#hardening — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #hardening, aggregated by home.social.
-
Anyone got a #nixos #flake exampke to share that uses #apparmour ? #flakes #hardening Cheers!
-
Harden supervisord by replacing TCP ports with a local UNIX domain socket. Restrict supervisorctl access using strict POSIX permissions (chmod/chown). #supervisor #hardening #ValtersIT
https://www.valtersit.com/vault/secure-unix-socket-control-interface-with-strict-file-permis-d86b48/
-
Harden supervisord by replacing TCP ports with a local UNIX domain socket. Restrict supervisorctl access using strict POSIX permissions (chmod/chown). #supervisor #hardening #ValtersIT
https://www.valtersit.com/vault/secure-unix-socket-control-interface-with-strict-file-permis-d86b48/
-
Harden supervisord by replacing TCP ports with a local UNIX domain socket. Restrict supervisorctl access using strict POSIX permissions (chmod/chown). #supervisor #hardening #ValtersIT
https://www.valtersit.com/vault/secure-unix-socket-control-interface-with-strict-file-permis-d86b48/
-
Good news about these CSS attacks / exfiltration attacks on webmails and email clients? Mailove is fully secure with remote content off (=by default)!
Now based on these news, I've added also fix in viewersecurity.cpp that narrows the opt-in to images only. Inline <style>, style attributes, and cid:/data: fonts are untouched.
https://github.com/nekromoff/mailove
#email #mail #css #hacking #exfiltration #security #hardening #software #hack
-
Зачем переводить сухой регламент в работающие настройки — харденинг Linux
Большинство документов по защите информации читаются как перевод с иностранного языка. Красивые слова, логичная структура, ни одного конкретного шага. Администратор получает такой регламент, ставит галочку в чек-листе и идёт дальше. Через полгода сервер оказывается в ботнете, потому что никто не объяснил, почему именно этот пункт важен именно в этой инфраструктуре. Реальная защита строится не на соблюдении регламента, а на понимании механики атак. Каждый пункт требований появился потому, что когда-то кто-то забыл закрыть порт, оставил пароль по умолчанию или не обновил пакет. Разбор этих пунктов через конкретные ситуации даёт больше, чем десять страниц общих формулировок. В подсистеме nf_tables ядра Linux обнаружена уязвимость CVE-2026-23111, которую вызвал единственный лишний символ «!» в исходном коде. Логическая ошибка в функции nf_tables_addchain() создаёт условие use-after-free, позволяющее локальному непривилегированному пользователю выполнить код в контексте ядра и получить полные привилегии root Патч сводится к удалению этого одиночного символа, но до его выпуска миллионы систем с активным пакетным фильтром nftables оставались открытыми для полного компрометирования хоста
-
El lado del mal - Despliegue Zero-Trust para Agentes IA https://www.elladodelmal.com/2026/06/despliegue-zero-trust-para-agentes-ia.html #Jailbreak #PromptInjection #Hardening #IA #AI #AgenticAI #ZeroTrust #Hardening #Fortificacion #NonHumanIdentities
-
El lado del mal - Despliegue Zero-Trust para Agentes IA https://www.elladodelmal.com/2026/06/despliegue-zero-trust-para-agentes-ia.html #Jailbreak #PromptInjection #Hardening #IA #AI #AgenticAI #ZeroTrust #Hardening #Fortificacion #NonHumanIdentities
-
El lado del mal - Despliegue Zero-Trust para Agentes IA https://www.elladodelmal.com/2026/06/despliegue-zero-trust-para-agentes-ia.html #Jailbreak #PromptInjection #Hardening #IA #AI #AgenticAI #ZeroTrust #Hardening #Fortificacion #NonHumanIdentities
-
El lado del mal - Despliegue Zero-Trust para Agentes IA https://www.elladodelmal.com/2026/06/despliegue-zero-trust-para-agentes-ia.html #Jailbreak #PromptInjection #Hardening #IA #AI #AgenticAI #ZeroTrust #Hardening #Fortificacion #NonHumanIdentities
-
El lado del mal - Despliegue Zero-Trust para Agentes IA https://www.elladodelmal.com/2026/06/despliegue-zero-trust-para-agentes-ia.html #Jailbreak #PromptInjection #Hardening #IA #AI #AgenticAI #ZeroTrust #Hardening #Fortificacion #NonHumanIdentities