TLDR newsletter: daily e-mail with technology newstldrnewsletter.com
I've been reading this one ever since I found out about it. The news is interesting, and the summaries are very well written.
I've been reading this one ever since I found out about it. The news is interesting, and the summaries are very well written.
I use 1Password to securely share passwords and notes with my colleagues. Can't recommend them enough and I'm super honoured to have them as a sponsor.
The vulnerabilities are collectively called "Bleedingbit". The issue impacts Wi-Fi access points made by Cisco, Meraki and HPE’s Aruba, although there is talk that the impact could be more widespread. Both vulnerabilities can be used for remote code execution, but do seem to require physical proximity (because, I suppose, Bluetooth) and need Bluetooth enabled, which it usually isn't in these devices.
It's apparently trivial to exploit, making it very easy to elevate oneself to root on affected systems.
It leverages an Hadoop YARN (Yet Another Resource Negotiator) bug to enroll the clusters in a DDoS network. If your cluster is Internet-facing, make sure to check it out.
It doesn't need user interaction anymore, and provides the website owner with a score between 0.1 and 1 to reflect how confident it is. More information can be found in Google's docs here.
The malicious package was called "colourama", typo-squatting the more popular "colorama". It sat in PyPi since December of last year, and was downloaded 55 times last month (which is, fortunately, not that bad). It installs a Windows script that monitors the clipboard for Bitcoin addresses, to then replace it with its own.
This is a great move, meant to mitigate the risk of something exploiting Defender itself (as Tavis Ormandy did a few times last year). It was apparently quite an undertaking, and it makes Windows Defender the first AV to be sandboxed.
It's specifically targeted at new Windows installs, where users open Edge and use Bing, just to download Chrome :-) Bing can't seem to keep up with it, even though Chrome and Firefox recognize the sites as malicious. Hackernews discussion here.
Including several high-level vulnerabilities in FaceTime, and a vulnerability that allows an attacker to crash any other Apple device on the network.
The sentence includes 2.500 hours of community service, 6 months house arrest and a whopping $8.6 million in fines.
Great article on how volunteer hacking, journalism and OSINT groups grew out of the Russian - Ukrainian conflict, and about the warning that the Ukrainians bring to the rest of the world of a new type of "hybrid warfare".
If you want a deeper dive in the T2 Security Chip that Apple just announced, here's your chance.