
Episode 243
It's the end of the year for official duties for the Ubuntu Security team so we take a look back on the security highlights of 2024 for Ubun...
Radio and PodcastLive Radio & PodcastsOpening Radio and Podcast...

Radio and PodcastLive Radio & PodcastsFetching podcast shows and categories...
Radio and PodcastLive Radio & PodcastsFetching podcast episodes...

A weekly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of the security vulnerabilities and fixes from the last week as well as...

It's the end of the year for official duties for the Ubuntu Security team so we take a look back on the security highlights of 2024 for Ubun...

This week we dive into the details of a number of local privilege escalation vulnerablities discovered by Qualys in the needrestart package,...

This week we take a deep dive into the latest Linux malware, GoblinRAT to look at how malware is evolving to stay stealthy and evade detecti...

For the third and final part in our series for Cybersecurity Awareness Month, Alex is again joined by Luci as well as Diogo Sousa to discuss...

In the second part of our series for Cybersecurity Awareness Month, Luci is back with Alex, along with Eduardo Barretto to discuss our top c...

For the first in a 3-part series for Cybersecurity Awareness month, Luci Stanescu joins Alex to discuss the recent CUPS vulnerabilities as w...

John and Maximé have been talking about Ubuntu's AppArmor user namespace restrictions at the the Linux Security Summit in Europe this past w...

The long awaited preview of snapd-based AppArmor file prompting is finally seeing the light of day, plus we cover the recent 24.04.1 LTS rel...

A recent Microsoft Windows update breaks Linux dual-boot - or does it? This week we look into reports of the recent Windows patch-Tuesday up...

This week we take a deep dive behind-the-scenes look into how the team handled a recent report from Snyk's Security Lab of a local privilege...

This week we take a look at the recent Crowdstrike outage and what we can learn from it compared to the testing and release process for secu...

This week we deep-dive into one of the best vulnerabilities we've seen in a long time _regreSSHion_ - an unauthenticated, remote, root code-...

A look into CISA's Known Exploited Vulnerability Catalogue is on our minds this week, plus we look at vulnerability updates for gdb, Ansible...

This week we bring you a special edition of the podcast, featuring an interview between Ijlal Loutfi and Karen Horovitz who deep-dive into C...

As the podcast winds down for a break over the next month, this week we talk about RSA timing side-channel attacks and the recently announce...

The team is back from Madrid and this week we bring you some of our plans for the upcoming Ubuntu 24.10 release, plus we talk about Google's...

Ubuntu 24.04 LTS is finally released and we cover all the new security features it brings, plus we look at security vulnerabilities in, and...

John and Georgia are at the Linux Security Summit presenting on some long awaited developments in AppArmor and we give you all the details i...

This week we cover the recent reports of a new local privilege escalation exploit against the Linux kernel, follow-up on the xz-utils backdo...

It's been an absolutely manic week in the Linux security community as the news and reaction to the recent announcement of a backdoor in the...

This week we bring you a sneak peak of how Ubuntu 23.10 fared at Pwn2Own Vancouver 2024, plus news of malicious themes in the KDE Store and...

We cover recent Linux malware from the Magnet Goblin threat actor, plus the news of Ubuntu 23.10 as a target in Pwn2Own Vancouver 2024 and w...

Andrei is back to discuss recent academic research into malware within the Python/PyPI ecosystem and whether it is possible to effectively c...

The Linux kernel.org CNA has assigned their first CVEs so we revisit this topic to assess the initial impact on Ubuntu and the CVE ecosystem...

This week the Linux kernel project announced they will be assigning their own CVEs so we discuss the possible implications and fallout from...

AppArmor unprivileged user namespace restrictions are back on the agenda this week as we survey the latest improvements to this hardening fe...

For the first episode of 2024 we take a look at the case of a raft of bogus FOSS CVEs reported on full-disclosure as well as AppSec tools in...

For the final episode of 2023 we discuss creating PoCs for vulns in tar and the looming EOL for Ubuntu 23.04, plus we look into security upd...

Mark Esler is our special guest on the podcast this week to discuss the OpenSSF's Compiler Options Hardening Guide for C/C++ plus we cover v...

This week we take a deep dive into the Reptar vuln in Intel processors plus we look into some relic vulnerabilities in Squid and OpenZFS and...

As we ease back into regular programming, we cover the various activities the team got up to over the past few weeks whilst away in Riga for...

With the Ubuntu Summit just around the corner, we preview a couple talks by the Ubuntu Security team, plus we look at security updates for O...

After a well-deserved break, we're back looking at the recent Ubuntu 23.10 release and the significant security technologies it introduces a...

It's the Linux Security Summit in Bilbao this week and we bring you some highlights from our favourite talks, plus we cover the 25 most stub...

Andrei is back this week with a deep dive into recent research around CVSS scoring inconsistencies, plus we look at a recent Ubuntu blog pos...

This week we detail the recently announced and long-awaited feature of TPM-backed full-disk encryption for the upcoming Ubuntu 23.10 release...

This week we cover reports of "fake" CVEs and their impact on the FOSS security ecosystem, plus we look at security updates for PHP, Fast DD...

This week we talk about HTTP Content-Length handling, intricacies of group management in container environments and making sure you check yo...

We're back after unexpectedly going AWOL last week to bring you the latest in Ubuntu Security including the recently announced Downfall and...

This week we look at the recent Zenbleed vulnerability affecting some AMD processors, plus we cover security updates for the Linux kernel, a...

This week we talk about the dual use purposes of eBPF - both for security and for exploitation, and how you can keep your systems safe, plus...

We take a sneak peek at the upcoming AppArmor 4.0 release, plus we cover vulnerabilities in AccountsService, the Linux Kernel, ReportLab, GN...

This week we look at the top 25 most dangerous vulnerability types, as well as the announcement of the program for LSS EU, and we cover secu...

For our 200th episode, we discuss the impact of Red Hat's decision to stop publicly releasing the RHEL source code, plus we cover security u...

For our 199th episode Andrei looks at Fuzzing Configurations of Program Options plus we discuss Google's findings on the `io_uring` kernel s...

This week we investigate the mystery of failing GPG signatures for the 16.04 ISO images, plus we look at security updates for CUPS, Avahi, t...

The venerable Ubuntu 18.04 LTS release has transitioned into ESM, plus we look at Till Kamppeter's excellent guide on how to set up your Git...

This week we look at some recent security developments from PyPI, the Linux Security Summit North America and the pending transition of Ubun...

Alex and Camila discuss security update management strategies after a recent outage at Datadog was attributed to a security update for syste...

The team are back from Prague and bring with them a new segment, drilling into recent academic research in the cybersecurity space - for thi...