Открытые практикумы DevOps, Linux, Networks, Golang (расписание на Февраль)
• 2 февраля Networks: ТСР и пропускная способность
• 7 февраля DevOps: Сквозное логирование с использованием транзакционных логов
• 8 февраля Linux: Базовые команды - 2
• 9 февраля Networks: Multicast, часть 3
• 13 февраля TeamLead: Документирование по Agile
• 14 февраля DevOps: Анализ скорости загрузки сайтов
• 15 февраля Linux: LVM - 2
• 16 февраля Golang: Организация асинхронных приложений
• 16 февраля Networks: Мониторинг и управление устройствами по протоколу SNMP
• 20 февраля TeamLead: Как тимлиду уйти в отпуск и продолжить эффективно управлять командой
• 21 февраля DevOps: Ansible 101
• 22 февраля Linux: Пакеты RPM и DEB
• 27 февраля TeamLead: Оптимизируем время команды
• 28 февраля DevOps: Основной алгоритм траблшутинга
Программа практикумов, бесплатная запись, все Здесь
• 2 февраля Networks: ТСР и пропускная способность
• 7 февраля DevOps: Сквозное логирование с использованием транзакционных логов
• 8 февраля Linux: Базовые команды - 2
• 9 февраля Networks: Multicast, часть 3
• 13 февраля TeamLead: Документирование по Agile
• 14 февраля DevOps: Анализ скорости загрузки сайтов
• 15 февраля Linux: LVM - 2
• 16 февраля Golang: Организация асинхронных приложений
• 16 февраля Networks: Мониторинг и управление устройствами по протоколу SNMP
• 20 февраля TeamLead: Как тимлиду уйти в отпуск и продолжить эффективно управлять командой
• 21 февраля DevOps: Ansible 101
• 22 февраля Linux: Пакеты RPM и DEB
• 27 февраля TeamLead: Оптимизируем время команды
• 28 февраля DevOps: Основной алгоритм траблшутинга
Программа практикумов, бесплатная запись, все Здесь
postimg.cc
telegram cloud photo size 2 5393486520498899931 y — Postimages
/ HeadCrab: A Novel State-of-the-Art Redis Malware in a Global Campaign
https://blog.aquasec.com/headcrab-attacks-servers-worldwide-with-novel-state-of-art-redis-malware
https://blog.aquasec.com/headcrab-attacks-servers-worldwide-with-novel-state-of-art-redis-malware
Aqua
HeadCrab: A Novel State-of-the-Art Redis Malware in a Global Campaign
Aqua Nautilus uncovers threat actor HeadCrab has created an advanced malicious Redis framework that has compromised over 1200 servers and how to protect yourself
/ Serious security hole plugged in infosec tool binwalk
https://portswigger.net/daily-swig/serious-security-hole-plugged-in-infosec-tool-binwalk
https://portswigger.net/daily-swig/serious-security-hole-plugged-in-infosec-tool-binwalk
The Daily Swig | Cybersecurity news and views
Serious security hole plugged in infosec tool binwalk
Path traversals could ‘void reverse engineering efforts and tamper with evidence collected’
/ Microsoft DART ransomware approach and best practices
This article describes how DART handles ransomware attacks for Microsoft customers so that you can consider applying elements of their approach and best practices for your own security operations playbook
— https://learn.microsoft.com/en-us/security/compass/incident-response-playbook-dart-ransomware-approach
This article describes how DART handles ransomware attacks for Microsoft customers so that you can consider applying elements of their approach and best practices for your own security operations playbook
— https://learn.microsoft.com/en-us/security/compass/incident-response-playbook-dart-ransomware-approach
Docs
Microsoft Incident Response ransomware approach and best practices
Understand how Microsoft Incident Response responds to ransomware attacks and their recommendations for containment and post-incident activities.
/ Hacking into Toyota’s global supplier management network
https://eaton-works.com/2023/02/06/toyota-gspims-hack/
https://eaton-works.com/2023/02/06/toyota-gspims-hack/
Eaton-Works
Hacking into Toyota’s global supplier management network
Inside an exploit that allowed logging in to Toyota’s GSPIMS application as any user, including system admins.
/ Cl0p Ransomware Targets Linux Systems with Flawed Encryption | Decryptor Available
https://www.sentinelone.com/labs/cl0p-ransomware-targets-linux-systems-with-flawed-encryption-decryptor-available/
https://www.sentinelone.com/labs/cl0p-ransomware-targets-linux-systems-with-flawed-encryption-decryptor-available/
SentinelOne
Cl0p Ransomware Targets Linux Systems with Flawed Encryption | Decryptor Available
An in-the-wild ELF variant of Cl0p ransomware shows the gang is looking beyond traditional Windows targets.
/ OpenSSL Security Advisory [7th February]
Severity: High
There is a type confusion vulnerability relating to X.400 address processing
inside an X.509 GeneralName.
https://www.openssl.org/news/secadv/20230207.txt
Severity: High
There is a type confusion vulnerability relating to X.400 address processing
inside an X.509 GeneralName.
https://www.openssl.org/news/secadv/20230207.txt
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
ESXiArgs-Recover is a tool to allow organizations to attempt recovery of virtual machines affected by the ESXiArgs ransomware attacks:
https://github.com/cisagov/ESXiArgs-Recover
https://github.com/cisagov/ESXiArgs-Recover
GitHub
GitHub - cisagov/ESXiArgs-Recover: A tool to recover from ESXiArgs ransomware
A tool to recover from ESXiArgs ransomware. Contribute to cisagov/ESXiArgs-Recover development by creating an account on GitHub.
