br00t4c, to random
@br00t4c@mastodon.social avatar

Shell Energy fined GBP1.4m for failing to flag end of mobile and broadband contracts

https://www.theguardian.com/money/2023/nov/21/shell-energy-fined-end-of-mobile-broadband-contracts-ofcom

br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to Law
@br00t4c@mastodon.social avatar

How international law is getting twisted in Gaza

https://breachmedia.ca/israel-international-law-self-defense/

c47, to Cybersecurity German
@c47@chaos.social avatar
omeraltundal, to Cybersecurity

Proper Access Control is the best security measure that you can apply to prevent security breaches.

#cybersecurity #breach #access #control

br00t4c, to random
@br00t4c@mastodon.social avatar

Monero Project admits thieves stole 6-figure sum from a wallet in mystery breach

https://go.theregister.com/feed/www.theregister.com/2023/11/08/monero_project_developers_announce_breach/

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 hit by another , this one stealing employee data from 3rd-party vendor
➝ 🔓 💸 breach linked to theft of $4.4 million in crypto
➝ 🇮🇳 's Biggest Data Leak So Far? Covid-19 Test Info of 81.5Cr Citizens With ICMR Up for Sale
➝ 🔓 ✈️ ransomware group claims to have hacked
➝ 🇳🇱 ⚖️ Dutch hacker jailed for extortion, selling stolen data on RaidForums
➝ 🇷🇺 🇺🇸 Russian Reshipping Service ‘SWAT USA Drop’ Exposed
➝ 🇮🇷 🦠 Iranian Cyber Spies Use ‘’ Malware in Latest Attacks
➝ 📉 Security researchers observed ‘deliberate’ takedown of notorious
➝ 🇮🇳 📱 Apple warns Indian opposition leaders of state-sponsored attacks
➝ 🌍 Four dozen countries declare they won’t pay ransoms
➝ 🇷🇺 How , an Automated Social Media Accounts Creation Service, Can Facilitate
➝ 🇪🇺 EU digital ID reforms should be ‘actively resisted’, say experts
➝ 🇷🇺 🇺🇦 arrests Russian hackers working for Ukrainian cyber forces
➝ 🇺🇸 FTC orders non-bank financial firms to report breaches in 30 days
➝ 🇨🇦 📱 Bans and Apps On Government Devices
➝ 🇺🇸 Charges and Its With Fraud and Cybersecurity Failures
➝ 🇺🇸 🤖 Wants to Move Fast on AI Safeguards and Will Sign an Executive Order to Address His Concerns
➝ 🦠 📱 confirms it tagged Google app as on Android phones
➝ 🦠 🇰🇵 North Korean Hackers Targeting Crypto Experts with Malware
➝ 👥 💸 EleKtra-Leak Attacks Exploit IAM Credentials Exposed on
➝ 🦠 🐍 Trojanized Software Version Delivered via Search Ads
➝ ✅ 🤖 adds security audit badges for Android apps
➝ 🔐 Microsoft pledges to bolster security as part of ‘Secure Future’ initiative
➝ 🆕 FIRST Releases 4.0 Vuln Scoring Standard
➝ 🆕 Releases ATT&CK v14 With Improvements to Detections, ICS, Mobile
➝ ⛔️ 🦠 Galaxy gets new Auto Blocker anti-malware feature
➝ 🍏 🔐 Improves Security With Contact Key Verification
➝ 🔓 Researchers Find 34 Drivers Vulnerable to Full Device Takeover
➝ 🔓 🪶 3,000 servers vulnerable to RCE attacks exposed online
➝ 🗣️ CISO Urges Quick Action to Protect Instances From Critical
➝ 🔓 🩸 “This vulnerability is now under mass exploitation.” bug bites hard
➝ 🐛 💰 HackerOne paid ethical hackers over $300 million in

📚 This week's recommended reading is: "Permanent Record" by Edward Snowden

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-442023

br00t4c, to Canada
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar

Okta breach affected 134 orgs, 'or less than 1%' of customers, company admits

https://go.theregister.com/feed/www.theregister.com/2023/11/06/security_in_brief/

thetechtutor, to random
@thetechtutor@me.dm avatar

So, this is… bad. If you don’t know about the company : they provide so users can prove who they are & sign into websites.

And they just got

The existed for two full weeks before the company shut it down.

So, once again, for those just joining us:

Q: In a digitally-interconnected world, who can you trust?

A: No one. Start from that assumption. Then build from there.

From: @briankrebs
https://infosec.exchange/@briankrebs/111268808532799070

br00t4c, to random
@br00t4c@mastodon.social avatar
br00t4c, to random
@br00t4c@mastodon.social avatar

Okta tells 5,000 of its own staff that their data was accessed in third-party breach

https://go.theregister.com/feed/www.theregister.com/2023/11/02/okta_staff_personal_data/

koreapro, to tech
@koreapro@federated.press avatar

ANALYSIS: Decoding ’s classifications: Strategies & stakes

"Companies aiming to export these technologies require ’s approval. Any , especially leaking these technologies abroad, can lead to severe penalties," writes Ben Forney.https://koreapro.org/2023/10/decoding-south-koreas-tech-classifications-strategies-and-stakes/

hackdefendr, to Cybersecurity

Ace Hardware hit with

Weekend incident interrupts key .

https://hbsdealer.com/ace-hardware-hit-cyber-breach

BishopFox, (edited ) to TableTop

True or false: #FinServ organizations are more likely to have mature crisis management programs inclusive of testing #tabletop exercises and different data #breach scenarios to ensure optimal operation.

