Summary

Top Articles:

  • GLAMIRA - 999,999 breached accounts
  • Volkswagen's bad streak: They know where your car is, Chaos Computer Club says – and they don't know how to secure it properly.
  • Unpatched Active Directory Flaw Can Crash Any Microsoft Server
  • US Army soldier who allegedly stole Trump's AT&T call logs arrested
  • 'Bad Likert Judge' Jailbreak Bypasses Guardrails of OpenAI, Other Top LLMs
  • Boffins carve up C so code can be converted to Rust
  • ShredOS
  • 7-Zip Zero-Day Exploit Allegedly Leaked Online
  • Google Chrome 2FA Bypass Attacks Confirmed-Millions Of Users At Risk
  • PentesterLab Blog: Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150

GLAMIRA - 999,999 breached accounts

Published: 2025-01-03 07:55:22

Popularity: 5585

Author: None

🤖: "Password fail"

In late 2023, the online jewellery store GLAMIRA suffered a data breach they attributed to "an unauthorised individual [who] briefly accessed one of our servers". The data was subsequently published on a popular hacking forum and included 875k email addresses, names, phone numbers and purchases.

...more

Volkswagen's bad streak: They know where your car is, Chaos Computer Club says – and they don't know how to secure it properly.

Published: 2024-12-29 13:42:33

Popularity: 147

Author: ReynardSec

🤖: ""Surveillance alert""

submitted by /u/ReynardSec[link][comments]

...more

Unpatched Active Directory Flaw Can Crash Any Microsoft Server

Published: 2025-01-02 16:28:38

Popularity: 54

Author: Becky Bracken, Senior Editor, Dark Reading

🤖: "Server crash"

Windows servers are vulnerable to a dangerous LDAP vulnerability that could be used to crash multiple servers at once and should be patched immediately.

...more

US Army soldier who allegedly stole Trump's AT&T call logs arrested

Published: 2025-01-01 08:32:08

Popularity: 21

Author: Jessica Lyons

🤖: "Leaked records"

Brings the arrest count related to the Snowflake hacks to 3 A US Army soldier has been arrested in Texas after being indicted on two counts of unlawful transfer of confidential phone records information. …

...more

'Bad Likert Judge' Jailbreak Bypasses Guardrails of OpenAI, Other Top LLMs

Published: 2025-01-02 14:00:00

Popularity: 21

Author: Elizabeth Montalbano, Contributing Writer

🤖: ""Judge's verdict hacked""

A novel technique to stump artificial intelligence (AI) text-based systems increases the likelihood of a successful cyberattack by 60%.

...more

Boffins carve up C so code can be converted to Rust

Published: 2025-01-03 12:33:11

Popularity: 12

Author: Thomas Claburn

🤖: "Code carving"

Mini-C is a subset of C that can be automatically turned to Rust without much fuss Computer scientists affiliated with France's Inria and Microsoft have devised a way to automatically turn a subset of C code into safe Rust code, in an effort to meet the growing demand for memory safety.…

...more

ShredOS

Published: 2025-01-03 14:46:03

Popularity: None

Author: Bruce Schneier

Keywords:

  • Uncategorized
  • data destruction
  • operating systems
  • 🤖: "Shredded files"

    ShredOS is a stripped-down operating system designed to destroy data. GitHub page here.

    ...more

    7-Zip Zero-Day Exploit Allegedly Leaked Online

    Published: 2024-12-31 00:45:27

    Popularity: None

    Author: Balaji N

    🤖: "bugged zip"

    A critical 7-Zip zero-day exploit has been publicly leaked by a hacker, allowing attackers to execute arbitrary code to control PCs remotely.

    ...more

    Google Chrome 2FA Bypass Attacks Confirmed-Millions Of Users At Risk

    Published: 2024-12-30 12:11:34

    Popularity: None

    Author: Davey Winder

    🤖: "Chrome hacked"

    An attack aimed at bypassing two-factor authentication cookies for Google Chrome users has been confirmed—here’s what you need to know.

    ...more

    PentesterLab Blog: Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150

    Published: 2024-12-26 15:15:52

    Popularity: None

    Author: None

    🤖: ""Token trouble""

    Discover how a code review uncovered a JWT algorithm confusion vulnerability (CVE-2024-54150). Learn key insights to enhance your security skills and spot vulnerabilities effectively.

    ...more

    I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny

    Published: 2024-12-20 15:04:29

    Popularity: None

    Author: Eaton

    🤖: "Hacky McFlurry"

    A series of API flaws in McDelivery India made it possible to order food for a penny, hijack other people’s delivery orders, view user information, and more.

    ...more

    end