Summary

Total Articles Found: 14

Top sources:

Top Keywords:

Top Authors

Top Articles:

  • Hackers remotely start, unlock Honda Civics with $300 tech
  • Marriott Hotels admits to third data breach in 4 years
  • Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info
  • Shape-shifting cryptominer savages Linux endpoints and IoT
  • Google settles location tracking lawsuit for only $39.9M
  • 'Almost every Apple device' vulnerable to CocoaPods supply chain attack
  • School laptop auction devolves into extortion allegation
  • WordPress-powered sites backdoored after FishPig suffers supply chain attack
  • That 3CX supply chain attack keeps getting worse: Other vendors hit
  • UK trio pleads guilty to running $10M MFA bypass biz

'Almost every Apple device' vulnerable to CocoaPods supply chain attack

Published: 2024-07-02 07:32:06

Popularity: 31

Author: Brandon Vigliarolo

🤖: "Vulnerable iOS"

Dependency manager used in millions of apps leaves a bitter taste CocoaPods, an open-source dependency manager used in over three million applications coded in Swift and Objective-C, left thousands of packages exposed and ready for takeover for nearly a decade – thereby creating opportunities for supply chain attacks on iOS and macOS apps, according to security researchers.…

...more

Google settles location tracking lawsuit for only $39.9M

Published: 2023-05-22 14:45:07

Popularity: 36

Author: Brandon Vigliarolo

Also, more OEM Android malware, Google's bug reports (mostly) ditch CVEs, and this week's critical vulns in brief  Google has settled another location tracking lawsuit, yet again being fined a relative pittance.…

...more

That 3CX supply chain attack keeps getting worse: Other vendors hit

Published: 2023-04-24 03:27:05

Popularity: 23

Author: Brandon Vigliarolo

Also, Finland sentences CEO of breach company to prison (kind of), and this week's laundry list of critical vulns In Brief  We thought it was probably the case when the news came out, but now it's been confirmed: The X_Trader supply chain attack behind the 3CX compromise last month wasn't confined to the telco developer.…

...more

School laptop auction devolves into extortion allegation

Published: 2023-02-06 07:32:11

Popularity: 29

Author: Brandon Vigliarolo

Also: Atlassian says Jira has a 9.4 severity bug and the TSA issues milquetoast no-fly list security advisory When a Texas school district sold some old laptops at auction last year, it probably didn't expect to end up in a public legal fight with a local computer repair shop – but a debate over what to do with district data found on the liquidated machines has led to precisely that.…

...more

WordPress-powered sites backdoored after FishPig suffers supply chain attack

Published: 2022-09-15 02:12:07

Popularity: 28

Author: Brandon Vigliarolo

And two other security snafus in this web publishing world It's only been a week or so, and obviously there are at least three critical holes in WordPress plugins and tools that are being exploited in the wild right now to compromise loads of websites.…

...more

GPT-3 'prompt injection' attack causes bad bot manners

Published: 2022-09-19 13:37:53

Popularity: 13

Author: Brandon Vigliarolo

Also, EA goes kernel-deep to stop cheaters, PuTTY gets hijacked by North Korea, and more. In Brief  OpenAI's popular natural language model GPT-3 has a problem: It can be tricked into behaving badly by doing little more than telling it to ignore its previous orders.…

...more

Shape-shifting cryptominer savages Linux endpoints and IoT

Published: 2022-09-10 11:00:07

Popularity: 38

Author: Brandon Vigliarolo

Also, Authorities seize WT1SHOP selling 5.8m sets of PII, The North Face users face tough security hike In brief  AT&T cybersecurity researchers have discovered a sneaky piece of malware targeting Linux endpoints and IoT devices in the hopes of gaining persistent access and turning victims into crypto-mining drones.…

...more

Marriott Hotels admits to third data breach in 4 years

Published: 2022-07-06 14:00:13

Popularity: 55

Author: Brandon Vigliarolo

Digital thieves made off with 20GB of internal documents and customer data Updated  Crooks have reportedly made off with 20GB of data from Marriott Hotels, which apparently included credit card info and internal company documents. …

...more

Hackers remotely start, unlock Honda Civics with $300 tech

Published: 2022-03-25 15:00:05

Popularity: 168

Author: Brandon Vigliarolo

Any models made between 2016 and 2020 can have key fob codes sniffed and re-transmitted If you're driving a Honda Civic manufactured between 2016 and 2020, this newly reported key fob hijack should start your worry engine.…

...more

OpenSSL patches crash-me bug triggered by rogue certs

Published: 2022-03-15 20:40:18

Popularity: 18

Author: Brandon Vigliarolo

Bad data can throw vulnerable apps and services for an infinite loop A bug in OpenSSL certificate parsing leaves systems open to denial-of-service attacks from anyone wielding an explicit curve. …

...more

OpenSSF sings a Siren song to steer developers away from buggy FOSS

Published: 2024-05-20 23:06:10

Popularity: 11

Author: Brandon Vigliarolo

🤖: "Siren song of bugs"

New infosec intelligence service aims to spread the word about recently discovered vulns in free code Securing open source software may soon become a little bit easier thanks to a new vulnerability info-sharing effort initiated by the Open Source Security Foundation (OpenSSF).…

...more

Patch management still seemingly abysmal because no one wants the job

Published: 2024-07-25 07:27:06

Popularity: 10

Author: Brandon Vigliarolo

🤖: "No one wants the task"

Are your security and ops teams fighting to pass the buck? Comment  Patching: The bane of every IT professional's existence. It's a thankless, laborious job that no one wants to do, goes unappreciated when it interrupts work, and yet it's more critical than ever in this modern threat landscape.…

...more

UK trio pleads guilty to running $10M MFA bypass biz

Published: 2024-09-03 21:30:07

Popularity: 19

Author: Brandon Vigliarolo

🤖: ""Phishing for cash""

Crew bragged they could help crooks raid victims' bank accounts Updated  A trio of men have pleaded guilty to running a multifactor authentication (MFA) bypass ring in the UK, which authorities estimate has raked in millions in less than two years. …

...more

Fired Disney staffer accused of hacking menu to add profanity, wingdings, removes allergen info

Published: 2024-10-30 15:12:39

Popularity: 48

Author: Brandon Vigliarolo

🤖: "Mickey messed up"

If you're gonna come at the mouse, you need to be better at hiding your tracks A disgruntled ex-Disney employee has been arrested and charged with hacking his former employer's systems to alter restaurant menus with potentially deadly consequences. …

...more

end