Oddbean new post about | logout

Notes by am | export

 "Me at the zoo" is a YouTube video uploaded on April 23, 2005. It is the first video to be uploaded to the platform. The 19-second video features YouTube's co-founder Jawed Karim in front of two elephants at the San Diego Zoo in California. Source: Wikipedia https://image.nostr.build/c11b9686aa359e7862b5be11ef4e111aa1d657984720efc99a07595bd57ae2f5.jpg  
 Released a new tool to handle CVE-2024-3094! Protect your systems from this critical xz-utils vulnerability. Easy to detect & automates the fix process. Check it out & stay secure!  #CyberSecurity #OpenSource #CVE2024_3094 https://github.com/alokemajumder/CVE-2024-3094-Vulnerability-Checker-Fixer 
 5.25” floppies were still running American nuclear weapons in 2019. Image collected from google. https://image.nostr.build/5eba8b072581b03bc1f131cb761214fbe78cf4e9a216d41c5f4ae6a75c1fdf7f.jpg  
 Got a handle on #Linux permissions with #umask, #chmod, and #setfacl. It's easier than you think! Check out my tips for quick read.
https://medium.com/it-security-in-plain-english/understanding-linux-permissions-a-guide-to-umask-chmod-and-setfacl-47382da76249 
 Ever thought your phone could be hacked while charging? Juice jacking is real and risky! Check out the guide on how to avoid these cyber traps at public charging stations. Stay safe and keep your data protected! https://medium.com/it-security-in-plain-english/guarding-against-juice-jacking-how-to-secure-your-devices-in-public-spaces-c609a65119aa #Juicejacking #CyberSecurity 
 Next version of signalapp will feature "usernames option", allowing users to keep their phone numbers secret  https://github.com/signalapp/Signal-Android/compare/v6.47.4...v7.0.0 
 Did you know HSTS can be your website's one of the best defense against cyber threats?  It ensures encrypted connections, deterring hackers and securing data. Perfect for anyone looking to enhance their site's security.  https://medium.com/@alokemajumder/what-is-hsts-and-why-should-we-use-it-caa080949a01 #HSTS #WebSecurity #CyberSecurity 
 Understanding Video Encoding: Formats, Packaging, and Device Compatibility for Beginners https://medium.com/media-cloud-tech/understanding-video-encoding-formats-packaging-and-device-compatibility-for-beginners-d58b50c71be1 
 Just explored GitHub Actions in my new article! From setup to continuous deployment, and even workflow optimization, it's all there. Aimed at developers looking to boost their project's efficiency and reliability. Dive in and see how GitHub Actions can transform your CI/CD pipelines. Let's innovate our development practices together!https://medium.com/hoichoi-tech/how-to-leverage-github-actions-for-continuous-delivery-and-deployment-a4219d8bf582  #DevOps #GitHubActions 
 Beeper Mini on Android stopped working and Apple confirmed today that it “took steps to protect our users by blocking techniques that exploit fake credentials in order to gain access to iMessage.” https://image.nostr.build/214ad3548411729f169f50c0aab8133bbde8be95ea8cfa66537cfbef13689684.jpg  
 Google’s new Gemini AI model is getting a mixed reception after its big debut yesterday, but users may have less confidence in the company’s tech or integrity after finding out that the most impressive demo of Gemini was pretty much faked.  https://techcrunch.com/2023/12/07/googles-best-gemini-demo-was-faked/amp/ 
 Windows and Linux computer models from virtually all hardware makers are vulnerable to a new attack that executes malicious firmware early in the boot-up sequence, that allows infections that are nearly impossible to detect or remove using current defense mechanisms. https://arstechnica.com/security/2023/12/just-about-every-windows-and-linux-device-vulnerable-to-new-logofail-firmware-attack/ 
 VulnCheck reports over 9,000 GitHub repositories at risk of repojacking from username changes, plus 6,000+ due to account deletions. In total, 15,000 repositories, supporting 800,000+ Go module-versions, are exposed to this vulnerability.  https://vulncheck.com/blog/go-repojacking #GitHubSecurity #RepojackingRisk 
 A step-by-step guide on creating a self-signed SSL certificate for Nginx on Ubuntu! Secure your web server with HTTPS in no time. Check it out now! 💻🛡️ #SSL #Nginx #WebSecurity #Ubuntu #HTTPS https://encryptnow.org/2023/12/how-to-create-a-self-signed-ssl-certificate-for-nginx-in-ubuntu-22-04-lts/ 
 French startup Biomemory is rolling out a credit-card-sized storage device that uses DNA to encode a kilobyte of text data. https://www.wired.com/story/store-a-message-in-dna/ 
 How Hackers Use Bluetooth to Take Over Your Mac Device
 https://www.threatlocker.com/blog/mac-bluetooth-impersonation-attacks 
 Microsoft Cybersecurity Reference Architectures (MCRA). A slide deck full of high-level guidance on securing one's organisation.  https://learn.microsoft.com/en-us/security/cybersecurity-reference-architecture/mcra 
 With the new Mountpoint for Amazon S3 Container Storage Interface (CSI) driver, your Kubernetes applications can access S3 objects through a file system interface, achieving high aggregate throughput without any changes to your application. https://aws.amazon.com/about-aws/whats-new/2023/11/mountpoint-amazon-s3-csi-driver/ 
 Varia is a simple download manager that conforms to the latest Libadwaita design guidelines, integrating nicely with GNOME. It uses the amazing aria2 to handle the downloads. https://github.com/giantpinkrobots/varia 
 AI tools for every niche that'll get you massively ahead . 
 AWS Kill Switch is an open-source incident response tool for quickly locking down AWS accounts and IAM roles during a security incident. https://github.com/secengjeff/awskillswitch 
 Amazon Q is an expert #GenerativeAI-powered assistant for building on AWS. Get started building faster, learn unfamiliar technologies, build new solutions, and streamline tedious tasks like maintenance.
 https://aws.amazon.com/q/ 
 Buying consumer electronics  is a mess. Most salespeople don't understand the technology they're selling, It's exhausting and frustrating being a power user here! 
 The most unusual OSINT guide you've ever seen.  https://github.com/OffcierCia/non-typical-OSINT-guide 
 A tool for extracting additional data from a person's personal identifiers  https://github.com/duk3r4/KD6-3.7 
 #Signal unveils its first-ever cost breakdown, projecting annual expenses of $50M by 2025. It emphasizes this move goes beyond seeking donations, aiming to shed light on the surveillance profit model they're challenging. 
 All the deals for InfoSec related software/tools this Black Friday / Cyber Monday. 

https://github.com/0x90n/InfoSec-Black-Friday