techwire | Technologies

Telegram-канал techwire - Tech Wire

93

Technology news Supporting these networks yamechanic.com/2Kkn TechCrunch Cnet Letstalkbitcoin TheHackersNews EnGadget PCMag Defcon Bitcoin Coindesk Wired Wisprtech KaliLinux BBC SecruityFocus Cisco Qubes-OS Google Wikileaks TorProject GameStop IGN E3

Subscribe to a channel

Tech Wire

Qubes Canary 043
https://www.qubes-os.org/news/2025/06/04/canary-043/

We have published Qubes Canary 043 (https://github.com/QubesOS/qubes-secpack/blob/b0211f33f0c10f13c4ee25600e5dbecbb92bebc8/canaries/canary-043-2025.txt). The text of this canary and its accompanying cryptographic signatures are reproduced below. For an explanation of this announcement and instructions for authenticating this canary, please see the end of this announcement.

Qubes Canary 043


---===[ Qubes Canary 043 ]===---


Statements
-----------

The Qubes security team members who have digitally signed this file [1]
state the following:

1. The date of issue of this canary is June 03, 2025.

2. There have been 107 Qubes security bulletins published so far.

3. The Qubes Master Signing Key fingerprint is:

427F 11FD 0FAA 4B08 0123 F01C DDFA 1A3E 3687 9494

4. No warrants have ever been served to us with regard to the Qubes OS
Project (e.g. to hand out the private signing keys or to introduce
backdoors).

5. We plan to publish the next of these canary statements in the first
fourteen days of September 2025. Special note should be taken if no new
canary is published by that time or if the list of statements changes
without plausible explanation.


Special announcements
----------------------

None.


Disclaimers and notes
----------------------

We would like to remind you that Qubes OS has been designed under the
assumption that all relevant infrastructure is permanently compromised.
This means that we assume NO trust in any of the servers or services
which host or provide any Qubes-related data, in particular, software
updates, source code repositories, and Qubes ISO downloads.

This canary scheme is not infallible. Although signing the declaration
makes it very difficult for a third party to produce arbitrary
declarations, it does not prevent them from using force or other means,
like blackmail or compromising the signers' laptops, to coerce us to
produce false declarations.

The proof of freshness provided below serves to demonstrate that this
canary could not have been created prior to the date stated. It shows
that a series of canaries was not created in advance.

This declaration is merely a best effort and is provided without any
guarantee or warranty. It is not legally binding in any way to anybody.
None of the signers should be ever held legally responsible for any of
the statements made here.


Proof of freshness
-------------------

Tue, 03 Jun 2025 06:49:12 +0000

Source: DER SPIEGEL - International (https://www.spiegel.de/international/index.rss)
Interview with Danish Prime Minister Frederiksen: "If Trump Wants a Trade War, We Will Respond"
A Difficult Relationship: How the Gaza War Is Changing Germany's View of Israel
The German Chancellor's Diplomacy Offensive: Can Friedrich Merz Help Keep Trump from Abandoning Europe?
Death Zone Drama on K2: "Brother, It's Just Me and You"
Ruqqia Fights for Survival: Children in Gaza Facing Malnourishment as Humanitarian Situation Worsens

Source: NYT > World News (https://rss.nytimes.com/services/xml/rss/nyt/World.xml)
Gaza Cease-Fire Negotiations Hit A New Impasse Over An Old Dispute
South Korea’s New President Will Lead A Country More Divided Than Ever
Ukraine and Russia Met for 2nd Round of Talks as Attacks Escalate
In Drone Attacks on Russia, Ukraine Aims for Strategic and Symbolic Blow
Poland Election: Karol Nawrocki Wins Presidential Vote

Source: BBC News (https://feeds.bbci.co.uk/news/world/rss.xml)
Suspect in Colorado fire attack planned for a year, FBI says
Russia and Ukraine fail again to agree ceasefire but commit to prisoner swap
How Ukraine carried out daring 'Spider Web' attack on Russian bombers
Disney makes hundreds more layoffs as it cuts costs
Mount Etna erupts as large plumes rise from volcano

Source: Blockchain.info
00000000000000000000ad08ae4d191a62914466df62c55d1785bea4b4fd2b01


Footnotes
----------

Читать полностью…

Tech Wire

Cisco Nexus Dashboard Fabric Controller SSH Host Key Validation Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-shkv-snQJtjrp?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%20Dashboard%20Fabric%20Controller%20SSH%20Host%20Key%20Validation%20Vulnerability%26vs_k=1

A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices.
This vulnerability is due to insufficient SSH host key validation. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on SSH connections to Cisco NDFC-managed devices, which could allow an attacker to intercept this traffic. A successful exploit could allow the attacker to impersonate a managed device and capture user credentials.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-shkv-snQJtjrp

Security Impact Rating: High


CVE: CVE-2025-20163

Читать полностью…

Tech Wire

Fortnite Star Wars Set to End With Massive Death Star Battle: Here's When It Happens
https://www.cnet.com/tech/gaming/fortnite-star-wars-set-to-end-with-massive-death-star-battle-heres-when-it-happens/#ftag=CADf328eec

After a season of lightsabers and fan favorite rewards, players will enter a one-time-only event to take on Palpatine and the Death Star.

