Each day Twitter remains running, CEOs worldwide will ask more questions about why they are paying so much for their IT staff. Make sure you are not paying for some executive’s bonus with your mental/physical health.
Johannes Ullrich (maybe not a bot)
Dean of Research, http://SANS.edu College | SANS Internet Storm Center | Intrusion Detection | Web App Security | Connoisseur of fine packets and honeypot logs
June 4th, 1989, Tiananmen Square, Beijing. I always think the "Tank Man" image is too clean and does not show the actual brutality of what happened when a brutal dictatorship felt challenged. hashtag#TiananmenSquareMassacre hashtag#freedom hashtag#tiananmen hashtag#毋忘六四 hashtag#june4
A quick note about the xz-utils backdoor:
1 - luckily, no mainstream distros are affected.
2 - most run xz-utils 5.2/5.4. 5.6 is vulnerable
3 - quick check: `xz -V`
4 - This makes you wonder what else is happening. Thanks to people who paid attention
https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094
Good weekend with some good dog walks. Need more of it.
Due to the June 19th holiday and travel, there will be no podcast for Wednesday and Thursday.
OS Command Injection. It doesn't get much more severe than that regarding web application/API vulnerabilities. Still, these issues keep coming up in security devices. https://isc.sans.edu/j/osinjection
I have traveled quite a bit over the years (less recently). Usually, I try to get an exit seat. In probably 100+ flights with different airlines, I remember only ONE instance where a flight attendant did a thorough exit row briefing. She explained how to open the door, what to watch out for, to wait for signals from the cabin crew before opening, and a couple of other things.
Usually, they do the “verbal yes” to acknowledge that you are in an exit row.
Yesterday, the flight attendant didn’t even do that and only made some jokes about the Delta credit card… no wonder most people look at their phones instead of the emergency briefing. :(
Interested in joining me at #SANSFIRE? We have some great special events planned. Honeypot Fest, ISC Keynote, great classes, and more. I will be teaching SEC522.. see https://www.youtube.com/watch?v=S81x1I6Ti5c
Welcome to SANSFIRE 2024
@screaminggoat not my find. I just saw the expo I’ll being used.
@screaminggoat @buherator@infosec.place you saw current models are affected? Or just that the old one never got fixed.