Ubuntu Security Podcast
Activity Overview
Episode publication activity over the past year
Episodes
Episode 243
20 Dec 2024
Contributed by Lukas
It's the end of the year for official duties for the Ubuntu Security team so we take a look back on the security highlights of 2024 for Ubuntu and p...
Episode 242
29 Nov 2024
Contributed by Lukas
This week we dive into the details of a number of local privilege escalation vulnerablities discovered by Qualys in the needrestart package, coverin...
Episode 241
14 Nov 2024
Contributed by Lukas
This week we take a deep dive into the latest Linux malware, GoblinRAT to look at how malware is evolving to stay stealthy and evade detection and h...
Episode 240
31 Oct 2024
Contributed by Lukas
For the third and final part in our series for Cybersecurity Awareness Month, Alex is again joined by Luci as well as Diogo Sousa to discuss future ...
Episode 239
18 Oct 2024
Contributed by Lukas
In the second part of our series for Cybersecurity Awareness Month, Luci is back with Alex, along with Eduardo Barretto to discuss our top cybersecu...
Episode 238
04 Oct 2024
Contributed by Lukas
For the first in a 3-part series for Cybersecurity Awareness month, Luci Stanescu joins Alex to discuss the recent CUPS vulnerabilities as well as t...
Episode 237
20 Sep 2024
Contributed by Lukas
John and Maximé have been talking about Ubuntu's AppArmor user namespace restrictions at the the Linux Security Summit in Europe this past week, pl...
Episode 236
06 Sep 2024
Contributed by Lukas
The long awaited preview of snapd-based AppArmor file prompting is finally seeing the light of day, plus we cover the recent 24.04.1 LTS release and...
Episode 235
23 Aug 2024
Contributed by Lukas
A recent Microsoft Windows update breaks Linux dual-boot - or does it? This week we look into reports of the recent Windows patch-Tuesday update bre...
Episode 234
09 Aug 2024
Contributed by Lukas
This week we take a deep dive behind-the-scenes look into how the team handled a recent report from Snyk's Security Lab of a local privilege escalat...
Episode 233
02 Aug 2024
Contributed by Lukas
This week we take a look at the recent Crowdstrike outage and what we can learn from it compared to the testing and release process for security upd...
Episode 232
05 Jul 2024
Contributed by Lukas
This week we deep-dive into one of the best vulnerabilities we've seen in a long time _regreSSHion_ - an unauthenticated, remote, root code-executio...
Episode 231
28 Jun 2024
Contributed by Lukas
A look into CISA's Known Exploited Vulnerability Catalogue is on our minds this week, plus we look at vulnerability updates for gdb, Ansible, CUPS, ...
Episode 230
20 Jun 2024
Contributed by Lukas
This week we bring you a special edition of the podcast, featuring an interview between Ijlal Loutfi and Karen Horovitz who deep-dive into Confident...
Episode 229
31 May 2024
Contributed by Lukas
As the podcast winds down for a break over the next month, this week we talk about RSA timing side-channel attacks and the recently announced DNSBom...
Episode 228
24 May 2024
Contributed by Lukas
The team is back from Madrid and this week we bring you some of our plans for the upcoming Ubuntu 24.10 release, plus we talk about Google's kernelC...
Episode 227
03 May 2024
Contributed by Lukas
Ubuntu 24.04 LTS is finally released and we cover all the new security features it brings, plus we look at security vulnerabilities in, and updates ...
Episode 226
19 Apr 2024
Contributed by Lukas
John and Georgia are at the Linux Security Summit presenting on some long awaited developments in AppArmor and we give you all the details in a snea...
Episode 225
12 Apr 2024
Contributed by Lukas
This week we cover the recent reports of a new local privilege escalation exploit against the Linux kernel, follow-up on the xz-utils backdoor from ...
Episode 224
05 Apr 2024
Contributed by Lukas
It's been an absolutely manic week in the Linux security community as the news and reaction to the recent announcement of a backdoor in the xz-utils...
