Security Leftovers
-
Threat Actors Use AWS SSM Agent as a Remote Access Trojan
Threat actors have been observed using Amazon Web Services ( AWS ) 's System Manager (SSM) agent as a Remote Access Trojan (RAT) on Linux and Windows machines.
-
The Rust Programming Language Blog: Security advisory for Cargo (CVE-2023-38497)
This is a cross-post of the official security advisory. The official advisory contains a signed version with our PGP key, as well.
The Rust Security Response WG was notified that Cargo did not respect the umask when extracting crate archives on UNIX-like systems. If the user downloaded a crate containing files writeable by any local user, another local user could exploit this to change the source code compiled and executed by the current user.
-
SUSE and IBM: Enhancing Data Security (a Technical Reference Documentation Getting Started guide) [Ed: "confidential computing" is a sham that encourages companies and governments to outsource their operations and data based on false premises of confidentiality]
The Essence of Confidential Computing At its core, confidential computing addresses the vital need of safeguarding data while it is in use. SUSE and IBM work together to deliver advanced technical capabilities, like confidential computing. IBM Z® and LinuxONE systems provide key hardware capabilities for the trusted execution environment.
-
Hackers can abuse Microsoft Office executables to download malware
The list of LOLBAS files – legitimate binaries and scripts present in Windows that can be abused for malicious purposes...