No Image

Architecting Zero Trust Security for Kubernetes Apps with NGINX

2022-09-27 KENNETH 0

Architecting Zero Trust Security for Kubernetes Apps with NGINX The sophistication and number of cybersecurity attacks is growing exponentially, creating significant risk of exposure for your apps deployed in on‑premises, hybrid, and multi‑cloud Kubernetes environments. Traditional security models are perimeter‑based, assuming that users are trustworthy (and the communication among them secure) if they’re located within the environment’s secured boundaries. In today’s distributed environments, the concept of a safe zone inside the perimeter no longer exists – communications originating from “inside” the environment can be just as dangerous as external threats. In this blog, we explore the benefits of adopting a Zero Trust model to secure your Kubernetes infrastructure and how NGINX can help improve your security posture. What Is Zero Trust? Zero Trust is a security model based on identity rather than location. It assumes that any request for access to [ more… ]

[도서] 디지털 뭐부터 시작해요?

2022-09-27 KENNETH 0

[도서] 디지털 뭐부터 시작해요? 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]디지털 뭐부터 시작해요? 정은영(주주월드) 저 | BOOKK(부크크) | 2022년 10월 판매가 9,100원 (0%할인) | YES포인트 0원(0%지급) 『디지털, 뭐부터 시작해요』는 현재 활용도가 높고 자주 사용하는 디지털 도구 3가지를 골라 쉽고 간단하게 익힐 수 있게 작성했다. 그렇기 때문에 디지털 세상이 아직은 낯설고 두렵지만, 용기 내어 새롭게 시작하 Source: [도서] 디지털 뭐부터 시작해요?

No Image

USN-5642-1: WebKitGTK vulnerabilities

2022-09-27 KENNETH 0

USN-5642-1: WebKitGTK vulnerabilities Several security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Source: USN-5642-1: WebKitGTK vulnerabilities

No Image

USN-5641-1: Squid vulnerabilities

2022-09-27 KENNETH 0

USN-5641-1: Squid vulnerabilities Mikhail Evdokimov discovered that Squid incorrectly handled cache manager ACLs. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-41317) It was discovered that Squid incorrectly handled SSPI and SMB authentication. A remote attacker could use this issue to cause Squid to crash, resulting in a denial of service, or possibly obtain sensitive information. (CVE-2022-41318) Source: USN-5641-1: Squid vulnerabilities

No Image

USN-5640-1: Linux kernel (Oracle) vulnerabilities

2022-09-27 KENNETH 0

USN-5640-1: Linux kernel (Oracle) vulnerabilities It was discovered that the framebuffer driver on the Linux kernel did not verify size limits when changing font or screen size, leading to an out-of- bounds write. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-33655) Duoming Zhou discovered that race conditions existed in the timer handling implementation of the Linux kernel’s Rose X.25 protocol layer, resulting in use-after-free vulnerabilities. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-2318) Roger Pau Monné discovered that the Xen virtual block driver in the Linux kernel did not properly initialize memory pages to be used for shared communication with the backend. A local attacker could use this to expose sensitive information (guest kernel memory). (CVE-2022-26365) Roger Pau Monné discovered that [ more… ]