Skip to main content

Search

Items tagged with: infosec


How do your apps/servers authenticate to your secret manager (e.g. #Vault) if you use one?

Boosts are apprecieted

#devops #secdevops #devsecops #secret #infosec

  • a symmetric secret (password, token, etc...) (30%, 9 votes)
  • a centralized identity provider (LDAP, KRB5, K8S, etc.) (20%, 6 votes)
  • a federated identity (OIDC, SAML, JWT, Github, etc.) (36%, 11 votes)
  • an asymmetric secret (public keys, certificates, etc.) (36%, 11 votes)
  • something else (please comment) (6%, 2 votes)
30 voters. Poll end: 2 days ago


Server Proofpoint usati per inviare milioni di e-mail di #phishing
https://go.squidapp.co/n/ikkINiv #security #infosec


WTF? Linksys Velop routers send Wi-Fi passwords in plaintext to US servers https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/ They found that several data packets being transmitted to an AWS server in the US. These packets included the configured SSID name and password in clear text, identification tokens for the network within a broader database, and an access token for a user session, potentially paving the way for a man-in-the-middle (MITM) attack. #security #infosec #wifi




Uhhh heads up everyone:
https://lwn.net/ml/oss-security/20240329155126.kjjfduxw2yrlxgzm@awork3.anarazel.de/

> After observing a few odd symptoms around liblzma (part of the xz package) on Debian sid installations over the last weeks (logins with ssh taking a lot of CPU, valgrind errors) I figured out the answer:

> The upstream xz repository and the xz tarballs have been backdoored.

As far as Debian is concerned, seems like only Sid was affected (fixed):
https://lists.debian.org/debian-security-announce/2024/msg00057.html

Generally, XZ Utils versions 5.6.0 and 5.6.1.

#InfoSec #Linux #Debian

This website uses cookies to recognize revisiting and logged in users. You accept the usage of these cookies by continue browsing this website.