Ubuntu Security Podcast show

Ubuntu Security Podcast

Summary: A weekly podcast talking about the latest developments and updates from the Ubuntu Security team, including a summary of the security vulnerabilities and fixes from the last week as well as a discussion on some of the goings on in the wider Ubuntu Security community.

Join Now to Subscribe to this Podcast
  • Visit Website
  • RSS
  • Artist: Ubuntu Security Team
  • Copyright: Copyright 2018-2024 Canonical

Podcasts:

 Episode 32 | File Type: audio/mpeg | Duration: 23:58

This week we look at updates to cover the latest Intel CPU vulnerabilities (MDS - aka RIDL, Fallout, ZombieLoad), plus other vulnerabilies in PostgreSQL, ISC DHCP, Samba and more, whilst special guest this week is Seth Arnold from the Ubuntu Security Team to talk Main Inclusion Review code audits.

 Episode 31 | File Type: audio/mpeg | Duration: 22:14

This week we cover security fixes for GNOME Shell, FFmpeg, Sudo, Ghostscript and others, and we talk to Joe McManus about malicious Dockerhub images, Git repos being ransomed more.

 Episode 30 | File Type: audio/mpeg | Duration: 20:48

Fixes for 19 different vulnerabilities across MySQL, Dovecot, Memcached and others, plus we talk to Joe McManus about the recent iLnkP2P IoT hack and the compromise of DockerHub's credentials database and more.

 Episode 29 | File Type: audio/mpeg | Duration: 21:03

This week we look at fixes from the past two weeks including BIND, NTFS-3G, Dovecot, Pacemaker and more, plus we follow up last episodes IoT security discussion with Joe McManus talking about Ubuntu Core. Finally we cover the release of Ubuntu 19.04 Disco Dingo and the transition of Ubuntu 14.04 Trusty Tahr to Extended Security Maintenance.

 Episode 28 | File Type: audio/mpeg | Duration: 21:44

This week we look at updates for vulnerabilities in wpa\_supplicant, Samba, systemd, wget and more and we talk to Joe about IoT security (or the prevailing lack-thereof).

 Episode 27 | File Type: audio/mpeg | Duration: 29:53

Carpe Diem for Apache HTTP Server, plus updates for Dovecot, PolicyKit and the Linux kernel, and we talk to Joe McManus about the recent Asus ShadowHammer supply chain attack and more.

 Episode 26 | File Type: audio/mpeg | Duration: 20:14

This week we look security updates for a heap of packages including Firefox & Thunderbird, PHP & QEMU, plus we discuss Facebook's recent password storage incident as well as some listener hardening tips and more.

 Episode 25 | File Type: audio/mpeg | Duration: 14:44

Ghostscript is back to haunt us for another week, plus we look at vulnerabilities in ntfs-3g, snapd, firefox and more.

 Episode 24 | File Type: audio/mpeg | Duration: 13:20

A look at recent fixes for vulnerabilities in poppler, WALinuxAgent, the Linux kernel and more. We also talk about some listener feedback on Ubuntu hardening and the launch of Ubuntu 14.04 ESM.

 Episode 23 | File Type: audio/mpeg | Duration: 13:10

This week we look at security updates for the Linux kernel, PHP and NVIDIA drivers, revealing recent research into GPU based side-channel attacks plus we call for suggestions on hardening features and more.

 Episode 22 | File Type: audio/mpeg | Duration: 15:57

This week we cover security updates including Firefox, Thunderbird, OpenSSL and another Ghostscript regression, plus we look at a recent report from Capsule8 comparing Linux hardening features across various distributions and we answer some listener questions.

 Episode 21 | File Type: audio/mpeg | Duration: 17:33

Double episode covering the security updates from the last 2 weeks, including snapd (DirtySock), systemd and more, plus we talk responsible disclosure and some open positions on the Ubuntu Security team.

 Episode 20 | File Type: audio/mpeg | Duration: 16:55

This week we look at Linux kernel updates for all releases, OpenSSH, dovecot, curl and more. Plus we answer some frequently asked questions for Ubuntu security, in particular the perennial favourite of why we choose to just backport security fixes instead of doing rolling package version updates to resolve outstanding CVEs.

 Episode 19 | File Type: audio/mpeg | Duration: 14:49

This week we look at updates to the Linux kernel in preparation for the 18.04.2 release, plus updates for Open vSwitch, Firefox, Avahi, LibVNCServer and more. We also revisit and discuss upstream changes to the mincore() system call to thwart page-cache side-channel attacks first discussed in [Episode 17](https://ubuntusecuritypodcast.org/episode-17/).

 Episode 18 | File Type: audio/mpeg | Duration: 14:27

This week we look at some details of the 46 unique CVEs addressed across the supported Ubuntu releases and take a deep dive into the recent apt security bug.

Comments

Login or signup comment.