moodle-3.11.8-1.fc35

Read Time:6 Second

FEDORA-2022-7e7ce7df2e

Packages in this update:

moodle-3.11.8-1.fc35

Update description:

Multiple security fixes.

Read More

Facebook Is Now Encrypting Links to Prevent URL Stripping

Read Time:54 Second

Some sites, including Facebook, add parameters to the web address for tracking purposes. These parameters have no functionality that is relevant to the user, but sites rely on them to track users across pages and properties.

Mozilla introduced support for URL stripping in Firefox 102, which it launched in June 2022. Firefox removes tracking parameters from web addresses automatically, but only in private browsing mode or when the browser’s Tracking Protection feature is set to strict. Firefox users may enable URL stripping in all Firefox modes, but this requires manual configuration. Brave Browser strips known tracking parameters from web addresses as well.

Facebook has responded by encrypting the entire URL into a single ciphertext blob.

Since it is no longer possible to identify the tracking part of the web address, it is no longer possible to remove it from the address automatically. In other words: Facebook has the upper hand in regards to URL-based tracking at the time, and there is little that can be done about it short of finding a way to decrypt the information.

Read More

Malicious emails sent from 11 hacked SEBI IDs, officials say

Read Time:33 Second

The Security and Exchange Board of India (SEBI) has filed a first information report (FIR) about a cybersecurity incident on its email system.

According to the report, filed last week, the email accounts of 11 officials were hacked by unknown persons. SEBI officials disclosed that the incident took place while the email system was undergoing a system upgrade, reporting that no sensitive information was stolen.

The incident was first brought to the notice of Varunkumar Kishan Gopal, assistant manager of IT at SEBI (BKC), when he received a complaint from Integrated Surveillance Department (ISD) manager Abhijit Chandrakant, on 23rd May.

To read this article in full, please click here

Read More

CVE-2016-15003

Read Time:18 Second

A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:Program FilesFileZilla FTP Clientuninstall.exe of the component Installer. The manipulation leads to unquoted search path. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Read More

6 security analyst job description red flags that make hiring harder

Read Time:23 Second

Hiring for the role of security analyst—that workhorse of security operations—could get even harder.

Demand for the position is expected to grow, with the U.S. Bureau of Labor Statistics predicting organizations to add tens of thousands of positions through the decade, with employment for security analysts expected to grow by 33% from 2020 to 2030—much faster than the average for all occupations.

To read this article in full, please click here

Read More

Auth0’s OpenFGA explained: Open source universal authorization

Read Time:36 Second

Auth0’s OpenFGA project is an open source effort that undertakes to provide a universal authentication solution. FGA stands for “Fine Grained Authorization,” a granular approach to authorization modeling that is flexible enough to handle almost any imaginable use case. 

Read on for an introduction to the OpenFGA project.

Authentication vs. authorization

Authentication is concerned with who and authorization with what.  Authentication answers the question: who are you?  Authorization answers the question: given who you are, what can you do?

Both of these are essential areas of cybersecurity, but of the two, authorization presents the more demanding architectural challenge.  That is because authorization deals with more complexity and far more data points. 

To read this article in full, please click here

Read More