Episode 223
22 Mar 2024
Contributed by Lukas
This week we bring you a sneak peak of how Ubuntu 23.10 fared at Pwn2Own Vancouver 2024, plus news of malicious themes in the KDE Store and we cover...
Episode 222
18 Mar 2024
Contributed by Lukas
We cover recent Linux malware from the Magnet Goblin threat actor, plus the news of Ubuntu 23.10 as a target in Pwn2Own Vancouver 2024 and we detail...
Episode 221
08 Mar 2024
Contributed by Lukas
Andrei is back to discuss recent academic research into malware within the Python/PyPI ecosystem and whether it is possible to effectively combat it...
Episode 220
01 Mar 2024
Contributed by Lukas
The Linux kernel.org CNA has assigned their first CVEs so we revisit this topic to assess the initial impact on Ubuntu and the CVE ecosystem, plus w...
Episode 219
16 Feb 2024
Contributed by Lukas
This week the Linux kernel project announced they will be assigning their own CVEs so we discuss the possible implications and fallout from such a s...
Episode 218
09 Feb 2024
Contributed by Lukas
AppArmor unprivileged user namespace restrictions are back on the agenda this week as we survey the latest improvements to this hardening feature in...
Episode 217
02 Feb 2024
Contributed by Lukas
For the first episode of 2024 we take a look at the case of a raft of bogus FOSS CVEs reported on full-disclosure as well as AppSec tools in Ubuntu ...
Episode 216
15 Dec 2023
Contributed by Lukas
For the final episode of 2023 we discuss creating PoCs for vulns in tar and the looming EOL for Ubuntu 23.04, plus we look into security updates for...
Episode 215
08 Dec 2023
Contributed by Lukas
Mark Esler is our special guest on the podcast this week to discuss the OpenSSF's Compiler Options Hardening Guide for C/C++ plus we cover vulnera...
Episode 214
01 Dec 2023
Contributed by Lukas
This week we take a deep dive into the Reptar vuln in Intel processors plus we look into some relic vulnerabilities in Squid and OpenZFS and finally...
Episode 213
17 Nov 2023
Contributed by Lukas
As we ease back into regular programming, we cover the various activities the team got up to over the past few weeks whilst away in Riga for the Ubu...
Episode 212
27 Oct 2023
Contributed by Lukas
With the Ubuntu Summit just around the corner, we preview a couple talks by the Ubuntu Security team, plus we look at security updates for OpenSSL, ...
Episode 211
20 Oct 2023
Contributed by Lukas
After a well-deserved break, we're back looking at the recent Ubuntu 23.10 release and the significant security technologies it introduces along wit...
Episode 210
22 Sep 2023
Contributed by Lukas
It's the Linux Security Summit in Bilbao this week and we bring you some highlights from our favourite talks, plus we cover the 25 most stubborn sof...
Episode 209
15 Sep 2023
Contributed by Lukas
Andrei is back this week with a deep dive into recent research around CVSS scoring inconsistencies, plus we look at a recent Ubuntu blog post on the...
Episode 208
08 Sep 2023
Contributed by Lukas
This week we detail the recently announced and long-awaited feature of TPM-backed full-disk encryption for the upcoming Ubuntu 23.10 release, plus w...
Episode 207
01 Sep 2023
Contributed by Lukas
This week we cover reports of "fake" CVEs and their impact on the FOSS security ecosystem, plus we look at security updates for PHP, Fast DDS, JOSE ...
Episode 206
25 Aug 2023
Contributed by Lukas
This week we talk about HTTP Content-Length handling, intricacies of group management in container environments and making sure you check your retur...
Episode 205
18 Aug 2023
Contributed by Lukas
We're back after unexpectedly going AWOL last week to bring you the latest in Ubuntu Security including the recently announced Downfall and GameOver...
Episode 204
04 Aug 2023
Contributed by Lukas
This week we look at the recent Zenbleed vulnerability affecting some AMD processors, plus we cover security updates for the Linux kernel, a high ...
