What a mess.
— @Richi 🤓 Jennings (@RiCHi) August 12, 2022
In today’s #SBBlogwatch, we try to learn from Cisco’s mistakes.
At @TechstrongGroup’s @SecurityBlvd: https://t.co/F3WgYaRi9c
Friday, 12 August 2022
Cisco Pwned by ‘Russian’ Gang — Data Leaked, Egg on Face - Security Boulevard
MFA FAIL: Cisco got hacked by a ransomware gang—a broker for the UNC2447 threat actor, linked to the Yanluowang crew (pictured). This was way back at the end of May, but Cisco’s only now talking about it.
Thursday, 11 August 2022
We Must Kill ‘Dinosaur’ JavaScript | Microsoft Open Sources 3D Emoji - DevOps.com
The moral of the story: The Devil hath power to assume a pleasing shape
In this week’s #TheLongView:
— @Richi 🤓 Jennings (@RiCHi) August 11, 2022
1⃣ #JavaScript is a bloated barrier to progress, and
2⃣ @Microsoft’s #emoji are on @GitHub.
At @TechstrongGroup’s @DevOpsDotCom: https://t.co/Bfcjp7bHbE #DevOps
DevOps: Fix your dangerous redirects! Amex shows how - ReversingLabs
And Snap shows how not: Recent ‘LogoKit’ spear phishing campaigns have misused open redirect URLs in web apps from Snapchat and American Express. When alerted, Amex quickly fixed the hole, but Snap’s is still open after more than a year.
Be better netizens, #DevOps teams.
— @Richi 🤓 Jennings (@RiCHi) August 11, 2022
In this week’s #SSBlogwatch we audit our URLs.
For @ReversingLabs’ @SecuredSoftware: https://t.co/MPBjV6uFjn
Tuesday, 9 August 2022
Twilio Fails Simple Test — Leaks Private Data via Phishing - Security Boulevard
“Sophisticated” Sophistry: Twilio (NYSE:TWLO) customer data has leaked—after a simple phishing attack on employees. The firm isn’t saying how many end-users are affected, but it could run into the millions.
… Twilio PR is spinning it as a “sophisticated” attack.
— @Richi 🤓 Jennings (@RiCHi) August 9, 2022
In today’s #SBBlogwatch, we just point and laugh.
At @TechstrongGroup’s @SecurityBlvd: https://t.co/nRi20mV3u7
Monday, 8 August 2022
Slack App Leaked Hashed User Passwords for 5 YEARS - Security Boulevard
‘One Way’ Hash — Yeah, Right: Since 2017, if you’ve invited anyone to a Slack workspace, your password has leaked—albeit in the form of a salted hash. People are asking how this could have happened, and how it remained undetected for so long—more than five years.
Egg on someone’s face at @SlackHQ.
— @Richi 🤓 Jennings (@RiCHi) August 8, 2022
In today’s #SBBlogwatch, we double-check our password manager.
At @TechstrongGroup’s @SecurityBlvd: https://t.co/caOOEwyWZ1
Subscribe to:
Posts (Atom)