Summary

Total Articles Found: 23

Top sources:

Top Keywords:

Top Authors

Top Articles:

  • Traeger security bugs bad news for grillers with neighborly beef
  • Using 1Password on Mac? Patch up if you don’t want your Vaults raided
  • Equifax scores £11.1M slap on wrist over 2017 mega breach
  • Ivanti discloses fifth vulnerability, doesn't credit researchers who found it
  • 1Password confirms attacker tried to pull list of admin users after Okta intrusion
  • Advance Auto Parts: 2.3M people's data accessed when crims broke into our Snowflake account
  • Ex-GCHQ software dev jailed for stabbing NSA staffer
  • Sweden's 'Doomsday Prep for Dummies' guide hits mailboxes today
  • Critical Fluent Bit bug affects all major cloud providers, say researchers
  • Critical vulnerability in Mastodon is pounced upon by fast-acting admins

Traeger security bugs bad news for grillers with neighborly beef

Published: 2024-07-03 16:24:09

Popularity: 64

Author: Connor Jones

🤖: "Burned neighbors"

Never risk it when it comes to brisket – make sure those updates are applied Keen meatheads better hope they haven't angered any cybersecurity folk before allowing their Traeger grills to update because a new high-severity vulnerability could be used for all kinds of high jinks.…

...more

Ivanti discloses fifth vulnerability, doesn't credit researchers who found it

Published: 2024-02-09 21:30:14

Popularity: 27

Author: Connor Jones

Software company's claim of there being no active exploits also being questioned In disclosing yet another vulnerability in its Connect Secure, Policy Secure, and ZTA gateways, Ivanti has confused the third-party researchers who discovered it.…

...more

Critical vulnerability in Mastodon is pounced upon by fast-acting admins

Published: 2024-02-02 18:32:09

Popularity: 16

Author: Connor Jones

Danger of remote account takeovers leaves lead devs scared of releasing many details Mastodon has called admins to action following the disclosure of a critical vulnerability affecting the decentralized social network favored by erstwhile Twitter lovers.…

...more

Jenkins jitters as 45,000 servers still vulnerable to RCE attacks after patch released

Published: 2024-01-30 17:45:15

Popularity: 9

Author: Connor Jones

Multiple publicly available exploits have since been published for the critical flaw The number of public-facing installs of Jenkins servers vulnerable to a recently disclosed critical vulnerability is in the tens of thousands.…

...more

SSH shaken, not stirred by Terrapin vulnerability

Published: 2023-12-20 08:34:11

Popularity: 12

Author: Connor Jones

No need to panic, but grab those updates or mitigations anyway just to be safe A vulnerability in the SSH protocol can be exploited by a well-placed adversary to weaken the security of people's connections, if conditions are right.…

...more

Four in five Apache Struts 2 downloads are for versions featuring critical flaw

Published: 2023-12-21 14:13:13

Popularity: 16

Author: Connor Jones

Seriously, people - please check the stuff you fetch more carefully Security vendor Sonatype believes developers are failing to address the critical remote code execution (RCE) vulnerability in the Apache Struts 2 framework, based on recent downloads of the code.…

...more

BreachForums boss busted for bond blunders – including using a VPN

Published: 2024-01-05 14:35:12

Popularity: 10

Author: Connor Jones

Fitzpatrick faces potentially decades in prison later this month, so may as well get some foreign Netflix in beforehand The cybercriminal behind BreachForums was this week arrested for violating the terms of his pretrial release and will now be held in custody until his sentencing hearing.…

...more

Ex-GCHQ software dev jailed for stabbing NSA staffer

Published: 2023-11-03 19:02:51

Popularity: 18

Author: Connor Jones

Terrorist ideology suspected to be motivation A former software developer for Britain's cyberspy agency is facing years in the slammer after being sentenced for stabbing a National Security Agency (NSA) official multiple times.…

...more

Ex-Navy IT manager gets 5 years in slammer for 2018 database heist

Published: 2023-10-19 14:01:08

Popularity: 14

Author: Connor Jones

Seafaring cybercrim's wife faces similar sentence next month A former IT manager for the US Navy is facing a five-and-a-half year prison sentence for selling thousands of people's personal records on the dark web.…

...more

1Password confirms attacker tried to pull list of admin users after Okta intrusion

Published: 2023-10-24 15:15:23

Popularity: 27

Author: Connor Jones

Says logins are safe, as high-profile customers complain they knew about the breach before Okta 1Password is confirming it was attacked by cyber criminals after Okta was breached for the second time in as many years, but says customers' login details are safe.…

...more

Equifax scores £11.1M slap on wrist over 2017 mega breach

Published: 2023-10-13 12:46:38

Popularity: 28

Author: Connor Jones

Not quite a pound for every one of the 13.8 million affected UK citizens, and it could have been more The UK's Financial Conduct Authority (FCA) has fined Equifax a smidge over £11 million ($13.6 million) for severe failings that put millions of consumers at risk of financial crime.…

...more

Management company settles for $18.4M after nuclear weapons plant staff fudged their timesheets

