Vulristics: как я создал инструмент анализа уязвимостей и теперь использую его практически ежедневно

Хабр, привет! Меня зовут Александр Леонов. Я ведущий эксперт PT Expert Security Center и среди прочего отвечаю в компании за ежемесячные подборки наиболее критичных (трендовых) уязвимостей, обзоры которых мы каждый месяц публикуем на Хабре. С 2020 года я развиваю проект Vulristics. Изначально это был мой личный инструмент для анализа уязвимостей из ежемесячных обновлений Microsoft Patch Tuesday. Но постепенно я расширял его функциональность. Теперь утилите можно подавать на вход любой набор идентификаторов CVE и БДУ . Главная задача Vulristics — оценивать и приоритизировать уязвимости. Для этого утилита анализирует несколько ключевых факторов: наличие признаков публичной эксплуатации, наличие публичного эксплойта, тип уязвимости, популярность ПО, а также оценки CVSS (Common Vulnerability Scoring System) и EPSS (Exploit Prediction Scoring System). Под катом — история создания Vulristics и рассказ о том, как этот инструмент экономит часы ручной работы, помогая аналитику не утонуть в потоке уязвимостей.

https://habr.com/ru/companies/pt/articles/975090/

#анализ_уязвимостей #инструменты_разработчика #инструменты_тестирования #cve #patching #cvss #vulnerability_management #json

Vulristics: как я создал инструмент анализа уязвимостей и теперь использую его практически ежедневно

Хабр, привет! Меня зовут Александр Леонов. Я ведущий эксперт PT Expert Security Center и среди прочего отвечаю в компании за ежемесячные подборки наиболее критичных (трендовых) уязвимостей,...

Хабр

The SolarWind cyberattack was one of the scariest examples of supply-chain attacks carried out by foreign hacking groups against Western companies. Attributed to APT29 / Cozy Bear, a Russian Foreign Intelligence Service (SVR) hacking unit, it spread through a patch and targeted some of the major IT corporations in the United States.

#cyberattacks #cyberwarfare #patching #cozyBear #sunburst

https://negativepid.blog/the-solarwinds-supply-chain-attack/
https://negativepid.blog/the-solarwinds-supply-chain-attack/

The SolarWinds Supply Chain Attack - PID Perspectives

Imagine downloading a patch to update a critical system, and that patch contained the malware to hack you. That really happened.

PID Perspectives

Do you Patch machines regularly? Even when your bandwidth is constrained take the time to patch them and be safe.

In this example I photographed the patching of one of the micro SD Cards of the SBC.

I've patched all of them.

For the X86 machines the Os on the main 2280 SSD is patched. Other SSD and HDD will follow. The BSD HDDs need patch Love 💕 too. They will get it

#Raspberry #Pi5 #SBC #technology #ARM #X86 #patching #Linux #OpenSource #BSD #freeBSD #ghostBSD #programming

The SolarWind cyberattack was one of the scariest examples of supply-chain attacks carried out by foreign hacking groups against Western companies. Attributed to APT29 / Cozy Bear, a Russian Foreign Intelligence Service (SVR) hacking unit, it spread through a patch and targeted some of the major IT corporations in the United States.

#cyberattacks #cyberwarfare #patching #cozyBear #sunburst

https://negativepid.blog/the-solarwinds-supply-chain-attack/
https://negativepid.blog/the-solarwinds-supply-chain-attack/

The SolarWinds Supply Chain Attack - PID Perspectives

Imagine downloading a patch to update a critical system, and that patch contained the malware to hack you. That really happened.

PID Perspectives

Cyber insurance is meant to protect you... so why are so many claims denied? 🤔

Turns out the biggest breach drivers aren’t sophisticated attacks — they’re the everyday hygiene gaps insurers assume you’ve already handled.

#MFA, #patching, leaked credentials… if these slip, payouts often do, too.

👉 Learn more as Coral Tayar uncovers why “mundane” threats are causing the biggest financial surprises: https://blog.checkpoint.com/security/cyber-insurance-wont-save-you-from-bad-hygiene/

#CyberSecurity #ThreatPrevention #CheckPoint

Cyber Insurance Won’t Save You from Bad Hygiene

Check Point Blog

The SolarWind cyberattack was one of the scariest examples of supply-chain attacks carried out by foreign hacking groups against Western companies. Attributed to APT29 / Cozy Bear, a Russian Foreign Intelligence Service (SVR) hacking unit, it spread through a patch and targeted some of the major IT corporations in the United States.

