Security

!security

@programming.dev
Create post
1.3 million Android-based TV boxes backdoored; researchers still don’t know how

1.3 million Android-based TV boxes backdoored; researchers still don’t know how

Open link in next tab

1.3 million Android-based TV boxes backdoored; researchers still don’t know how

https://arstechnica.com/security/2024/09/researchers-still-dont-know-how-1-3-million-android-streaming-boxes-were-backdoored/

Infection corrals devices running AOSP-based firmware into a botnet.

1.3 million Android-based TV boxes backdoored; researchers still don’t know how
Microsoft starts developing tools to prevent another global IT outage

Microsoft starts developing tools to prevent another global IT outage

Open link in next tab

Just a moment...

https://www.axios.com/2024/09/13/microsoft-summit-security-products-crowdstrike

DroidFS v2.2.0

DroidFS v2.2.0

Open link in next tab

DroidFS

https://forge.chapril.org/hardcoresushi/DroidFS/releases/tag/v2.2.0

Encrypted overlay filesystems implementation for Android. Also available on GitHub: https://github.com/hardcore-sushi/DroidFS

Secure Boot is completely broken on 200+ models from 5 big device makers

Secure Boot is completely broken on 200+ models from 5 big device makers

Open link in next tab

Secure Boot is completely broken on 200+ models from 5 big device makers

https://arstechnica.com/security/2024/07/secure-boot-is-completely-compromised-on-200-models-from-5-big-device-makers/

Keys were labeled "DO NOT TRUST." Nearly 500 device models use them anyway.

Secure Boot is completely broken on 200+ models from 5 big device makers
Doing language agnostic automated unit test generation with LLMs and contextually aware mutation testing to remove code vulnerabilities

Doing language agnostic automated unit test generation with LLMs and contextually aware mutation testing to remove code vulnerabilities

Open link in next tab

GitHub - codeintegrity-ai/mutahunter: Open Source, Language Agnostic Automatic Test Generation + LLM Mutation Testing

https://github.com/codeintegrity-ai/mutahunter

Open Source, Language Agnostic Automatic Test Generation + LLM Mutation Testing - codeintegrity-ai/mutahunter

GitHub - codeintegrity-ai/mutahunter: Open Source, Language Agnostic Automatic Test Generation + LLM Mutation Testing
Microsoft IT outage latest: Airports, businesses and banks including Sky News experiencing issues worldwide

Microsoft IT outage latest: Airports, businesses and banks including Sky News experiencing issues worldwide

Open link in next tab

Microsoft IT outage latest: Airports, businesses and banks including Sky News experiencing issues worldwide

https://news.sky.com/story/outages-latest-airports-business-and-broadcasters-experiencing-issues-worldwide-13180821

Planes have been grounded as several airports are hit by a global IT outage, with Windows PCs shutting down and broadcasters and businesses also taken offline.

Microsoft IT outage latest: Airports, businesses and banks including Sky News experiencing issues worldwide
Presenting our DIY Dead Man Switch @ DEF CON 32

Presenting our DIY Dead Man Switch @ DEF CON 32

Open link in next tab

BusKill goes to DEF CON 32 - BusKill

https://www.buskill.in/defcon32/

Join BusKill at DEF CON 32 for our presentation titled "Open Hardware Design for BusKill Cord" in the Demo Lab

BusKill goes to DEF CON 32 - BusKill
The Stark Truth Behind the Resurgence of Russia’s Fin7

The Stark Truth Behind the Resurgence of Russia’s Fin7

Open link in next tab

The Stark Truth Behind the Resurgence of Russia’s Fin7 – Krebs on Security

https://krebsonsecurity.com/2024/07/the-stark-truth-behind-the-resurgence-of-russias-fin7/

CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems

CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems

Open link in next tab

oss-sec: CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems

https://seclists.org/oss-sec/2024/q3/2

oss-sec: CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems
Cloudflare's recent blog regarding polyfill shows that Cloudflare never authorized Polyfill to use their name in their product

Cloudflare's recent blog regarding polyfill shows that Cloudflare never authorized Polyfill to use their name in their product

Open link in next tab

Automatically replacing polyfill.io links with Cloudflare’s mirror for a safer Internet

https://blog.cloudflare.com/automatically-replacing-polyfill-io-links-with-cloudflares-mirror-for-a-safer-internet

polyfill.io, a popular JavaScript library service, can no longer be trusted and should be removed from websites

Automatically replacing polyfill.io links with Cloudflare’s mirror for a safer Internet