Security Leftovers
-
Microsoft and cybersecurity firm Fortra go after top hacking tool [Ed: Grotesque inversion of narratives. Microsoft is to blame here. But it's trying to present itself as the hero. Has Axios absorbed too many Microsoft moles like Fried?]
-
Security updates for Thursday [LWN.net]
Security updates have been issued by Debian (cairosvg, ghostscript, grunt, tomcat9, and trafficserver), Fedora (golang, podman, xen, and zchunk), Red Hat (kpatch-patch), SUSE (systemd), and Ubuntu (apache-log4j1.2, liblouis, linux-aws, and linux-bluefield).
-
Global DDoS-for-hire takedown
Guest Post: Measuring the globally coordinated disruption of DDoS services.
-
Hard Truths of Kubernetes Secrets Management
The recent CircleCI breach highlights the risk of storing secrets in places like private code repositories (GitHub), scripts, configuration files, files encrypted at rest, CI/CD pipeline code or even Kubernetes Secrets where they cannot easily be rotated, audited, authenticated and secured.
-
Article: The Silent Platform Revolution: How eBPF Is Fundamentally Transforming Cloud-Native Platforms
There is a silent eBPF revolution reshaping platforms and the cloud-native world in its image, and this is its story.