"“Magic links” can end up in Bing search results — rendering them useless."
"The OpenSSL 3.0.4 release introduced a serious bug in the RSA
implementation for X86_64 CPUs supporting the AVX512IFMA instructions.
This issue makes the RSA implementation with 2048 bit private keys
incorrect on such machines and memory corruption will happen during
the computation. As a consequence of the memory corruption an attacker
may be able to trigger a remote code execution on the machine performing
"Multiple Vulnerabilities in Flower and Downstream Attacks on Airflow"
Issues were addressed in Airflow, but not in flower.
"MitM at the Edge: Abusing Cloudflare Workers"
"Python packages upload your AWS keys, env vars, secrets to the web"
"How to: Look for TLS private keys on Docker Hub"
"Terraform as part of the software supply chain"
"... Looking at the security of Terraform itself and the things which could go wrong when running it, however, have very little coverage so far."
"Firefox rolls out Total Cookie Protection by default to all users worldwide"
"Changing the End-of-Life Date for Node.js 16 to September 11th, 2023"
"When we put together Node.js 16 the hope was that we would be able to include OpenSSL 3. Unfortunately, the timing of the releases did not allow that to be possible, and we released Node.js 16 with OpenSSL 1.1.1. OpenSSL 1.1.1 is scheduled to be supported up until September 11th, 2023, which is seven months before the planned End-of-Life date of Node.js 16 (April 2024)."
"“PACMAN” Hack Can Break Apple M1’s Last Line of Defense"
Open Letter: #Chatcontrol – A danger for everyone’s privacy, security, free expression, incl. the very children it aims to protect https://edri.org/our-work/european-commission-must-uphold-privacy-security-and-free-expression-by-withdrawing-new-law/