Critical vulnerability in Fortinet products

https://www.fortiguard.com/psirt/FG-IR-22-300

https://www.fortiguard.com/psirt/FG-IR-22-300

Summary

An external control of file name or path vulnerability [CWE-73] in FortiNAC webserver may allow an unauthenticated attacker to perform arbitrary write on the system.

Affected Products

FortiNAC version 9.4.0
FortiNAC version 9.2.0 through 9.2.5
FortiNAC version 9.1.0 through 9.1.7
FortiNAC 8.8 all versions
FortiNAC 8.7 all versions
FortiNAC 8.6 all versions
FortiNAC 8.5 all versions
FortiNAC 8.3 all versions

Critical vulnerability in Fortinet products

https://www.fortiguard.com/psirt/FG-IR-22-398

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

Affected Products

FortiOS version 7.2.0 through 7.2.2
FortiOS version 7.0.0 through 7.0.8
FortiOS version 6.4.0 through 6.4.10
FortiOS version 6.2.0 through 6.2.11
FortiOS-6K7K version 7.0.0 through 7.0.7
FortiOS-6K7K version 6.4.0 through 6.4.9
FortiOS-6K7K version 6.2.0 through 6.2.11
FortiOS-6K7K version 6.0.0 through 6.0.14

Who is a coach and what does he/she do

Let’s start with a few definitions :

MENTOR

Mentor is a person with considerable experience in the same or a related field of life or business that you are in. You meet, you talk, and he (or she) can simply advise you on something based on his (or her) own experience, and, if necessary, back it up by consulting his (usually wide and valuable) network of contacts.

COACH

The main difference from a mentor is that he (or she) doesn’t have to know exactly what you’re doing. He doesn’t have to, because a coach doesn’t give advice, but instead asks wise and skillful questions. He or she does it in such a way that you yourself arrive at the right answer that is in line with you and your values, which is somewhere inside you, in Bohemia. And finally: the coach is screwed because of the ongoing spoiling of the market for these services by people without good education, experience and aptitude. Unfortunately, sometimes admitting that you are a coach is a real shame.

Read more Who is a coach and what does he/she do

Bring your own key

What is bring your own key (BYOK)?

Bring your own key (BYOK) is an innovative concept to allow public cloud users to keep control of the cryptographic keys used in the cloud to secure their data. With public cloud services exploding, BYOK is now supported by all major cloud services. BYOK enables public cloud users to generate their own high-quality master key locally and securely transmit the key to a cloud service provider (CSP) to protect data in multi-cloud environments. To generate and manage high-quality keys, BYOK uses FIPS and Common Criteria Certified Hardware Security Modules (HSMs) that the cloud user maintains locally or leases as a service.

BYOK enables organizations that migrate to the cloud to achieve:

Read more Bring your own key

Metaverse

What is Metaverse?

Metaverse is augmented virtual reality. A digital world that we will be able to connect to through VR goggles and spend time in. Right now, using the Internet is primarily a two-dimensional experience mediated by a screen. The Metaverse could make it possible for us to literally immerse ourselves in it and perform activities there, previously reserved only for the real world. This is one of the fastest growing technologies of the future.

Metaverse is a compound of the words meta and verse. The term was invented by American science fiction writer Neal Stephenson and first appears in his 1992 book. The novel is set in a dystopian world ruled by greedy corporations. Its inhabitants escape from everyday problems into cyberspace, the metaverse, where they can move around as their avatars. Of course, it costs money to beautify one’s character, and the poorer ones have to settle for gray images.

Read more Metaverse

Steam Deck

Is the Steam Deck a game console or a computer?

Actually, the answer to this question is up to you. If you just want a working game console from the steam catalog, then Steam Deck out of the box is the solution for you. You just turn it on and use it, the same level of difficulty as a PlayStation or Xbox.

If you want to take advantage of the PC potential that’s hiding in that little box, you can use Steam OS, which is simply Linux or install Windows 10 or Windows 11 (both are officially supported, and there are official drivers for both).
In that case, you can use Deck to play games not only from Steam but also Epic, GOG, Ubisoft, Blizzard, etc.

But you can also use it as a portable computer. And if you connect it to a docking station, monitor, keyboard, and mouse, you have a desktop computer, perfect for work (as long as you’re not someone who puts up a million virtual machines and needs a herd of cores and terabytes of RAM).

And what is it for me? At first, it was a console for playing Steam games, but it became clear pretty quickly that I wanted more. I simply have too many games bought elsewhere and can’t use them. In addition, the service software for my car is only on Windows, so I have a service computer right away, ideal because it’s small, convenient, with a long-lasting battery 🙂

But as I wrote – it all depends on the owner.

Is Mastodon a new Twitter?

What is Mastodon

Mastodon is a microblogging network, it is not controlled by a company or a server, it works through a decentralized federation of servers. The network is open source and we can access it on GitHub, where it is hosted so that anyone can access it.

Mastodon does not use a single server, it consists of several, and it is fast in terms of loading both the network and the application. The user has the option to create a community or instance. In addition, if you don’t want to do that, you can join one of the many available.

The first thing to start using Mastodon is to register with a short registration, when we say concise, that is, it won’t ask for much information about us. There will be four fields you must fill out to register with the site/app, including your username.

Read more Is Mastodon a new Twitter?

New, lower prices of Atlassian trainings

Now you can learn at Atlassian University for less. They changed the price of their basic trainings, and now they are free or starting from $39.
The whole catalog of free and cheap courses is here: https://university.atlassian.com/student/catalog/list?category_ids=21723-on-demand

If you do not have any experience with Jira or Jira Service Management I recommend starting with free courses:

If you will work with Confluence:

Those are basics, but it’s really hard to work with Jira/Confluence without them.