📢 Version 1.2.3 of the GHAS Reporting Tool is out - a Python script to fetch GitHub Advanced Security alerts.
Bug Fixes
- Update requirements.txt to resolve vulnerabilities in script dependencies
| https://twitter.com/rhe403/ | |
| GitHub | https://github.com/rhe403/ |
📢 Version 1.2.3 of the GHAS Reporting Tool is out - a Python script to fetch GitHub Advanced Security alerts.
Bug Fixes
- Update requirements.txt to resolve vulnerabilities in script dependencies
A lot of interesting stats about CVE's in 2023
Among other:
- Almost 29,000 CVE's registered, over 15% increase vs 2022
- 36 CVEs scored a “perfect” 10.0 CVSS score.
- The lowest published CVSS score was 1.8
- On average, 79.18 CVEs were published each day.
- 22.3% of all CVE's were published on Tuesdays.
https://jerrygamblin.com/2024/01/03/2023-cve-data-review/
Also around 4,200 CVEs with CVSS score 9.8 https://www.cvedetails.com/vulnerability-search.php?f=1&vaendor=&product=&cweid=&cvssscoremin=9.8&cvssscoremax=9.8&publishdatestart=2023-01-01&publishdateend=2023-12-31&updatedatestart=&updatedateend=&cisaaddstart=&cisaaddend=&cisaduestart=&cisadueend=&page=1
Private Eye has a special report (free PDF) on the U.K. Post Office IT scandal that resulted in the wrongful convictions of hundreds of sub-postmasters accused of stealing money.
What actually transpired was that bugs in the outsourced IT system resulted in money appearing as if it was missing. A huge, if not one of the biggest miscarriages of justice in recent U.K. history
How the Post Office wrecked the lives of its own workers.
https://www.private-eye.co.uk/special-reports/justice-lost-in-the-post

CONCEIVED in 1996 as one of the first private finance initiative (PFI) contracts, between the Post Office and the Benefits Agency on the one hand and computer company ICL on the other, the Horizon IT system had an unpromising start. It had been set up to create a swipe card system for payment of pensions and benefits from Post Office branch counters. But, as with most mega-IT projects of the time, it soon fell victim to over-ambition, management consultancy snake oil and the inability of a PFI contract to deliver a complex public service.
KrebsOnSecurity celebrates its 14th year of existence today! I promised myself this post wouldn’t devolve into yet another Cybersecurity Year in Review. Nor do I wish to hold forth about whatever cyber horrors may await us in 2024. But I do want to thank you all for your continued readership, encouragement and support, without which I could not do what I do.
And a big thanks to everyone following my work from here!
https://krebsonsecurity.com/2023/12/happy-14th-birthday-krebsonsecurity/
The World Depends on 60-Year-Old Code No One Knows Anymore | PCMag
https://www.pcmag.com/articles/ibms-plan-to-update-cobol-with-watson
Doom was released 30 years ago today, on December 10th, 1993.