • Al Arabiya reports from Russian sources that there will be "change in leadership" in the Ministry of Defense tomorrow

  • Prigozhin confirmed that he accepted the deal via audio message. Previous statements that he rejected them were faked. "We came within 200km of Moscow without shedding a single drop of blood, now there is still the possibility of blood being shed, and understanding that responsibility we will turn around our convoys and return to base."

  • Wagner source says "concessions announcement to follow" amid Shoigu and Gerasimov rumors.

  • Noel: “Prigozhin was offered to give up the idea of going to #Moscow, and in response was offered the security of Wagner. They also promised to resolve the issue of #Shoigu and #Gerasimov,” Russian media report.

  • Sources claim that some #Wagner fighters are dissatisfied with the decision to reach an agreement

  • Defense Minister Sergei Shoigu has allegedly been detained.

  • Russian troops stationed at checkpoints in Moscow have packed up and are leaving.

The picture is from earlier today where defensive settings were prepared around strategic locations in Moscow

#Russia #Update #CoupInRussia #Putin

kennychaffin@diasp.org

They's on top of it this month! Just popped up on my phone.

Google Pixel Update - May 2023
Announcement
Google Pixel Update - May 2023

Hello Pixel Community,

We have provided the monthly software update for May 2023. All supported Pixel devices running Android 13 will receive these software updates starting today. The rollout will continue over the next week in phases depending on carrier and device. Users will receive a notification once the OTA is available for their device. We encourage you to check your Android version and update to receive the latest software.

Details of this month’s security fixes can be found on the Android Security Bulletin: https://source.android.com/security/bulletin

Thanks,
Google Pixel Support Team

https://support.google.com/pixelphone/thread/213627684?hl=en&sjid=12638080890493754116-NA

#android #pixel #update