Hacker News with Generative AI: Security Vulnerabilities

D-Link says replace vulnerable routers or risk pwnage (theregister.com)
Owners of older models of D-Link VPN routers are being told to retire and replace their devices following the disclosure of a serious remote code execution (RCE) vulnerability.
Unauthenticated RCE vs. all GNU/Linux systems (+ others) disclosed 3 weeks ago (twitter.com)
Zero-Click Calendar invite vulnerability chain in macOS (medium.com)
I found a zero-click vulnerability in macOS Calendar, which allows an attacker to add or delete arbitrary files inside the Calendar sandbox environment. This could lead to many bad things including malicious code execution which can be combined with security protection evasion with Photos to compromise users’ sensitive Photos iCloud Photos data. Apple has fixed all of the vulnerabilities between October 2022 and September 2023.
BSI discovers serious vulnerabilities in Mastodon, some minor ones in Matrix (heise.de)
The new frontier in script kiddie security vulnerability reports (microsoft.com)
New Blast-RADIUS attack breaks 30-year-old protocol used in networks everywhere (arstechnica.com)
New Blast-RADIUS attack breaks 30-year-old protocol used in networks everywhere (arstechnica.com)
'Skeleton Key' attack unlocks the worst of AI, says Microsoft (theregister.com)
Apple refused to pay bounty to Kaspersky for uncovering vulnerability (9to5mac.com)
Format String Attacks (2000) (seclists.org)
Microsoft PlayReady – Complete Client Identity Compromise (seclists.org)
Attackers can decloak routing-based VPNs (leviathansecurity.com)
Xz sshd backdoor collecting usernames from logs (isc.sans.edu)