Hardening repositories against credential theft
Some best practices and important defenses to prevent common attacks against GitHub Actions that are enabled by stolen personal access tokens, compromised accounts, or compromised GitHub sessions.
The post Hardening repositories against credential theft appeared first on The GitHub Blog. ⌘ Read more
snac/the fediverse for a few days and already I've had to mute somebody. I know I come on strongly with my opinions sometimes and some people don't like that, but this person had already started going ad hominem (in my reading of it), and was using what felt to me like sketchy tactics to distract from the point I was trying to make and to shut down conversation. They were doing similar things to other people in the thread so rather than wait for it to get bad for me I just muted them. People get so weirdly defensive so fast when you disagree with something they said online. Not sure I fully understand that.
@prologic@twtxt.net attacking the person, not the idea. It’d be like if you said “yarn is better than mastodon because it isn’t push based” and someone who disagreed with you said “well you think that because you’re an idiot” or something like that.
Power LED Attack - Computerphile ⌘ Read more
Crypto collapse? Get in loser, we’re pivoting to AI – Attack of the 50 Foot Blockchain
Someone on here gave me a hard time when I suggested that the crypto grifters were pivoting to AI after crypto collapsed. But, they were and they still are.
@movq@www.uninformativ.de wow. I’d trade crow sounds for car sounds, or jet sounds, or leaf blower sounds, or lawn mower sounds, or…..100% of the time.
As far as fighting the birds goes, maybe they’re right, but probably it’d be better to re-balance the ecosystem so that crows aren’t so dominant? At least there are things to try. When it comes to reducing how much air travel people use, it takes a terrorist attack or a pandemic to affect it.
Orcas attacking boats wasn’t on my 2023 bingo card but amused all the same
@stigatle@yarn.stigatle.no @prologic@twtxt.net @eldersnake@we.loveprivacy.club I love VR too, and I wonder a lot whether it can help people with accessibility challenges, like low vision.
But Meta’s approach from the beginning almost seemed like a joke? My first thought was “are they trolling us?” There’s open source metaverse software like Vircadia that looks better than Meta’s demos (avatars have legs in Vircadia, ffs) and can already do virtual co-working. Vircadia developers hold their meetings within Vircadia, and there are virtual whiteboards and walls where you can run video feeds, calendars and web browsers. What is Meta spending all that money doing, if their visuals look so weak, and their co-working affordances aren’t there?
On top of that, Meta didn’t seem to put any kind of effort into moderating the content. There are already stories of bad things happening in Horizon Worlds, like gangs forming and harassing people off of it. Imagine what that’d look like if 1 billion people were using it the way Meta says they want.
Then, there are plenty of technical challenges left, like people feeling motion sickness or disoriented after using a headset for a long period of time. I haven’t heard announcements from Meta that they’re working on these or have made any advances in these.
All around, it never sounded serious to me, despite how much money Meta seems to be throwing at it. For something with so much promise, and so many obvious challenges to attack first that Meta seems to be ignoring, what are they even doing?
@prologic@twtxt.net Because they are rightwing assholes with a huge platform and they are literally HURTING PEOPLE. People get attacked because of things people like Shapiro and Peterson say. This is not just idle chitchat over coffee. They are saying things like it’s OK to rape women (and NO I am not going to dig out the videos where they say that –that’s up to YOU to do, do your own homework before defending these ghouls).
LogJam Attack - Computerphile ⌘ Read more
SUSE CEO out effective immediately, replacement CEO not available until later.
