Sys-Admin InfoSec – Telegram
Sys-Admin InfoSec
12.7K subscribers
235 photos
2 videos
103 files
4.54K links
News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Forum - forum.sys-adm.in
* Chat - @sysadm_in
* Job - @sysadm_in_job
* ? - @sysadminkz
Download Telegram
/ Elastic Security Labs discovers the LOBSHOT malware

Adversaries continue to abuse and increase reach through malvertising such as Google Ads by impersonating legitimate software..

Deep dive research and protection steps:

https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware

🥋 Malware domains already blocked in Sys-Admin BLD DNS
 
OpenBLD - Next Stage to Growth with ClouDNS

GeoDNS and Global Anycast DNS features from ClouDNS - it as a brilliant opportunity for additional OpenBLD Performance and Availability

Today ClouDNS supported OpenBLD DNS and provided own features for free:
• Anycast DNS service and Anycast GeoDNS servers
• DDoS Protection
• DNS Failover checks
• EDNS-client-subnet support
• and more...

ClouDNS providing flexible tools for managements services and very affordable pricing plans and it is I like it very much.

This can be a key milestone in the development phase of the OpenBLD project, it is a next stage for growth. I have special domain name for OpenBLD DNS project, may be it is a "that very moment"...

• All ClouDNS features you can found on ClouDNS Site
• How to protect for your self and family with OpenBLD Here
Sys-Admin InfoSec pinned «  OpenBLD - Next Stage to Growth with ClouDNS GeoDNS and Global Anycast DNS features from ClouDNS - it as a brilliant opportunity for additional OpenBLD Performance and Availability Today ClouDNS supported OpenBLD DNS and provided own features for free:…»
Открытый практикум Linux by Rebrain: ФСТЭК для Linux. Часть 2
 
• 10 Мая (Среда) в 20:00 по МСК. Детали

Программа:
• Продолжаем выполнять требования
• Что нужно поправить в работе ядра
• Что может быть если это не исправить

Ведет:
• Андрей Буранов - Специалист по UNIX-системам в компании VK. Опыт работы с ОС Linux более 7 лет.
OpenBLD Pre-release Testing Program
 
I'm working on new OpenBLD DoH/DoT release with Anycast DNS, GeoDNS (Europe, Asia locations) functionality.

I think this or next month, I'll start the new faster DoH/DoT OpenBLD testing release with automatic identification of the closest server location continent and network route detection for OpenBLD clients.

You can fill this form in, after review I'll "ping" you with testing as soon as possible:

🔶 REQUEST PARTICIPATION

Let's make internet surfing faster and safer together. Peace ✌️
When Good APIs Go Bad: Uncovering 3 Azure API Management Vulnerabilities

Vulnerabilities in the Azure API Management service. These included two SSRF (Server-Side Request Forgery) vulnerabilities and a file upload path traversal on an internal Azure workload:

Read more…
GitLab Critical Security Release: 15.11.2, 15.10.6, and 15.9.7

GitLab Community Edition (CE) and Enterprise Edition (EE) - Malicious Runner Attachment via GraphQL:

https://about.gitlab.com/releases/2023/05/05/critical-security-release-gitlab-15-11-2-released/
[CVE-2023-32233] Linux kernel use-after-free in Netfilter nf_tables

https://www.openwall.com/lists/oss-security/2023/05/08/4
MS released update consists of the following 40 Microsoft CVEs:

https://msrc.microsoft.com/update-guide/releaseNote/2023-May

One of CVE indicated as CVE-2023-24932, article for Windows Boot Manager revocations for Secure Boot changes:

https://support.microsoft.com/en-us/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d
From One Vulnerability to Another: Outlook Patch Analysis Reveals Important Flaw in Windows API


An unauthenticated attacker on the internet could use the vulnerability to coerce an Outlook client to connect to an attacker-controlled server. This results in NTLM credentials theft. It is a zero-click vulnerability, meaning it can be triggered with no user interaction


https://www.akamai.com/blog/security-research/important-outlook-vulnerability-bypass-windows-api
Открытый практикум DevOps by Rebrain: Введение в Docker
 
Успевайте зарегистрироваться. Количество мест строго ограничено! Запись практикума “DevOps by Rebrain” в подарок за регистрацию!

16 Мая (Вторник), 19:00 по МСК. Детали

Программа:
• Основы технологии контейнеризации
• Установка всех необходимых компонент
• Запуск первого контейнера
• Основные команды docker
• Разбор сетей в docker
• Обзор того, зачем нужен docker-compose
• Практика

Ведет:
Николай Лавлинский - Веб-разработчик более 15 лет. Специализация: ускорение сайтов и веб-приложений