You are here |
nbailey.ca | ||
| | | |
blog.talosintelligence.com
|
|
| | | | CVE-2023-44487, a vulnerability in the HTTP/2 protocol, was recently used to launch intensive DDoS attacks against several targets. | |
| | | |
thehackernews.com
|
|
| | | | Beware! Kinsing cryptojacking attacks are targeting Kubernetes clusters through misconfigured PostgreSQL. | |
| | | |
educatedguesswork.org
|
|
| | | | ||
| | | |
logr.cogley.info
|
|
| | Devs check out « @ProjectSigstore », a project that aims to ease adoption of cryptographic software signing and transparency, like what LetsEncrypt does for SSL certs. ?? What goals does it have, problems does it aim to solve? reduce software supply chain risk make maintainer key management easier reduce sw supply chain attacks such as build system compromises, malicious hashes, compromised keys, replay or freeze attacks It is not quite there yet, but is one to watch. |