VMware Aria Operations: Sicherheitslücke erlaubt Rechteausweitung
Broadcom warnt vor einer hochriskanten Lücke in VMware Aria Operations. Angreifer können dadurch ihre Rechte ausweiten.

VMware Aria Operations: Sicherheitslücke erlaubt Rechteausweitung
Broadcom warnt vor einer hochriskanten Lücke in VMware Aria Operations. Angreifer können dadurch ihre Rechte ausweiten.
Eine der letzten: Code-Knackerin mit 101 Jahren gestorben
Charlotte "Betty" Webb knackte im zweiten Weltkrieg für die Briten Nazi-Codes. Nun ist sie mit 101 Jahren verstorben.
this makes me really happy: over 1/6th of the top (by download) Python projects are producing attestations!
that's a meteoric adoption rate, given that we only enabled attestation upload support on PyPI ~5 months ago!
tracker here: https://trailofbits.github.io/are-we-pep740-yet/
"To accelerate my output, AI Chatbots and their use seemed to provide a great opportunity to grow and expand what I am able to accomplish. That’s how I arrived where I am in my AI journey."
#Technology #Information #Sharing #Webiste #FreeSpeech #OpenSource #FOSS #News #Freedom #Archive #Security #AI #ChatBot #Genealogy #Writing #Research
https://eirenicon.org/choosing-primary-chatbot-environments-ai/
Ex-Pentagon Chief Discusses Signalgate Fallout, Ukraine, and Iran https://www.byteseu.com/885089/ #Conflicts #DonaldTrump #homepage_regional_americas #Iran #NuclearWeapons #Security #Trump100Days #Ukraine #UnitedStates #War
Data #security experts have expressed alarm that US #NationalSecurity professionals are not…[just]…using the govt’s suite of secure encrypted systems for work communications such as JWICS, the Joint Worldwide Intelligence Communications System.
Most concerning, however, is the use of personal email, which is widely acknowledged to be susceptible to hacking, spearfishing & other types of digital compromise.
"How popular is Donald Trump?
Silver Bulletin approval ratings for President Trump — and all presidents since Truman."
#Crisis #Tariffs #USA #EU #News #Lies #Democrats #MAGA #Fascism #Security #Canada #NATO #Economy #GDP #Oligarchy #Inflation #USA #House #Elections #Polls
https://www.natesilver.net/p/trump-approval-ratings-nate-silver-bulletin
Cross your fingers; cross your toes
"Republicans are acting like there’s a Blue Wave coming Could Democrats retake the House ... *before* the midterms?"
#Crisis #Tariffs #USA #EU #News #Lies #Democrats #MAGA #Fascism #Security #Canada #NATO #NationalSecurity #Economy #GDP #Oligarchy #Inflation #USA #House #Elections
https://www.natesilver.net/p/republicans-are-acting-like-theres
The use of #Gmail, a FAR LESS secure method of communication than the encrypted messaging app #Signal [which isn’t secure enough for these kinds of comms either], is the latest example of questionable #security practices by top #NationalSecurity ofcls already under fire for the mistaken inclusion of a journalist in a group chat about high-level planning for #military ops in Yemen.
The #StableGenius once again is clueless...
"‘Nowhere to absorb it’: From consumer small business to big food CEOs, Trump tariff costs will hit wallets"
#Crisis #Tariffs #USA #EU #News #Lies #Democrats #MAGA #Fascism #Security #Canada #NATO #NationalSecurity #Economy #GDP #Oligarchy #Inflation
https://www.cnbc.com/2025/04/01/trump-liberation-day-tariffs-consumer-food-cost-price-warning.html
The way Gitlab, Forgejo, Gitea etc. use the server-side SSH server to accept pushed data over SSH relies on a system user called git
having SSH access. (or forgejo
in their case).
Access is granted by the standard authorized_keys
inside ~/.ssh, which for forgejo means /var/lib/forgejo/.ssh/authorized_keys
. When a user adds an SSH key to their account, it's added to this authorized_keys file.
I really hate this, this means that any user of Forgejo is only inches away from having full shell access. The default shell of the forgejo
user is /bin/bash
, it exists inside of /etc/passwd
:
forgejo:x:122:130:Forgejo (Beyond coding. We forge.):/var/lib/forgejo:/bin/bash
I really really hate this. The only thing preventing random users of Forgejo having shell access is the default command of the SSH session as stipulated by the authorized_keys
entry, this is what it looks like:command="/usr/bin/forgejo --config=/etc/forgejo/app.ini serv key-1",no-port-forwarding,no-X11-forwarding,no-agent-forwarding,no-pty,no-user-rc,restrict ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOgnZeNC4fMCXYuWxir7NlKts9Zj4sYZZJzzHh4IyTm2 Baa-New
forgejo
user. It will immediately disconnect you, and if you try submitting any specific command you'll receive Disallowed command
.control userpasswords2
and then explicitly disallow them RDP access. That RDP config is the only thing preventing them for remoting straight into your server. This si what it feels like, I can't help but wish SSH was entirely separate from everything else going on here.#WaPo: Waltz and staff used Gmail for government communications, officials say
Wait, "Gmail" is not "Government Mail"?
North Korean IT worker army expands operations in Europe - North Korea's IT workers have expanded operations beyond the United States and are now i... https://www.bleepingcomputer.com/news/security/north-korean-it-worker-army-expands-operations-in-europe/ #security
Blogged: Creating SBOM attestations in GitHub Actions
https://andrewlock.net/creating-sbom-attestations-in-github-actions/
In this post I show how you can create attestations for SBOM documents that you have created for your application or Nuget package
We Smell a (DC)Rat: Revealing a Sophisticated Malware Delivery Chain - A RAR file, a fake summons, and a Nietzsche quote—all part of a multi-stage malware chain... https://www.bleepingcomputer.com/news/security/we-smell-a-dcrat-revealing-a-sophisticated-malware-delivery-chain/ #security
»Gmail Gets End-To-End Encryption From Google As 21'st Birthday Present:
[…] Google Claims To Have Invented An Entirely New Type Of Encryption For Gmail Users […]«
This is not an April joke and yes Google offers OpenPGP for Gmail Accounts. This is not difficult to set up but too many people are too lazy in my opinion.
More powers to #Europol, #Eurojust, #Frontex; criminal law rules on organised #crime and #firearms trafficking; possible review of #EuropeanArrestWarrant, European Investigation Order #EIO; breaking #encryption...
Please @EUCommission let this be a late April Fools thing
https://ec.europa.eu/commission/presscorner/detail/en/ip_25_920
#Google funds this #EU think tank to put out policy papers saying #DigitalMarketsAct will break their lovely #PlayProtect scare screens, making us all less safe and "it require[s] Google to allow developers to insert links inside their Play Store apps".
https://ecipe.org/publications/eu-dma-undermine-security-mobile-operating-systems/#_ftn13
As I've always said in relation to the #DMA, let @fdroidorg compete on trustworthiness. I'd love to see this think thank include analysis malware rates of #CalyxOS with #FDroid and compare that to #GooglePlay #security