Nikos Alexiou

35 Followers
74 Following
46 Posts
Father & husband
#AppSec by day, breaker of things at night
ex-dev who turned to the dark side
#OWASP Stockholm πŸ‡ΈπŸ‡ͺ local chapter leader
Personal account πŸ‘‰πŸΌ Opinions are my own
Bloghttps://www.appsecguy.se/

Several DDoS attacks against swedish websites during Sunday, by the so-called hacker group Sudan. They supposedly revenge the burning of quran by a far-right extremist group, but there are suspicions that Russia is using this as an opportunity to attack.

Seems like a good timing to organize your DDoS defences?

#cybersecuritynews #cybersecurity

πŸ’₯ NEW UPDATES RELEASED πŸ’₯

πŸ’» macOS 13.2.1 - 3 bugs fixed
πŸ“± iOS and iPadOS 16.3.1 - 2 bugs fixed
πŸ“Ί tvOS 16.3.2 - details available soon
⌚ watchOS 9.3.1 - details available soon
https://support.apple.com/en-us/HT201222

#apple #cybersecurity #infosec #security #ios

Apple security releases

This document lists security updates and Rapid Security Responses for Apple software.

Apple Support
GitHub Breach: Hackers Stole Code-Signing Certificates for GitHub Desktop and Atom

GitHub reports unauthorized access to Desktop & Atom apps repositories, leading to exposure of encrypted code-signing certificates.

The Hacker News

A new Golang-based information stealer malware dubbed Titan Stealer is being advertised by threat actors through their Telegram channel.

https://thehackernews.com/2023/01/titan-stealer-new-golang-based.html?m=1 #cybersecuritynews

Titan Stealer: A New Golang-Based Information Stealer Malware Emerges

Hackers are distributing a Golang-based information stealer malware, known as Titan Stealer, through Telegram channels to other cyber criminals

The Hacker News
Microsoft 365 to block downloaded Excel XLL add-ins to boost security

Microsoft is working on adding XLL add-in protection for Microsoft 365 customers by including automated blocking of all such files downloaded from the Internet.

BleepingComputer

When I hear about the coup attempt in Germany & the desire of these violent extremists to insert Prince Heinrich XIII of Reuss as the leader after a planned execution of the German chancellor, it sounds ludicrous, laughable. But that's the thing: These people are deadly serious.

Because the plots of these anti-democratic extremists often seem so ludicrous, they can succeed because the public--& too many leaders--don't take them seriously enough. This tendency is how Trump got as far as he did.

#OWASP Stockholm held a presentation on #Github Advanced Security with help from Solidify at Microsoft reactor.

You can find the recorded version here: https://youtu.be/9dOR1Y8g3h4

Topics covered include dependabot, secrets scanning, codeQL scanning and shifting left. Rich presentation full of content.

#appsec #cybersecurity

Github Advanced Security

YouTube

@SonarResearch The hostname part of the URL does not end with a slash. The appended user input from the `path` parameter can change the domain of the API request which could leak the Authorization environment variable.

The domain github.computer is available and could be reached by the API handler if the `path` parameter is set to "puter".

The main reason to become an employee of a product focused company and not a consultant was the will to feel part part of the pack. Watch their back, protect the data and all the assets while willing to do the β€œright” thing no matter what it takes. Some companies support that but many don’t. Do not fight wars you cannot win.

A short ~this week in security~ just went out:

β€’ Police seize iSpoof call spoofing site
β€’ U.S. bans Huawei, ZTE, Hikvision
β€’ Corellium offered trial to spyware maker
β€’ Tax filers' data sent to Facebook
β€’ A new cyber cat

Sign up: https://this.weekinsecurity.com

Read: https://mailchi.mp/zackwhittaker/this-week-in-security-november-27-edition

~this week in security~

a free cybersecurity newsletter by @zackwhittaker, delivered weekly.