Security Leftovers
-
Docker Introduces Hardened Desktop for Business Users
Enhanced Container Isolation aims to harden container isolation by applying a number of techniques, including running all containers unprivileged through the Linux user-namespace, isolating critical system call to prevent containers escapes, and preventing console access to the Docker Desktop VM.
-
Lemonduck Cryptojacking Botnet Reveals Ongoing API
It takes advantage of Docker, a mainstream platform used for building, running and managing containerized workloads. Since Docker runs container workloads in the cloud, a misconfigured cloud instance can expose a Docker API to the internet. Attackers can then exploit this API to run a hidden crypto miner inside an attacker-controlled container.
-
How to Avoid Software Supply Chain Vulnerabilities [Ed: ['FOSSlife Team' is parroting Microsoft talking points and FUD again]]
-
syslog-ng Store Box federated single sign-on support via OpenID Connect - Blog - syslog-ng Community - syslog-ng Community
The syslog-ng Store Box (SSB) appliance is built upon syslog-ng Premium Edition (PE). SSB inherits most of syslog-ng PE’s features and makes them available with an easy-to-use graphical user interface. There are multiple ways how users can authenticate when using SSB. Recent versions also introduced federated single sign-on (SSO) via OpenID Connect (OIDC).
The SSB appliance can collect log messages from many different log sources, in many formats. These include UNIX / Linux / Windows system logs, firewall and router logs, various application logs, and now SQL sources as well. SSB can parse, rewrite, filter, and store log messages. In addition to the traditional syslog-ng features, the SSB appliance provides an interface to search log messages, and does complete log life cycle management, including archiving and backup. Finally, it can also forward events to various on-premises and cloud destinations. It allows you to optimize your SIEM installations both for resources and licensing, as you can collect log messages in a single step, store them on SSB, and only forward a reduced subset of logs to various analytics tools.
-
Apple Releases Security Updates for Multiple Products | CISA
Apple has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected device.