Читать полностью…

Tech Wire

How to Use ChatGPT to Find Your Signature Scent and Actually Get Good Advice
https://www.cnet.com/tech/services-and-software/how-to-use-chatgpt-to-find-your-signature-scent-and-actually-get-good-advice/#ftag=CADf328eec

Does a robot with no sense of smell have what it takes to find your perfect perfume?

Читать полностью…

Tech Wire

Tariff Impacts Are Real: I Found 12 Companies That Have Confirmed Price Hikes
https://www.cnet.com/personal-finance/tariff-impacts-are-real-i-found-12-companies-that-have-confirmed-price-hikes/#ftag=CADf328eec

Whether price hikes have already hit or are coming in the near future, you can definitely expect them from these companies.

Читать полностью…

Tech Wire

Psychologists Are Calling for Guardrails Around AI Use for Young People. Here's What to Watch Out For
https://www.cnet.com/tech/services-and-software/psychologists-are-calling-for-guardrails-around-ai-use-for-young-people-heres-what-to-watch-out-for/#ftag=CADf328eec

The American Psychological Association suggests parents help teens understand how AI works and how to use it wisely.

Читать полностью…

Tech Wire

French Open 2025: How to Watch, Stream Zverev vs. Djokovic Free From Anywhere
https://www.cnet.com/tech/services-and-software/french-open-2025-how-to-watch-stream-zverev-vs-djokovic-free-from-anywhere/#ftag=CADf328eec

World number three takes on the three-time Roland Garros winner.

Читать полностью…

Tech Wire

Earn a Special Apple Watch Running Day Badge, but You'll Have to Work for It
https://www.cnet.com/tech/mobile/earn-a-special-apple-watch-running-day-badge-but-youll-have-to-work-for-it/#ftag=CADf328eec

The race is on for Apple Watch owners to celebrate Global Running Day, but earning this badge won't come easy.

Читать полностью…

Tech Wire

We have entered the agentic AI era, where for the first time, intelligent, autonomous systems will be capable of automating entire workflows in every industry.
More RSS Feeds: https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html (https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html?source=rss)

Читать полностью…

Tech Wire

Today's NYT Connections Hints, Answers and Help for June 4, #724
https://www.cnet.com/tech/gaming/todays-nyt-connections-hints-answers-and-help-for-june-4-724/#ftag=CADf328eec

Hints and answers for Connections for June 4, #724.

Читать полностью…

Tech Wire

Free Movies You Can Stream This June on Tubi, Pluto TV and More
https://www.cnet.com/tech/services-and-software/free-movies-you-can-stream-this-june-on-tubi-pluto-tv-and-more/#ftag=CADf328eec

Here's where you can find Oscar-winner Anora, classic thrillers like Jaws and 28 Days Later, and many more movies for free this June.

Читать полностью…

Tech Wire

Wyze's New Bulb Cam Turns Any Light Bulb Socket Into a Security Camera
https://www.cnet.com/home/security/wyzes-new-bulb-cam-turns-any-light-bulb-socket-into-a-security-camera/#ftag=CADf328eec

The next step in smart home security transforms existing fixtures into batteries for your surveillance equipment.

Читать полностью…

Tech Wire

ChatGPT Will Now Reference Past Conversations With Free-Tier Chatters
https://www.cnet.com/tech/services-and-software/chatgpt-will-now-reference-past-conversations-with-free-tier-chatters/#ftag=CADf328eec

The AI chatbot will change its responses based on your message history, even if you aren't a Plus or Pro subscriber.

Читать полностью…

Tech Wire

Your Social Security Benefits Won't Be Garnished if Your Student Loans Are in Default -- for Now
https://www.cnet.com/personal-finance/loans/student-loans/your-social-security-benefits-wont-be-garnished-if-your-student-loans-are-in-default-for-now/#ftag=CADf328eec

There's still a chance benefits could be garnished in the future. Here's what to do in the meantime.

Читать полностью…

Tech Wire

I Tried Microsoft's New Free AI Video Generator: Here's How to Use It
https://www.cnet.com/tech/services-and-software/i-tried-microsofts-new-free-ai-video-generator-heres-how-to-use-it/#ftag=CADf328eec

Bing Video Creator will come to desktops and Copilot Search, but for now it is only on the Bing Search mobile app.

