Snyk Found Over Four Times More Vulnerabilities in RHEL, Debian, and Ubuntu – DZone Security
Impressive list of vulnerabilities this year and even the purchase of Redhat by IBM isn’t making the paid OS immune. Check out the docker images that are floating around and be careful when trusting someone else’s container build.
https://dzone.com/articles/snyk-found-over-four-times-more-vulnerabilities-la?fromrel=true
What’s in a container image: Meeting the legal challenges | Opensource.com
Do you remember when you bought a license and installed your copy of windows X on a VM and didn’t think twice about it. You loaded your software and maybe setup a reoccurring backup for it and you were done right?
Nowadays, there are risks at even using that Windows license on a cloud provider other than Azure (but that is another story)
Today, running containers is the new thing and that software is open source right? Not always!
You could have more than just Vulnerability risk to worry about. Some container images can also have License risk and you could have legal troubles too!
https://opensource.com/article/18/7/whats-container-image-meeting-legal-challenges
Scotiabank does it again
Beginning Jan. 1, 2020, the bank’s Canadian workforce will have a
total of five personal days and the flexibility to take them as needed,
in addition to existing sick and vacation days.
“Our people are our most important asset and their well-being is a
top priority for Scotiabank,” said Barbara Mason, chief human resources
officer, in a press release. “We strongly believe that by offering
employees greater flexibility to take time off to achieve greater
work-life balance, our employee population will be healthier and
happier, and therefore enabled to perform at their very best.”
Picard is back!
… and he is teaming up with 7 of 9!
Go borg GO! This is going to be so exciting… https://twitter.com/WIRED/status/1180899318024163328?s=09
Debit cards and TD are in trouble (again)
Toronto business owner loses $14K to technical glitch at mobile payment company.
https://www.cbc.ca/news/canada/toronto/mobile-payment-glitch-1.5300313
You may remember the post a few months ago that may be related…
Multi-stage, fileless Nodersok campaign delivers rare Node.js-based malware – Microsoft Security
If you are a security operations analyst, your job just got a whole lot harder.
Lock all your doors and keep your children inside; this one is hard to find…
Over 1 million Google Chrome users affected by Cookie Stuffing from two popular adblockers | Cyware Hacker News
If you have ever visited a webpage that took a really long time to load or was filled with ads all over the site, you may have already heard that you need an ad blocker. If you were not sure of which one to use, you might be a victim of a knock off; a piece of software that is created with a similar name to the original but one that can monetize you use of it and put you at risk.
Learn about how many Google Chrome users were tricked into installing fake extensions and why you need to be sure of the names which extensions you trust.
CWE – 2019 CWE Top 25 Most Dangerous Software Errors
If you are a software developer (and not living in a cave) you may already know about vulnerabilities but did you know that there is a list of the 25 most dangerous put out by Mitre?
Well they have released the new 2019 list and some of these might surprise you…
https://cwe.mitre.org/top25/archive/2019/2019_cwe_top25.html
Quality Of Code Doesn’t Matter Much In Open Source Contributions: Study
For those of you in the software industry, you may be shocked to learn that contributor reputation trumps good old fashioned peer review when it comes to committing code in your project in a study on open source projects. I suspect this might mirror the real world where tight deadlines and outsourced labor are regular parts of the workload.
https://fossbytes.com/quality-of-code-doesnt-matter-open-source-contributions/#