Published: 2024-04-24 15:00:09

Popularity: 9

Author: Connor Jones

The firm 'fessed up to staff misconduct and avoided criminal liability A company contracted to manage an Amarillo, Texas nuclear weapons facility has to pay US government $18.4 million in a settlement over allegations that its atomic technicians fudged their timesheets to collect more money from Uncle Sam.…

...more

Critical Fluent Bit bug affects all major cloud providers, say researchers

Published: 2024-05-21 17:45:15

Popularity: 17

Author: Connor Jones

Crashes galore, plus especially crafty crims could use it for much worse Infosec researchers are alerting the industry to a critical vulnerability in Fluent Bit – a logging component used by a swathe of blue chip companies and all three major cloud providers.…

...more

Suspected supply chain attack backdoors courtroom recording software

Published: 2024-05-24 20:29:11

Popularity: 10

Author: Connor Jones

🤖: ""Backdoored audio""

An open and shut case, but the perps remain at large – whoever they are Justice is served… or should that be saved now that audio-visual software deployed in more than 10,000 courtrooms is once again secure after researchers uncovered evidence that it had been backdoored for weeks.…

...more

Using 1Password on Mac? Patch up if you don’t want your Vaults raided

Published: 2024-08-08 13:45:09

Popularity: 43

Author: Connor Jones

🤖: "Vaults getting hacked"

Hundreds of thousands of users potentially vulnerable Password manager 1Password is warning that all Mac users running versions before 8.10.36 are vulnerable to a bug that allows attackers to steal vault items.…

...more

Adobe fixed Acrobat bug, neglected to mention whole zero-day exploit thing

Published: 2024-09-12 18:29:06

Popularity: 6

Author: Connor Jones

🤖: ""oops did it again""

SaaS seller sets severity to 'critical' Adobe's patch for a remote code execution (RCE) bug in Acrobat this week doesn't mention that the vulnerability is considered a zero-day nor that a proof-of-concept (PoC) exploit exists, a researcher warns.…

...more

Snowflake slams 'more MFA' button again – months after Ticketmaster, Santander breaches

Published: 2024-09-16 16:45:10

Popularity: 10

Author: Connor Jones

🤖: ""Who needs MFA?""

Now it's the default for all new accounts Snowflake continues to push forward in strengthening its users' cybersecurity posture by making multi-factor authentication the default for all new accounts.…

...more

Cops across the world arrest 51 in orchestrated takedown of Ghost crime platform

Published: 2024-09-18 12:16:40

Popularity: 8

Author: Connor Jones

🤖: "Ghost busted"

Italian mafia mobsters and Irish crime families scuppered by international cops Hours after confirming they had pwned the supposedly uncrackable encrypted messaging platform used for all manner of organized crime, Ghost, cops have now named the suspect they cuffed last night, who is charged with being the alleged mastermind.…

...more

Necro malware continues to haunt side-loaders of dodgy Android mods

Published: 2024-09-23 21:30:10

Popularity: 12

Author: Connor Jones

🤖: "Zombie app 😈"

11M devices exposed to trojan, Kaspersky says Updated  The Necro trojan is once again making a move against Android users, with up to eleven million individuals thought to be exposed to infected apps.…

...more

Why the long name? Okta discloses auth bypass bug affecting 52-character usernames

Published: 2024-11-04 11:28:07

Popularity: 14

Author: Connor Jones

🤖: "Long username fail"

Mondays are for checking months of logs, apparently, if MFA's not enabled In potentially bad news for those with long names and/or employers with verbose domain names, Okta spotted a security hole that could have allowed crims to pass Okta AD/LDAP Delegated Authentication (DelAuth) using only a username.…

...more

Sweden's 'Doomsday Prep for Dummies' guide hits mailboxes today

Published: 2024-11-18 16:03:15

Popularity: 18

Author: Connor Jones

🤖: "Nuclear panic"

First in six years is nearly three times the size of the older, pre-NATO version Residents of Sweden are to receive a handy new guide this week that details how to prepare for various types of crisis situations or wartime should geopolitical events threaten the country.…

...more

Snowflake lets admins make MFA mandatory across all user accounts

Published: 2024-07-10 16:45:14

Popularity: 11

Author: Connor Jones

🤖: ""Two-factor tyranny""

Company announces intent following Ticketmaster, Santander break-ins A month after incident response giant Mandiant suggested the litany of data thefts linked to Snowflake account intrusions had the common component of lacking multi-factor authentication (MFA) controls, the cloud storage and data analytics company is offering a mandatory MFA option to admins.…

...more

Advance Auto Parts: 2.3M people's data accessed when crims broke into our Snowflake account

Published: 2024-07-11 13:15:07

Popularity: 25

Author: Connor Jones

🤖: "Data breach alert"

Letters from CISO Ethan Steiger suggest the data related to job applications Advance Auto Parts' CISO just revealed for the first time the number of individuals affected when criminals broke into its Snowflake instance – a hefty 2.3 million.…

...more

end