Security Leftovers
-
It’s not just you — Microsoft admits it broke OneDrive | Digital Trends
If you’ve been experiencing OneDrive crashes and error messages, before digging too deep for a solution, note that it might be Microsoft’s fault. Common solutions like restarting, or signing out and back in won’t help because the issue is with the latest Windows 10 update.
-
Hardening the Election Security: Supply Chain, Zero Trust and Insider Threats [Ed: Elections should just not be done on computers]
In the past, supply chain risks to elections were typically comprised of risks of ballot availability, voting locations, and personnel to facilitate voting. This was demonstrated during the pandemic as the influx of mail-in ballots threatened the supply of paper ballots. Integrity was maintained through physical control that could be readily cataloged and captured through two-person integrity and other commands. Fraud, in general, was not scalable. Supply chain risks, in this sense, affected availability.
-
Living off the Orchard: Leveraging Apple Remote Desktop for Good and Evil | Mandiant
Mandiant has observed attackers using the ARD screen sharing function to move laterally between systems. If remote desktop was not enabled on a target system, Mandiant observed attackers connecting to systems via SSH and executing a kickstart command to enable remote desktop management. This allowed remote desktop access to the target systems.
-
New open-source tool scans public AWS S3 buckets for secrets
A new open-source 'S3crets Scanner' scanner allows researchers and red-teamers to search for 'secrets' mistakenly stored in publicly exposed or company's Amazon AWS S3 storage buckets.
Amazon S3 (Simple Storage Service) is a cloud storage service commonly used by companies to store software, services, and data in containers known as buckets.
Unfortunately, companies sometimes fail to properly secure their S3 buckets and thus publicly expose stored data to the Internet.