Automating Internal Certificate Issuance With ACME-based Certificate Authority
Lessons learned from running Let's Encrypt Boulder certificate authority software in the company.
Posted
#Articles
Lessons learned from running Let's Encrypt Boulder certificate authority software in the company.
Posted
#Articles
Leverage PKCS#11 support in curl to authenticate with the Vault's TLS Certificates Auth Method
Posted
#Articles
35-year-old vulnerability has been discovered in the SCP file transfer utility. According to the advisory impact section, 'Malicious scp server can write arbitrary files to scp target directory, change the target directory permissions and to spoof the client output.'
Posted
#Weekly-News
Sennheiser's HeadSetup software is installing a root certificate into the OS Trusted CA Certificate store. They have also put a private key on a device, the same one for all users, which allows any user to perform a man-in-the-middle SSL attacks against SSL communication.
Posted
#Weekly-News
A Comcast security flaws exposed more than 26 millions of customers’ personal information. Basically, an attacker could spoof IP address using 'X-forwarded-for' header on a Comcast login page and reveal the customer’s location.
Posted
#Weekly-News
Samsung Galaxy S9 and S9+ devices, maybe others, are texting camera photos to random contacts through the Samsung Messages app without user permission.
Posted
#Weekly-News
Yet another high severity attack against the Intel CPUs. Unpatched systems can leak SIMD, FP register state between privilege levels. These registers are used for private keys nowadays. The cost of a patch is more expensive context switches because the fix has to unload and reload all SIMD, FP state.
Posted
#Weekly-News
Wandera security researchers spotted a new sophisticated Android RedDrop malware hidden in at least 53 Android applications. It can intercept SMS, record audio and exfiltrate data to the remote server.
Posted
#Weekly-News
The 'Janus' Android vulnerability (CVE-2017-13156) allows attackers to modify the code in applications without affecting their signatures. The root of the problem is that a file can be a valid APK file and a valid DEX file at the same time. The vulnerability allows attackers to inject malware into legitimate application and avoiding detection.
Posted
#Weekly-News