LAPSUS$ se paye @okta ?
Le fournisseur de services d'authentification Okta enquête sur une probable cyberattaque après la publication de captures d'écran montrant des données internes...
#infosec#cybersecurity#threatintelligence
https://t.co/6Jvj3T7Yop
Researchers warn of a new high-risk #vulnerability (CVE-2022-0492) affecting the #Linux kernel's cgroups feature that could potentially be abused to escape a container to execute arbitrary commands on the host.
Read details: https://t.co/kj4EYGauRX
#infosec#cybersecurity
Releasing our latest project, CVEs! A constantly updated collection of 𝘢𝘭𝘮𝘰𝘴𝘵 every publicly available CVE PoC.
👉 Browse, find a PoC, and test away!
👉 Search for a specific product.
👉 Watch the repo to be notified when new PoCs go public!
https://t.co/O4NQeQvDcM
😱😱😱 This is worse than ChaosDB for AWS. @orcasec gained access to all AWS resources in all AWS accounts! They accessed the AWS internal CloudFormation service.
https://t.co/2oCCRvo389
Separately, they did something similar for Glue.
https://t.co/BDFMLQI06B
💡 Votre historique Git est obscure pour vous ? Besoin d'y voir plus clair ?
👉 « Un bon croquis vaut mieux qu'un long discours »
🚀 L'extension "Git Graph" pour VSCode est faite pour : https://t.co/RT6rQATV28
👌 Naviguer dans l'historique graphiquement hyper simplement !
🚨 S'il n'y avait qu'un seul article à lire sur #Log4Shell... regardez ici : https://t.co/IFJRvFWvvZ
1️⃣ Le mieux: maj #log4j vers la version 2.15.0
2️⃣ Sinon: maj de la variable log4j2.formatMsgNoLookups à True
3️⃣ Plus radical: enlever la classe JndiLookup
Bon courage à tous !