#security (2022-03)
Archive: https://archive.sweetops.com/security/
2022-03-17
Zachary Loeber
New Vulnerability in CRI-O Engine Lets Attackers Escape Kubernetes Containers
A new vulnerability in the CRI-O engine allows attackers to escape Kubernetes containers and gain root access.
2022-03-19
Jim Park
https://arstechnica.com/information-technology/2022/03/sabotage-code-added-to-popular-npm-package-wiped-files-in-russia-and-belarus/ TL;DR: open source developer releases protestware in popular node library that wipes computers with russian / belarusian ips.
Sabotage: Code added to popular NPM package wiped files in Russia and Belarus
When code with millions of downloads nukes user files, bad things can happen.
2022-03-21
jaydhulia
Oh man, if this it what it looks (Okta got popped)… Blue Team everywhere is gonna be crazy busy. https://pbs.twimg.com/media/FObGSr8VIAcOyh2.jpg
2022-03-26
Erik Osterman (Cloud Posse)
Google Issues Emergency Security Warning For 3.2 Billion Chrome Users—Attacks Underway
Google confirms an emergency Chrome update as attackers strike