Lessons Learned Using Vault As A Secret Store
Lessons learned from the multi year operation of the HashiCorp Vault Open Source deployment.
Posted
#Articles
Lessons learned from the multi year operation of the HashiCorp Vault Open Source deployment.
Posted
#Articles
Dutch security researcher Victor Gevers found misconfigured MongoDB database containing facial recognition and other sensitive information about the Uyghur Muslim minority in China. Looks like the company behind the database is Chinese surveillance company SenseNets.
Posted
#Weekly-News
Sennheiser's HeadSetup software is installing a root certificate into the OS Trusted CA Certificate store. They have also put a private key on a device, the same one for all users, which allows any user to perform a man-in-the-middle SSL attacks against SSL communication.
Posted
#Weekly-News
Researchers at the University of California have found that GPUs are vulnerable to side-channel attacks and demonstrated multiple types of attacks. After reverse engineering Nvidia GPU, researchers were able to steal rendered password box from a browser, sniffed other browser related data and also settings from the neural network computations on a GPU in the data center.
Posted
#Weekly-News
A reverse shell connection is possible from an OpenVPN configuration file. So be cautious and treat ovpn files like shell scripts.
Posted
#Weekly-News
There is a first ransomware which is taking advantage of a new Process Doppelgänging fileless code injection technique. Working on all modern versions of Microsoft Windows, since Vista. This variant of a known SynAck ransomware is using NTFS transactions to launch a malicious process by replacing the memory of a legitimate process.
Posted
#Weekly-News
Fraudsters are impersonating authors and publishing computer generated books so they can launder money via Amazon.
Posted
#Weekly-News