#cyberattacks #cyberwarfare #patching #cozyBear #sunburst

https://negativepid.blog/the-solarwinds-supply-chain-attack/
https://negativepid.blog/the-solarwinds-supply-chain-attack/

The SolarWinds Supply Chain Attack - PID Perspectives

Imagine downloading a patch to update a critical system, and that patch contained the malware to hack you. That really happened.

PID Perspectives
Why can you trust us to have secure servers? 🔐 Philipp explains this in his blog post. ✍️ In today's digital world, server security is not just “nice to have”, but a necessity for smooth operation – and it's no different for us. 👉 You can find Philipp's full article on the topic here https://nine.ch/why-you-can-trust-our-servers-to-be-fundamentally-secure/ in our blog on our website. 👈 #security #server #patching #configuration #cloudnavigators #nine
🎉 Welcome to the riveting world of #SimpleText patching! 🤯 Navigate a labyrinth of forums and resources just to relive the #90s joy of #editing #text files on a #68K #Mac. Because who needs modern software when you can have endless #assembly #code fun? 🙄💾
https://tinkerdifferent.com/threads/patching-68k-software-simpletext.4793/ #Patching #Nostalgia #HackerNews #ngated
Assembly - Patching 68K software - SimpleText

Someone asked to have SimpleText open a smaller text window at startup. Initially, I assumed this would be a fairly easy fix by just overwriting a few constant values in SimpleText code. It turned out to be a pain -- but I learned a lot along the way. You need to have the code editor (from one...

TinkerDifferent

Sewing can be oddly soothing

I spent about an hour this morning trying to avoid jabbing myself with a sharp metal object. The experience was more satisfying than I would have expected–not just because it left me without injury, but because it left me with a inexpertly patched pair of jeans.

I’ve been sewing buttons back in place since I was in high school, that being one of many things my mom taught me to do. It’s not hard, it doesn’t take that long, and even if you need to make this repair away from home, you’ve got decent odds of a hotel room including a mending kit with all the materials needed.

It took me a little while longer to get in the habit of picking up a needle and thread to sew together a tear in a shirt or a pair of pants. That’s not too difficult either, plus you get the satisfaction of restoring an item of clothing to service without having to pay somebody to do it.

Then I devoted part of a Saturday in July to level up my mending game at a free clothing-repair tutorial in Arlington hosted by Art on the Mend (yes, that is me in the picture on the home page), a program founded by cartographer Alison Davis-Holland.

With a small room’s worth of people, I got some hands-on coaching in picking the right kind of fabric to patch an item of clothing, a few different stitching techniques to employ for the work, and how to proceed with it. The “why” of this lesson was just as important: not only because it’s cost-effective to repair something, but because that act of DIY mending personalizes that object.

And it allows you the chance to put some creativity into the required stitching, as Davis-Holland showed with some of her own fine work.

I left the class with a pair of jeans in which a developing rip in the wallet pocket had been sewn up–with a lot of help from the attendee seated next to me–as well as a set of fabric patches to use in other fabric-repair attempts.

Saturday morning was one of them, involving another pair of jeans that needed patching. (I don’t remember Levi’s wearing that badly in my younger days, but maybe I just keep them longer now.) Sewing a patch on fabric that’s begun to fray is more work than re-attaching a button to an intact shirt, especially if you’re not that practiced at this task, and so I had to take my time with it.

But I also found this exercise so oddly soothing that I didn’t mind the minutes going by. Slip the needle and thread through, send it back, through and back, through and back… and the risk of poking yourself with the pointy end forces a level of concentration that my screen time rarely allows.

See also: why I’m so crazy about gardening and cooking, two other hobbies that help me less like a digital man and more like the analog kid I once was.

#ArtOnTheMend #craft #crafty #DIY #fabric #jeans #LeviS #mend #mending #needleAndThread #patch #patching #sewing

Yet another example on the vast amount of posibilities, on the #MS20... This particular patch makes the otherwise monophonic synth duophonic❤️

#musicproduction #music #learning #gear #synth #soundrecording #patching