Summary

Top Articles:

  • Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info
  • Law Enforcement Deanonymizes Tor Users
  • Chinese attackers accessed Canadian government networks – for five years
  • Beijing claims it's found 'underwater lighthouses' that its foes use for espionage
  • Authenticated Remote Code Execution in multiple Xerox printers
  • Fired Employee Allegedly Hacked Disney World's Menu System to Alter Peanut Allergy Information
  • EMERALDWHALE: 15k Cloud Credentials Stolen in Operation Targeting Exposed Git Config Files
  • Exploiting a 0-Day Opera Vulnerability with a Cross-Browser Extension Store Attack
  • Use PicoGlitcher For Voltage Glitching Attacks
  • CVE-2024-9632 xorg-x11-server: heap-based buffer overflow privilege escalation vulnerability

Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info

Published: 2024-10-30 15:12:39

Popularity: 48

Author: Brandon Vigliarolo

🤖: "Mickey messed up"

If you're gonna come at the mouse, you need to be better at hiding your tracks A disgruntled ex-Disney employee has been arrested and charged with hacking his former employer's systems to alter restaurant menus with potentially deadly consequences. …

...more

Law Enforcement Deanonymizes Tor Users

Published: 2024-10-29 11:02:15

Popularity: 24

Author: Bruce Schneier

Keywords:

  • Uncategorized
  • de-anonymization
  • law enforcement
  • Tor
  • 🤖: "Tor nope"

    The German police have successfully deanonymized at least four Tor users. It appears they watch known Tor relays and known suspects, and use timing analysis to figure out who is using what relay. Tor has written about this. Hacker News thread.

    ...more

    Chinese attackers accessed Canadian government networks – for five years

    Published: 2024-10-31 05:34:23

    Popularity: 17

    Author: Laura Dobberstein

    🤖: ""Hacked and proud""

    India makes it onto list of likely threats for the first time A report by Canada's Communications Security Establishment (CSE) revealed that state-backed actors have collected valuable information from government networks for five years.…

    ...more

    Beijing claims it's found 'underwater lighthouses' that its foes use for espionage

    Published: 2024-10-30 08:31:08

    Popularity: 13

    Author: Laura Dobberstein

    🤖: "Spy lights down 🔦🔮"

    Release the Kraken! China has accused unnamed foreign entities of using devices hidden in the seabed and bobbing on the waves to learn its maritime secrets.…

    ...more

    Authenticated Remote Code Execution in multiple Xerox printers

    Published: 2024-10-24 14:13:46

    Popularity: None

    Author: None

    🤖: "Printer hack"

    Multiple Xerox printers (EC80xx, AltaLink, VersaLink, WorkCentre) were affected by an authenticated remote code execution vulnerability which allowed an attacker with administrative web credentials to fully compromise the devices with root privileges on the operating system.

    ...more

    Fired Employee Allegedly Hacked Disney World's Menu System to Alter Peanut Allergy Information

    Published: 2024-10-31 12:36:38

    Popularity: None

    Author: None

    🤖: "Hacked menu"

    The employee separately changed all menu text to Wingdings, the complaint says.

    ...more

    EMERALDWHALE: 15k Cloud Credentials Stolen in Operation Targeting Exposed Git Config Files

    Published: 2024-10-31 12:31:50

    Popularity: None

    Author: Miguel Hernández

    🤖: "Cloud hack fail"

    EMERALDWHALE is an operation targeting exposed Git configurations, resulting in more than 15,000 cloud service credentials stolen.

    ...more

    Exploiting a 0-Day Opera Vulnerability with a Cross-Browser Extension Store Attack

    Published: 2024-10-31 12:30:03

    Popularity: None

    Author: Guardio

    🤖: ""Opera hack fail""

    By Nati Tal (Head of Guardio Labs)

    ...more

    Use PicoGlitcher For Voltage Glitching Attacks

    Published: 2024-10-31 12:00:26

    Popularity: None

    Author: odsquad64

    🤖: "Electric shock"

    We see a fair few glitcher projects, especially the simpler voltage glitchers. Still, quite often due to their relative simplicity, they’re little more than a microcontroller board and a few …

    ...more

    CVE-2024-9632 xorg-x11-server: heap-based buffer overflow privilege escalation vulnerability

    Published: 2024-10-29 18:29:20

    Popularity: None

    Author: bugzilla.redhat.com via eBPF

    Keywords:

  • security
  • c
  • 🤖: "Buffer Overflow"

    Comments

    ...more

    woodruffw/zizmor: A tool for finding security issues in GitHub Actions setups.

    Published: 2024-10-31 14:53:40

    Popularity: None

    Author: None

    🤖: "GitHub bug hunt"

    A tool for finding security issues in GitHub Actions setups. - woodruffw/zizmor

    ...more

    OpenPaX Announced As "Open-Source Alternative To GrSecurity" With Free Kernel Patch

    Published: 2024-10-31 12:42:08

    Popularity: None

    Author: Written by

    🤖: "Kernel patch party"

    Enterprise security firm Edera today is announcing OpenPaX that they promoted in their advance press notice as a 'new open-source alternative to GrSecurity.' GrSecurity being the firm focused on providing out-of-tree Linux kernel patches focused in the name of security enhancements

    ...more

    end