"“Magic links” can end up in Bing search results — rendering them useless."
"The OpenSSL 3.0.4 release introduced a serious bug in the RSA
implementation for X86_64 CPUs supporting the AVX512IFMA instructions.
This issue makes the RSA implementation with 2048 bit private keys
incorrect on such machines and memory corruption will happen during
the computation. As a consequence of the memory corruption an attacker
may be able to trigger a remote code execution on the machine performing
the computation."
"Multiple Vulnerabilities in Flower and Downstream Attacks on Airflow"
https://tprynn.github.io/2022/05/26/flower-vulns.html
Issues were addressed in Airflow, but not in flower.
We’re not kidding ourselves: #Fairphone won’t improve the electronics industry by outselling huge competitors. Instead, we’ll improve it step by step by demonstrating there is a better way of doing business. Find out how in our latest Impact Report📱🌿 : https://bit.ly/3dnTkrY
"MitM at the Edge: Abusing Cloudflare Workers"
https://blog.christophetd.fr/abusing-cloudflare-workers/
#security #cloudflare #cloudflare-workers
"Packj (pronounced package) is a command line (CLI) tool to vet open-source software packages for "risky" attributes that make them vulnerable to supply chain attacks."
"Controlling the access to the clipboard contents"
"Python packages upload your AWS keys, env vars, secrets to the web"
https://blog.sonatype.com/python-packages-upload-your-aws-keys-env-vars-secrets-to-web
"How to: Look for TLS private keys on Docker Hub"
https://labs.detectify.com/2022/06/16/how-to-look-for-tls-private-keys-on-docker-hub/
"Terraform as part of the software supply chain"
"... Looking at the security of Terraform itself and the things which could go wrong when running it, however, have very little coverage so far."
"Firefox rolls out Total Cookie Protection by default to all users worldwide"
👍
"Dockerfile best-practices for writing production-worthy Docker images."
"Public Travis CI Logs (Still) Expose Users to Cyber Attacks"
"Changing the End-of-Life Date for Node.js 16 to September 11th, 2023"
"When we put together Node.js 16 the hope was that we would be able to include OpenSSL 3. Unfortunately, the timing of the releases did not allow that to be possible, and we released Node.js 16 with OpenSSL 1.1.1. OpenSSL 1.1.1 is scheduled to be supported up until September 11th, 2023, which is seven months before the planned End-of-Life date of Node.js 16 (April 2024)."
"“PACMAN” Hack Can Break Apple M1’s Last Line of Defense"
https://spectrum.ieee.org/pacman-hack-can-break-apple-m1s-last-line-of-defense
Open Letter: #Chatcontrol – A danger for everyone’s privacy, security, free expression, incl. the very children it aims to protect https://edri.org/our-work/european-commission-must-uphold-privacy-security-and-free-expression-by-withdrawing-new-law/
Full-stack developer, advocate of a free, secure and safe Internet. Nature lover and sports enthusiast.
[Header photo by Colin Watts, source Unsplash]