5.4K Followers
66 Following
106 Posts
Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon đŸ„“
LocationFrance
Is your iPhone secure? Verifium is a free open-source iOS auditor. It runs local checks against renowned security and privacy guidelines. Zero data leaves your device: https://verifium.app
Verifium - iOS Security & Privacy Auditor

An open-source iOS privacy and security auditor based on industry-standard best practices.

The XZ-Utils backdoor, first discovered in March 2024, is still present in at least 35 Linux images on Docker Hub, potentially putting users, organizations, and their data at risk.

https://www.bleepingcomputer.com/news/security/docker-hub-still-hosts-dozens-of-linux-images-with-the-xz-backdoor/

Docker Hub still hosts dozens of Linux images with the XZ backdoor

The XZ-Utils backdoor, first discovered in March 2024, is still present in at least 35 Linux images on Docker Hub, potentially putting users, organizations, and their data at risk.

BleepingComputer
Don’t use “Outlook (new)” in #Windows 11. I just did a tcpdump and looked also at my #mail servers when setting up an account in there. The mail client only spoke with Microsoft-servers, never with my mail-servers and I saw on my mail-servers only connections from Microsoft-IPs.

A case of lawful intercepts being piggy-backed by the NSA.

Not great for other countries wanting "secure" client-side scanning of E2EE just for them.

But great for the foreign intelligence service that backdoors it.

cc: @Mer__edith

https://www.computerweekly.com/news/366552520/New-revelations-from-the-Snowden-archive-surface

New revelations from the Snowden archive surface

A decade after Snowden exposed NSA’s mass surveillance in cooperation with the British GCHQ, only about 1% of the documents have been published – but three major facts can finally be revealed thanks to a doctoral thesis in applied cryptography by Jacob Appelbaum

ComputerWeekly.com
Software patch on the front page of the Financial Times Companies and Markets section. The IT/software industry has come a long way.

NEW: Researchers have found that several people in Armenia, including a govt worker, journalists, activists, and the country's human rights ombudsperson, were hacked with NSO.

The infections happened during a flare up in the years-long Nagorno-Karabakh conflict between Armenia and Azerbaijan. Because of this, researchers believe these are the first cases of spyware use in the context of a war.

https://techcrunch.com/2023/05/25/researchers-say-they-found-spyware-used-in-war-for-the-first-time/

TechCrunch is part of the Yahoo family of brands

‘Technical difficulties’? ‘Encryption event’? Minneapolis Public Schools set to open Monday after mysterious week of computer malfunctions. 

Technology problems in Minneapolis Public Schools affected the operability of systems across the district, including MPS internet, phones, cameras, badge access, copiers/printers, and building alarms.

Sahan Journal
@trojanfoxtrot depends on the size of your networks, but « high noise - low value Â»alerts are generally not worth it, except if you have the budget for extra analysts
"LockBit said it was demanding 0.5 per cent of the revenues of Royal Mail International" (ÂŁ65m?).
"the negotiator appears to have asked for help to decrypt a large file, saying it would allow to send out some crucial medical equipment, but was rebuffed by LockBit,
“You’re a very clever negotiator — I appreciate your experience in stalling and bamboozling,” the LockBit negotiator said." https://www.ft.com/content/1ffe23b3-e0a3-4545-80d7-0c4ed28a0895
Royal Mail hackers demanded ÂŁ65mn ransom

News, analysis and comment from the Financial Times, the worldÊŒs leading global business publication

Financial Times