"Python packages upload your AWS keys, env vars, secrets to the web"
https://blog.sonatype.com/python-packages-upload-your-aws-keys-env-vars-secrets-to-web
"How to: Look for TLS private keys on Docker Hub"
https://labs.detectify.com/2022/06/16/how-to-look-for-tls-private-keys-on-docker-hub/
"Terraform as part of the software supply chain"
"... Looking at the security of Terraform itself and the things which could go wrong when running it, however, have very little coverage so far."
"Firefox rolls out Total Cookie Protection by default to all users worldwide"
👍
"Dockerfile best-practices for writing production-worthy Docker images."
"Public Travis CI Logs (Still) Expose Users to Cyber Attacks"
"Changing the End-of-Life Date for Node.js 16 to September 11th, 2023"
"When we put together Node.js 16 the hope was that we would be able to include OpenSSL 3. Unfortunately, the timing of the releases did not allow that to be possible, and we released Node.js 16 with OpenSSL 1.1.1. OpenSSL 1.1.1 is scheduled to be supported up until September 11th, 2023, which is seven months before the planned End-of-Life date of Node.js 16 (April 2024)."
"“PACMAN” Hack Can Break Apple M1’s Last Line of Defense"
https://spectrum.ieee.org/pacman-hack-can-break-apple-m1s-last-line-of-defense
Open Letter: #Chatcontrol – A danger for everyone’s privacy, security, free expression, incl. the very children it aims to protect https://edri.org/our-work/european-commission-must-uphold-privacy-security-and-free-expression-by-withdrawing-new-law/
📝 We are gathering articles and actions against #chatcontrol in this document: https://cryptpad.fr/code/#/2/code/view/+8pkd4-2AxP4QusFjKtVLQVgMXsfqsKYo0TJ3kjuDrQ/present/
If you have any suggestions send them our way!
"Python 3.11 Performance Benchmarks Are Looking Fantastic"
https://www.phoronix.com/scan.php?page=article&item=python-311-benchmarks
"Fallacies of Distributed Systems"
https://architecturenotes.co/fallacies-of-distributed-systems/
"The faces from China’s Uyghur detention camps"
https://www.bbc.co.uk/news/extra/85qihtvw6e/the-faces-from-chinas-uyghur-detention-camps
Sad ... as someone once said:
"Those who cannot learn from history are doomed to repeat it."
Tails 5.1 is out
This release fixes the security vulnerability in the JavaScript engine of Firefox and Tor Browser announced on May 24.
It was delayed from May 31 to June 5 because of a delay in the release of Tor Browser.
this is also new:
- automatically fixing the clock when connecting to Tor
- new homepage for the "Unsafe Browser" to make it easier for users to understand how to sign into a captive portal
- better Kleopatra integration
...and more.
Full report:
https://tails.boum.org/news/version_5.1/
"Zero-Day Exploitation of Atlassian Confluence"
https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/
"Certificate Transparency data is used to compromise WordPress before installation"
Not restricted to WP, also applies to many other PHP applications.
Full-stack developer, advocate of a free, secure and safe Internet. Nature lover and sports enthusiast.
[Header photo by Colin Watts, source Unsplash]