Secursive
@Secursive
I write on security topics that I find interesting. http://blog.secursive.com
You might like
Time to go wear a "New Critical [ubiquitous-open-source] vulnerability dropping soon" shirt to halloween parties! #openssl #cve #halloween
find / -name "log4j-core-*.jar" -exec zip -q -d {} org/apache/logging/log4j/core/lookup/JndiLookup.class \; > /dev/null 2>&1
Got a Ring door bell? There is an increasing trend of law enforcement agencies requesting videos from the Ring devices. gizmodo.com/police-and-fir…
gizmodo.com
Police and Fire Departments in 48 U.S. States Are Reportedly Involved in Amazon’s Ring Program
If you have an Amazon Ring smart doorbell, there’s something you should know. A growing number of fire and police departments are interested in your
If you use a Github Action that prints untrusted data to standard output, your repository contents and secrets in the workflow are at risk.
bugs.chromium.org/p/project-zero… is an interesting design flaw in Github Actions. Actions that print untrusted data to STDOUT are vulnerable to an injection attack that can be turned into code exec.
Unauthenticated remote code execution on Linux Bluetooth stack. If you are using a linux distro with bluetooth, better disable bluetooth if you aren't social distancing in the woods. intel.com/content/www/us…
Successful push back on corporate narratives equating free users to criminals by default. Privacy and safety go hand in hand and are a juggling act. "Free/Basic users seeking access to E2EE will participate in a one-time verification process..." blog.zoom.us/zoom-rolling-o…
If this is really about balancing safety vs privacy, would Zoom offer e2e encryption to free tier users who would use same authentication mechanism as any paid business/org tier user, e.g. credit card verification or organization email based verification? $ZM #privacy #encryption
Watch devs throw hands up in the air due to too many false positives eating up their time.
If this is really about balancing safety vs privacy, would Zoom offer e2e encryption to free tier users who would use same authentication mechanism as any paid business/org tier user, e.g. credit card verification or organization email based verification? $ZM #privacy #encryption
An interestring statistical look at Financial Crime Enforcement Network's Suspicious Activity Reports. buzzfeednews.com/article/jsvine… #FinCENFiles #FinCen #moneylaundering
Reverse engineering of Electronic Baggage Tags (Lufthansa @lufthansa, British Airways @British_Airways) by @reversemode. labs.ioactive.com/2020/09/breaki…
gnutls: "In TLS 1.3, that can only bypass the authentication, but in TLS 1.2, it may allow attackers to recover the previous conversations." #gnutls #tls #security #vulnerabilities CVE-2020-13777: gitlab.com/gnutls/gnutls/…
United States Trends
- 1. Thanksgiving 395K posts
- 2. Golesh 2,607 posts
- 3. Camp Haven 7,315 posts
- 4. Fani Willis 16.5K posts
- 5. Trumplican 3,343 posts
- 6. #WipersDayGiveaway N/A
- 7. Khabib 8,315 posts
- 8. Hong Kong 16.8K posts
- 9. NextNRG 1,143 posts
- 10. Tom Hardy 1,732 posts
- 11. Denzel 3,293 posts
- 12. Mendy 4,857 posts
- 13. Wine 39.5K posts
- 14. Stranger Things 167K posts
- 15. Africans 27.1K posts
- 16. Idris 7,822 posts
- 17. #PuebloEnBatallaYVictoria 4,759 posts
- 18. Riker N/A
- 19. Breyers 2,451 posts
- 20. #TejRan 4,172 posts
Something went wrong.
Something went wrong.