A critical Linux vulnerability (CVE-2025-32463) in Sudo lets any local unprivileged user gain root via the --chroot (-R) option
Affects default configs on Ubuntu, Fedora & others — no Sudo rules needed
Fix: Update to Sudo 1.9.17p1+ (no workarounds)
CVSS: 9.8 (Critical)
Highlights persistent risks in open-source privilege handling
https://cybersecuritynews.com/linux-sudo-chroot-vulnerability/
#Linux #Sudo #FOSS #CyberSecurity #InfoSec #OpenSource #Vulnerability #Root #Exploit #SysAdmin #DevSecOps #Tech @TechNews
Healthcare CISOs must secure more than what’s regulated https://www.helpnetsecurity.com/2025/07/03/henry-jiang-ensora-health-healthcare-devsecops-strategy/ #cybersecurity #EnsoraHealth #automation #healthcare #regulation #Don'tmiss #DevSecOps #Features #Hotstuff #strategy #News #CISO
Missed one of my past conference talks? Let’s fix that.
I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.
“Security is Everybody’s Job” https://twp.ai/4in9rk
"regal-main test bundle ran 2.54 times faster than regal test bundle"
#OPA's new parallel test runner doing it's magic in Regal, where 800 unit tests now execute in half a second (down from 1.4). Shipping with the next OPA release, which if all goes well should be later today :)
Amazing work by OPA maintainer Sebastian Spaink
Hi y'all! New to infosec.exchange!
We're RSOLV - building automated security vulnerability detection + remediation (yes, a _fix_, not just a red flag)
While researching AI-generated code, we discovered something wild: 19.6% of AI package suggestions don't exist. Hackers are pre-registering them.
Traditional scanners miss this completely. We detect AND fix it.
Learn how Windows manages authentication, access control, and resource permissions with clarity and precision.
This book offers hands-on PowerShell examples that guide you through key internals like the Security Reference Monitor, SAM, and Kerberos—ideal for researchers, defenders, and developers.
We also discuss Dustin’s new venture, Katilyst (https://twp.ai/9PSJTv), a new startup focused on empowering engineering teams to take ownership of security in a practical, scalable way.
#RSAC2025 #SecurityChampions #Katilyst #AppSec #DevSecOps
2/2
Missed one of my past conference talks? Let’s fix that.
I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs.
“DevSecOps with OWASP DevSlop” https://twp.ai/4in9rP