A failed IPO, political attacks, and purchased “awards” are the legacy of the departing CEO of the oldest Linux company. ⌘ Read more
お知らせ:J-CLICS攻撃経路対策編 ⌘ Read more
GitHub Security Lab audited DataHub: Here’s what they found
The GitHub Security Lab audited DataHub, an open source metadata platform, and discovered several vulnerabilities in the platform’s authentication and authorization modules. These vulnerabilities could have enabled an attacker to bypass authentication and gain access to sensitive data stored on the platform. ⌘ Read more
PEP 708: Extending the Repository API to Mitigate Dependency Confusion Attacks
Dependency confusion attacks, in which a malicious package is installed instead of the one the user expected, are an increasingly common supply chain threat. Most such attacks against Python dependencies, including the recent PyTorch incident, occur with multiple package repositories, where a dependency expected to come from one repository (e.g. a custom index) is installed from another (e.g. PyPI). ⌘ Read more
The importance of improving supply chain security in open source
We think a lot about a high-profile supply chain attack that might cause developers, teams, and organizations to lose trust in open source. That’s why we’re investing in new ways to protect the open source ecosystem. ⌘ Read more
❤️ 🎶: Divine Attack - Shingeki - by BABYMETAL
Resolve Vulnerabilities Sooner With Contextual Data
OpenSSL 3.0.7 and “Text4Shell” might be the most recent critical vulnerabilities to plague your development team, but they won’t be the last. In 2021, critical vulnerabilities reached a record high. Attackers are even reusing their work, with over 50% of zero-day attacks this year being variants of previously-patched vulnerabilities. With each new security vulnerability, we’re […] ⌘ Read more
How Lunduke handles conflict, personal attacks, & political differences in the Tech industry
Listen now (51 min) | The Lunduke Journal Podcast - September 7, 2022 ⌘ Read more
New request for comments on improving npm security with Sigstore is now open
Supply chain attacks exploit our implicit trust of open source to hurt developers and our customers. Read our proposal for how npm will significantly reduce supply chain attacks by signing packages with Sigstore. ⌘ Read more
Corrupting memory without memory corruption
In this post I’ll exploit CVE-2022-20186, a vulnerability in the Arm Mali GPU kernel driver and use it to gain arbitrary kernel memory access from an untrusted app on a Pixel 6. This then allows me to gain root and disable SELinux. This vulnerability highlights the strong primitives that an attacker may gain by exploiting errors in the memory management code of GPU drivers. ⌘ Read more
Thanks for the feedback! This site was designed to look perfect on good old 800x600 monitors (I even left a comment next to the meta tag). Maybe I’ll add a mobile-friendly version someday :-) P.S. Nice try with SQL injection, haha. Do you have any plans for XSS attacks? :D
**Apparently, there are still those who they’re able to fool others with the argument “we cannot fight the climate crisis now, because we have to take care of the economy.”
This “economy first” approach is naive: the climate crisis attacks the economy too:
https://www.weforum.org/agenda/2021/06/impact-climate-change-global-gdp/**
Apparently, there are still those who they’re able to fool others with the argument “we cannot fight the climate crisis now, because we have to take care of the economy.”
This “econ … ⌘ Read more
Lone surviving attacker in Paris massacre guilty of murder, jailed for life
Islamic State extremist Salah Abdeslam was given the most severe sentence possible for his role in the deadly 2015 bombings and shootings that killed 130 people. ⌘ Read more
Russia’s Putin visits ‘friendly’ Central Asia on first trip abroad during war
Russia has been at pains to show it’s not under international isolation despite unprecedented US and European sanctions imposed over its attack on Ukraine. ⌘ Read more
Hindu man beheaded in India over support for Prophet Mohammed remarks
The victim was a tailor who shared a social media post supporting former BJP spokeswoman Nupur Sharma, according to local media. A video of the attack was widely shared online. Two men have been arrested. ⌘ Read more
US urged to plan minelaying campaign to halt mainland Chinese attack on Taiwan
A US navy commander suggests that laying mines in the Yellow Sea and Pearl River Delta could help bring Beijing to the negotiating table. ⌘ Read more
Russian missiles hit crowded shopping centre in Ukraine, Zelensky says
More than 1,000 people were in the shopping centre at the time of the attack, according to President Volodymyr Zelensky. ;It is impossible to even imagine the number of victims’, he said. ⌘ Read more
