Security Leftovers
-
PowerDNS Recursor 4.8.2 Released
We are proud to announce the release of PowerDNS Recursor 4.8.2. This release is a maintenance release, fixing some issues, in particular: Please refer to the change log for the 4.8.2 release for additional details.
-
Ransomware Leads to Nantucket Public Schools Shutdown [Ed: Microsoft shutting down schools?]
Nantucket’s public schools shut its doors to students and teachers after a data encryption and extortion attack on its computer systems.
-
30k Internet-Exposed QNAP NAS Devices Affected by Recent Vulnerability
Censys finds 30,000 internet-exposed QNAP appliances that are likely affected by a recently disclosed critical code injection vulnerability.
-
Fedora Magazine: Automatically decrypt your disk using TPM2
This article demonstrates how to configure clevis and systemd-cryptenroll using a Trusted Platform Module 2 chip to automatically decrypt your LUKS-encrypted partitions at boot.
-
Slammer: 20 years after
Guest Post: Where were you when SQL Slammer nearly broke the Internet? Could it happen again?
-
[Podcast] Is my Internet Down?
Measuring Internet outages with Google Trends.
-
Malicious NPM, PyPI Packages Stealing User Information
Security researchers are warning of a new wave of malicious NPM and PyPI packages designed to steal user information and download additional payloads.
-
Sandboxed NPM
I recently started a new project, and all the anxiety around someone running peacenotwar or other similar malicious code which would simply wipe my computer is coming up again.
-
98% of Firms Have a Supply Chain Relationship That Has Been Breached: Analysis
A new report found that 98% of organizations have a relationship with a third party that has been breached, while more than 50% have an indirect relationship with more than 200 fourth parties that have been breached.
-
Dutch, European Hospitals ‘Hit by Pro-Russian Hackers’
Dutch cyber authorities said several hospital websites in the Netherlands and Europe were likely targeted by a pro-Kremlin hacking group because of their countries' support for Ukraine.
-
VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities
VMware confirms the publication of exploit code and urged VMware vRealize Log Insight users to implement mitigations immediately.