Malcolm v26.05.1 is out?!? What, already? Dรฉjร  vu? We bumped up to the timetable on this release as a critical vulnerability found in NGINX made it expedient for us to do so.

Malcolm v26.05.1 focuses heavily on security updates, most notably upgrading OpenResty to address a critical NGINX remote code execution heap buffer overflow vulnerability. It also adds new Suricata OT detections for D-Link HNAP abuse, improves alerting webhook support, introduces the File Tree dashboard, and includes Suricata parsing/mapping fixes and documentation updates. Several other components received version bumps as well.

If you are upgrading from an existing Malcolm installation, run ./scripts/status for Malcolm to migrate some settings prior to running ./scripts/configure, ./scripts/start, or other Malcolm control scripts.

https://github.com/idaholab/Malcolm/compare/v26.05.0...v26.05.1

  • โœจ Features and enhancements
  • โœ… Component version updates
  • ๐Ÿ› Bug fixes
    • Reference Counting (Use-After-Free) Bug for PyList_SetItem in filescan's python-statfs (#960 #962)
    • Added a few missing Suricata fields (suricata.tc_progress, suricata.ts_progress, suricata.tunnel.pcap_cnt, suricata.tunnel.pkt_src) to the index mapping template
    • When suricata.app_proto_ts and/or suricata.app_proto_tc reported that protocol parsing had failed (due to malformed input data), invalid data could be stored in HTTP, DNS, and/or TLS fields. This is now detected and those invalid values are dropped, and some combination of proto_parse_failed, client_stream_failed, or server_stream_failed are added to tags.
    • Suricata's HTTP version was not being normalized to network.protocol_version.
  • ๐Ÿงน Code and project maintenance

Malcolm is a powerful, easily deployable network ๐Ÿ–ง traffic analysis tool suite for network security monitoring ๐Ÿ•ต๐Ÿปโ€โ™€๏ธ.

Malcolm operates as a cluster of containers ๐Ÿ“ฆ, isolated sandboxes which each serve a dedicated function of the system. This makes Malcolm deployable with frameworks like Docker ๐Ÿ‹, Podman ๐Ÿฆญ, and Kubernetes โŽˆ. Check out the Quick Start guide for examples on how to get up and running.

Alternatively, dedicated official ISO installer images ๐Ÿ’ฟ for Malcolm and Hedgehog Linux ๐Ÿฆ” can be downloaded from Malcolm's releases page on GitHub. Due to limits on individual files in GitHub releases, these ISO files have been split ๐Ÿช“ into 2GB chunks and can be reassembled with scripts provided for both Bash ๐Ÿง (release_cleaver.sh) and PowerShell ๐ŸชŸ (release_cleaver.ps1). See Downloading Malcolm - Installer ISOs for instructions.

As always, join us on the Malcolm discussions board ๐Ÿ’ฌ to engage with the community, or pop some corn ๐Ÿฟ and watch a video ๐Ÿ“ผ.

#Malcolm #HedgehogLinux #Zeek #Arkime #Strelka #NetBox #OpenSearch #Elasticsearch #Suricata #PCAP #NetworkTrafficAnalysis #networksecuritymonitoring #OT #ICS #icssecurity #CyberSecurity #Cyber #Infosec #INL

Montrealers celebrate as Canadiens advance to East final with OT win against Sabres
Habs fans celebrated in the Bell Centre after Alex Newhook scored in overtime against the Buffalo Sabres, lifting the Canadiens to a 3-2 Game 7 victory and sending Montreal to the Eastern Conference final for the first time since 2021.
https://www.cbc.ca/player/play/9.7203702?cmp=rss
Canadiens advance to Eastern Conference final with OT win over Sabres in Game 7
The Montreal Canadiens are heading to the Eastern Conference final after defeating the Buffalo Sabres 3-2 in overtime in Game 7 on Monday night at KeyBank Center.
https://www.cbc.ca/news/canada/montreal/habs-sabres-game-seven-second-round-9.7203205?cmp=rss
Bambu Lab's AGPL Problem Just Got Worse

YouTube

๐ŸšจNew GigaOm Radar for Operational Technology Security โž• Webinar

โ€œrunZero excels in environments requiring comprehensive visibility into converged IT and OT networks.โ€ โ€” GigaOm Radar for OT Security ๐Ÿ‘

๐ŸŽฅ Join GigaOm Field CTO Chris Ray and runZero CEO HD Moore for a live webinar as they explore new methods for hardening #OT defenses & discuss insights from the OT Radar.

Webinar
๐Ÿ—“๏ธ Thursday, May 28 @ 12PM ET / 9AM PT
๐Ÿ‘‰ Register for the webinar & read the report at: https://www.runzero.com/gigaom-radar-ot-security

#ot

If you've ever been curious about the way a pipe organ works, here is an absolutely delightful explanation that will get you underway.

https://youtu.be/TzK-tYFGQx4

How does a pipe organ actually work? | Anna Lapwood | Classic FM

YouTube
Anna Lapwood

Official organist of the Royal Albert Hall!

YouTube
Roque's OT winner helps Victoire edge Charge in Game 1 of all-Canadian Walter Cup final
The Montreal Victoire have struck first blood in the all-Canadian Walter Cup final. Abby Roque scored early in overtime to give the Victoire a frantic 3-2 home win over the Ottawa Charge after Montreal's Nicole Gosling equalized with 2.1 seconds remaining in the third period.
https://www.cbc.ca/sports/hockey/pwhl/pwhl-walter-cup-final-game-1-victoire-charge-9.7199386?cmp=rss
Roque buries OT winner as Victoire edge Charge in Game 1 of all-Canadian Walter Cup final
The Montreal Victoire have struck first blood in the all-Canadian Walter Cup final. Abby Roque scored early in overtime to give the Victoire a frantic 3-2 home win over the Ottawa Charge after Montreal's Nicole Gosling equalized with 2.1 seconds remaining in the third period.
https://www.cbc.ca/sports/hockey/pwhl/pwhl-walter-cup-final-game-1-victoire-charge-9.7199386?cmp=rss