Violence against women in China: outrage over video of furious attack by teen boy on secondary schoolgirl classmate after a board game dispute
A wave of public outrage has spread across social media in mainland China after the emergence of a graphic video of a boy violently attacking a female secondary school classmate. ⌘ Read more
Call reveals Russia’s Putin told Macron he ‘wanted to play ice hockey’ on eve of Ukraine invasion
The final call between the French and Russian leaders just four days before Putin ordered the attack on Ukraine is filled with tension and bizarre moments. ⌘ Read more
China ‘no-limits’ vow with Russia raises Pentagon urgency to prepare for Guam attack: US commander
‘Extremely dangerous’ if Beijing and Moscow were to make good on recent doubling down of partnership, says US Indo-Pacific Commander John Aquilino. ⌘ Read more
Hong Kong chauffeur acquitted on charge of inciting members of drivers’ WhatsApp group to attack police with machetes
District Court accepts Fong Man-ho’s defence that he was merely venting his frustration at police’s handling of 2019 protests and posted remarks on impulse. ⌘ Read more
Chinese security official calls for crackdown on gangs following Tangshan attack
The political and legal affairs chief urges authorities to ‘fight against evil’ in the wake of a brutal assault on women in northern China. ⌘ Read more
US Capitol riot hearings to take break as new evidence floods in
Lawmakers investing the January 6 attack have received a glut of new video footage of Trump and his family from a documentary filmmaker. ⌘ Read more
Ukraine says it hit Black Sea oil platform used by Russia’s troops
The attack was the first such strike against offshore energy infrastructure in Crimea since the start of Moscow’s invasion in February. ⌘ Read more
Police officer fired and 5 placed under investigation over attack in women in Chinese city of Tangshan
A deputy district commander was dismissed from his post with the others being investigated by the local disciplinary watchdog ⌘ Read more
Hong Kong protests: 2 teenagers sentenced to correctional training, hard labour for vandalising bakery during 2019 protests
Student, 18, and boy, 15, plead guilty to count of criminal damage for attack on Arome Bakery in Tseung Kwan O Plaza. ⌘ Read more
Cloudflare and the Web sites it uses to perform MiTM attacks are down in many places around the world. Rejoice!
Beijing is likely to step up its campaign to ‘reunify’ with Taiwan, analysts say
Chance of an armed conflict is higher than five years ago as PLA ‘will soon be equipped with the tools needed’ to attack the island, analyst says. ⌘ Read more
Woman arrested for making anti-Asian remarks, pepper spraying 4 people in New York
Madeline Barker was charged with hate crimes over the June 11 attack in which she pepper-sprayed four Asian women. ⌘ Read more
Tangshan restaurant attack suspect was wanted by Chinese authorities over previous crimes
One of the man accused of attacking women in a restaurant was named as a fugitive in court records over a previous assault. ⌘ Read more
Chinese destroyer on long-distance exercises in Sea of Japan, to deter ‘attack on Taiwan’
Japan’s Defence Ministry said 3 ships were spotted on Sunday travelling toward Sea of Japan. Global Times reported the mission was part of China’s military build-up aimed at deterring a foreign intervention in the event of an attack on Taiwan. ⌘ Read more
‘No basis’ for attack fears in China’s new rules for PLA activities
Regulation covers PLA missions from disaster relief to humanitarian aid and peacekeeping, as well as its response to political crises at home and overseas. ⌘ Read more
Indian forces in Kashmir kill militants suspected of targeted shooting, part of increased counter-insurgency effort
It’s believed they were Kashmir Freedom Fighters who claim responsibility for shooting a bank manager this month. At least 16 people – both Hindu and Muslims – have been killed in targeted attacks in Kashmir this year. ⌘ Read more
https://www.hertzbleed.com/ side-channel attack
d65536
⌘ Read more
d65536
⌘ Read more
npm security update: Attack campaign using stolen OAuth tokens
npm’s impact analysis of the attack campaign using stolen OAuth tokens and additional findings. ⌘ Read more
Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators
On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm. Read on to learn more about the impact to GitHub, npm, and our users. ⌘ Read more
How to secure your end-to-end supply chain on GitHub
Securing your projects is no easy task, but end-to-end supply chain security is more top of mind than ever. We’ve seen bad actors expand their focus to taking over user accounts, commonly used dependencies, and also build systems. Defending against these attacks is hard, because there’s no one thing you can do to protect your […] ⌘ Read more
Spacecraft Debris Odds Ratio
⌘ Read more