Security Now!

SN 891: Poisoning Akamai - Turnstile vs CAPTCHA, Microsoft Teams Under Attack

Hinzugefügt: 5. Oktober 2022

Picture of the Week. (What Could Possibly Go Wrong)
Microsoft Teams - Unecessarily Insecure
Roskomnadzor blocks Soundcloud
Microsoft Exchange Server Under Attack Again
I'm (Still) Not a Robot!...

SN 890: DarkNet Politics - EU and Google Analytics, Rockstar hacker busted, Mozilla says no fair

Hinzugefügt: 28. September 2022

Picture of the Week.
Can't have it both ways.
Denmark has become the fourth EU member to rule that the use of Google Analytics is illegal.
Rockstar Games hacker is busted!
Mozilla says: No...

SN 889: Spell-Jacking - Cyber-Insurance, GTA 6 leak, MiraclePtr, CVSS9.8 for WordPress, Uber Oops!

Hinzugefügt: 21. September 2022

Picture of the Week.
This is Patch News-Day.
Lloyd's of London backing away from Cyber-Insurance.
Uber Oops!
Rockstar Games: Grand Theft Auto 6 Massive Leak.
LastPass Breach Update.
A CVSS...

SN 888: The EvilProxy Service - MooBot, Crypto Heist, Cyberwarfare, QNAP, The Silver Ships

Hinzugefügt: 14. September 2022

Picture of the Week. 
Cyberwarfare: Albania vs Iran. 
Crypto Heist — this or that. 
The White House "Tech Platform Accountability" Listening Session. 
Changes to the Dutch Intelligence Law. ...

SN 887: Embedded AWS Credentials - TikTok leak, urgent Chrome patch, PyPI warning, Quantum Hype Bubble

Hinzugefügt: 7. September 2022

Picture of the Week. 
Google's (newest) Open Source Software Vulnerability Rewards Program. 
Did TikTok leak 2.05 BILLION User Records? 
An urgent Chrome update patches new 0-day flaw. ...

SN 886: Wacky Data Exfiltration - LastPass breach, FTC Kochava lawsuit, Hikvision IoT mess

Hinzugefügt: 31. August 2022

Picture of the Week. 
LastPass Breached. 
The US Federal Trade Commission filed a lawsuit against data broker Kochava. 
The US Federal Communications Commission launched an investigation into...

SN 885: The Bumblebee Loader - RTL819x Exploit, RubyGems Update, Chrome's Fifth 0-Day of 2022

Hinzugefügt: 24. August 2022

VIDEO of the Week
Crashing Laptop Computers With Janet Jackson
RealTek SoC flaw affects many millions of IoT devices
46 Million RPS - requests per second
Chrome's 5th 0-Day of 2022
Apple: Not...

SN 884: TLS Private Key Leakage - BIG patch Tuesday, Facebook E2E encryption, VNC insecurity, Cyotek WebCopy

Hinzugefügt: 17. August 2022

Picture of the Week.
Patch Flashback Tuesday.
Facebook is cautiously creeping toward default E2E encryption.
VNC's inherent insecurity.
The need to control domain names.
And speaking of...

SN 883: The Maker's Schedule - VirusTotal, Daniel Bernstein sues the NSA, Win 11 might damage encrypted data

Hinzugefügt: 10. August 2022

Picture of the Week.
Crypto is Hard.
VirusTotal: Deception at a scale.
Windows 11 might damage encrypted data.
Microsoft Defender External Attack Surface Management.
Closing The Loop.
Daniel...

SN 882: Rowhammer's Nine Lives - TLS-Anvil, Chrome cookies stick around, Atlassian Confluence under attack

Hinzugefügt: 3. August 2022

Picture of the Week.
Atlassian's "Confluence" under attack.
LS-Anvil.
Google delays Chrome's cookie phase-out again.
Attacker responding to loss of Office Macros.
SpinRite.
Closing The Loop....