Episode 203
21 Jul 2023
Contributed by Lukas
This week we talk about the dual use purposes of eBPF - both for security and for exploitation, and how you can keep your systems safe, plus we cove...
Episode 202
07 Jul 2023
Contributed by Lukas
We take a sneak peek at the upcoming AppArmor 4.0 release, plus we cover vulnerabilities in AccountsService, the Linux Kernel, ReportLab, GNU Screen...
Episode 201
30 Jun 2023
Contributed by Lukas
This week we look at the top 25 most dangerous vulnerability types, as well as the announcement of the program for LSS EU, and we cover security upd...
Episode 200
23 Jun 2023
Contributed by Lukas
For our 200th episode, we discuss the impact of Red Hat's decision to stop publicly releasing the RHEL source code, plus we cover security updates f...
Episode 199
16 Jun 2023
Contributed by Lukas
For our 199th episode Andrei looks at Fuzzing Configurations of Program Options plus we discuss Google's findings on the `io_uring` kernel subsystem...
Episode 198
09 Jun 2023
Contributed by Lukas
This week we investigate the mystery of failing GPG signatures for the 16.04 ISO images, plus we look at security updates for CUPS, Avahi, the Linux...
Episode 197
02 Jun 2023
Contributed by Lukas
The venerable Ubuntu 18.04 LTS release has transitioned into ESM, plus we look at Till Kamppeter's excellent guide on how to set up your GitHub proj...
Episode 196
26 May 2023
Contributed by Lukas
This week we look at some recent security developments from PyPI, the Linux Security Summit North America and the pending transition of Ubuntu 18.04...
Episode 195
19 May 2023
Contributed by Lukas
Alex and Camila discuss security update management strategies after a recent outage at Datadog was attributed to a security update for systemd on Ub...
Episode 194
11 May 2023
Contributed by Lukas
The team are back from Prague and bring with them a new segment, drilling into recent academic research in the cybersecurity space - for this inaugu...
Episode 193
13 Apr 2023
Contributed by Lukas
The release of Ubuntu 23.04 Lunar Lobster is nigh so we take a look at some of the things the security team has been doing along the way, plus it's ...
Episode 192
31 Mar 2023
Contributed by Lukas
Ubuntu gets pwned at Pwn2Own 2023, plus we cover security updates for vulns in GitPython, object-path, amanda, url-parse and the Linux kernel - and ...
Episode 191
24 Mar 2023
Contributed by Lukas
This week saw the unexpected release of Ubuntu 20.04.6 so we go into the detail behind that, plus we talk Everything Open and we cover security upda...
Episode 190
10 Mar 2023
Contributed by Lukas
The Ubuntu Security Podcast is on a two week break to focus on [Everything Open 2023](https://2023.everythingopen.au/) in Melbourne next week - come...
Episode 189
03 Mar 2023
Contributed by Lukas
This week we dive into the BlackLotus UEFI bootkit teardown and find out how this malware has some roots in the FOSS ecosystem, plus we look at secu...
Episode 188
24 Feb 2023
Contributed by Lukas
This week the common theme is vulnerabilities in setuid-root binaries and their use of environment variables, so we take a look at a great blog post...
Episode 187
17 Feb 2023
Contributed by Lukas
After the announcement of Ubuntu Pro GA last week, we take the time to dispel some myths around all things Ubuntu Pro, esm-apps and apt etc, plus Ca...
Episode 186
10 Feb 2023
Contributed by Lukas
The Ubuntu Security Podcast is back for 2023! We ease into the year with coverage of the recently announced launch of Ubuntu Pro as GA, plus we look...
Episode 185
16 Dec 2022
Contributed by Lukas
For our final episode of 2022, Camila is back with a special holiday themed discussion of the security of open source code, plus we hint at what is ...
Episode 184
09 Dec 2022
Contributed by Lukas
This week we cover Mark Esler's keynote address from UbuCon Asia 2022 on Improving FOSS Security, plus we look at security vulnerabilities and updat...
