Sys-Admin InfoSec – Telegram
Sys-Admin InfoSec
12.7K subscribers
235 photos
2 videos
103 files
4.54K links
News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Forum - forum.sys-adm.in
* Chat - @sysadm_in
* Job - @sysadm_in_job
* ? - @sysadminkz
Download Telegram
/ Performance Regression in Linux Kernel 5.19

As part of VMware's performance regression testing for Linux
Kernel upstream releases, we have evaluated the performance
of Linux kernel 5.19 against the 5.18 release and we have
noticed performance regressions in Linux VMs on ESXi as shown
below.
- Compute(up to -70%)
- Networking(up to -30%)
- Storage(up to -13%)

https://lkml.iu.edu/hypermail/linux/kernel/2209.1/02248.html
/ Miltiple vulnerabilities in Trend Micro Apex One

(Japanese article)

https://success.trendmicro.com/jp/solution/000291471
Hey all, tmrw I will speak at the KazHackStan conference with my presentation with subject:

* Open-Source Projects Responsibility Awareness (by Open BLD Example)

All details you can see on KazHackStan.kz, let's burn 🔥 tomorrow, who will be in Almaty let's get acquainted and let's talk, try to share knowledge with each other 🤘
Открытые практикумы DevOps и Linux by Rebrain (20 и 21 Сентября)
 
DevOps by Rebrain: Деплой докер приложений через ansible.
• Расскажем, зачем нужен Ansible и в чем его киллер-фичи
• Изучим базовые понятия Ansible
• Разберемся, как писать Ansible-playbook
• Задеплоим небольшое приложение

• 20 Сентября 19.00 МСК. Детали
• Захар Трегубов - 7 лет опыта работы с Linux. 2 года опыта работы в клиентском сервисе.

Linux by Rebrain: Скрипты bash.
• Shebang
• Параметры запуска скрипта
• Что нужно знать работая с переменными в скрипте

• 21 Сентября 20.00 МСК. Детали
• Андрей Буранов - Специалист по UNIX-системам в компании VK. Опыт работы с ОС Linux более 7 лет.
/ The FLEXLAN FXA2000 and FXA3000 series devices from CONTEC are WiFi access point mainly used in airplanes and allows very high speed communication to provide movies, musics, but also buy foods and goodies during the flight trip

https://samy.link/blog/pages/contec-flexlan-fxa2000-and-fxa3000-series-vulnerability-repo/contec-1.jpg
Today I had improved DoH speed in Open BLD DNS, you can try BLD DoH in your browser with address: https://bld.sys-adm.in/dns-query

How to setup:
- https://lab.sys-adm.in/en/instructions/
/ Chrome & Edge Enhanced Spellcheck Features Expose PII, Even Your Passwords

Some of the largest websites in the world have exposure to sending Google and Microsoft sensitive user PII, including username, email, and passwords..

https://www.otto-js.com/news/article/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords
/ The Evolution of the Chromeloader Malware

ChromeLoader proves to be an extremely prevalent and persistent malware. It initially drops as an .iso and can be used to leak users’ browser credentials, harvest recent online activity and hijack the browser searches to display ads. The VMware Carbon Black Managed Detection and Response (MDR) team observed the first Windows variants of ChromeLoader in the wild in January 2022 and the macOS version in March 2022…

Tech. analysis:

https://blogs.vmware.com/security/2022/09/the-evolution-of-the-chromeloader-malware.html
/ Threat Actors Continue to Abuse Google Tag Manager for Payment Card e-Skimming

https://www.recordedfuture.com/threat-actors-continue-to-abuse-google-tag-manager-for-payment-card-e-skimming
Открытые практикумы Linux и Networks by Rebrain (28 и 29 Сентября)
 
Linux by Rebrain: Прокси-сервер.
• Базовые принципы модели OSI
• На каком уровне работает прокси
• Tor прокси

• 28 Сентября 20.00 МСК. Детали
• Андрей Буранов - Специалист по UNIX-системам в компании VK. Опыт работы с ОС Linux более 7 лет.

Networks by Rebrain: Резервирование маршрутов в пределах автономной системы.
• отличия в настройке маршрутизации на L3-коммутаторах и маршрутизаторах
• управление приоритетами статических и динамических маршрутов
• плавающие статические маршруты

• 29 Сентября 20.00 МСК. Детали
• Ольга Яновская - Руководитель направления Networks by Rebrain. Ph.D. in Information Technology. Cisco NetAcad Instructor/Success Lead/Instructor-Trainer.
 
/ Creosote - solution to searching for the tarfile vulnerability described by CVE-2007-4559

This CVE - Directory traversal vulnerability in the extract and extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267:

https://github.com/advanced-threat-research/Creosote
/ An incident impacting password resets on Twitter

..
We want to let you know that we recently fixed a bug that allowed Twitter accounts to stay logged in from multiple devices after a voluntary password reset. In order to help ensure the safety and security of everyone that may have been affected, we’ve proactively logged people who may have been affected out of active sessions..
..

https://privacy.twitter.com/en/blog/2022/an-issue-impacting-password-resets