Justi autem in perpetuum vivent et apud Dominum est merces eorum β Wisdom 5:16
Justi autem in perpetuum vivent et apud Dominum est merces eorum β Wisdom 5:16
"It is evening in the soul... when the light of this world fades and a man is indrawn and rests" β Meister Eckhart, Sermon 38
π¨Patch up your Kubernetes installs.
β οΈ Affected @kubernetesio versions:
< v1.11.0
v1.11.0 - 1.11.4
v1.12.0
π¦ VulnerabilitiesΒ
CVE-2025-1974
CVE-2025-1097Β
CVE-2025-1098Β
CVE-2025-24514
CVE-2025-24513
Rare urgent advisory from @Meta π¨β οΈ CVE-2025-27363: FreeType flaw risks millions. Remote code execution possible on major platforms. Patch urged as exploitation rises. Severity: 8.2/10. Affects versions pre-2.13.3. Update now!Β
RIP $TSLA... π₯ππ
Snack makers are shifting away from artificial colors in processed foods. PepsiCo's new Simply Ruffles product uses natural ingredients like tomato powder. This change aligns with a trend following the FDA's ban on Red No. 3 due to health concerns.
The iPhone 16e: the priciest budget phone! πΈ It boasts a solid display, performance, and battery life but ditches fun features like MagSafe and Dynamic Island. ποΈ Appleβs strategy? Hike prices while streamlining production. Great for profitsπ±π¬ @arstechnica
π¨Medusa #ransomware claims 40+ victims in 2025, including a US healthcare org hit in Jan. @Symantec reports nearly 400 victims since 2023, with ransom demands up to $15M. True victim count likely higher. From @InfosecurityMag π
π¨Akira ransomware gang used an unsecured webcam to deploy a Linux encryptor, bypassing EDR and encrypting network shares via SMB π€―. Highlights need for broader device monitoring beyond Windows endpoints. From @BleepinComputer
π¨@BleepinComputer: @Ethereum key stealer hits PyPI as "set-utils", downloaded 1K+ times! @billtoulas
Β warns blockchain devs to stay vigilant. #crypto
π¨ Akira ransomware exploited an unsecured webcam (yes this is an initial security vector and one reason why #Pwn2Own has IoT cameras as a target category) to encrypt a network, bypassing EDR. @BleepinComputer reports rapid attack from initial access to encryption in hours. π€― #Ransomware
@Microsoft takes down massive malvertising campaign hit ~1M PCs via GitHub repos. Malware stole system data & dropped payloads. Tracked as Storm-0408.π½π‘οΈ via @BleepingComputer
@jenkinsci releases Jenkins Security Advisory 2025-03-05
π©ΉSMR-MAR-2025: @SamsungMobile releases patches for flagship model phones π± make sure to apply the latest patch in order to secure your @Samsung devices.
https://security.samsungmobile.com/securityUpdate.smsb?year=2025&month=03
Over 37,000 VMware ESXi servers are vulnerable to a critical flaw (CVE-2025-22224) that is being actively exploited, prompting urgent updates and mitigation efforts from affected organizations. From @BleepinComputer @billtoulas
A sophisticated cyber-intrusion campaign π₯· has been reported, targeting various Japanese sectors π―π΅π― by exploiting a remote code execution flaw to gain access, deploying Cobalt Strike π¦ for persistent control, while engaging in credential theft and lateral movement
π¨@BleepinComputer: BadBox malware π¦ disrupted on 500K Android devices! @billtoulas reports.
π¬π@NVIDIA & @Broadcom are testing chips with @Intel's 18A process, showing confidence in Intel's manufacturing comeback. Details from @Reuters π
So many security advisories going out! π€― Including VMWare, HUAWEI, Paragon, and Mozilla. Here is what the vulnerability landscape looks like. Lots of Injection and Memory Corruption issues across all of these advisories.
Microsoft finalizes EU Data Boundary, keeping EU customer data local per regulations. Some still wary of US vendor ties. @TheRegister reports. ππͺπΊ
Polish Space Agency (@POLSA_GOV_PL) hit by cyberattack, systems secured. Officials probe culprits amid tensions with Moscow. @TheRegister reports. ππ
Hackers exploit ClickFix to deploy NetSupport RAT via fake CAPTCHAs, tricking users into running malicious PowerShell. @TheHackersNews ππ¨π» https://thehackernews.com/2025/03/hackers-use-clickfix-trick-to-deploy.html