Sat.Jun 04, 2022

article thumbnail

Weekly Update 298

Troy Hunt

I somehow ended up blasting through an hour and a quarter in this week's video with loads of discussion on the CTARS / NDIS data breach then a real time "let's see what the fuss is about" with news that one of our state's digital driver's licenses (DDL) may be easily forgeable. I think the whole discussion is actually really interesting when looked at through the lens of how on balance, a digitised license compares to a physical one.

article thumbnail

Just Copy What Works

Daniel Miessler

I’ve had an idea lingering for years about habits and behaviors and outcomes. If we accept that peoples’ output usually comes from their inputs, what if we just completely copied their inputs? For example, I’m a heavy guy because I eat too much. I have a friend who eats way less. He’s very thin. So here’s the crazy part: What if I just ate what he ate ?

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Apple blocked 1.6 millions apps from defrauding users in 2021

Bleeping Computer

Apple said this week that it blocked more than 343,000 iOS apps were blocked by the App Store App Review team for privacy violations last year, while another 157,000 were rejected for attempting to mislead or spamming iOS users. [.].

142
142
article thumbnail

GitLab addressed critical account take over via SCIM email change

Security Affairs

GitLab addresses a critical security vulnerability, tracked as CVE-2022-1680, that could be exploited by an attacker to take over users’ accounts. GitLab has fixed a critical security flaw in its GitLab Enterprise Edition (EE), tracked as CVE-2022-1680 (CVSS score 9.9), that could be exploited to take over an account. The vulnerability impacts all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. R

article thumbnail

The Importance of User Roles and Permissions in Cybersecurity Software

How many people would you trust with your house keys? Chances are, you have a handful of trusted friends and family members who have an emergency copy, but you definitely wouldn’t hand those out too freely. You have stuff that’s worth protecting—and the more people that have access to your belongings, the higher the odds that something will go missing.

article thumbnail

Bored Ape Yacht Club, Otherside NFTs stolen in Discord server hack

Bleeping Computer

Hackers reportedly stole over $257,000 in Ethereum and thirty-two NFTs after the Yuga Lab's Bored Ape Yacht Club and Otherside Metaverse Discord servers were compromised to post a phishing scam. [.].

Scams 136
article thumbnail

Anonymous: Operation Russia after 100 days of war

Security Affairs

Operation Russia continues, albeit much more slowly than last month, RKPLaw, Vyberi Radio, and Metprom Group are the last victims. The #OpRussia launched by Anonymous on Russia after the criminal invasion of Ukraine continues, albeit much more slowly than last month. The collective recently leaked stolen data via DDoSecrets. This is my update on the recent attack and associated data leaks via the DDoSecrets platform: RRustam Kurmaev and Partners (RKP Law) – RKP Law is a Russian law firm th

Banking 124

More Trending

article thumbnail

Atlassian Releases Patch for Confluence Zero-Day Flaw Exploited in the Wild

The Hacker News

Atlassian on Friday rolled out fixes to address a critical security flaw affecting its Confluence Server and Data Center products that have come under active exploitation by threat actors to achieve remote code execution. Tracked as CVE-2022-26134, the issue is similar to CVE-2021-26084 — another security flaw the Australian software company patched in August 2021.

Software 117
article thumbnail

Windows 11 'Restore Apps' feature will make it easier to set up new PCs

Bleeping Computer

Microsoft is working on a new 'Restore Apps' feature for Windows 11 that will allow users to quickly reinstall all of their previously installed apps from the Microsoft Store on a new or freshly installed PC. [.].

126
126
article thumbnail

Understanding The Windows 10 Ransomware Protection – UPDATED 2022

SecureBlitz

This post will help you to understand Windows 10 ransomware protection. The WannaCry Ransomware hit was a significant blow. It. Read more. The post Understanding The Windows 10 Ransomware Protection – UPDATED 2022 appeared first on SecureBlitz Cybersecurity.

article thumbnail

Your Tim Hortons Coffee App Knew Where You Were at All Times

WIRED Threat Level

The Canada-based company illegally collected “vast amounts of location data,” such as every time a person entered or left their home, workplace, or another coffee shop.

84
article thumbnail

IDC Analyst Report: The Open Source Blind Spot Putting Businesses at Risk

In a recent study, IDC found that 64% of organizations said they were already using open source in software development with a further 25% planning to in the next year. Most organizations are unaware of just how much open-source code is used and underestimate their dependency on it. As enterprises grow the use of open-source software, they face a new challenge: understanding the scope of open-source software that's being used throughout the organization and the corresponding exposure.

article thumbnail

Imperva Customers are protected from Atlassian Confluence CVE-2022-26134

Security Boulevard

This is an evolving storyline. Last update: June 4, 2022. On June 2, 2022, Atlassian published a security advisory regarding a CVE for versions of Confluence Server and Data Center applications greater than 1.3.0. The advisory details a critical severity unauthenticated remote code execution vulnerability and is identified as CVE-2022-26134. This Object-Graph Navigation Language (OGNL) […].

69
article thumbnail

Your Tim Hortons Coffee App Knew Where You Were at All Times

WIRED Threat Level

The Canada-based company illegally collected “vast amounts of location data,” such as every time a person entered or left their home, workplace, or another coffee shop.

84
article thumbnail

Zero Day Initiative’s Pwn2Own Vancouver 2022 – Dustin Childs’, Mike Gibson’s And Mat Powe’l’s ‘Day 2 Recap’

Security Boulevard

Our thanks to Zero Day Initiative for publishing their outstanding Pwn2Own Vancouver 2022 videos on the organization’s’ YouTube channel. Permalink. The post Zero Day Initiative’s Pwn2Own Vancouver 2022 – Dustin Childs’, Mike Gibson’s And Mat Powe’l’s ‘Day 2 Recap’ appeared first on Security Boulevard.

article thumbnail

Google May Owe You a Chunk of $100 Million

WIRED Threat Level

Plus: The US admits to cyber operations supporting Ukraine, SCOTUS investigates its own, and a Michael Flynn surveillance mystery is solved.

article thumbnail

Cybersecurity Predictions for 2024

Within the past few years, ransomware attacks have turned to critical infrastructure, healthcare, and government entities. Attackers have taken advantage of the rapid shift to remote work and new technologies. Add to that hacktivism due to global conflicts and U.S. elections, and an increased focus on AI, and you have the perfect recipe for a knotty and turbulent 2024.

article thumbnail

XKCD ‘Types Of Scopes’

Security Boulevard

via the comic artistry and dry wit of Randall Munroe , resident at XKCD ! Permalink. The post XKCD ‘Types Of Scopes’ appeared first on Security Boulevard.

69
article thumbnail

Google May Owe You a Chunk of $100 Million

WIRED Threat Level

Plus: The US admits to cyber operations supporting Ukraine, SCOTUS investigates its own, and a Michael Flynn surveillance mystery is solved.

article thumbnail

Zero Day Initiative’s Pwn2Own Vancouver 2022 – REverse Tactics’ ‘Bruno Pujos Vs. Microsoft Windows 11’

Security Boulevard

Our thanks to Zero Day Initiative for publishing their outstanding Pwn2Own Vancouver 2022 videos on the organization’s’ YouTube channel. Permalink. The post Zero Day Initiative’s Pwn2Own Vancouver 2022 – REverse Tactics’ ‘Bruno Pujos Vs. Microsoft Windows 11’ appeared first on Security Boulevard.