Secursive's profile picture. I write on security topics that I find interesting. http://blog.secursive.com

Secursive

@Secursive

I write on security topics that I find interesting. http://blog.secursive.com

Time to go wear a "New Critical [ubiquitous-open-source] vulnerability dropping soon" shirt to halloween parties! #openssl #cve #halloween


Long live the "risk accepted" tag/keyword! youtube.com/watch?v=JAkFhO… #security #humor


find / -name "log4j-core-*.jar" -exec zip -q -d {} org/apache/logging/log4j/core/lookup/JndiLookup.class \; > /dev/null 2>&1


Update your iPhone and iPad immediately. support.apple.com/en-us/HT211929


If you use a Github Action that prints untrusted data to standard output, your repository contents and secrets in the workflow are at risk.

bugs.chromium.org/p/project-zero… is an interesting design flaw in Github Actions. Actions that print untrusted data to STDOUT are vulnerable to an injection attack that can be turned into code exec.

_fel1x's tweet image. bugs.chromium.org/p/project-zero… is an interesting design flaw in Github Actions. Actions that print untrusted data to STDOUT are vulnerable to an injection attack that can be turned into code exec.


Unauthenticated remote code execution on Linux Bluetooth stack. If you are using a linux distro with bluetooth, better disable bluetooth if you aren't social distancing in the woods. intel.com/content/www/us…


Successful push back on corporate narratives equating free users to criminals by default. Privacy and safety go hand in hand and are a juggling act. "Free/Basic users seeking access to E2EE will participate in a one-time verification process..." blog.zoom.us/zoom-rolling-o…

If this is really about balancing safety vs privacy, would Zoom offer e2e encryption to free tier users who would use same authentication mechanism as any paid business/org tier user, e.g. credit card verification or organization email based verification? $ZM #privacy #encryption



Watch devs throw hands up in the air due to too many false positives eating up their time.

If this is really about balancing safety vs privacy, would Zoom offer e2e encryption to free tier users who would use same authentication mechanism as any paid business/org tier user, e.g. credit card verification or organization email based verification? $ZM #privacy #encryption



An interestring statistical look at Financial Crime Enforcement Network's Suspicious Activity Reports. buzzfeednews.com/article/jsvine… #FinCENFiles #FinCen #moneylaundering


Reverse engineering of Electronic Baggage Tags (Lufthansa @lufthansa, British Airways @British_Airways) by @reversemode. labs.ioactive.com/2020/09/breaki…


gnutls: "In TLS 1.3, that can only bypass the authentication, but in TLS 1.2, it may allow attackers to recover the previous conversations." #gnutls #tls #security #vulnerabilities CVE-2020-13777: gitlab.com/gnutls/gnutls/…


Loading...

Something went wrong.


Something went wrong.