Incoming Hong Kong leader John Lee vows US sanctions will not interfere with safeguarding national security
John Lee says sanctions imposed by ‘some bullying countries’ will not deter him and his government from their ‘must-fulfil’ responsibility. ⌘ Read more
China chalks up success in push to promote favoured candidates on international bodies
The country’s representative has secured another term on a leading UN maritime body that rules on important economic and political disputes. ⌘ Read more
US, China talks in Luxembourg may set stage for Biden-Xi face-to-face summit
US National Security Adviser Jake Sullivan and Chinese Communist Party Politburo member Yang Jiechi met in Europe’s Luxembourg on Monday, the 4th in-person meeting of US-China officials in 15 months. ⌘ Read more
Candidates running for Hong Kong arts body will need to get nominations from powerful Election Committee to ensure ‘national security elements’ addressed
Change will bring the Arts Development Council poll in line with others held under Beijing’s ‘patriots-only’ electoral shake-up, the Home Affairs Bureau says. ⌘ Read more
WTO strikes landmark deals after tense Geneva talks, prompting cheers
The World Trade Organization concluded hard-won deals on fishing subsidies, food insecurity and Covid-19 vaccines in a landmark bundle of agreements secured through hectic round-the-clock talks in Geneva. ⌘ Read more
White House adviser calls relationship with India ‘most important for the United States’
Kurt Campbell, US President Joe Biden’s Indo-Pacific adviser, discusses plans to offer more security guarantees to New Delhi and also hints at developments in the Aukus pact. ⌘ Read more
US security adviser says hard line on Russia is needed to dissuade China from similar moves
National Security Adviser Jake Sullivan says an unchallenged invasion of Ukraine would embolden ‘other would-be aggressors, like China’. ⌘ Read more
WTO talks down to the wire with no major deals yet in sight, India holds its ground
First meeting for four years wrapped up without solutions to issues such as food security, overfishing and access to Covid vaccines. India said it was a voice for developing countries resisting high-handed Western demands. ⌘ Read more
Top US human rights official decries ‘transnational repression’ campaign by China
Uzra Zeya, undersecretary of state for civilian security, democracy and human rights, says federal government lacks funding to meet all requests for protection; China denies targeting dissidents overseas. ⌘ Read more
China’s party congress promotions to emphasise political security
Appointments are expected to sharpen focus on potential threats to the state and draw a line under the corruption scandals of recent years. ⌘ Read more
Can Joe Biden’s proposed Middle East trip unite fractured region by aligning militaries against Iran?
The US President will visit Saudi Arabia in mid-July for a scheduled summit, where he is expected to table a “national security programme” for Israel and eight Arab states, to integrate their militaries into an alliance against Iran. ⌘ Read more
Taiwan-US security and military talks will discuss weapons and strategies to defend island against Beijing
Working-level talks between security and military officials this week precede high-level talks next week in Washington and Annapolis, Maryland. ⌘ Read more
Australia-China relations: Canberra’s foreign minister Penny Wong to travel to Solomon Islands amid China security pact concerns
Australia, New Zealand, Japan and the US have voiced concerns Beijing could establish a military presence in the Pacific following the signing of a security pact with the Solomon Islands. ⌘ Read more
RT by @mind_booster: 1/10 @EU_Commission needs to understand that playing with online privacy & security affects EVERYONE. @edri alongside 70+ civil society & professional organisations urge the withdrawal of the CSA Regulation & call for an alternative that is compatible with EU href=”https://we.loveprivacy.club/search?q=%23FundamentalRights👇🏿”>#FundamentalRights👇🏿**
1/10 @EU_Commission needs to understand that playing with online privacy & security affects EVERYONE. @edri alongside 70+ … ⌘ Read more
What’s new in security and user management for GitHub Enterprise
Learn how you can securely manage users with the latest ships for GitHub Enterprise. ⌘ Read more
GitHub Enterprise Server 3.5 is now generally available
GitHub Enterprise Server 3.5 is available now, including access to the Container registry, the addition of Dependabot, enhanced administrator capabilities, and features for GitHub Advanced Security. ⌘ Read more
npm security update: Attack campaign using stolen OAuth tokens
npm’s impact analysis of the attack campaign using stolen OAuth tokens and additional findings. ⌘ Read more
How we use Dependabot to secure GitHub
A two-part story about how GitHub’s Product Security Engineering team rolled out Dependabot internally to track vulnerable dependencies, and how GitHub tracks and prioritizes technical debt. ⌘ Read more
Eight years of the GitHub Security Bug Bounty program
It was another record year for our Security Bug Bounty program. We’re excited to highlight some achievements we’ve made together with the bounty community from 2021! ⌘ Read more
Securing and delivering high-quality code with innersource metrics
With innersource, it’s important to measure both the amount of innersource activity and the quality of the code being created. Here’s how. ⌘ Read more
GitHub Achieves ISO/IEC 27001:2013 Certification!
