FOSSlife · @fosslife
2012 followers · 200 posts · Server fosstodon.org

Advisory issued by cybersecurity agencies shows older vulnerabilities are the most frequently exploited by attackers fosslife.org/older-vulnerabili

#cybersecurity #cisa #log4j #systemadministration #networking

Last updated 1 year ago

Stefan Rother-Stübs · @roterstuebs
6 followers · 177 posts · Server norden.social

@einfachnurRoland

@kuketzblog

Im Unterschied zu Log4J ist es wohl mit einem Update einer Abhängigkeit nicht getan .

Und selbst Log4Shell war schon teilweise mit einigem Aufwand für Nacharbeiten verbunden.

Dieses Problem klingt eher systemisch.

#supergau #itsicherheit #log4j

Last updated 1 year ago

einfachnurRoland · @einfachnurRoland
33 followers · 1496 posts · Server nrw.social

@heiseonline der Artikel spricht genau das aus, was wir alle seit , und wissen: man weiß nichts, außer man hat selbst nachgesehen. Letzteres klappt bei OpenSource auch nur theoretisch.
So systemimmament und zwangsläufig diese Probleme bei sind, ist es unerklärlichliches Mysterium, das es Branchen gibt, die funktionieren.

#log4j #bonify #mscloud #software

Last updated 1 year ago

einfachnurRoland · @einfachnurRoland
32 followers · 1478 posts · Server nrw.social

@kuketzblog der letzte der ist ja schon 1,5 Jahre her.

#supergau #itsicherheit #log4j

Last updated 1 year ago

Christian · @apas_csc
41 followers · 1075 posts · Server ruhr.social

Clients asking us if we are affected by the vulnerabilities. Never heard of it, never used it. But if customers start to ask their suppliers that's an indication of panic. Last time this happened with .

#moveit #log4j #Log4Shell

Last updated 1 year ago

Onno Bos :cybersec: :verified: · @admin
97000000012 followers · 97001983 posts · Server mastodon.adtension.com

#log4j

Last updated 1 year ago

PyLadies Bot · @pyladies_bot
94 followers · 80 posts · Server botsin.space
Nerdeiro :debian: :steamdeck: · @nerdeiro
128 followers · 619 posts · Server fosstodon.org

I got sick tired of people hammering my web server trying to exploit vulnerabilities on things like or that I don't even run. My list of blocked IPs on was getting out of control, so I took off and nuked the site from orbit (only way to be sure). I blocked ALL IP addresses from China using and

#log4j #wordpress #fail2ban #iptables #ipset #firewall #linux #nginx

Last updated 1 year ago

Tarnkappe.info · @tarnkappeinfo
2135 followers · 4567 posts · Server social.tchncs.de
Joe Warminsky · @jwarminsky
52 followers · 281 posts · Server journa.host

"We're still responding to that hack today," House Homeland Security chairman says about the incident as the panel advances legislation on gov use of open-source software

therecord.media/house-senate-c

#log4j

Last updated 1 year ago

GeekProjects News · @news
4 followers · 3116 posts · Server geekprojects.com
IT News · @itnewsbot
3197 followers · 258911 posts · Server schleuss.online

This Week in Security: Oracle Opera, Passkeys, and AirTag RFC - There’s a problem with Opera. No, not that kind of opera. The Oracle kind. Oracle ... - hackaday.com/2023/05/05/this-w

#news #log4j #oracle #airtag #securityhacks #hackadaycolumns

Last updated 1 year ago

warns of exploiting
The US government's Cybersecurity and Infrastructure Security Agency (CISA) is adding three more flaws to its list of known-exploited , including one involving TP-Link routers that is being targeted by the operators of the notorious Mirai botnet.
The other two placed on the list this week involve versions of 's Server software and the Apache Foundation's Java logging library
theregister.com/2023/05/02/cis

#cisa #mirai #botnet #tplink #routers #vulnerabilities #oracle #weblogic #log4j

Last updated 1 year ago

This week's episode of Talos Takes has the latest advice from Talos Incident Response on how to prepare for cyber attacks. We're here to lend a helping hand to put together everything from a software bill of goods to tabletop exercises to help your organization prepare for the next time a or happens buzzsprout.com/2018149/1264991

#log4j #3cx #supplychain

Last updated 2 years ago

AG Connect · @AGConnect
240 followers · 723 posts · Server mstdn.social

De overheid heeft een nieuwe nationale veiligheidsstrategie opgesteld, waarin een topprioriteit wordt genoemd. Concreet worden in het rapport onder meer impactvolle als genoemd als bedreiging, maar ook de kwetsbaarheid in de wijdverbreid gebruikte -software.
agconnect.nl/artikel/ransomwar

#log4j #NotPetya #Ransomware #CyberSecurity

Last updated 2 years ago

Hendrik · @intelligensbestien
0 followers · 4 posts · Server me.dm

Log4j programmers, wake up! 15+ months after fixing a critical vulnerability, software still uses the old, broken version. Take it offline & force a fix NOW. Don't wait for a catastrophic data breach to act. Your negligence risks the entire industry.

#log4j #softwaresecurity

Last updated 2 years ago

Marcel SIneM(S)US · @simsus
174 followers · 2828 posts · Server social.tchncs.de
kurtseifried (he/him) · @kurtseifried
605 followers · 159 posts · Server infosec.exchange

In the olden days if you had a 1000+ software packages to manage you were a fully fledged operating system with software, nowadays we call this a "web app."

Find out some hard lessons learned over the year from @kurtseifried and @joshbressers on the opensourcesecurity.io/2023/03/ TL;DR: counting vulnerabilities is both completely stupid, and completely neccesary. The trick is to think about them the right way (hint: statistics, not pets. Except when they are pets like . Who's a good vulnerability? You are!).

#osspodcast #log4j

Last updated 2 years ago

LMG Security · @LMGsecurity
45 followers · 26 posts · Server infosec.exchange