Security Leftovers
-
APIs Used by Bots to Detect Public IP address, (Mon, Feb 6th)
It may be helpful to detect these requests. Many use unique host names. This will make detecting the request in DNS logs easy even if TLS is not intercepted.
-
Critical Baicells Device Vulnerability Can Expose Telecoms Networks to Snooping
A critical vulnerability affecting wireless communications base stations from Baicells can be exploited to cause disruption or take complete control of data and voice traffic.
-
The Birth of “Disable JavaScript”
Did you know: “Disable JavaScript” as a browser feature was born out of an exasperation with plugging security holes?
I didn’t. But then I watched “A Hipster History of CORS” and the speaker, Devdatta Akhawe, references the history of the feature as outlined in the book JavaScript: The Definitive Guide.
Security in JavaScript in those early days was WDD: whack-a-mole driven development.
-
Hackers are using a critical flaw in VMware as part of a ransomware campaign targeting thousands of organizations
Hackers are targeting a two-year-old VMware server software vulnerability in a ransomware campaign aimed at extorting thousands of companies around the world, Italy’s National Cybersecurity Agency warned on Saturday (Feb. 4).
-
VMware and governments warn of ransomware attack targeting unpatched ESXi servers
VMware Inc. and government agencies in Europe are warning users of VMware's ESXi hypervisors today to ensure their software is up to date following the emergence of a widespread ransomware campaign targeting unpatched installs. -
First-ever CloudNativeSecurityCon offers insights into ongoing challenge of protecting vital architectures [Ed: This site publishes this spam just because 'Linux' Foundation pays for it; that does not promote real security]
After two full days of keynote presentations and track sessions, CloudNativeSecurityCon is officially in the books. -
Florida Hospital Cancels Procedures, Diverts Patients Following Cyberattack
Tallahassee Memorial HealthCare was forced to cancel procedures and divert patients after taking systems offline following a Thursday night cyberattack.
-
VMware ESXi Servers Targeted in Ransomware Attack via Old Vulnerability
Unpatched and unprotected VMware ESXi servers worldwide have been targeted in a ransomware attack exploiting a vulnerability patched in 2021.
-
Phony cybersecurity regulation
Episode 441 of the Cyberlaw Podcast