AUTO-UPDATED

This Week in Security: Ubiquiti Fixes, and FreeBSD Joins the Club you Don’t Want to Join

Ubiquiti has released critical security patches for six vulnerabilities, while other major industry developments include a botnet takedown, new phishing threats, and emerging hardware-based tracking techniques.

Key Points

  • Ubiquiti patched six security flaws in its equipment, including one critical vulnerability rated 9.1 and another scoring a perfect 10.0 on the CVE scale.
  • A coalition including CrowdStrike and Google successfully disrupted the Glassworm botnet, which targeted open-source repositories like NPM and PyPI to steal credentials.
  • The FBI issued a warning regarding Kali365, a "Phishing-as-a-Service" platform that automates credential theft for Microsoft 365 accounts.
  • Researchers identified a new side-channel attack called FROST, which uses SSD performance timing via JavaScript to fingerprint devices and monitor user activity.
  • Microsoft is enhancing C# memory safety in .NET 11 to prevent common vulnerabilities like use-after-free errors by adopting stricter object lifetime enforcement.

Why it Matters

These developments highlight the persistent risks within both enterprise network infrastructure and the global software supply chain. As attackers increasingly leverage automated services and sophisticated side-channel techniques, organizations must prioritize rapid patch management and adopt modern memory-safe programming practices to maintain security.
Hackaday Published by Mike Kershaw
Read original