Network Security News Summary for Monday August 28th, 2023



Network Security News Summary for Monday August 28th, 2023

Network Security News Summary for Monday August 28th, 2023

Postgresql C2; MacOS Network Connections; Fake/Bad CVEs; Windows Cert Confusion; Bad NPM Package

Python Malware Using Postgresql for C2 Communications
https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158

macOS: Who is Behind This Network Connection?
https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160

CVE-2020-19909 Is Everything that is Wrong with CVEs
https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/

Windows Certificate Confusion
https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/

NPM E-Mail Validator Package Malware
https://blog.phylum.io/npm-emails-validator-package-malware/

keywords: npm; windows; certificate; cve-2020-19909; curl; macos; python; postgresql