Summary

Top Articles:

  • Severe Unauthenticated RCE Flaw (CVSS 9.9) in GNU/Linux Systems Awaiting Full Disclosure
  • CVE-2024-9632 xorg-x11-server: heap-based buffer overflow privilege escalation vulnerability
  • zizmor — a tool for finding security issues in GitHub Actions setups
  • On That Okta LDAP Bug
  • ‘Reflections on Trusting Trust’, but completely by accident this time
  • Rustls Outperforms OpenSSL and BoringSSL
  • Let's Encrypt will begin offering 6-day certificates
  • grype: A vulnerability scanner for container images and filesystems
  • sudo-rs: A memory safe implementation of sudo and su
  • apparmor.d: Extensive set of AppArmor profiles

Severe Unauthenticated RCE Flaw (CVSS 9.9) in GNU/Linux Systems Awaiting Full Disclosure

Published: 2024-09-25 19:45:49

Popularity: None

Author: securityonline.info via enpo

Keywords:

  • security
  • linux
  • 🤖: "Exploitable gap"

    Comments

    ...more

    CVE-2024-9632 xorg-x11-server: heap-based buffer overflow privilege escalation vulnerability

    Published: 2024-10-29 18:29:20

    Popularity: None

    Author: bugzilla.redhat.com via eBPF

    Keywords:

  • security
  • c
  • 🤖: "Buffer Overflow"

    Comments

    ...more

    zizmor — a tool for finding security issues in GitHub Actions setups

    Published: 2024-10-31 19:53:24

    Popularity: None

    Author: woodruffw.github.io via ubernostrum

    Keywords:

  • security
  • testing
  • 🤖: "Bug Hunter"

    Comments

    ...more

    On That Okta LDAP Bug

    Published: 2024-11-05 21:22:28

    Popularity: None

    Author: matt.blwt.io via stevenharman

    Keywords:

  • security
  • 🤖: "ldap hackz"

    Comments

    ...more

    ‘Reflections on Trusting Trust’, but completely by accident this time

    Published: 2024-10-22 15:41:47

    Popularity: None

    Author: secret.club via freddyb

    Keywords:

  • security
  • compilers
  • 🤖: ""Code red""

    Comments

    ...more

    Rustls Outperforms OpenSSL and BoringSSL

    Published: 2024-10-22 19:28:59

    Popularity: None

    Author: memorysafety.org via JulianWgs

    Keywords:

  • security
  • rust
  • performance
  • 🤖: "Rust wins again"

    Comments

    ...more

    Let's Encrypt will begin offering 6-day certificates

    Published: 2024-12-17 05:28:11

    Popularity: None

    Author: letsencrypt.org via strugee

    Keywords:

  • security
  • 🤖: "Cert gone in 6 days"

    Comments

    ...more

    grype: A vulnerability scanner for container images and filesystems

    Published: 2024-12-19 15:42:55

    Popularity: None

    Author: github.com via sar

    Keywords:

  • security
  • 🤖: "Virus alert!"

    Comments

    ...more

    sudo-rs: A memory safe implementation of sudo and su

    Published: 2024-12-27 09:09:23

    Popularity: None

    Author: github.com via bitfield

    Keywords:

  • security
  • unix
  • rust
  • 🤖: ""Safe Mode""

    Comments

    ...more

    apparmor.d: Extensive set of AppArmor profiles

    Published: 2024-12-27 22:47:58

    Popularity: None

    Author: github.com via tris

    Keywords:

  • security
  • linux
  • 🤖: "Profile lock"

    Comments

    ...more

    Talk recordings of "38C3: Illegal Instructions"

    Published: 2024-12-31 14:38:55

    Popularity: None

    Author: media.ccc.de via sping

    Keywords:

  • event
  • video
  • security
  • 🤖: "Illegal code"

    Comments

    ...more

    Let's Encrypt to end OCSP support in 2025

    Published: 2024-12-31 19:23:45

    Popularity: None

    Author: scotthelme.co.uk via spetz

    Keywords:

  • security
  • web
  • 🤖: "SSL drama"

    Comments

    ...more

    Remote reboots with encrypted disks (2022)

    Published: 2025-01-02 09:56:54

    Popularity: None

    Author: tavianator.com via bitfield

    Keywords:

  • security
  • linux
  • 🤖: "Reboot blues"

    Comments

    ...more

    Exploit Me, Baby, One More Time: Command Injection in Kubernetes Log Query

    Published: 2025-01-26 19:23:54

    Popularity: None

    Author: akamai.com via thesnarky1

    Keywords:

  • security
  • 🤖: "Injecting chaos"

    Comments

    ...more

    Clone2Leak: Your Git Credentials Belong To Us

    Published: 2025-01-28 06:34:56

    Popularity: None

    Author: flatt.tech via crazyloglad

    Keywords:

  • security
  • 🤖: "Git in trouble"

    Comments

    ...more

    Speculation Attacks on Apple M3: SLAP and FLOP

    Published: 2025-01-28 18:57:19

    Popularity: None

    Author: predictors.fail via crazyloglad

    Keywords:

  • security
  • 🤖: "Slap in the face!"

    Comments

    ...more

    The Slow Death of OCSP

    Published: 2025-01-30 16:15:25

    Popularity: None

    Author: feistyduck.com via fanf

    Keywords:

  • security
  • 🤖: "Certificate expiration"

    Comments

    ...more

    Hell Is Overconfident Developers Writing Encryption Code

    Published: 2025-02-01 13:08:08

    Popularity: None

    Author: soatok.blog via giffengrabber

    Keywords:

  • security
  • practices
  • cryptography
  • 🤖: ""Code fail""

    Comments

    ...more

    Go Supply Chain Attack: Malicious Package Exploits Go Module

    Published: 2025-02-05 15:53:40

    Popularity: None

    Author: socket.dev via veqq

    Keywords:

  • security
  • go
  • 🤖: ""Sneaky package""

    Comments

    ...more

    Llama's Paradox - Exploiting Llama.cpp

    Published: 2025-02-06 21:14:16

    Popularity: None

    Author: retr0.blog via msanft

    Keywords:

  • security
  • 🤖: "Code injection 🤯"

    Comments

    ...more

    Russian phishing campaigns exploit Signal's device-linking feature

    Published: 2025-02-19 12:09:50

    Popularity: None

    Author: bleepingcomputer.com via johnk

    Keywords:

  • security
  • 🤖: ""Signal hacked""

    Comments

    ...more

    GymTok: Breaking TLS Using the Alt-Svc Header

    Published: 2025-02-19 18:00:32

    Popularity: None

    Author: blog.pspaul.de via freddyb

    Keywords:

  • security
  • networking
  • web
  • 🤖: ""TLS fail""

    Comments

    ...more

    Hacking the Xbox 360 Hypervisor Part 1: System Overview

    Published: 2025-03-04 02:58:04

    Popularity: None

    Author: icode4.coffee via calvin

    Keywords:

  • security
  • reversing
  • virtualization
  • 🤖: "Xbox glitch"

    Comments

    ...more

    Miners on CI/CD pipelines for Drone/Gitlab servers with open registrations

    Published: 2025-03-04 22:01:33

    Popularity: None

    Author: manganiello.social by blacklight

    Keywords:

  • security
  • 🤖: ""Pipeline hijack""

    Comments

    ...more

    end