Episode 183
02 Dec 2022
Contributed by Lukas
This week we look at a recent report from Elastic Security Labs on the global Linux threat landscape, plus we look at a few of the security vulnerab...
Episode 182
25 Nov 2022
Contributed by Lukas
After a longer-than-expected break, the Ubuntu Security Podcast is back, covering some highlights of the various security items planned during the 2...
Episode 181
21 Oct 2022
Contributed by Lukas
It's the release of Ubuntu 22.10 Kinetic Kudu, and we give you all the details on what's new and improved, with a particular focus on the security f...
Episode 180
14 Oct 2022
Contributed by Lukas
Ubuntu Pro beta is announced and we cover all the details with Lech Sandecki and Eduardo Barretto, plus we cover security updates for DHCP, kitty, T...
Episode 179
30 Sep 2022
Contributed by Lukas
Finer grained control for unprivileged user namespaces is on the horizon for Ubuntu 22.10, plus we cover security updates for PCRE, etcd, OAuthLib, ...
Episode 178
23 Sep 2022
Contributed by Lukas
You can't test your way out of security vulnerabilities (at least when writing your code in C), plus we cover security updates for Intel Microcode, ...
Episode 177
16 Sep 2022
Contributed by Lukas
Alex talks with special guests Nishit Majithia and Matthew Ruffell about a recent systemd regression on Ubuntu 18.04 LTS plus we cover security upda...
Episode 176
09 Sep 2022
Contributed by Lukas
On this week's episode we dive into the Shikitega Linux malware report from AT&T Alien Labs, plus we cover security updates for the Linux kernel, cu...
Episode 175
02 Sep 2022
Contributed by Lukas
An increased rate of CVEs in curl is a good thing, and we'll tell you why, plus we cover security updates for the Linux kernel, Firefox, Schroot, sy...
Episode 174
26 Aug 2022
Contributed by Lukas
This week we cover the debate around the decision in Ubuntu 22.10 to disable presenting platform security assessments to end users via GNOME, plus w...
Episode 173
19 Aug 2022
Contributed by Lukas
This week we take a look at the recent announcement of .NET 6 for Ubuntu 22.04 LTS, plus we cover security updates for the Linux kernel, Booth, We...
Episode 172
12 Aug 2022
Contributed by Lukas
Finally, Ubuntu 22.04.1 LTS is released and we look at how best to upgrade, plus we cover security updates for NVIDIA graphics drivers, OpenJDK, D...
Episode 171
05 Aug 2022
Contributed by Lukas
This week we dig into what community sponsored security updates are all about, plus Ubuntu 22.04.1 LTS gets delayed by a week and we cover security ...
Episode 170
29 Jul 2022
Contributed by Lukas
This week we're diving down into the depths of binary exploitation and analysis, looking at a number of recent vulnerability and malware teardowns...
Episode 169
22 Jul 2022
Contributed by Lukas
It's the 22.10 mid-cycle roadmap sprint at Canonical this week plus we look at security updates for Git, the Linux kernel, Vim, Python, PyJWT and mo...
Episode 168
15 Jul 2022
Contributed by Lukas
This week we rocket back into your podcast feed with a look at the OrBit Linux malware teardown from Intezer, plus we cover security updates for c...
Episode 167
11 Jul 2022
Contributed by Lukas
This week we bring you part 3 of Camila's cybersecurity buzzwords series - looking at blockchain, zero trust and quantum / post-quantum security.
Episode 166
02 Jul 2022
Contributed by Lukas
From the deep-web to encryption we decode more cybersecurity buzzwords, plus we cover security updates for Squid, Vim, the Linux kernel, curl and ...
Episode 165
24 Jun 2022
Contributed by Lukas
This week Camila dives into the details on some of the most prolific buzzwords flying around the cybersecurity community, plus we cover security u...
Episode 164
17 Jun 2022
Contributed by Lukas
More Intel CPU issues, including Hertzbleed and MMIO stale data, plus we cover security vulnerabilities and updates for ca-certificates, Varnish C...
