@zackwhittaker@mastodon.social
@zackwhittaker@mastodon.social avatar

zackwhittaker

@zackwhittaker@mastodon.social

Security editor, TechCrunch
zack.whittaker@techcrunch.com
Signal: +1 646.755.8849
New York, NY

This profile is from a federated server and may be incomplete. Browse more on the original instance.

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

New: Amazon is selling Android TV boxes laced with malware, security researchers confirm.

When reached, an Amazon spokesperson declined to comment. The malware-infected models are still for sale.

More: https://techcrunch.com/2023/05/18/popular-android-tv-boxes-sold-on-amazon-are-laced-with-malware/

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

New: U.K. outsourcing giant Capita is facing heat after leaving gigabytes of customer data exposed to the internet for years.

Colchester City Council told TechCrunch that its data was exposed by Capita's error.

Capita told us that the exposed data was limited to "release notes and user guides," and did not indicate any of the data was sensitive.

It's Capita's second security incident in a month, weeks after it was hit by a ransomware attack.

More by @carlypage: https://techcrunch.com/2023/05/15/capita-breach-fallout-widens-as-customers-learn-of-data-theft/

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

A busy this week in security just went out, featuring:

• DOJ takes down Russian malware, booters
• MSI code-signing keys leaked, no easy way to revoke
• Capita slated as Britain's "largest hack"
• Twitter's badly-encrypted DMs roll out
• Department of Transportation tells lawmakers it was hacked
• EU says spyware should be banned
• Toyota Japan vehicle locations exposed for a decade
• A very cute cyber cat, and more

Sign up: https://this.weekinsecurity.com

Read online: https://mailchi.mp/zackwhittaker/this-week-in-security-may-14-2023-edition

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

Hope everyone is having a peaceful weekend. Here's Toby, aka smush face.

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

New: Hackers stole 3 million SchoolDude user accounts in an April data breach.

Brightly, which makes the software, reset user passwords amid fears they weren't stored securely. When reached for comment, the company declined to say if the stolen passwords were encrypted.

More: https://techcrunch.com/2023/05/12/brightly-schooldude-data-breach/

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

New: Toyota has apologized after it exposed the vehicle locations and car video footage of at least 2 million vehicles in Japan for close to a decade due to a server misconfiguration.

https://techcrunch.com/2023/05/12/toyota-japan-exposed-millions-locations-videos/

SwiftOnSecurity, to random

If the central Mastodon server ever goes down follow me on Bluesky too I'm @swiftonsecurity.com

zackwhittaker,
@zackwhittaker@mastodon.social avatar

@mattblaze @hacks4pancakes @SwiftOnSecurity me as well! thanks for the reminder. (i hope i don't screw it up.)

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

These kids are awesome. High school students wore t-shirts that say "I read banned books" and shouted “trans rights are human rights” in protest at Iowa laws during the governor's scholar ceremony.

The full video is well worth it: https://www.desmoinesregister.com/videos/news/2023/05/01/ihsaascholarshipceremony/11778011002/

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

T-Mobile, the second largest U.S. cell carrier, has disclosed nine data breaches since 2009, according to New Hampshire's DOJ. (Three listed here are duplicates.)

The breaches range from T-Mobile employees abusing their internal access to obtain customer data, through to huge thefts of personal information of tens of millions of customers.

T-Mobile's disclosed its most recent breach last week. Hackers stole hundreds of customer account PINs (for SIM swaps).

NH DOJ: https://www.doj.nh.gov/consumer/security-breaches/t.htm

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

New, by me: Apple has released its first batch of "rapid" security fixes for iPhones, iPads and Macs, which are designed to quickly fix security threats.

But the rollout isn't going so smoothly... Still, update when you can!

More: https://techcrunch.com/2023/05/01/apple-rapid-security-fixes/

GossiTheDog, to random
@GossiTheDog@cyberplace.social avatar

deleted_by_author

  • Loading...
  • zackwhittaker,
    @zackwhittaker@mastodon.social avatar
    zackwhittaker, to random
    @zackwhittaker@mastodon.social avatar

    CommScope employees say they haven’t heard from executives in over a week about how the company is responding to a ransomware attack.

    The March 27 ransomware attack caused several days of disruption, employees said.

    New by @carlypage and me: https://techcrunch.com/2023/04/27/commscope-ransomware-data/

    zackwhittaker, to random
    @zackwhittaker@mastodon.social avatar

    Incredible reporting by @lorenzofb:

    Hackers said they had access to AT&T's internal network, which allowed them to break into customers' email accounts and steal their cryptocurrency.

    Two victims confirmed they were hacked. One of them had $134,000 from his Coinbase account.

    AT&T said it's reset some customers' passwords as a "precaution," and "updated our security controls to prevent this activity."

    More: https://techcrunch.com/2023/04/26/hackers-are-breaking-into-att-email-accounts-to-steal-cryptocurrency/

    zackwhittaker, to random
    @zackwhittaker@mastodon.social avatar

    Important as it is to not let AI launch nuclear weapons, it's precisely this kind of thumb-twiddling bullshit lawmakers spend their time on that illustrates why Americans don't have healthcare.

    zackwhittaker, to random
    @zackwhittaker@mastodon.social avatar

    New by @carlypage: PaperCut, a print management software used by tens of thousands of organizations the world, says hackers are exploiting a 'critical' security flaws in unpatched servers.

    Security firm Huntress says the hackers exploited the flaws to deploy Truebot — the same initial malware that was used by the Clop ransomware group to mass-hack dozens of Fortra customers running its GoAnywhere software.

    More:
    https://techcrunch.com/2023/04/25/papercut-hackers-critical-flaw-clop-ransomware/

    zackwhittaker, to random
    @zackwhittaker@mastodon.social avatar

    New: @lorenzofb spoke with one of the hackers behind the Western Digital hack.

    As proof, the hacker provided a file signed with Western Digital's code-signing certificate (below), non-public phone numbers of company executives, and a screenshot of a video call featuring the company's CISO.

    More here: https://techcrunch.com/2023/04/13/hackers-claim-vast-access-to-western-digital-systems/

    zackwhittaker,
    @zackwhittaker@mastodon.social avatar

    In a statement today, Western Digital confirmed hackers stole "customer names, billing and shipping addresses, email addresses and telephone numbers" after a March 26 data breach.

    WD said regarding the stolen code-signing certificate that it is "equipped to revoke certificates as needed."

    Two security researchers told @lorenzofb that WD's code signing certificate was valid at the time the hackers used it signed a file as proof of still having access to WD's network.

    zackwhittaker,
    @zackwhittaker@mastodon.social avatar

    @gsuberland it's real. WD sent it as a press release. there's no reason (that I'm aware of) to send a data breach disclosure to customers by email as an image-only statement unless as a company they're just trying to be difficult and have absolutely zero regard for those who are visually impaired or use screen readers.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • everett
  • magazineikmin
  • khanakhh
  • InstantRegret
  • rosin
  • Youngstown
  • ngwrru68w68
  • mdbf
  • slotface
  • normalnudes
  • Durango
  • kavyap
  • DreamBathrooms
  • JUstTest
  • cubers
  • GTA5RPClips
  • ethstaker
  • thenastyranch
  • osvaldo12
  • Leos
  • tester
  • tacticalgear
  • cisconetworking
  • modclub
  • anitta
  • provamag3
  • lostlight
  • All magazines