Zum Inhalt der Seite gehen

Suche

Beiträge, die mit Security getaggt sind


#IslamChannel U.N. Security Council meets on humanitarian situation in Gaza

U.N. Security Council meets on humanitarian situation in Gaza U.N. Security Council meets on humanitarian situation in Gaza #UN #security #gaza from Islam Channel اهد الفيديو الخاص بهذا المقال هنا "

https://www.shibuyaworldnews.online/islamchannel-u-n-security-council-meets-on-humanitarian-situation-in-gaza/


:github: GitHub uncovers new Ruby-SAML Vulnerabilities allowing Account Takeover Attacks.

Two high-severity security flaws have been disclosed in the open-source ruby-saml library that could allow malicious actors to bypass Security Assertion Markup Language (SAML) authentication protections.

https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/

#github #ruby #saml #library #it #security #privacy #engineer #media #programming #tech #news


Mastodon friends, I've heard a few suggestions of companies moving from US cloud providers to those based in the EU, due to risks with the Trump administration/Cloud Act, etc.

Has anyone come across any businesses that have made the leap recently? Feel free to DM or message on Signal, mattburgess.20

#infosec #privacy #cloud #security


‘Critical concerns’ about internet of things security


A person seated in a cosy living room interacts with smart home devices, showcasing modern technology and a relaxed atmosphere. There are connecting lines going out from the person's smartphone to the various devices, indicating their phone is connected to the devices.
“GlobalData’s Internet of Things report outlines that the fragmented security standards landscape and the weak security of many internet of things (IoT) devices could hold back further adoption of the technology. Furthermore, it suggests that existing IoT deployments could become a security risk due to the current state of affairs.”

Way too many IoT devices have no real security (they don’t get updates and patches, they freely call out onto the Internet, sometimes have no login security, use weak security standards, etc).

It’s partly because they are cheap devices and do not adhere to any strict security compliance.

So whilst many users have a firewall turned on for their router, that usually only blocks incoming traffic. These IoT devices can still freely establish links with the outside world, and if compromised, could end up creating a bridge to everything else on the LAN behind the firewall.

Which is why I went to quite a bit of trouble to isolate my IoT devices onto their own VLANs. If you do not have the hardware to configure VLANs for them, at least ensure they are connected to your guest network, and that the guest network is isolated from the main LAN network (there is typically a toggle setting for that).

See https://www.verdict.co.uk/critical-concerns-about-internet-of-things-security
#Blog, #IoT, #security, #technology


https://www.europesays.com/1917588/ UNDP Report on Syria’s Economic Losses #Conflicts #economics #security #Syria
UNDP Report on Syria’s Economic Losses


:microsoft: 240 Million Windows 10 Users are vulnerable to six different Exploits.

⚠️Protect yourself Now!!!⚠️

If you’re running a Windows 10 PC, make sure you download the latest update right now. Microsoft patched 57 vulnerabilities affecting its foundational systems and core products, including six actively exploited zero-day vulnerabilities.

https://msrc.microsoft.com/update-guide/releaseNote/2025-Mar

#microsoft #windows #update #it #security #privacy #engineer #media #tech #news


“There is significant public interest in knowing when and on what basis the UK government believes that it can compel a private company to undermine the privacy and security of its customers.”

ORG, Big Brother Watch and Index on Censorship call for the Tribunal into the UK government's secret order for Apple to break encryption to be held in public.

The case happens TOMORROW.

Read more ⬇️

https://techcrunch.com/2025/03/13/apples-appeal-against-uks-secret-icloud-backdoor-order-must-be-held-in-public-rights-groups-urge/

#encryption #e2ee #privacy #security #ukpolitics #ukpol #cybersecurity #apple


:apple_inc: Apple releases Emergency Security Patch for WebKit Zero-Day Vulnerability.

The vulnerability is tracked as CVE-2025-24201 and was found in the WebKit cross-platform browser engine used by Apple's Safari and many other apps.

⚠️Install the Update immediately!!!⚠️
[For your device security, it’s a good practice to install updates within 36 hours of becoming available.]

https://support.apple.com/en-us/100100

#apple #ios #macos #update #it #security #privacy #engineer #media #tech #news
However, the advisory does not mention if Apple's own security team discovered the flaw or if it was reported to it by an external researcher. It also does not mention when the attacks began, how long they lasted and who was targeted.

The update is available for the following devices and operating system versions:

• iOS 18.3.2 and iPadOS 18.3.2 - iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
• macOS Sequoia 15.3.2 - Macs running macOS Sequoia
• Safari 18.3.1 - Macs running macOS Ventura and macOS Sonoma
• visionOS 2.3.2 - Apple Vision Pro

With the latest development, Apple has addressed a total of three actively exploited zero-days in its software since the start of the year, the other two being CVE-2025-24085 & CVE-2025-24200.

