Security researchers at #Mandiant say #China-backed #hackers are likely behind the mass-exploitation of a recently discovered #zeroday #securityflaw in #BarracudaNetworks' #email security gear, which prompted a warning to customers to remove and replace affected devices. Their goal was to spy on #government and #academic accounts https://techcrunch.com/2023/06/15/mandiant-china-hackers-barracuda-espionage-governments/
#mandiant #China #hackers #zeroday #securityflaw #barracudanetworks #email #government #academic
Beware the new two-factor authentication tool from Google doesn’t seem to be end-to-end encrypted, which could expose users to significant security risks☝️🤖 #2FA #SecurityFlaw
Time to hit Ye Ole "Yum Update"!
That's righ! I said "Yum"!
You may want to run system updates, after a recent sudo security flaw https://www.gamingonlinux.com/2023/02/you-may-want-to-run-system-updates-after-a-recent-sudo-security-flaw/
#Update #Sudo #SecurityFlaw #Linux #SteamDeck #InfoSec #OpenSource #TechNews
#update #sudo #securityflaw #linux #SteamDeck #infosec #opensource #technews
Got an old iOS device?
Time to patch that up, too!
Apple just updated iOS 12 to patch a critical security flaw https://www.macworld.com/article/1483041/ios-12-5-7-iphone-6-security-update-zero-day.html
#apple #ios12 #iphone #securityflaw #infosec #technews
This one's fairly fresh and hasn't seen much coverage: CloudSek has discovered a cookie-stealing authentication bypass that works against a bunch of Atlassian products: Jira, Confluence, Trello and BitBucket. No word as yet from Atlassian on a patch. Keep an eye out.
Not super easy to exploit, but still troubling.
#Atlassian #Jira #Confluence #Trello #BitBucket #SecurityFlaw #exploit
#atlassian #jira #confluence #trello #bitbucket #securityflaw #exploit
#ChatGPT: the following toot went viral on infosec.exchange mastodon server
"Just found out that the new iOS update has a major security flaw that allows hackers to gain access to your personal information. Update your phone ASAP to protect yourself!" #infosec #iOS #securityflaw
Are we getting too predictable? Asking for a friend.
#chatgpt #infosec #ios #securityflaw #notreal #fakenews
Update Chrome now!!!!!
Google ships 8th emergency Chrome update for Mac to fix ‘high-severity’ flaw https://www.macworld.com/article/1395816/google-chrome-update-for-mac-high-severity-flaw.html
#GoogleChrome #Emergency #Update #macOS #HighSeverity #SecurityFlaw #InfoSec
#googlechrome #emergency #update #macos #highseverity #securityflaw #infosec
An interesting article on Mastodon-related security. And a reminder that it is safest to have two factor authentication turned on if possible. 💖 #securityflaw
https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
One-minute hack allowed lock screen bypass on Android, current Pixels are safe
https://www.androidpolice.com/one-minute-hack-allowed-lock-screen-bypass-on-android-current-pixels-are-safe/
#OperatingSystems #securityflaw #lockscreen #AndroidOS #security #Tablets #Phones #News #sim
#operatingsystems #securityflaw #lockscreen #AndroidOS #security #tablets #phones #news #sim
#Twitter "may currently have foreign intelligence agents on the payroll" and is a threat for #dissidents: "The disclosure also claims that Twitter has taken money from Chinese sources and shared information in return that could potentially lead to the identification of Chinese Twitter users who have illegally circumvented government censorship in order to access the platform."
https://edition.cnn.com/2022/08/24/tech/twitter-whistleblower-takeaways/index.html
#Zatko #Zwitsch #CNN #security #securityflaw
#securityflaw #security #cnn #Zwitsch #Zatko #dissidents #twitter
🔴 #LISTENUP
ATTENTION
#Apple Warns Of #SecurityFlaw For iPhones, iPads, Macs
Apple released two security reports about the issue on Wednesday, although they didn't receive wide attention outside of tech publications. Apple's explanati...
#ListenUp #apple #securityflaw
@CSB having bluetooth you have to disable with software switches,
= #SecurityFlaw
@adam might agree?
Critical Intel Active Management Technology Flaw Allows Privilege Escalation - The critical Intel vulnerability could allow unauthenticated attackers gain escalated privileges o... https://threatpost.com/critical-intel-active-management-technology-flaw-allows-privilege-escalation/159036/ #privilegeescalationflaw #vulnerabilities #intelsecurity #criticalflaw #securityflaw #intelpatch #hacks #intel #patch
#patch #intel #hacks #intelpatch #securityflaw #criticalflaw #intelsecurity #vulnerabilities #privilegeescalationflaw
OkCupid Security Flaw Threatens Intimate Dater Details - Attackers could exploit various flaws in OkCupid's mobile app and webpage to steal victims' sensit... more: https://threatpost.com/okcupid-security-flaw-threatens-intimate-dater-details/157809/ #crossoriginresourcesharing #vulnerabilities #okcupidsecurity #maliciouscode #mobileappflaw #vulnerability #securityflaw #websecurity #datingapp #okcupid #hack
#hack #okcupid #datingapp #websecurity #securityflaw #vulnerability #mobileappflaw #maliciouscode #okcupidsecurity #vulnerabilities #crossoriginresourcesharing
Critical Zoho Zero-Day Flaw Disclosed - A Zoho zero day vulnerability and proof of concept (PoC) exploit code was disclosed on Twitter. more: https://threatpost.com/critical-zoho-zero-day-flaw-disclosed/153484/ #vulnerabilities #proofofconcept #securityflaw #exploitcode #zerodayflaw #pocexploit #exploit #zeroday #zoho
#zoho #zeroday #exploit #pocexploit #zerodayflaw #exploitcode #securityflaw #proofofconcept #vulnerabilities
Billions of Devices Open to Wi-Fi Eavesdropping Attacks - The Kr00k bug arises from an all-zero encryption key in Wi-Fi chips that reveals communications fr... more: https://threatpost.com/billions-of-devices-wifi-encryption-hack/153267/ #vulnerabilities #mobilesecurity #cve-2019-15126 #vulnerability #cryptography #appledevices #securityflaw #encryption #wi-fichips #broadcom #cypress #kr00k #krack #rsac #iot
#iot #rsac #krack #Kr00k #cypress #broadcom #wi #encryption #securityflaw #appledevices #cryptography #vulnerability #cve #mobilesecurity #vulnerabilities
Update now! Popular WordPress plugins have password bypass flaws - Researchers have discovered bad authentication bypass vulnerabilities affecting two WordPress plug... more: https://nakedsecurity.sophos.com/2020/01/16/update-now-popular-wordpress-plugins-have-password-bypass-flaws/ #infinitewpclient #passwordsecurity #wordpressplugins #securitythreats #passwordbypass #vulnerability #wptimecapsule #securityflaw #wordpress #plugins #webarx
#webarx #plugins #wordpress #securityflaw #wptimecapsule #vulnerability #passwordbypass #securitythreats #wordpressplugins #passwordsecurity #infinitewpclient
[Veille Techno] NetCAT: New Attack Lets Hackers Remotely Steal Data From Intel CPUs
#cybersecurity #cpu #intel #securityflaw
"My voice is my password" dit au téléphone ma voisine d'open-space
#securityFlaw
Oups ! #Intel #SecurityFlaw
Des processeurs Intel parmi les dernières gammes Core sont susceptibles de hacking (nécessite toutefois un accès à la machine).
L'outil de détection (WIN/Linux) est là : https://downloadcenter.intel.com/download/27150