Sys-Admin InfoSec – Telegram
Sys-Admin InfoSec
12.7K subscribers
235 photos
2 videos
103 files
4.54K links
News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Forum - forum.sys-adm.in
* Chat - @sysadm_in
* Job - @sysadm_in_job
* ? - @sysadminkz
Download Telegram
/ How to Detect Malicious OAuth Device Code Phishing

Here’s a quick TL;DR of the attack – in short, an attacker generates a user code and sends it to a victim in a phishing email. The user is then tricked into inputting the code into a Microsoft owned verification link. Upon success, the attacker can fetch both the user’s refresh and access token. This allows the attacker access to the user account:

https://www.inversecos.com/2022/12/how-to-detect-malicious-oauth-device.html
/ New Samba security release available

This is the latest stable release of the Samba 4.17 release series.
It also contains security changes in order to address the following defects:

https://www.samba.org/samba/history/samba-4.17.4.html
/ Updated Debian 11: 11.6 released

https://www.debian.org/News/2022/20221217
/ VMware ESXi, Workstation, and Fusion updates address a heap out-of-bounds write vulnerability (CVE-2022-31705)

https://www.vmware.com/security/advisories/VMSA-2022-0033.html
Open BLD DNS Service: December/End of the year 2022. Update News.
 
Open BLD DNS Service - it is a free DoH / DoT / DNS project for blocking trackers, telemetry, advertising, malware with support TLS v1.2/v1.3.

🌱 New Services Added
      Adaptive Open BLD Service - A-BLD
      A-BLD service can be convenient for most Open BLD users
      New donation service added

🧘 Infra Improvements/Updates/Fixes
      New BLD build released and deployed
      Updated HTTP header for BLD serves to: Open BLD Server
      Added HTTPS root redirect from BLD to LAB site
      Updated & Optimized BLD caching infrastructure mechanisms
      Optimized on-line stability & balancing
      Now in most maintenance cases it is not affect endpoint BLD service users
      Optimized automation deplyment routines
      Fixed Firefox OCSP STAPLE issue/Fixed caching break issues

🧩 New Open BLD Project micro-tools
      Check-reboot, Get-Log, Bld-agregator, Alertmanager installer, Timestamp converter
      Updated: https://github.com/m0zgen/dns-tester
      Updated: https://github.com/m0zgen/check-dns-servers

🤝 The Open BLD DoH service is mentioned
      Curl project (https://github.com/curl/curl/wiki/DNS-over-HTTPS) (thx for contribute ✌️)
      AlternativeTo (https://alternativeto.net/software/open-bld-dns/)

🏂 Setup/How to use Open BLD DNS
      How to setup Open BLD DNS in Browses, OSs and etc: https://lab.sys-adm.in
      Donation service: https://donorbox.org/open-bld-dns-donation
 
/ Critical Vulnerability – Hikvision Wireless Bridge

…An attacker can exploit the vulnerability by sending crafted messages to the affected devices..:

https://www.redinent.com/blog/critical-vulnerability-hikvision-wireless-bridge/
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Domain Name System (DNS) Parameters

Last Updated 2022-12-06

https://www.iana.org/assignments/dns-parameters/dns-parameters.xhtml
Открытый практикум DevOps by Rebrain: IT-Quiz
 
Программа:
• квизы на разбор проблем в Kubernetes кластере
• решение в онлайн-формате
• призы победителям

• 27 Декабря (Вторник) в 19:00 по МСК. Детали
• Василий Озеров - Co-Founder REBRAIN. Более 8 лет Devops практик.
/ LastPass Data Breach December Update

...We recently notified you that an unauthorized party gained access to a third-party cloud-based storage service, which LastPass uses to store archived backups of our production data. In keeping with our commitment to transparency, we want to provide you with an update regarding our ongoing investigation.

What We’ve Learned..:

https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/
/ Detecting Azure AD Account Takeover Attacks

Cloud account takeover(ATO) is an attack where attackers gain access to cloud identities by using methods like social engineering, device code phishing, etc. Detecting these attacks can sometimes be difficult. In this blog, I’ll explain how we can develop a generic detection that covers almost any, if not all, methods for Azure AD (Well, the method can be applied to other identity providers, too)..:

https://posts.bluraven.io/detecting-azure-ad-account-takeover-attacks-b2652bb65a4c
Sys-Admin InfoSec pinned «Open BLD DNS Service: December/End of the year 2022. Update News.   Open BLD DNS Service - it is a free DoH / DoT / DNS project for blocking trackers, telemetry, advertising, malware with support TLS v1.2/v1.3. 🌱 New Services Added       Adaptive Open BLD…»