March 2023 Patch Tuesday forecast: It’s not about luck

Every month I touch on a few hot topics related to security around patching and some important updates to look out for on the upcoming Patch Tuesday. Diligence to this ongoing patch process, and not luck, is critical to protecting systems and avoiding … Continue reading March 2023 Patch Tuesday forecast: It’s not about luck

Fake ChatGPT Chrome extension targeted Facebook Ad accounts

ChatGPT has garnered a lot of questions about its security and capacity for manipulation, partly because it is a new software that has seen unprecedented growth (hosting 100 million users just two months following its launch). Security concerns vary fr… Continue reading Fake ChatGPT Chrome extension targeted Facebook Ad accounts

What are the potential vulnerabilities with containerized rootless Chrome and –no-sandbox?

I’m evaluating running Chromium without native sandboxing in a rootless container. A few points:

You can containerize Chrome using rootless containers with something like podman. This will utilize kernel user-namespaces to isolate the Chr… Continue reading What are the potential vulnerabilities with containerized rootless Chrome and –no-sandbox?