Amazon Detective, 보안 조사를 위해 EKS에서 Kubernetes 워크로드 지원

2022-08-02 KENNETH 0

Amazon Detective, 보안 조사를 위해 EKS에서 Kubernetes 워크로드 지원 2020년 3월에 AWS는 잠재적인 보안 문제 또는 의심스러운 활동의 근본 원인을 쉽게 분석 및 조사하고 빠르게 식별할 수 있는 완전관리형 서비스인 Amazon Detective를 도입했습니다. Amazon Detective는 Amazon GuardDuty, AWS CloudTrail 및 Amazon Virtual Private Cloud(Amazon VPC) 흐름 로그에서 로그인 시도, API 호출 및 네트워크 트래픽과 같은 임시 이벤트를 전체 AWS 환경에서 관찰된 리소스 활동 및 상호 작용을 요약하는 그래프 모델로 계속 추출합니다. 그리고 AWS IAM 역할 세션 분석, 향상된 IP 주소 분석, Splunk 통합, Amazon S3 및 DNS 조사 결과 유형, AWS Organizations에 대한 지원과 같은 새로운 기능을 추가했습니다. 최근 AWS 고객은 Amazon Elastic Kubernetes Service(Amazon EKS)를 통해 Kubernetes 워크로드를 배포하기 위해 컨테이너로 빠르게 이전하고 있습니다. 컨테이너에서는 뛰어난 프로그래밍 기능 덕분에 수천 개의 개별 컨테이너 배포와 수백만 건의 구성 변경을 몇 초 만에 수행할 수 있습니다. EKS 워크로드를 효과적으로 보안하려면 EKS [ more… ]

No Image

USN-5544-1: Linux kernel vulnerabilities

2022-08-02 KENNETH 0

USN-5544-1: Linux kernel vulnerabilities It was discovered that the Atheros ath9k wireless device driver in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1679) Felix Fu discovered that the Sun RPC implementation in the Linux kernel did not properly handle socket states, leading to a use-after-free vulnerability. A remote attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-28893) Arthur Mongodin discovered that the netfilter subsystem in the Linux kernel did not properly perform data validation. A local attacker could use this to escalate privileges in certain situations. (CVE-2022-34918) Minh Yuan discovered that the floppy disk driver in the Linux kernel contained a race condition, leading [ more… ]

No Image

WP Briefing: Episode 37: The World of WordPress on World Wide Web Day

2022-08-02 KENNETH 0

WP Briefing: Episode 37: The World of WordPress on World Wide Web Day In the thirty-seventh episode of the WordPress Briefing, WordPress users and contributors reflect on how WordPress has changed their understanding of the web as we celebrate World Wide Web Day. Have a question you’d like answered? You can submit them to [email protected], either written or as a voice recording. Credits Editor: Dustin HartzlerLogo: Beatriz FialhoProduction: Santana Inniss & Chloé BringmannSong: Fearless First by Kevin MacLeod Guests: Adam Warner Alice Orrù Dee Teal Femy Praseeth Jill Binder Mary Job Oneal Rosero Theophilus Adegbohungbe Ugyen Dorji References Diverse Speaker Training Group Support Underrepresented Speakers at WordCamp US Call of Speakers – WordCamp Asia 2023 Refocusing the WordPress App on Core Features WordPress.org Homepage and Download Redesign Transcript [Josepha Haden Chomphosy 00:00:00]  Hello, everyone! And welcome to the WordPress Briefing: the podcast where [ more… ]

No Image

The Xbox Pride Controller: Available to customize year-round thanks to collective effort

2022-08-02 KENNETH 0

The Xbox Pride Controller: Available to customize year-round thanks to collective effort In the hands of a gamer, an Xbox Wireless Controller helps navigate unfamiliar worlds. With it, you can jump huge chasms, escape from seemingly impossible situations and explore an endless array of characters and places. And thanks to the recently relaunched Xbox Design Lab, it’s also a canvas players can customize – a way to express who they are and what matters to them. The latest choices for that personalization debuted in June as Microsoft’s Pride 2022 observances commenced: more than 30 LGBTQIA+ interwoven community flags that celebrate intersectionality and unity on the Xbox Pride controller. This design honors the ever expanding and ever evolving diversity of LGBTQIA+ experiences and identities that span the globe. “At the end of the day, this was a collective effort that kicked [ more… ]

No Image

USN-5543-1: Net-SNMP vulnerabilities

2022-08-01 KENNETH 0

USN-5543-1: Net-SNMP vulnerabilities Yu Zhang and Nanyu Zhong discovered that Net-SNMP incorrectly handled memory operations when processing certain requests. A remote attacker could use this issue to cause Net-SNMP to crash, resulting in a denial of service, or possibly execute arbitrary code. Source: USN-5543-1: Net-SNMP vulnerabilities