We've released 35 new Semgrep rules targeting infrastructure, supply chain, and Ruby security issues. Plus, learn how to leverage regex mode and HCL support for better infrastructure-as-code security.
https://blog.trailofbits.com/2024/12/09/35-more-semgrep-rules-infrastructure-supply-chain-and-ruby/
Gee, I wonder who likes to target electrical infrastructure and why they would want to target Romania... 🤔
https://therecord.media/electric-distributor-cyberattack-romania
Here's a link to today's AI slop #curl #hackerone report. Freshly disclosed: https://hackerone.com/reports/2887487
The #curl CVE we will publish on Wednesday addresses an issue that has existed in source code for almost twenty-five years.
severity low though, so the sky might not fall this week either
I published an Advanced Persistent Threat (APT) profile on Gamaredon, a Russian state-sponsored cyberespionage group. Gamaredon (Group) is also known as Aqua Blizzard/ACTINIUM, and BlueAlpha, but most vendors do refer to them as Gamaredon. In 2021, they were publicly attributed by the Security Service of Ukraine (SSU) to Russia's Federal Security Service (FSB) Centers 16 and 18.
#gamaredon #russia #cyberespionage #fsb #bluealpha #aquablizzard #infosec #cybersecurity #cyberthreatintelligence #CTI #threatintel
Mandiant's Thibault Van Geluwe de Berlaere demonstrates a novel technique that can be used to circumvent all three current types of browser isolation (remote, on-premises, and local) for the purpose of controlling a malicious implant via C2. https://cloud.google.com/blog/topics/threat-intelligence/c2-browser-isolation-environments/
itch.io is reporting on bsky that their domain has been taken down due to ...well.
Can confirm that the Mastodon archive export will just randomly stop doing anything. No email, no error message, it just stops and acts like you didn't just ask for an archive.
But since no one has been able to do much with their archive until now, I guess none of the power users noticed it's broken.
But it's very much broken, there's no exporting happening if you've got a lot of data.
I have about 215Mb in media, and that seems to be too much. And that's an assumption because it's not like I actually have any information to go on as to why it just stopped.
Is there an api endpoint for this or something?
Lies, damned lies, and photodiodes: https://lcamtuf.substack.com/p/lies-damned-lies-and-photodiodes
New episode is up!
https://unnamedre.com/episode/72
I was surprised to receive an email from Amazon that indicated that two items in my wishlist were shipped. I mean... I only expressed the desire to maybe purchase them in the future, right?
As it turns out, that email you read in Gmail isn't the email from Amazon. It's a summary of what Gmail thinks Amazon emailed you about. You have to scroll down to see the actual email that they sent. Amazon stopped emailing you what's being shipped to you a long time ago, anyway.
play the grindr notification noise at Christmas dinner to see which conservative relatives panickedly check their phone ringer