THREAT_ALERT_GootLoader_Large_payload_leading_to_compromise_BLOG.pdf
8.9 MB
/ THREAT ALERT: GootLoader - SEO Poisoning and Large Payloads Leading to Compromise
Full deep dive analyses
Full deep dive analyses
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Bash noscripting - DNS Tester Tool
DNS Tester Tool can test speed response for IP addresses from list and collect and show speed statistics in terminal:
— IP address
— Average response
— Minimal time of response
— Maximum time of response
• [en] - https://lab.sys-adm.in/blog/tool-dns-tester
• [ru] - https://lab.sys-adm.in/ru/blog/tool-dns-tester
DNS Tester Tool can test speed response for IP addresses from list and collect and show speed statistics in terminal:
— IP address
— Average response
— Minimal time of response
— Maximum time of response
• [en] - https://lab.sys-adm.in/blog/tool-dns-tester
• [ru] - https://lab.sys-adm.in/ru/blog/tool-dns-tester
/ High Vulnerability – Dahua – CVE-2022-30564
Redinent Researchers discovered unauthorised device timestamp modification vulnerability in Dahua products.
— https://www.redinent.com/blog/dahua-cve-2022-30564/
Redinent Researchers discovered unauthorised device timestamp modification vulnerability in Dahua products.
— https://www.redinent.com/blog/dahua-cve-2022-30564/
/ Reddit was hacked
Reddit systems were hacked as a result of a sophisticated and highly-targeted phishing attack. They gained access to some internal documents, code, and some internal business systems..:
https://www.reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/
Reddit systems were hacked as a result of a sophisticated and highly-targeted phishing attack. They gained access to some internal documents, code, and some internal business systems..:
https://www.reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/
Reddit
From the reddit community on Reddit
Explore this post and more from the reddit community
/ Globalping CLI
This CLI tool provide access a global network of probes without leaving console. In short: this tool allow use
Tool supplied in docker, or pre-builded packages, or own build binary which can build with Go. Repo:
— https://github.com/jsdelivr/globalping-cli
Tis project has API, which can try on link: https://api.globalping.io/demo/
This CLI tool provide access a global network of probes without leaving console. In short: this tool allow use
ping from different regions from the world, example:globalping ping lab.sys-adm.in --from "Paris"Tool supplied in docker, or pre-builded packages, or own build binary which can build with Go. Repo:
— https://github.com/jsdelivr/globalping-cli
Tis project has API, which can try on link: https://api.globalping.io/demo/
/ Fool’s Gold: dissecting a fake gold market pig-butchering scam
Scammers use counterfeit bank website, hijacked legitimate app to defraud and steal identifying information:
https://news.sophos.com/en-us/2023/02/13/fools-gold-dissecting-a-fake-gold-market-pig-butchering-scam/
Scammers use counterfeit bank website, hijacked legitimate app to defraud and steal identifying information:
https://news.sophos.com/en-us/2023/02/13/fools-gold-dissecting-a-fake-gold-market-pig-butchering-scam/
Sophos News
Fool’s Gold: dissecting a fake gold market pig-butchering scam
Scammers use counterfeit bank website, hijacked legitimate app to defraud and steal identifying information.
/ iOS, iPadOS, macOS, and Safari Under Attack with New Zero-Day
CVE-2023-23529 - bug in the WebKit browser engine that could be activated when processing maliciously crafted web content, culminating in arbitrary code execution:
— macOS: https://support.apple.com/en-us/HT213633
— iOS: https://support.apple.com/en-us/HT213635
— Safari: https://support.apple.com/en-us/HT213638
CVE-2023-23529 - bug in the WebKit browser engine that could be activated when processing maliciously crafted web content, culminating in arbitrary code execution:
— macOS: https://support.apple.com/en-us/HT213633
— iOS: https://support.apple.com/en-us/HT213635
— Safari: https://support.apple.com/en-us/HT213638
Apple Support
About the security content of macOS Ventura 13.2.1
This document describes the security content of macOS Ventura 13.2.1.
/ Crypto Wallet Address Replacement Attack
https://blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack
https://blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack
Phylum Research | Software Supply Chain Security
Phylum Discovers Revived Crypto Wallet Address Replacement Attack
Phylum discovers over 451 unique malicious packages targeting popular PyPI packages like Selenium.
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
/ Windows Graphics Component Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21823
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21823
/ VMware ESXi 8.0b Release Notes
https://docs.vmware.com/en/VMware-vSphere/8.0/rn/vsphere-esxi-80b-release-notes/index.html
https://docs.vmware.com/en/VMware-vSphere/8.0/rn/vsphere-esxi-80b-release-notes/index.html
/ Android launches yet another way to spy on users with “Privacy Sandbox” beta
https://arstechnica.com/gadgets/2023/02/googles-privacy-sandbox-advertising-system-arrives-on-android-in-beta/
https://arstechnica.com/gadgets/2023/02/googles-privacy-sandbox-advertising-system-arrives-on-android-in-beta/
Ars Technica
Android launches yet another way to spy on users with “Privacy Sandbox” beta
Rather than match iOS's tracking limits, Google built an additional tracking system.