Hi folks!
A day early and a bit of a quick one, as I'm still very much focused on onboarding in the new job, and leaving for a trip with friends over the weekend :-)
Enjoy the end of the week, kick butt at whatever you do, and see you next week!
Supported by 1Password.
Hi folks!
A day early and a bit of a quick one, as I'm still very much focused on onboarding in the new job, and leaving for a trip with friends over the weekend :-)
Enjoy the end of the week, kick butt at whatever you do, and see you next week!
Dmitry Yuryevich Khoroshev, a 31-year-old Russian national, ran the LockBit ransomware gang under the alias LockbitSupp, said authorities from the U.S., U.K. and Australia.
Microsoft has highlighted a novel attack dubbed "Dirty Stream," which could allow malicious Android apps to overwrite files in another application's home directory, potentially leading to arbitrary code execution and secrets theft.
Microsoft CEO Satya Nadella is now making it clear to every employee that security should be prioritized above all else. Quote: "If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security."
He outlines three core principles:
They'll also base part of the compensation of the senior leadership team on progress towards those milestones, which is probably the best way to ensure improvement.
All in all it sounds fantastic. I truly hope that they'll follow through on this.
This vulnerability made a few headlines this week, but it's worth reading this HN discussion on how it might not be all that novel, widespread or complicated. To the researcher's credit, who's post you can read here, they recognise this.
It's becoming pretty clear now that the XZ Utils project isn't the only place where these takeover attempts are happening. Interesting HN discussion here.
A massive network of 75,000 fake online shops called 'BogusBazaar' tricked over 850,000 people in the US and Europe into making purchases, allowing the criminals to steal credit card information and attempt to process an estimated $50 million in fake orders.
Artifact Attestations provides a verifiable way to link software artifacts back to their source code and build instructions. Sounds like a great step forward in supply chain security.
I don't think most developers realise how valuable 1Password can be. It doesn't just hold passwords, it also hold your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)