bagder, to random
@bagder@mastodon.social avatar

Remember two years ago? During the #log4j craze I received this demanding email requiring quick answers to where my open source projects used log4j:

https://daniel.haxx.se/blog/2022/01/24/logj4-security-inquiry-response-required/

log4j, to Java

Hello,

my name is #Log4j, and I just had my 20th birthday!

We are looking forward to the next 20 years!

https://logging.apache.org/blog/2023/12/18/20-years-of-innovation.html

#java #opensource #log4j

haubles,
@haubles@fosstodon.org avatar

@log4j Happy birthday #log4j

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 🇺🇸 U.S. nuclear research lab impacts 45,000 people
➝ 🇩🇪 Germany Says Customer Data Stolen in Attack
➝ 🔓 🏧 ATM company Coin Cloud got hacked. Even its new owners don’t know how
➝ 🔓 🇺🇸 Norton discloses data breach after May ransomware attack
➝ 🇷🇺 Russian SVR-Linked Targets TeamCity Servers in Ongoing Attacks
➝ 👥 ransomware now poaching , NoEscape affiliates
➝ 🇻🇳 💻 seizes domains used to sell fraudulent accounts
➝ 🇫🇷 💸 French police arrests Russian suspect linked to ransomware
➝ 🇨🇳 Chinese APT Volt Typhoon Linked to Unkillable SOHO Router
➝ 🇺🇦 🇷🇺 Ukrainian military says it hacked 's federal tax agency
➝ 🇨🇳 🚪 Researchers Unmask Sandman APT's Hidden Link to China-Based Backdoor
➝ 🇺🇦 📡 ’s largest mobile communications provider down after apparent
➝ 🇪🇸 Kelvin Security hacking group leader arrested in
➝ 🔻 👮🏻‍♂️ ransomware site outage rumored to be caused by law enforcement
➝ 📹 🕵🏻‍♂️ devices broadcasted private video to other users’ accounts
➝ 🇷🇺 🇪🇺 Russian Diplomat Expelled Amid EU Spy Purge Is Now An OSCE Election Observer In Serbia
➝ 🇺🇸 Harry Coker confirmed to be the next National Cyber Director
➝ 🇪🇸 🇺🇸 Spain expels two US spies for infiltrating secret service
➝ 📝 Unveils EMB3D Threat Model for Embedded Devices Used in Critical Infrastructure
➝ 🩹 Patch Tuesday: Electromagnetic Fault Injection, Critical Redis Vulnerability
➝ 🦠 🇵🇸 New Pierogi++ by Cyber Gang Targeting Palestinian Entities
➝ 🦠 🇮🇷 Iranian State-Sponsored Group Deploys 3 New Malware Downloaders
➝ 🦠 🇩🇪 New MrAnon Stealer Malware Targeting German Users via Booking-Themed
➝ 🍪 's New Tracking Protection in Chrome Blocks Third-Party
➝ 🐛 👨🏻‍💻 Unveils Open Source Vulnerability Impact Scoring System
➝ 🩹 🧱 backports RCE fix after attacks on unsupported
➝ 🔓 🧱 Over 1,450 servers exposed to RCE attacks via bug chain
➝ 🩹 🍏 Ships iOS 17.2 With Urgent Security
➝ 🐛 Over 30% of apps use a vulnerable version of the library

📚 This week's recommended reading is: "Black Hat Python, 2nd Edition: Python Programming for Hackers and Pentesters (2nd Edition)" by Justin Seitz and Tim Arnold

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-502023

senficon, to random German
@senficon@ohai.social avatar

Vor zwei Jahren schrieb @patrickbeuth im Spiegel über #Log4shell und den Plan der Bundesregierung, mit Einrichtung eines Sovereign Tech Fund zur Förderung offener digitaler Basistechnologien beizutragen. https://www.spiegel.de/netzwelt/web/log4j-sicherheitsluecke-wie-loescht-man-ein-brennendes-internet-a-27729847-8e28-4187-b4a2-468a45137fb4 Heute ist der @sovtechfund Realität und fördert #Log4J. Ein Weihnachtsmärchen. https://www.sovereigntechfund.de/news/log4j-investment

kylewritescode, to Cybersecurity
@kylewritescode@allthingstech.social avatar
securityaffairs, to hacking Italian
thenewoil, to Cybersecurity
YourAnonRiots, to infosec Japanese
@YourAnonRiots@mstdn.social avatar

Don’t wait for the next #Log4j to compromise your web app supply chain.

