ZeroHour
Product

curl

0 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

USN-8670-3: curl vulnerability

Ubuntu issued USN-8670-3 updating curl for Ubuntu 26.04 LTS to fix a flaw where wrong client certificates could be used on reused connections.

Ubuntu Security Notice USN-8670-3 extends the curl fix from USN-8670-1 to Ubuntu 26.04 LTS. The flaw, discovered by Joshua Rogers, involves incorrect handling of connection reuse when client certificate settings change, potentially causing the wrong client certificate to be presented. The issue can lead to authentication mix-ups rather than remote code execution.

Ubuntu Security Notices · 7d agoAdvisory

curl: a CVE dispute

curl maintainer Daniel Stenberg details a dispute over a CVE assigned to the curl project.

Daniel Stenberg, lead maintainer of curl, published a post describing a dispute over a CVE affecting the project. The piece covers the vulnerability disclosure and CVE assignment process rather than a new exploitable flaw. Given curl's ubiquity, the process discussion is relevant to defenders tracking CVE quality, but no immediate risk is described.

Lobsters · security · 15d agoVulnerability

Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains

Microsoft correlates over 30 rotating domains to track MacSync Stealer, which steals passwords, SSH keys, wallets and AWS credentials.

Microsoft Defender Experts tracked MacSync Stealer, a macOS information stealer, by analyzing recurring behaviors rather than individual domains, linking over 30 domains to the campaign. The infection chain uses the ClickFix social engineering technique, tricking victims into pasting commands in Terminal, then uses curl, AppleScript, and native macOS tools to deploy the payload. The stealer targets Keychain data, browser passwords and cookies, SSH keys, AWS credentials, Kubernetes configurations, and Ledger and Trezor wallet data, staging data before exfiltration via chunked HTTP PUT requests. RST Cloud identified rapid C2 infrastructure replacement after initial public disclosure.

Security Affairs · 27d agoMalware