Looks like we really get back to the same type of vulnerabilities... it's only a couple of dozens usual suspects.
Definitely not as fashionable as the kubernetes craze. This gives very interesting properties that multi-tenant applications can't really provide. The article is nice as it lays out properly the pros and cons, helps make the choice depending on the context.
A reminder that Secure Boot is worth nothing if the device makers don't manage cryptographic keys properly...
Interesting story. This is getting harder to hire for remote positions I guess.
Make sure to read also part 2. You'd expect critical infrastructure like this to not be exposed over the Internet, and to be properly protected...
Wow! This is a really bad data breach. Apparently related to the recent data theft on the Snowflake end.
The title is a bit pushing it. Still, I didn't realize some of the fine prints of the Ubuntu support schemes.
Good tour of all the way dependencies might get compromised in your supply chain. Getting this easy to detect is needed.
This is a concerning finding. One can escape from the browser to the system with such chaining.
Looks like a nice tool indeed. Might be handy.
This organization indeed doesn't seem healthy. Especially regarding the amount of user data they are responsible of.
Make sure your OpenSSH server is up to date.
This is bad for two reasons: 1) people clearly put too much trust in random CDNs to distribute their dependencies and 2) people don't track depencendies obsolescence properly.
A new type of attack targeting the CPU indirect branch predictor.
JSON, its grammar and the security implications. The approach of looking at a restricted subset is interesting.
The creative ways to exfiltrate data from chat systems built with LLMs...
This is indeed a real concern... with no propre solution in sight.
On the peculiarities of running a network for a university... this is an interesting way to frame it as basically being an ISP with benefits.
A deep dive into the events which led to the SolarWinds breaches. The responsibility from Microsoft as an organization is staggering. Their handling of security matters massively failed once more. I don't get how governmental agencies or other companies can still turn to Microsoft with sensitive data.
Very unsurprising, the harm is probably done though. They'll have to work hard for their reputation to recover (even though it was probably low already).