Discover the answer for yourself when you download the #PonemonInstitute #offensivesecurity report focusing on the financial services industry.

https://bfx.social/48lV3sU

0x58, to Cybersecurity

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #43/2023 is out! It includes the following and much more:

➝ 🇺🇸 🎰 Hackers that breached Las Vegas casinos rely on violent threats, research shows
➝ 🔓 🇺🇸 University of Michigan employee, student data stolen in #cyberattack
➝ 🔓 #1Password discloses security incident linked to #Okta breach
➝ 🇺🇸 Cyber attacks hit NY state #casino operation, two Hudson Valley hospitals
➝ 🇺🇸 🗳️ D.C. Board of Elections: Hackers may have breached entire voter roll
➝ 🔓 🇮🇪 Thousands of drivers have sensitive data exposed to hackers in major IT #breach
➝ 🇷🇺 📨 Pro-Russia hackers target inboxes with #0day in webmail app used by millions
➝ 🇫🇷 🇷🇺 #France says Russian state hackers breached numerous critical networks
➝ 🇳🇬 Nigerian Police dismantle #cybercrime recruitment, mentoring hub
➝ 🇵🇸 💸 #Palestine #crypto donation scams emerge amid Israel-Hamas war
➝ 🇪🇸 👮🏻‍♂️ #Spain arrests 34 #cybercriminals who stole data of 4 million people
➝ 🇨🇦 🇨🇳 #Canada: Lawmakers Targeted by China-Linked ‘#Spamouflage’ Disinformation
➝ 🇺🇸 🇷🇺 Ex-NSA Employee Pleads Guilty to Leaking Classified Data to #Russia
➝ 🦠 🇰🇵 N. Korean #Lazarus Group Targets Software Vendor Using Known Flaws
➝ 🦠 🇮🇷 Iranian Group #Tortoiseshell Launches New Wave of IMAPLoader #Malware Attacks
➝ 🦠 🪰 #StripedFly malware framework infects 1 million #Windows, #Linux hosts
➝ 🦠 📱 #iOS Zero-Day Attacks: Experts Uncover Deeper Insights into Operation Triangulation
➝ 🔓 📱 #Samsung Galaxy S23 hacked two more times at #Pwn2Own Toronto
➝ 🔓 Critical #OAuth Flaws Uncovered in #Grammarly, #Vidio, and #Bukalapak Platforms
➝ 🔓 🩺 Critical Flaw in NextGen's Mirth Connect Could Expose #Healthcare Data
➝ 🔓 #F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP
➝ 🔓 🍏 Hackers can force iOS and #macOS browsers to divulge #passwords and much more
➝ 🩹 #Citrix warns admins to patch #NetScaler CVE-2023-4966 bug immediately
➝ 🔓 ✌🏻 #Cisco Finds Second Zero-Day as Number of Hacked Devices Apparently Drops
➝ 🔓 Critical RCE flaws found in #SolarWinds access audit solution

📚 This week's recommended reading is: "Click Here to Kill Everybody: Security and Survival in a Hyper-connected World" by Bruce Schneier

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-432023

br00t4c, to security
@br00t4c@mastodon.social avatar

Okta's Latest Security Breach Is Haunted by the Ghost of Incidents Past

https://www.wired.com/story/okta-support-system-breach-disclosure/

cybersecpitchbot, to Cybersecurity

BREAKING: University of Michigan Adding ‘Ways to Protect Your Identity 101’ After Student and Employee Data Stolen in Cyberattack.

br00t4c, to random
@br00t4c@mastodon.social avatar

1Password confirms attacker tried to pull list of admin users after Okta intrusion

https://go.theregister.com/feed/www.theregister.com/2023/10/24/1password_confirms_all_logins_are/

semperinlimbo, to random

So Okta was breached (Oct 2023) and the Threat Actor(s) pivot tired to pivot to other services. According to @vxunderground the Threat Actor(s) successfully pivoted to 1Password. Cloudflare is also reporting the attempt to pivot to them but they managed to contain and minimize the impact. More on it here: https://cfl.re/3Q6VpuR

PrivacyDigest, to random
@PrivacyDigest@mas.to avatar
SteveThompson, to privacy
@SteveThompson@mastodon.social avatar
majorlinux, to infosec
@majorlinux@toot.majorshouse.com avatar

Not how I expected genetics data to be used, but just as bad.

More 23andMe user records appear online - Desk Chair Analysts

https://dcanalysts.net/more-23andme-user-records-appear-online/

0x58, to infosec

On Wednesday, October 18, 2023, we @cloudflare] discovered attacks on our system that we were able to trace back to Okta – threat actors were able to leverage an authentication token compromised at Okta to pivot into Cloudflare’s Okta instance.

.. and they wrap up with recommendations...

Take any report of compromise seriously and act immediately to limit damage; in this case Okta was first notified on October 2, 2023 by @beyondtrust but the attacker still had access to their support systems at least until October 18, 2023.

#Okta #breach #infosec #cybersecurity

https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/

PrivacyDigest, to CASIO
@PrivacyDigest@mas.to avatar

data involves customers in 149 countries • The Register

Crooks broke into the server and swiped online learning database

https://www.theregister.com/2023/10/19/casio_data_theft/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • InstantRegret
  • everett
  • ngwrru68w68
  • magazineikmin
  • thenastyranch
  • rosin
  • ethstaker
  • GTA5RPClips
  • Youngstown
  • slotface
  • osvaldo12
  • kavyap
  • DreamBathrooms
  • provamag3
  • cubers
  • tacticalgear
  • khanakhh
  • mdbf
  • modclub
  • Durango
  • anitta
  • cisconetworking
  • normalnudes
  • tester
  • Leos
  • megavids
  • lostlight
  • All magazines