Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


freitasm

BDFL - Memuneh
80646 posts

Uber Geek
+1 received by user: 41030

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

#318046 10-Dec-2024 07:30
Send private message

A supply chain attack was identified last week and is now doing the news round.

 

     

  1. https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/ 
  2. https://www.theregister.com/2024/12/09/openwrt_firmware_vulnerabilities/ 

 

Builds created in the last seven days (from yesterday) seem clean but there's no guarantees about older builds.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Create new topic
cddt
1965 posts

Uber Geek
+1 received by user: 1904


  #3318680 10-Dec-2024 08:06
Send private message

The first link has the write up from the researcher who discovered the vulnerability - it's very interesting. 

 

 

 

Also impressed with how the OpenWRT team responded: 

 

 Soon after acknowledging the issue, they stopped the sysupgrade.openwrt.org service temporarily and investigated the issue. Within 3 hours, they released the fixed version and restarted the service.





My referral links: BigPipeMercury


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.