This week's newsletter issue is out! Have a look at it. It includes, but not only:

  • CISA warns of actively exploited bug after breach
  • Brazil seizing shipments to prevent use in crime
  • X-Force on defining the Reflective Loader
  • Security researchers targeted with new via job offers on
  • Alleged NetWire RAT Operator Arrested in Croatia as FBI Seizes Website
  • Xenomorph malware now steals data from 400 banks
  • makes 2FA mandatory next week for active developers
  • The E11 door phone/intercom is riddled with security holes
  • Custom Chinese Malware Found on Appliance
  • Building Great OT Incident Response Tabletop Exercises, by @hacks4pancakes
  • Warning: Don't Let Manage Your
  • warns of new critical unauthenticated RCE
  • fixes bug that lets hackers breach infrastructure
  • AI-Powered '' Keylogging Attack Evades Modern Security
  • Hard-coded secrets up 67% as secrets sprawl threatens software supply chain
  • malware attacks return after three-month break

.. And many more. Subscribe to receive it directly in your inbox every Sunday!

0x58.substack.com/p/my-shared-

#infosec #plex #lastpass #FlipperZero #ibm #cobaltstrike #malware #linkedin #android #github #akuvox #sonicwall #google #passwords #fortinet #vulnerability #veeam #backup #blackmamba #edr #emotet #cybersecurity #security #newsletter

Last updated 2 years ago

The E11 door phone/intercom is riddled with holes.

The 13 vulnerabilities found by Claroty include a missing authentication for critical functions, missing or improper authorization, hard-coded keys that are encrypted using accessible rather than cryptographically hashed keys, and the exposure of sensitive information to unauthorized users. As bad as the vulnerabilities are, their threat is made worse by the failure of Akuvox—a China-based leading supplier of smart intercom and door entry systems—to respond to multiple messages from Claroty, the CERT coordination Center, and Cybersecurity and Infrastructure Security Agency over a span of six weeks. Claroty and CISA publicly published their findings on Thursday here and here.

arstechnica.com/information-te

#akuvox #security #infosec #privacy #smarthome

Last updated 2 years ago

IT News · @itnewsbot
2990 followers · 252146 posts · Server schleuss.online

Go ahead and unplug this door device before reading. You’ll thank us later. - Enlarge / The Akuvox E11 (credit: Akuvox)

The Akuvox E11 is bi... - arstechnica.com/?p=1922784

#iot #akuvox #biz #doorphones #internetofthings #securityvulnerabilities

Last updated 2 years ago

Tech news from Canada · @TechNews
338 followers · 9137 posts · Server mastodon.roitsystems.ca