Kenn White

@kennwhite
6.3K Followers
633 Following
2.1K Posts
cryptography • neuro • cloud • biscuits
ORD-DCA-NYC-BCN ✈️
twitterhttps://twitter.com/kennwhite
webhttps://opencryptoaudit.org/people

Day in the life of a Black Hat reviewer

submission #37/219: Here's 2 years of work in which we pwned several Internet exchanges and ISPs, spent 6 mos coordinating disclosure w/ 16 vendors, and a completed 40 slide deck & full whitepaper.

#38: Cybersecurity is a serious concern to CEOs nowadays…

This week saw a scramble to save the CVE Program after federal funding was set to expire. The program's long-term future remains unclear. @lhn dives in.

https://www.wired.com/story/cve-program-cisa-funding-chaos/

‘Stupid and Dangerous’: CISA Funding Chaos Threatens Essential Cybersecurity Program

The CVE Program is the primary way software vulnerabilities are tracked. Its long-term future remains in limbo even after a last-minute renewal of the US government contract that funds it.

WIRED

NEW: U.S. Treasury officials say the department was hacked in early December by Chinese government hackers, which gained remote access to workstations and obtained unclassified documents.

More + Treasury's letter to lawmakers, which we've published: https://techcrunch.com/2024/12/30/us-treasury-says-china-stole-documents-in-major-cyberattack/

US Treasury says China accessed government documents in 'major' cyberattack | TechCrunch

Treasury officials attributed the December theft of unclassified documents to China.

TechCrunch

Grab some coffee, it's ~ this week in security ~

• Cleo software hit by zero-day hacks
• China spying on calls of senior US politicians
• DOJ has a busy week indicting North Korean IT workers
• SEC's cyber disclosure rules are a hot mess
• Yahoo Paranoids loses 25% of staff this year
• Krispy Kreme hacked; Rhode Island, too.
• Plus: brand new cyber cat, the happy corner and more.

Sign up/RSS: https://this.weekinsecurity.com

Read online: https://mailchi.mp/weekinsecurity/this-week-in-security-december-15-2024-edition

Support/donate: https://ko-fi.com/thisweekinsecurity

~this week in security~

a free cybersecurity newsletter by @zackwhittaker, delivered weekly.

Leopold wishes you a happy Saturday.
Why yes, yes I am setting up DKIM & DMARC records on the horrific platform that is Google Workspaces on Thanksgiving morning. As one does.

Advanced #Programming in the #UNIX Environment

Week 13, POSIX.1e ACLs

In this week, we look at the various ways in which processes can be restricted from impacting one another, beginning with methods we've already discussed to some degree (e.g., unix file access semantics, resource limits) and ultimately leading up to #containers.

In the first video, we show how POSIX.1e Access Control Lists (ACLs) can be used for more fine-grained file system access control.

https://youtu.be/lCACl3NE058

#apue

Advanced Programming in the UNIX Environment: Week 13, Segment 1 - POSIX ACLs

YouTube
Popped up on my phone today. Sebastian about 4 years ago.
🚨 Timeline cleanse.
Good Samaritans rescue baby goat stranded on West Oahu cliff for 4 days

Inspired by a Hawaii News Now social media post, a group of strangers launched a mission to save a baby goat stuck on a cliff in West Oahu.

Hawaii News Now