As a Norwegian security nerd I am probably biased, but this is a brilliant long-read by Ben Taub/@NewYorker on life and (security) challenges in the Arctic High North. A must-read with jaw dropping details on some of Russia's cross-border, sub-threshold advances.
Which security controls reduce cyber risk and by how much?
Until recently, vendors tried to answer with peacock like competition, e.g. ever fancier marketing campaigns.
Our new article is a step towards answering with empirical evidence.
It’s official – #Sweden is now the 32nd member of #NATO, taking its rightful place at our table. Sweden’s accession makes NATO stronger, Sweden safer, and the whole Alliance more secure. I look forward to raising their flag at NATO HQ on Monday.
CISA is requiring all Federal agencies to disconnect Ivanti products by Friday at midnight (Ivanti Connect Secure & Ivanti Policy Secure). This is roughly 48 hours notice, to not patch, but rip it out! Ivanti is an American company. This is unprecedented.
https://t.co/cJZRuHHF5o
Good call with @PM_ViktorOrban of #Hungary. I welcome the clear support of the Prime Minister and his government for #Sweden’s #NATO membership. I look forward to the ratification as soon as parliament reconvenes.
New from 404 Media: we got hold of an HDMI adaptor that brazenly demands your location, browsing, photos, and spams you with ads. Used with a test phone but wild amount of data collection. Privacy policy straight up says it sends the data to "China" https://t.co/dUss6NVKFP
Yeah, so once you are safely in the provinces with your rebellious legions, you do not, in fact, return to Rome unarmed to attend meetings of the Senate on day-trips.
You stay in the provinces with your legions.
mnemonic researchers found a 0-day RCE #vulnerability within Ivanti Sentry tracked as CVE-2023-38035.
Exploitation allows an unauthenticated threat actor to read and write files to the Ivanti Sentry server and execute OS commands as root:
https://t.co/UbUZQMxN6B
#mnemonicblog
@matthew_d_green «Hash all the things, always» seemed like the Right approach when I did this 15 years ago. Even if some security proof might have a perverse need for the extra wiggle room given by *not* hashing all the things, there seems no practical reason not to feed the random oracle.
@si_ferlin I am not 100% sure if I understand what you need, but TLS_AES_128_GCM_SHA256 and TLS_CHACHA20_POLY1305_SHA256 would be the good suites to start with. (See RFC8446.)