shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

289
active users

#supplychainattack

0 posts0 participants0 posts today

Inside the SunBurst Attack
A Bit of Security for December 9, 2024
SunBurst has two important lessons for us: supply chain security and security vendor claims. Listen to this -
youtu.be/Gu1dFqfzf6s
Let me know what you think!
#cybersecuritytips #supplychainattack #SDLC #softwarebuild #AIforsecurity #BitofSec

youtu.be- YouTubeEnjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

There's A LOT going on (analysis, discussion, vendor notices, etc...) related to the ongoing xz/liblzma compromise so I created a "link roundup" which centralizes and buckets a lot of the awesome links and threads I've seen flying around.

shellsharks.com/xz-compromise-

I will *try* to keep this up-to-date (ish) for a few days while things are hot but I make no promises beyond that.

shellsharks · xz/liblzma Compromise Link RoundupLinks to analysis, discussion and more related to the xz/liblzma compromise (CVE-2024-3094)
Continued thread

Unit 42 (waiting about 38 hours after the news broke) gives a threat brief on CVE-2024-3094, which is the result of a supply chain compromise impacting the versions 5.6.0 and 5.6.1 of XZ Utils. XZ Utils is data compression software included in major Linux distributions. To be fair, Unit 42's list of affected distros and versions is more comprehensive than the other companies. 🔗 unit42.paloaltonetworks.com/th

Unit 42 · Threat Brief: Vulnerability in XZ Utils Data Compression Library Impacting Multiple Linux Distributions (CVE-2024-3094)By Unit 42