Читать полностью…

Tech Wire

Cisco Unified Communications Products Command Injection Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vos-command-inject-65s2UCYy?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Unified%20Communications%20Products%20Command%20Injection%20Vulnerability%26vs_k=1

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user.
This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerability by executing crafted commands on the CLI of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vos-command-inject-65s2UCYy

Security Impact Rating: Medium


CVE: CVE-2025-20278

Читать полностью…

Tech Wire

Cisco Customer Collaboration Platform Information Disclosure Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ccp-info-disc-ZyGerQpd?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Customer%20Collaboration%20Platform%20Information%20Disclosure%20Vulnerability%26vs_k=1

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data.
This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ccp-info-disc-ZyGerQpd


Security Impact Rating: Medium


CVE: CVE-2025-20129

Читать полностью…

Tech Wire

Cisco Unified Intelligent Contact Management Enterprise Cross-Site Scripting Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-icm-xss-cfcqhXAg?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Unified%20Intelligent%20Contact%20Management%20Enterprise%20Cross-Site%20Scripting%20Vulnerability%26vs_k=1

A vulnerability in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
This vulnerability is due to insufficient user input validation. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Cisco plans to release software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-icm-xss-cfcqhXAg

Security Impact Rating: Medium


CVE: CVE-2025-20273

Читать полностью…

Tech Wire

Cisco Identity Services Engine Arbitrary File Upload Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-upload-P4M8vwXY?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Arbitrary%20File%20Upload%20Vulnerability%26vs_k=1

A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device.
This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-upload-P4M8vwXY

Security Impact Rating: Medium


CVE: CVE-2025-20130

Читать полностью…

Tech Wire

Don't Trust That Link? Here's How to Make Sure You're Not Faling for a Scam
https://www.cnet.com/tech/services-and-software/can-you-identify-a-scam-link-dont-worry-well-teach-you-how/#ftag=CADf328eec

We'll teach you how to identity phishing links from legitimate ones on your phone or inbox.

Читать полностью…

Tech Wire

Watch UEFA Nations League Semifinal Soccer: Livestream Germany vs. Portugal From Anywhere
https://www.cnet.com/tech/services-and-software/watch-uefa-nations-league-semifinal-soccer-livestream-germany-vs-portugal-from-anywhere/#ftag=CADf328eec

Ronaldo and company take on Julian Nagelsmann's team at the Allianz Arena.

Читать полностью…

Tech Wire

Disney's 'Snow White' Gets a June Streaming Release Date
https://www.cnet.com/tech/services-and-software/disneys-snow-white-gets-a-june-streaming-release-date/#ftag=CADf328eec

The live-action film made just over $205 million at the box office.

Читать полностью…

Tech Wire

Sony's PlayStation State of Play Is Happening Today: Here's How to Watch
https://www.cnet.com/tech/gaming/sonys-playstation-state-of-play-is-happening-today-how-to-watch-it/#ftag=CADf328eec

Some of the big PlayStation 5 games that may be highlighted include Death Stranding 2 and Ghost of Yōtei.

Читать полностью…

Tech Wire

I Ditched My Portable Charger — Here's How I Charge My Phone When I'm on the Go
https://www.cnet.com/tech/no-phone-charger-or-outlet-theres-another-way-to-give-your-device-a-power-boost/#ftag=CADf328eec

I realized I was already carrying a device that doubles as a power bank.

Читать полностью…

Tech Wire

Today's Wordle Hints, Answer and Help for June 4, #1446
https://www.cnet.com/tech/gaming/todays-wordle-hints-answer-and-help-for-june-4-1446/#ftag=CADf328eec

Here are hints and the answer for today's Wordle No. 1,446 for June 4.

Читать полностью…

Tech Wire

Today's NYT Strands Hints, Answers and Help for June 4, #458
https://www.cnet.com/tech/gaming/todays-nyt-strands-hints-answers-and-help-for-june-4-458/#ftag=CADf328eec

Here are hints and answers for the NYT Strands puzzle No. 458 for June 4.

Читать полностью…

Tech Wire

How to Watch the 'Phineas and Ferb' Revival Series
https://www.cnet.com/tech/services-and-software/how-to-watch-the-phineas-and-ferb-revival-series/#ftag=CADf328eec

Spend summer with the stepbrothers, Perry the Platypus and Dr. Doofenshmirtz.

Читать полностью…

Tech Wire

New Footage Confirms Switch 2 Versions of Pokemon Scarlet and Violet Run at 60fps
https://www.cnet.com/tech/gaming/new-footage-confirms-the-switch-2-versions-of-pokemon-scarlet-and-violet-run-at-60-fps/#ftag=CADf328eec

Nintendo's Paldean adventure had often struggled to reach half that frame rate on the original Switch console.

Читать полностью…

Tech Wire

Texas Bill Would Have Banned Social Media for Minors: Here's How
https://www.cnet.com/tech/services-and-software/texas-bill-would-have-banned-social-media-for-minors-heres-how/#ftag=CADf328eec

The legislation aimed let parents to ask for the deletion of social media accounts for kids under 18.

Читать полностью…

Tech Wire

French Open 2025: How to Watch, Stream Paul vs. Alcaraz Free From Anywhere
https://www.cnet.com/tech/services-and-software/french-open-2025-how-to-watch-stream-paul-vs-alcaraz-free-from-anywhere/#ftag=CADf328eec

The defending champ takes on a first-time quarterfinalist at Roland Garros.

Читать полностью…
Subscribe to a channel