Security Leftovers
-
[CFT] sec(4) for Route Based IPSec VPNs
A new tool for creating flexible, route based site to site virtual private networks (site-to-site VPNs) is entering its call for testing phase on OpenBSD-current.
-
You've patched right? '340K+ Fortinet firewalls' wide open to critical security bug
More than 338,000 FortiGate firewalls are still unpatched and vulnerable to CVE-2023-27997, a critical bug Fortinet fixed last month that's being exploited in the wild.
This is according to infosec outfit Bishop Fox, which has developed an example exploit for achieving remote code execution via the hole. Successful exploitation of the pre-authentication vulnerability can allow an intruder to take over the network equipment. Bishop Fox warned: "You should patch yours now."
-
“Outdated” IT and digital skills gap hinder NHS digital transformation, say MPs
Cross-party MPs in the Health and Social Care Committee published a report today entitled Digital Transformation in the NHS, which looked at barriers for the national health service to achieve its “top priority” of digitally transforming its operations. The report features conclusions based on several oral sessions held during the inquiry period, which launched in May 2022 and looked at the current use of digital technology, as well as exploring what needed to change in the NHS to deliver improvements for patients.
The committee also looked at the digital transformation of health and records, interoperability across primary, secondary and social care, and legacy IT systems in the health service. Digital health inequalities, and how to educate patients on the potential benefits of digital healthcare, were also discussed.
-
Web servers should refuse requests for random, unnecessary URLs
PS: Security scanners and other tools could adopt various heuristics to detect this sort of situation and reduce false positives, but ultimately they're only heuristics, which means they'll always be incomplete and sometimes may be wrong. Dealing with this in the web server is the better way.