Search
Items tagged with: infosec
How do your apps/servers authenticate to your secret manager (e.g. #Vault) if you use one?
Boosts are apprecieted
#devops #secdevops #devsecops #secret #infosec
- a symmetric secret (password, token, etc...) (30%, 9 votes)
- a centralized identity provider (LDAP, KRB5, K8S, etc.) (20%, 6 votes)
- a federated identity (OIDC, SAML, JWT, Github, etc.) (36%, 11 votes)
- an asymmetric secret (public keys, certificates, etc.) (36%, 11 votes)
- something else (please comment) (6%, 2 votes)
https://go.squidapp.co/n/ikkINiv #security #infosec
Server Proofpoint usati per inviare milioni di e-mail di phishing - Securityinfo.it
I ricercatori di Guardio Labs hanno individuato una massiccia campagna di phishing che sfrutta i server Proofpoint per inviare e-mail autenticate.Marina Londei (Securityinfo.it)
Pic of the Day
#infosec #cybersecurity #cybersecuritytips #pentesting #cybersecurityawareness #informationsecurity
Antivirus vs EDR vs XDR
#infosec #cybersecurity #cybersecuritytips #pentesting #redteam #informationsecurity #CyberSec #networking #networksecurity #infosecurity #cyberattacks #security #linux #cybersecurityawareness #bugbounty #bugbountytips
Linksys Velop routers send Wi-Fi passwords in plaintext to US servers
According to Testaankoop, the Belgian equivalent of the Consumers' Association, two types of Linksys routers are sending Wi-Fi login details in plaintextAlex Ivanovs (Stack Diary)
Call for papers is now open for hack.lu 2024
🔗 https://2024.hack.lu/blog/hack.lu-2024-call-for-papers/
#hacklu #conference #infosec #luxembourg #hacklu2024 #cfp #security
Call for papers is now open for hack.lu 2024
Time to submit a talk, training or workshop to hack.luhack.lu (hack.lu 2024)
Novel attack against virtually all VPN apps neuters their entire purpose
TunnelVision vulnerability has existed since 2002 and may already be known to attackers.Ars Technica
Urgent security alert for Fedora Linux 40 and Fedora Rawhide users
Red Hat Information Risk and Security and Red Hat Product Security learned that the latest versions of the “xz” tools and libraries contain malicious code that appears to be intended to allow unauthorized access., (Red Hat)
Uhhh heads up everyone:
https://lwn.net/ml/oss-security/20240329155126.kjjfduxw2yrlxgzm@awork3.anarazel.de/
> After observing a few odd symptoms around liblzma (part of the xz package) on Debian sid installations over the last weeks (logins with ssh taking a lot of CPU, valgrind errors) I figured out the answer:
> The upstream xz repository and the xz tarballs have been backdoored.
As far as Debian is concerned, seems like only Sid was affected (fixed):
https://lists.debian.org/debian-security-announce/2024/msg00057.html
Generally, XZ Utils versions 5.6.0 and 5.6.1.
The whole story:
Users ditch Glassdoor, stunned by site adding real names without consent.
#infosec #security #IT #enshitification #jobs
Users ditch Glassdoor, stunned by site adding real names without consent
Anonymous review site Glassdoor now consults public sources to identify users.Ars Technica