QubesOS released a security update addressing a critical vulnerability that allows arbitrary code execution through an error reporting backchannel in the copy-to-VM function. The flaw affects multiple Qubes versions.
A vulnerability in QubesOS's copy-to-VM feature creates an information disclosure path via error reporting mechanisms that can be exploited for arbitrary code execution. The backchannel exists in how the system handles and reports errors during inter-VM file transfers.
Qubes Security Bulletin 118 details the issue and provides patches for affected systems. Users are advised to apply updates immediately, particularly those running older versions of the OS.
The vulnerability highlights how security-focused operating systems must carefully audit error handling and inter-process communication channels. Even systems designed with strong isolation principles require ongoing scrutiny of edge cases in system utilities.
The security community's response on platforms like Hacker News (51 comments, 123 points) emphasizes the importance of responsible disclosure and prompt patching in security-critical software. Qubes developers have made the full advisory and fixes available on their official security page.
Android devices offer built-in protections against malicious apps, scam calls, and privacy breaches. Activating the correct security settings is essential to maximize these defenses.
File servers remain essential infrastructure for most organizations, but managing access permissions securely grows increasingly complex as systems expand. tenfold Software has outlined five best practices to simplify administration and enforce least-privilege access.
Two Nigerian men have been extradited to the U.S. and charged in connection with sextortion schemes that led to the deaths of two minors in Mississippi and North Carolina.
Threat actors are exploiting a vulnerability chain in Microsoft SharePoint to execute arbitrary code on unpatched servers. Defused has confirmed attackers are leveraging proof-of-concept exploits in the wild.