securepaul, to random
@securepaul@fosstodon.org avatar

A bit later than usual, and perhaps not very exciting this time around, but here are the LSM, SELinux, and audit* highlights from the Linux v6.10 merge window.

https://paul-moore.com/blog/d/2024/05/linux_v610_merge_window.html

kuketzblog, to firefox German
@kuketzblog@social.tchncs.de avatar
br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar

Border officers relied on outdated intel to decide whether to search incoming vessels, audit warns

https://www.cbc.ca/news/politics/cbsa-audit-marine-ports-humans-goods-1.7191621?cmp=rss

br00t4c, to random
@br00t4c@mastodon.social avatar

Number of antisemitic incidents reached record high in 2023, says B'nai Brith Canada audit

https://www.cbc.ca/news/politics/bnai-brith-antisemitic-report-record-high-1.7195197?cmp=rss

ErikJonker, to ai
@ErikJonker@mastodon.social avatar

For people in the field of algorithms, AI, auditing etc.
"Law and the Emerging Political Economy of Algorithmic Audits"
(preprint)
https://osf.io/preprints/lawarchive/xvqz7

br00t4c, to random
@br00t4c@mastodon.social avatar

Critical Audit of California's Efforts to Reduce Homelessness Has Silver Linings

https://capitalandmain.com/critical-audit-of-californias-efforts-to-reduce-homelessness-has-silver-linings

br00t4c, to Arkansas
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar
IHI, to hiring
@IHI@social.network.europa.eu avatar

📢: Could you be our next colleague? IHI is an administrative assistant & an ex-post control & officer! If you're looking for the next step in your or career, this might be for you. More info: https://europa.eu/!Jc6g3b

br00t4c, to random
@br00t4c@mastodon.social avatar

JK Rowling, gender critical U.K. groups cheer release of Cass Review--as activists push back

https://www.dailydot.com/debug/cass-review-uk/

daieuxetdailleurs, to random French
@daieuxetdailleurs@framapiaf.org avatar
securepaul, to random
@securepaul@fosstodon.org avatar

The Linux v6.9 merge window opened earlier this week, here is my write-up on the LSM, SELinux, and audit highlights that were merged into Linus' tree.

https://paul-moore.com/blog/d/2024/03/linux_v69_merge_window.html

br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar

Former NSW government accused of 'pork barrelling at public's expense' after scathing audit

https://www.theguardian.com/australia-news/2024/feb/28/former-nsw-government-accused-pork-barrelling-audit-covid-19-pandemic

argosopentech, to random
@argosopentech@fosstodon.org avatar

I’ve had a few people reach out to me to ask how secure Argos Translate is.

I try to take security seriously; but of course all software has bugs. To my knowledge, to date, no one has found a serious security vulnerability in Argos Translate or LibreTranslate. It’s probably inevitable though that ArgosTranslate/LibreTranslate or one of it’s dependencies will have a security vulnerability at some point.

https://community.libretranslate.com/t/argos-translate-security/974

ButterflyOfFire,
@ButterflyOfFire@mstdn.fr avatar
br00t4c, to random
@br00t4c@mastodon.social avatar

Infrastructure projects 'GBP2.5bn more than planned'

https://www.bbc.co.uk/news/uk-northern-ireland-68405234

vansari, to php German
@vansari@phpc.social avatar

Do you use the composer audit option in your CI/CD Pipeline and if so how do you use it?

I have implemented it very simple and all security vulnerabilities and abandoned packages must be fixed before the pipeline continues. The reason is that we don’t want this issues in our production code anymore.

bagder, to security
@bagder@mastodon.social avatar

HTTP/3

Performed by Trail of Bits. They found things to fix but nothing critical and no security flaws.

https://daniel.haxx.se/blog/2024/02/23/curl-http-3-security-audit/

mattotcha, to China
@mattotcha@mastodon.social avatar

China conducts first nationwide review of retractions and research misconduct
https://www.nature.com/articles/d41586-024-00397-x

br00t4c, to random
@br00t4c@mastodon.social avatar

'Incredibly disturbing': calls for audit of out-of-home care providers after court hears Aboriginal baby's aunt refused as carer due to same-sex relationship

https://www.theguardian.com/australia-news/2024/feb/10/calls-for-audit-of-out-of-home-care-providers-after-aboriginal-babys-aunt-refused-as-carer-due-to-same-sex-relationship

nono2357, to random
securepaul, to random
@securepaul@fosstodon.org avatar

A bit later than usual due to some personal travel earlier this week (Go Blue!), but here is my write-up on the SELinux and audit highlights from the Linux v6.8 merge window. As a bonus, I'm also going to start including LSM layer highlights as we've got some cool new things starting with Linux v6.8 :)

https://paul-moore.com/blog/d/2024/01/linux_v68_merge_window.html

krlaboratories, to Cybersecurity Ukrainian

ДЕЩО ПРО МЕРЕЖЕВІ З'ЄДНАННЯ WHATSAPP...

Приклад того як мобільний додаток WhatsApp Messenger лізе на нестандартні (5022) і незахищені (80) мережеві порти (в ідеалі має бути лише 443).

З'єднання відбуваються з інфраструктури Facebook і серверів Amazon.

З tcp 5022 впринципі зрозуміло - це XMPP, тобто Джаббер (завдяки якому WhatsApp такий швидкий в плані миттєвого обміну повідомленнями - https://isc.sans.edu/data/port/5222). А от 80-й, незахищений порт, навіщо? Про нього в довідці щось нічого не сказано: https://developers.facebook.com/docs/whatsapp/guides/network-requirements/

Цікаво, що деякі з цих IP-адрес мають шкідливі індикатори і б'ються по VirusTotal... Де гарантія того, що через них не пролізе бекдор...? Ми, звичайно, відфільтруємо подібні з'єднання фаєрволом і зашифруємось vpn'ом. А звичайний користувач? У нього усі "брами" відкриті по дефолту...

Виявляється, в інтернеті є мапа індикаторів, які були якось пов'язані з WhatsApp: https://www.virustotal.com/graph/embed/gc884e1c5d9b84730b3b00a90f2f4a73cc145436e48ae438794e2a7dd053993a1

Ось так, ведемо слідство над WhatsApp, щоб знати що поробляє жук Цук за спиною юзера... )

Далі буде.

#whatsapp #reverse #cybersecurity #messenger #messengers #audit #webappsec #appsec #network #networksecurity #networkintelligence #threatintel

image/png
image/png
image/jpeg

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • tacticalgear
  • cubers
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • osvaldo12
  • ngwrru68w68
  • GTA5RPClips
  • provamag3
  • InstantRegret
  • everett
  • Durango
  • cisconetworking
  • khanakhh
  • ethstaker
  • tester
  • anitta
  • Leos
  • normalnudes
  • modclub
  • megavids
  • lostlight
  • All magazines