⚠️Installing security updates as soon as possible is highly recommended to block potentially ongoing attack attempts.⚠️


US dominates European weapons purchases: report – POLITICO https://www.byteseu.com/822955/ #Europe #France #Germany #Imports #india #Israel #Military #NATO #Pakistan #Poland #Procurement #Qatar #Russia #SaudiArabia #Security #SouthKorea #Ukraine #UnitedStates #WarInUkraine #Weapons
US dominates European weapons purchases: report – POLITICO


Nutzt ihr Antivirus-Apps auf eurem Android? Spart euch den unnötigen Ballast – sie bieten nur trügerische Sicherheit und sind oft voller Tracker. 👇

https://www.kuketz-blog.de/truegerische-sicherheit-virenscanner-apps-sind-schlichtweg-ueberfluessig/

#android #security #google #tracking #virus #antivirus #app


OPM Watchdog Says Review of DOGE Work Is Underway

The acting inspector general says the Office of Personnel Mgmt is investigating whether any “emerging threats” have arisen as Elon Musk’s #DOGE works to rapidly transform #government systems.
https://www.wired.com/story/opm-doge-review-underway/

"In addition to #OPM, #Democrats have pressed for similar #security assessments at five other agencies...

Congressional #Republicans have committed to little, if any, formal oversight of DOGE’s work"

#Musk #Coup #GOP #USPol #News
Headline from Wired:
OPM Watchdog Says Review of DOGE Work Is Underway

The acting inspector general says the Office of Personnel Management is investigating whether any “emerging threats” have arisen as Elon Musk’s DOGE works to rapidly transform government systems.

by Dell Cameron
Politics
Mar 10, 2025 5:51 PM


:linux: Strap in, get ready for more Rust Drivers in Linux Kernel.

Rust is alive and well in the Linux kernel and is expected to translate into noticeable benefits shortly, though its integration with the largely C-oriented codebase still looks uneasy. [The Linux and Rust communities still have some issues to work out.]

https://rust-for-linux.com/rust-kernel-policy

#linux #kernel #memory #safety #rust #drivers #it #security #privacy #engineer #media #programming #tech #news
In a hopeful coda to the recent maintainer drama that raised questions about the willingness of Linux maintainers to accommodate Rust code, Josh Aas, who oversees the Internet Security Research Group's Prossimo memory-safety project, late last week hailed Miguel Ojeda's work to advance memory safety in the kernel without mentioning the programming language schism.

<https://www.memorysafety.org/blog/linux-kernel-2025-update/>

"While our goal was never to rewrite the entire kernel in Rust, we are glad to see growing acceptance of Rust's benefits in various subsystems," said Aas. "Today, multiple companies have full time engineers dedicated to working on Rust in the Linux kernel."
Security – in the form of memory safety – is Rust's selling point.

Rust provides ways to avoid memory safety vulnerabilities that crop up in programming languages like C and C++ where manual memory management is allowed. Though other languages such as Python, Java, JavaScript, Swift and C# are also considered memory safe. Rust has received most of the memory safety evangelism, partly because it's suited for the sort of low-level, performance-sensitive code that for the past few decades has tended to be written in C and C++.

"Many of the most critical software vulnerabilities are memory safety issues in C and C++ code, and while there are ways to reduce the risk, including fuzzing and static analysis, memory safety vulnerabilities continue to plague the Internet," said Josh Aas in a write-up.

<https://www.memorysafety.org/blog/initiative-criteria/>


New #Blog: My Scammer Girlfriend: Baiting A Romance Fraudster
Author: Ben Tasker

https://www.bentasker.co.uk/posts/blog/security/seducing-a-romance-scammer.html?utm_source=rss

#infosec #osint #scams #security


Over 1,000 WordPress Sites Infected with JavaScript Backdoors enabling persistent Attacker Access.

"Creating four backdoors facilitates the attackers having multiple points of re-entry should one be detected and removed," c/side researcher Himanshu Anand said in a analysis last week.

https://cside.dev/blog/thousands-of-websites-hit-by-four-backdoors-in-3rd-party-javascript-attack

#wordpress #javascript #backdoors #it #security #privacy #engineer #media #tech #news


While data on the proportion of each state's defence capability made up of imported weaponry is difficult (impossible) to find, what we do have is data on exports;

This reveals that two thirds of all military imports used by European states come from America.