Episode 163
10 Jun 2022
Contributed by Lukas
This week we dig into some of the details of another recent Linux malware sample called Symbiote, plus we cover security updates for the Linux ker...
Episode 162
03 Jun 2022
Contributed by Lukas
This week we cover security updates for dpkg, logrotate, GnuPG, CUPS, InfluxDB and more, plus we take a quick look at some open positions on the t...
Episode 161
27 May 2022
Contributed by Lukas
This week we take a look into BPFDoor, a newsworthy backdoor piece of malware which has been targeting Linux machines, plus we cover security upda...
Episode 160
20 May 2022
Contributed by Lukas
Ubuntu get's pwned again at Pwn2Own Vancouver 2022, plus we look at security updates for the Linux kernel, RSyslog, ClamAV, Apport and more.
Episode 159
15 May 2022
Contributed by Lukas
This week we bring you part 2 of our look at the new Ubuntu 22.04 LTS release and what's in it for security, plus we cover security updates for DP...
Episode 158
06 May 2022
Contributed by Lukas
Microsoft's Nimbuspwn sets the Linux security media ablaze but where there's smoke there's not always fire, plus we bring you the first part of a ...
Episode 157
22 Apr 2022
Contributed by Lukas
Ubuntu 22.04 LTS (Jammy Jellyfish) is officially released 🎉 and so this week we take a quick look at the new features and enhancements, with a ...
Episode 156
08 Apr 2022
Contributed by Lukas
This week we bring you the TL;DL (too-long, didn't listen 😉) version of Camila's recent 4-part Ubuntu hardening series, plus we look at security ...
Episode 155
01 Apr 2022
Contributed by Lukas
It's an off-by-one error in the podcast this week as we bring you part 4 of Camila's 3-part Ubuntu hardening series, plus we look at security update...
Episode 154
25 Mar 2022
Contributed by Lukas
It's PIE🥧 for everyone this week as Python finally becomes a position independent executable for Ubuntu 22.04, plus Camila brings you the third ...
Episode 153
18 Mar 2022
Contributed by Lukas
This week we bring you part 2 of Camila's guide on Ubuntu server hardening, plus we cover vulnerabilities and updates in Expat, Firefox, OpenSSL, ...
Episode 152
11 Mar 2022
Contributed by Lukas
It's a big week for kernel security vulnerabilities - we cover Dirty Pipe and fixes for the latest microarchitectural side channel issues, plus we ...
Episode 151
04 Mar 2022
Contributed by Lukas
This week we do the usual round-up of security vulnerability fixes for the various Ubuntu releases, plus we discuss enabling PIE for Python and pr...
Episode 150
25 Feb 2022
Contributed by Lukas
Ubuntu 20.04.4 LTS is released, plus we talk about Google Project Zero's metrics report as well as security updates for the Linux kernel, expat, c...
Episode 149
18 Feb 2022
Contributed by Lukas
This week Qualys dominate the week in security updates, disclosing details of 4 different SUID-root vulnerabilities, including Oh Snap! More Lemming...
Episode 148
11 Feb 2022
Contributed by Lukas
It's main vs universe as we take a deep dive into the Ubuntu archive and look at these components plus what goes into each and how the security team...
Episode 147
04 Feb 2022
Contributed by Lukas
We're back after a few weeks off to cover the launch of the Ubuntu Security Guide for DISA-STIG, plus we detail the latest vulnerabilities and updat...
Episode 146
14 Jan 2022
Contributed by Lukas
Ubuntu 21.04 goes EOL soon, plus we cover security updates for Django, the Linux kernel, Apache httpd2 + Log4j2, Ghostscript and more.
Episode 145
06 Jan 2022
Contributed by Lukas
The Ubuntu Security Podcast is back for 2022 and we're starting off the year with a bang💥! This week we bring you a special interview with Kees ...
Episode 144
31 Dec 2021
Contributed by Lukas
Happy holidays! This week we bring you the second part of a special two-part holiday themed feature by Camila from the Ubuntu Security team discus...