Explore ongoing risks and why proactive tools like Reflectiz are your shield against vulnerabilities.

https://thehackernews.com/2023/09/do-you-really-trust-your-web.html

#infosec #cybersecurity

fosslife, to security
@fosslife@fosstodon.org avatar

New roadmap for open source security released by the Cybersecurity & Infrastructure Security Agency https://www.fosslife.org/cisa-lays-out-roadmap-open-source-software-security #security #CISA #OpenSource #SoftwareSupplyChain #Log4j #FOSS

tk, to Java
@tk@bbs.kawa-kun.com avatar

Who remembers the most recent #log4j vulnerability? #Java

fosslife, to Cybersecurity
@fosslife@fosstodon.org avatar

Advisory issued by cybersecurity agencies shows older vulnerabilities are the most frequently exploited by attackers https://www.fosslife.org/older-vulnerabilities-most-frequently-exploited-attackers

heiseonline, to linux German

Studie: Proprietäre Software kann nicht sicherer sein als Open-Source

Das Entwicklungsmodell an sich erlaube keine Aussage über die Sicherheit, lautet eine Experten-Analyse. Bei Open Source sei Sicherheit aber für jeden prüfbar.

https://www.heise.de/news/Studie-Proprietaere-Software-kann-nicht-sicherer-sein-als-Open-Source-9226451.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege

einfachnurRoland,

@heiseonline der Artikel spricht genau das aus, was wir alle seit #Log4j, #Bonify und #MSCloud wissen: man weiß nichts, außer man hat selbst nachgesehen. Letzteres klappt bei OpenSource auch nur theoretisch.
So systemimmament und zwangsläufig diese Probleme bei #Software sind, ist es unerklärlichliches Mysterium, das es Branchen gibt, die funktionieren.

kuketzblog, to microsoft German
@kuketzblog@social.tchncs.de avatar

Nach meiner Einschätzung sind nicht nur große Teile der Microsoft-O365-Service kompromittiert, sondern auch alle Windows-Rechner, die damit verbunden waren. Ein Super-Gau epischen Ausmaßes - scheint vielen aktuell nicht klar zu sein. 🤷‍♂️ 👇

https://www.heise.de/news/Neue-Erkenntnisse-Microsofts-Cloud-Luecken-viel-groesser-als-angenommen-9224640.html

einfachnurRoland,

@kuketzblog der letzte der ist ja schon 1,5 Jahre her.

itnewsbot, to random
@itnewsbot@schleuss.online avatar

This Week in Security: Oracle Opera, Passkeys, and AirTag RFC - There’s a problem with Opera. No, not that kind of opera. The Oracle kind. Oracle ... - https://hackaday.com/2023/05/05/this-week-in-security-oracle-opera-passkeys-and-airtag-rfc/ #hackadaycolumns #securityhacks #airtag #oracle #log4j #news

grobmeier, to programming German
@grobmeier@mastodon.social avatar

Nur 6 Teilnehmer für meinen Talk morgen in der Usergroup - aber juckt mich nicht. Für die 6 geb ich trotzdem meine 100%! :) Bißchen und kommt eigentlich auch immer zur Sprache. Wer doch noch kommen will: https://www.meetup.com/de-DE/java-user-group-augsburg/events/291635420/

tarnkappeinfo, to macos German
@tarnkappeinfo@social.tchncs.de avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • rosin
  • thenastyranch
  • Durango
  • DreamBathrooms
  • ngwrru68w68
  • magazineikmin
  • cisconetworking
  • Youngstown
  • mdbf
  • slotface
  • osvaldo12
  • GTA5RPClips
  • kavyap
  • megavids
  • InstantRegret
  • everett
  • cubers
  • vwfavf
  • normalnudes
  • tacticalgear
  • tester
  • ethstaker
  • khanakhh
  • modclub
  • Leos
  • anitta
  • JUstTest
  • All magazines