GitHub’s Information Security Management System (ISMS) has been certified against ISO 27001:2013, an internationally recognized standard for security program best practices. ⌘ Read more
Today’s most common security vulnerabilities explained
We’re taking a look at some of the most common security vulnerabilities and detailing how developers can best protect themselves. ⌘ Read more
Software security starts with the developer: Securing developer accounts with 2FA
GitHub will require all users who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA) by the end of 2023. ⌘ Read more
rosuH/EasyWatermark
🔒 🖼 Securely, easily add a watermark to your sensitive photos. 安全、简单地为你的敏感照片添加水印,防止被小人泄露、利用
Language: Kotlin
Star: 890
Watch: 890 ⌘ Read more
Best practices to keep your projects secure on GitHub
These days software is subject to an ever-changing threat landscape. Check out the many ways you can keep your projects secure on GitHub today. ⌘ Read more
5 simple things every developer can do to ship more secure code
From plug-and-play automations to protected branches, here are simple ways any developer can build more secure software on GitHub—all with a free account. ⌘ Read more
Your guide to GitHub InFocus: Improving the way software development teams work in 2022
We’re kicking off InFocus, a global virtual event focused on accelerating, securing, and improving the way software development teams work. ⌘ Read more
Sharing security expertise through CodeQL packs (Part I)
Introducing CodeQL packs to help you codify and share your knowledge of vulnerabilities. ⌘ Read more
Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators
On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm. Read on to learn more about the impact to GitHub, npm, and our users. ⌘ Read more
Git security vulnerability announced
Upgrade your local installation of Git, especially if you are using Git for Windows, or you use Git on a multi-user machine. ⌘ Read more
Git Credential Manager: authentication for everyone
Ensuring secure access to your source code is more important than ever. Git Credential Manager helps make that easy. ⌘ Read more
How Dependabot empowers you to keep your projects secure
We want to take away the pain and effort of keeping your code secure, so check out how Dependabot empowers developers to keep to their projects secure. ⌘ Read more
Proactively prevent secret leaks with GitHub Advanced Security secret scanning
Organizations with GitHub Advanced Security can now proactively protect against secret leaks with secret scanning’s new push protection feature. ⌘ Read more
How to secure your end-to-end supply chain on GitHub
Securing your projects is no easy task, but end-to-end supply chain security is more top of mind than ever. We’ve seen bad actors expand their focus to taking over user accounts, commonly used dependencies, and also build systems. Defending against these attacks is hard, because there’s no one thing you can do to protect your […] ⌘ Read more
GitHub Actions: secure self-hosted runners by limiting them to specific workflows
You can now enforce consistent usage of self-hosted runner groups across your organization and enterprise. ⌘ Read more
Validate all the things: improve your security with input validation!
If there’s one habit that can make software more secure, it’s probably input validation. Here’s how to apply OWASP Proactive Control C5 (Validate All Inputs) to your code. ⌘ Read more
I would HIGHLY recommend reading up on the keybase architecture. They designed device key system for real time chat that is e2e secure. https://book.keybase.io/security
A property of ec keys is deriving new keys that can be determined to be “on curve.” bitcoin has some BIPs that derive single use keys for every transaction connected to a wallet. And be derived as either public or private chains. https://qvault.io/security/bip-32-watch-only-wallets/
Can an Internet connected computer be unhackable?
I mean… really, truly secure? Can it be done? ⌘ Read more
Get started with ease using security workflows!
In-line with the other categories, workflows in the Security category will be recommended based on a repository’s content. ⌘ Read more
GitHub Advisory Database now open to community contributions
Anyone can now provide additional information to further the community’s understanding and awareness of security advisories. ⌘ Read more
Ok, so I have now installed CloudReady, switched to the beta channel as well, but I can’t use Linux because my CPU is not secured against Spectre/Meltdown and CloudReady doesn’t come with microcode updates. Until that comes, my ThinkPad will probably only be for browsing, watching videos, and blogging… ⌘ Read more
How I can access Linux with Chrome OS Flex
I recently installed CloudReady on my ThinkPad. Unfortunately, the Linux feature is not available there because microcode updates are missing, there is no BIOS update and Crostini is quite strict about security. ⌘ Read more
Ok, so I have now installed CloudReady, switched to the beta channel as well, but I can’t use Linux because my CPU is not secured against Spectre/Meltdown and CloudReady doesn’t come with microcode updates. Until that comes, my ThinkPad will probably only be for browsing, watching videos, and blogging… ⌘ Read more
Leveraging machine learning to find security vulnerabilities
A behind-the-scenes peek into the machine learning framework powering new code scanning security alerts. ⌘ Read more
Ignite Realtime Blog: Openfire 4.7.1 Released!
The Ignite Realtime Community is happy to announce the 4.7.1 release of Openfire. This release fixes a number of bugs and represents our effort to provide a stable 4.7.x series while work continues on the next feature release of Openfire.
Notable fixes include security updates to bundled database drivers, logging configuration fixes, and an important fix for users experiencin … ⌘ Read more
Dino: Dino 0.3 Release
Dino is a secure and privacy-friendly messaging application. It uses the XMPP (Jabber) protocol for decentralized communication. We aim to provide an intuitive, clean and modern user interface.
The 0.3 release is all about calls. Dino now supports calls between two or more people!
Calls are end-to-end encrypted and use a direct connection between … ⌘ Read more
The Impacts of an Insecure Software Supply Chain
Today, software regularly integrates open-source code from third-party sources into applications. While this practice empowers developers to create more capable software in a shorter time frame, it brings with it the risk of introducing inadequately vetted code. How aware are we of the security of our open-source code? Most of us use pip or npm […]
The post [The Impacts of an Insecure Software Supply Chain](https://www.docker.com/blog/the-im … ⌘ Read more
Top-100 npm package maintainers now require 2FA, and additional security-focused improvements to npm
Starting today, we are rolling out mandatory 2FA to all maintainers of top-100 npm packages by dependents. ⌘ Read more
Thinking beyond SQL injection: OWASP tips for secure database access
When it comes to secure database access, there’s more to consider than SQL injections. OWASP Top 10 Proactive Control C3 offers guidance. ⌘ Read more
Prosodical Thoughts: Prosody 0.11.13 released
We are pleased to announce a new minor release from our stable branch.
This is a(nother!) release for our stable branch to fix a memory leak caused
by the security fix. Deployments using websockets, SQL storage and possibly
other configurations may have noticed increasing memory usage after upgrading
to 0.11.12. This is resolved by this new release.
A summary of changes in this release:
Minor changes