Category: CyberSec / ITSec / Sicherheit / Security / SPAM

cyber: keep ssh updated: ssh is critical infrastructure
30.06.2026

… is of course very very critical infrastructure, blunders in this area will have devastating consequences for the whole globe. this time it is luckily only the CLIENT ssh side that is affected libssh2 is a client-side C library implementing […]

primitive simple iptables based brute force ssh attack ban
22.05.2026

it is a common thing and a massive traffic causing annoyance… somewhere someone tries all possible usernames for ssh: this bunch of iptables/nftables scripts will: create a list of blockable IP adresses every 3h and thus block those IPs for […]

not the first Use-after-free vulnerability in Adobe Reader – no pdf mail attachments are ALSO not safe (UNFORTUNATELY) (Minimal GNU Linux OS and (of course) Doom runs in PDF document)
10.02.2025

cybersecurity wise mankind is doomed if mad CEOs (on drugs?) think it’s a good idea to allow the most bizare embedding of software into word.doc, excel.xls, just-want-to-print-that-file-properly.pdf and other formats “Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.9 […]

2024 is the year + SuperCharge IT processes with OpenSource + GNU Linux + kvm + there is still more potential + Intel Xeon vs AMD EPYC vs Altra ARM CPU vs Apple M1 benchmark battle! + M$ Office for GNU Linux
30.03.2024

Hetzner is already doing it with very energy efficient Ampere ARM servers delivering world-class-cost-and-energy-saving-virtual-servers. (Gigabyte has them as well UNTESTED!) #SuperCharge #IT processes with #OpenSource + #GNU #Linux (call it #GNU #Linux and give the dude that wrote gcc some […]

GNU Linux howto ssh sshd config hardening security guide
10.03.2024

update: 2024-06: ed25519 is currently “the way to go” ssh can be regarded as “critical core infrastructure” time spend on it’s security is time well spend time + money well invested: https://www.openssh.com https://github.com/openssh current manpage: ssh.man.txt WARNING: this howto guide […]

All Android users: Update, Update, Update
05.12.2023

https://source.android.com/docs/security/bulletin/2023-12-01?hl=en <- unfortunately does not export an RSS feed so a user needs to write a converter-aggregator https://www.heise.de/news/Patchday-Android-Android-11-12-13-und-14-fuer-Schadcode-Attacken-anfaellig-9548839.html as seen in https://www.heise.de/security/rss/alert-news-atom.xml for the news junkies – how to read news in the 21st century (APPs & RSS FEEDS) – […]

the hardcore security challenge any app store faces
05.08.2023

No matter if docker repository called “hub”, Google’s App Store “PlayStore” or Apple’s App Store they are ALL facing the same security problems: https://www.bleepingcomputer.com/news/security/google-explains-how-android-malware-slips-onto-google-play-store/ plus: https://www.bleepingcomputer.com/news/security/thousands-of-android-apks-use-compression-trick-to-thwart-analysis/ what if… a malicious actor uploads an App or docker container that is totaly […]

the positive the negative: bigdata + AI could help early detect cancer | privacy is security – why mass surveillance – German court rules mass bulk data gathering (calls, SMS, IP including location) illegal
31.03.2023

the positive: Okay let’s ALWAYS focus on the positive first: data, the web, free flow of information has given mankind new abilities: online learning-from-each-other (“social learning” one of said to be strong points of humans vs animals) better decision making […]

2023-03 IT Cyber Security Updates – Unfixed Cisco routers, Google ads to distribute malware, Evil Dota 2 game mods, Reddit’s internal documents and source code stolen, Apple zero-day vulnerabilities, malware in images, stealthy malware, fileless malware, SIM-Swapping scammer, Street magic steals crypto, Gootkit malware is actively attacking medical and financial institutions, American Megatrends BMC vulnerabilities, publicly accessible QNAP NAS again at risk, worm via USB drives, first suggested attacks on quantum cryptography, hurray for the cloud: misconfigured cloud database leaked data on ALL Australien citizens (spell it “klaut” wich is German for “steal”), Hackers modify DNS settings to redirect victims to malicious via vulnerable WiFi routers
05.03.2023

(knowing that manually auto-translating Russian CyberSec news to English, is not a feasable concept and need to be automated, but as this blog is non-profit, it is for curiosity.) Booking.com found an authentication vulnerability that allows account hijacking A vulnerability […]

Stop using Telegram – it is not safe – at all
22.02.2023

“know in some countries they believe Telegram is safe. I will show you how safe it is,” he said, before showing a screen in which he appeared to scroll through the Telegram contacts of one Kenyan strategist https://www.theguardian.com/world/2023/feb/15/revealed-disinformation-team-jorge-claim-meddling-elections-tal-hanan