SN 881: The MV720 - MS Office VBA macros, Win 11 security changes, start button failure

Hinzugefügt: 27. Juli 2022

Picture of the Week.
Patch Tuesday Redux Redux.
Windows 11 Start button failure.
The continuing saga of Windows VBA macros.
Windows 11 now blocks RDP brute-force attacks by default.
Black Hat...

SN 880: RetBleed - Facebook encrypted URLs, cracking Lockdown Mode, ClearView AI resistance, Roskomnadzor

Hinzugefügt: 20. Juli 2022

Picture of the Week. 
The Rolling Pwn, take II. 
The great IPv4 Address Space Depletion. 
Confronting Reality in Cyberspace: Foreign Policy for a Fragmented Internet. 
Facebook has started...

SN 879: The Rolling Pwn - OpenSSL patch, iOS Lockdown Mode, Yubikey's to Ukraine, Office Macros re-enabled

Hinzugefügt: 13. Juli 2022

 Picture of the Week. 
 OpenSSL's Patch For Heap Memory Corruption Vulnerability. 
 NIST Announces First Four Quantum-Resistant Cryptographic Algorithms. 
 Yubico donated 30,000 Yubikeys to...

SN 878: The ZuoRAT - 0-Day Chrome, Firefox v102, HackerOne

Hinzugefügt: 6. Juli 2022

 Picture of the week.
 Chrome's fourth zero-day of 2022.
 Mozilla's new Firefox privacy-enhancing feature.
 HackerOne discloses a malicious insider incident.
 Closing the loop.
 The ZuoRAT....

SN 877: The "Hertzbleed" Attack - 3rd Party FIDO2, Log4Shell, '311" Proposal

Hinzugefügt: 28. Juni 2022

Picture of the Week.
Errata: Firefox's "Total Cookie Protection"
3rd Party FIDO2 Authenticators
Germany's not buying the EU's proposal which subverts encryption
The Conti Gang have finally...

SN 876: Microsoft's Patchy Patches - 3rd Party Authenticators, MS-DFSNM, Safari Regression, Firefox Cookies

Hinzugefügt: 22. Juni 2022

Picture of the Week.
Double Decryption (Last week's key-strength puzzler).
3rd Party Authenticators.
Firefox: Total Cookie Protection.
We keep breaking DDoS attack records.
MS-DFSNM.
An Apple...

SN 875: The PACMAN Attack - WebAuthn, Passkeys at WWDC, Free Kali Linux Pen Test Course, Proof of Simulation

Hinzugefügt: 15. Juni 2022

Picture of the Week.
Apple's Passkeys presentation at WWDC 2022.
WebAuthn.
FREE Penetration Testing course with Kali Linux.
Proof of Simulation.
A valid use for facial recognition: The Smart...

SN 874: Passkeys, Take 2 - ServiceNSW Responds, Follina, Windows Search URL, UNISOC Chip Vulnerability

Hinzugefügt: 8. Juni 2022

Picture of the Week.
ServiceNSW Responds.
ExpressVPN pulls the plug in India.
And speaking of pulling the plug.
"Follina" under active exploitation.
And a Windows Search URL schema can be...

SN 873: DuckDuckGone? - Digital Driver's License, MS Office 0-day, GhostTouch, Vodafone TrustPiD

Hinzugefügt: 1. Juni 2022

Picture of the Week.
New South Wales DDL — Digital Driver's License.
The latest Microsoft Office 0-day remote code execution vulnerability.
GhostTouch.
Vodafone's new TrustPiD.
Closing the...

SN 872: Dis-CONTI-nued: The End of Conti? - Clearview AI in Ukraine, Vancouver Pwn2Own, Voyager 1

Hinzugefügt: 25. Mai 2022

Picture of the Week.
Emergency mid-cycle update for Active Directory.
Clearview AI -vs- {Illinois, Australia, Canada and the United Kingdom}.
Clearview AI in Ukraine.
Pwn2Own Vancouver 2022....