The first vulnerability, CVE-2025-5054, affects Ubuntu’s Apport crash reporting system, while the second, CVE-2025-4598, impacts systemd-coredump, the default core dump handler used across Red Hat Enterprise Linux 9 and 10, as well as Fedora distributions.
Leak extortion is the main issue nowadays, not covered by backups, I'm afraid.
!selfhosted@lemmy.world to the win!
I didn't know about that tool. Apparently, it is a CDR, which I like very much. I'm not aware of any good open-source implementations.
Very nice approach!
Some points about the article:
Nature of the Vulnerability: The vulnerability is a security flaw that allows leaking the email associated with a YouTube channel by exploiting endpoints from both YouTube and Google Pixel Recorder.
Impact: It allows an attacker to obtain the email associated with any YouTube channel, which can lead to phishing attacks, privacy invasion, and other malicious activities. This potentially affects all YouTube users who own a channel.
Fix Status: The vulnerability has been fixed by Google. Both parts of the exploit were resolved by 02/09/2025, and the report was disclosed on 02/12/2025.
Apparently was not related to a cyber attack, as stated in status page (https://status.proton.me/)
We have resolved all service outages, and the situation has been stable for some time. We have identified the root cause of the problem, implemented a fix, and are now monitoring the results. Jan 09, 2025 - 19:27 CET
For now, the threat actor is just claiming that they hacked BT. No prove whatsoever. Groups usually post a sample of the data when they claim a victim, but that is not the case, for now.
Thanks! Corrected