Hi folks! I'm back!
The break took a bit longer than expected, it was an intense few months.
In short (takes deep breath): we moved house, I burned out, found myself in a dark place of anxiety and depression, found help, got through it thanks to the incredible people around me, went back to working for myself, immediately found work, settled in to the new house much smoother than we thought, went back to working from home on my own schedule, and am now enjoying life more than ever.
It has been quite the ride. But looking back, it all needed to happen, and I am in a much better place now than I've been in years. I've learned a lot about myself, and look forward to learning more.
So, after some recharging I'm picking up the newsletter again. Did I miss much? ;-)
As always, I hope you get value out of this issue and the upcoming ones.
Thank you for your patience! Cheers!
In case you missed it: Citrix Netscaler has a very high-impact vulnerability, dubbed "Citrix Bleed 2" because of how much it resembles the first.
It's exploited by "omitting the equal sign in the 'login=' parameter, causing the device to leak 127 bytes of memory". Yikes. When doing this repeatedly one can gain access to valid session tokens. It's so bad that CISA gave US agencies 24 hours before a patch needed to be installed (and that was a week ago).
Citrix is facing some backlash because they failed to share all available information about exploitation in the wild. Either way, if you run a vulnerable Netscaler install and haven't patched yet, I would assume compromise and go from there.
OpenVSX is an open-source marketplace for extensions that power various developer tools such as Cursor, Windsurf, and VSCodium. It turns out that the way it gathers extensions to be built and published was vulnerable for takeover, meaning one exploitation could essentially compromise millions of developer machines in one go.
It's a very important example of the fact that supply-chain attacks don't just exist in the software we deploy to our servers, but also in what we run on our own machines. Honestly, be it extensions for VSCode or your browser, there doesn't seem to be a good way to fully protect yourself, except to just assume that nothing is safe. But that doesn't really help anyone. More work left to do folks!
If you're not using a password manager yet, please consider doing so. And if you're looking for one to try, give 1Password a shot.
I wouldn't know what to do without it, it's such a great help when navigating between devices, storing anything from passwords to tokens to passkeys and SSH keys.
And as always, thank you 1Password for supporting this humble newsletter.