If Military Keynsianism (implied or explicit) is about ramping up domestic capacity, pivoting away from US-made weapons systems looks like being a major priority.

In the short(ish) term that may be pretty difficult

#security
h/t FT


Israeli-U.S. Joint Exercise Serves as Warning to Iran https://www.byteseu.com/814817/ #Conflicts #F15I #F35I #Iran #Israel #IsraeliAirForce #Military #Security
Isreali F-15I on take off at RAF Waddington on 4th September 2019.


https://www.europesays.com/1900587/ Israeli-U.S. Joint Exercise Serves as Warning to Iran #Conflicts #F15I #F35I #Iran #Israel #IsraeliAirForce #military #security
Isreali F-15I on take off at RAF Waddington on 4th September 2019.


I met Lena at BSides London; she's an exceptional, very talented, enthusiastic and passionate human being

sadly, it wasn't valued in Japanese #InfoSec society, esp. when calling out sexual harassment & because of that Lena was ostracised. she deserves better than this

sharing her msg in hope someone in #Fediverse would be interested in hiring her outside of Japan. reposts appreciated

https://lambdamamba.com/index.html

#FediHired #GetFediHired #Malware #CyberSecurity #Job #JobSearch #Hiring #Security
Lena Yu (LinkedIn):

Hi everyone,
I need help to start a new life outside of Japan. All my conference activities, creating Malware Village, Malmons, research, projects, etc. was a way for me to create opportunities, so me and those in similar situations can finally have the freedom to go anywhere their heart desires. I want to work on the things I love, while being physically and emotionally away from the painful memories in Japan

I am deeply unhappy with Japan’s lack of respect for young female talents and its backward-minded society. Misogyny, victim blaming, power abuse, sexual harassment, ageism, etc. It’s not improving, and having hope will only lead to disappointment

I feel truly happy and alive when I’m overseas for conferences, but the depression hits as soon as I return to Japan, and it is eroding my mental well-being

In Japan, some people have threatened to withhold “help”, support, cancel sponsorships and deals, blacklist me, and punish me even further for speaking out against sexism and harassment. This is regarding the incident, that got me fired and banned from Japanese security conferences for standing up against harassment towards women

Also, they have threatened to withhold support towards my friends and colleagues in Japan who has been sympathetic towards me

I could just take the easy route, and shut up about all the injustice and pretend it never happened. But, that dishonors all the things I fought so hard for. I can never forgive myself if I did that
I don’t want “help” from people who threaten to withhold it unless I obey them. I came this far without their “help”, so keep the damn “help”.

Although I love malware analysis and cybersecurity, I no longer want to contribute to a society like this. I want to be completely free from Japan, to a place where they have no power over me.

I want to prioritize my own happiness and well-being. I dedicated my life to improving Japan’s security, but in return, I was met with only disrespect. When I finally opened up, people in Japan were more upset about my reaction to the mistreatment than about the mistreatment itself.

If you know of any opportunities that sponsor visas, please let me know.

Thank you all.

My email: lena.yu@malwarevillage.org


Iran Update, March 7, 2025 https://www.byteseu.com/809450/ #Afghanistan #Conflicts #Institute #InstituteForTheStudyOfWar #Iran #IranProject #Iraq #ISW #Libya #MiddleEast #ORBAT #report #Security #Study #Syria #War
Iran Update, March 7, 2025


BSI-Studie: Mangelhafte Information über IT-Sicherheit bei vernetzten Geräten

Im stationären Handel sind Angaben zur IT-Security bei Routern & Co. kaum vorhanden, hat eine Analyse fürs BSI ergeben. Im E-Commerce sieht es kaum besser aus.

https://www.heise.de/news/BSI-Studie-Mangelhafte-Information-ueber-IT-Sicherheit-bei-vernetzten-Geraeten-10308898.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#BSI #Cybersecurity #eCommerce #Security #Router #news


Whoa! Japanese companies are currently facing a serious threat due to a PHP vulnerability (CVE-2024-4577). It might sound like tech jargon, but trust me, it's a huge deal! 😬

Attackers are exploiting this flaw to run malicious code and install Cobalt Strike (yeah, that penetration testing tool – go figure 🙄). And that's when things get really nasty: password theft, lateral movement within the network... 🤬

The bottom line is this: vulnerabilities like these are like striking gold for cybercriminals. A quick update is absolutely essential! But what's even more critical? Regular, hands-on penetration tests! Automated tools often miss these types of vulnerabilities. ☝️

I'm curious to know: What steps do you take to secure your PHP applications? What penetration testing methods do you find most effective? 🤔

#Security #Pentesting #PHP