Category: CyberSec / ITSec / Sicherheit / Security / SPAM

the hardcore security challenge any app store faces
05.08.2023

No matter if docker repository called “hub”, Google’s App Store “PlayStore” or Apple’s App Store they are ALL facing the same security problems: https://www.bleepingcomputer.com/news/security/google-explains-how-android-malware-slips-onto-google-play-store/ plus: https://www.bleepingcomputer.com/news/security/thousands-of-android-apks-use-compression-trick-to-thwart-analysis/ what if… a malicious actor uploads an App or docker container that is totaly […]

the positive the negative: bigdata + AI could help early detect cancer | privacy is security – why mass surveillance – German court rules mass bulk data gathering (calls, SMS, IP including location) illegal
31.03.2023

the positive: Okay let’s ALWAYS focus on the positive first: data, the web, free flow of information has given mankind new abilities: online learning-from-each-other (“social learning” one of said to be strong points of humans vs animals) better decision making […]

2023-03 IT Cyber Security Updates – Unfixed Cisco routers, Google ads to distribute malware, Evil Dota 2 game mods, Reddit’s internal documents and source code stolen, Apple zero-day vulnerabilities, malware in images, stealthy malware, fileless malware, SIM-Swapping scammer, Street magic steals crypto, Gootkit malware is actively attacking medical and financial institutions, American Megatrends BMC vulnerabilities, publicly accessible QNAP NAS again at risk, worm via USB drives, first suggested attacks on quantum cryptography, hurray for the cloud: misconfigured cloud database leaked data on ALL Australien citizens (spell it “klaut” wich is German for “steal”), Hackers modify DNS settings to redirect victims to malicious via vulnerable WiFi routers
05.03.2023

(knowing that manually auto-translating Russian CyberSec news to English, is not a feasable concept and need to be automated, but as this blog is non-profit, it is for curiosity.) Booking.com found an authentication vulnerability that allows account hijacking A vulnerability […]

Stop using Telegram – it is not safe – at all
22.02.2023

“know in some countries they believe Telegram is safe. I will show you how safe it is,” he said, before showing a screen in which he appeared to scroll through the Telegram contacts of one Kenyan strategist https://www.theguardian.com/world/2023/feb/15/revealed-disinformation-team-jorge-claim-meddling-elections-tal-hanan

Rust vs Go – Open Source is about enabling users – Rust lang will complement C around the GNU Linux Kernel (for better safety) “Amazon, Microsoft, Google” and the White House, want to make Open Source more secure
16.05.2022

Open Source is about enabling users “Amazon, Microsoft, Google” and the White House, want to help make Open Source more secure… https://www.golem.de/news/openssf-150-millionen-us-dollar-sollen-open-source-absichern-2205-165382.html https://www.golem.de/news/openssf-linux-foundation-will-security-praxis-vereinheitlichen-2008-150036.html src of src: “White House OSS Mobilization Plan” 2022: https://openssf.org/blog/2022/05/11/testimony-to-the-us-house-committee-on-science-and-technology/ 2020: “The OpenSSF is a cross-industry collaboration […]

FreeBSD based Citrix VPN hacked in massive hostpital healthcare hack in Germany CVE 2019 19781 – hits healthcare hospital in Germany, causing death of (at least) 1 person
27.04.2022

https://cve.circl.lu/cve/CVE-2019-19781 https://www.healthcare-computing.de/bsi-warnt-vor-schwachstelle-bei-vpn-produkten-von-citrix-a-964940/ https://www.cnblogs.com/lsgxeva/p/12116150.html hits healthcare hospital in Germany, causing death of (at least) 1 person https://www.businessinsider.de/politik/deutschland/hacker-legen-uniklinik-duesseldorf-lahm-staatsanwaltschaft-ermittelt-wegen-todesfall-einer-patientin/

2021-11 Russian IT Security Updates – why it is impossible to turn off the Internet in Russia – what is the “Mitnick attack”? – are the odds against the defenders? Browser Sidechannel Attacks “We confirm that none of these approaches completely defend against our attacks” – 2010: AI amok: how AIs almost crashed wallstreet and why it can have real world consequences (1929)
04.11.2021

warning: no guarantee of completeness! contains ads! (but owner of blog get’s nothing, maybe source of source does) Are the odds against the (itsec) defenders? It certainly feels that way, because no human can ever find all bugs, so Fuzzing […]

Open Web Application Security Project (OWASP) online community web application security
07.08.2021

the wiki: https://en.wikipedia.org/wiki/OWASP the top 10: https://owasp.org/www-project-top-ten/2017/Top_10.html the ebook: https://github.com/OWASP/owasp-mstg/releases/download/v1.2/OWASP_MSTG-1.2.pdf the text: https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/01-Test_Network_Infrastructure_Configuration the conferences: https://owasp.org/www-board/ https://www.blackhat.com/us-21/ the costs: https://training.owasp.org/ 2-part Training: $505 Member 2-part Training: $455 * For member discount code contact events ÄT owasp DOOOT com https://www.udemy.com/course/intro-to-bug-bounty-by-nahamsec/ it’s […]

GNU Linux Debian – basic simple update.sh script – security-tracker.debian.org tracker status release stable – semi-manual system update method vs full automatic updates – apt can do https now: update /etc/apt/sources.list http -> https
26.07.2021

updates are a bless (fixes to problems, keep system secure from hackerz) but also a curse (it might break things) on systems that follow the UNIX K.I.S.S principle, they should “just work”, to the extreme of (kernel) live patching (currently […]

What is Right – What is Wrong – with great powers comes great responsibility (aka the “Peter-Parker-principle” (Spiderman 2002)) – Big Tech with better and betters Tools and without better Ethics Morals unkowing what is Right or Wrong
17.07.2021

in short: humans per default, without an education might just be “better” apes. Some parts of mankind behave very primitive and clearly show no signs of higher intelligence or education. The troubles start, when the tools become more and more […]

for the news junkies – how to read news in the 21st century (APPs & RSS FEEDS) – turns the user’s Android based device into an independent Open Source based news aggregator that respects the user’s privacy
16.06.2021

Yes! What RSS does NOT stand for “Rashtriya Swayamsevak Sangh” , “Nathuram Godse, who assassinated Gandhi, on January 30, 1948, was a member of the Rashtriya Swayamsevak Sangh, or R.S.S., a violent right-wing organization that promotes Hindu supremacy.” (src: HolyCow!) […]