In this episode, we talk about coding standards and guidelines and ways to build better integration between them. We look at how we can embed the security parts into the existing standards for a more streamlined and approachable resource.
NEWS
Old Jenkins vulnerability used for crypto-mining
It appears as though attacker's are using an old, patched vulnerability in Jenkins to install crypto-mining software. It is important to point out that The patch for this issue was released back in April of 2017. This highlights the importance of keeping systems up-to-date. The other point to highlight is that the vulnerability is related to a deserialization flaw. If you remember, back in Ep. 1, we talked about deserialization being added into the OWASP Top 10 for 2017. This is a good example of how this flaw can be used to remotely execute commands on a server.
https://www.theregister.co.uk/2018/02...
https://jenkins.io/security/advisory/...
Tesla cloud hacked to run crypto-mining software
It was reported that Tesla's cloud environment was hacked to use its resources for crypto-mining. The attack occurred due to a Kubernetes administrative console with no password defined. This console provided the credentials to access the Amazon S3 buckets containing sensitive data, including telemetry data. This incident highlights the need to make sure that all administrative consoles have strong authentication mechanisms to keep attackers out. It also highlights that crypto mining is becoming very popular and any CPU resources are a target.
https://arstechnica.com/information-t...
FedEx Customer Records Exposed
A large number of scanned documents were found on a public Amazon S3 bucket. The data was from Bongo International, which was acquired by FedEx in 2016 and relaunched as FedEx Cross-Border International. The data included passports, drivers licenses and other information from 2009-2012. It is important to audit any S3 buckets you have to ensure you have not inadvertently made them public. Buckets are private by default.
https://mackeepersecurity.com/post/fe...
On this page of the site you can watch the video online DevelopSec Live Ep. 03 - Secure Coding Standards and Guidelines with a duration of hours minute second in good quality, which was uploaded by the user DevelopSec 01 January 1970, share the link with friends and acquaintances, this video has already been watched 27 times on youtube and it was liked by 0 viewers. Enjoy your viewing!