Security Leftovers
-
OpenSSF (Linux Foundation) ☛ OSS Security Sessions & FOSDEM Survival Guide
Are you going to FOSDEM - the biggest open source event in Europe? It can be very overwhelming for anyone new to the event. If you are interested in open source security and policy, there are be some events and talks that you do not want to miss. Here is a survival guide that I made after consulting the community about what their recommendations are and here are some tips for you.
-
Silicon Angle ☛ Menlo Security reports significant increase in browser-based phishing attacks in 2023
Cloud security startup Menlo Security Inc. today released a new report revealing a large increase in browser-based phishing attacks last year amid a growth in highly evasive adaptive threats.
-
Security Week ☛ Major US, UK Water Companies Hit by Ransomware
Two major water companies, Veolia in the US and Southern Water in the UK, have been targeted in ransomware attacks that resulted in data breaches.
-
Security Week ☛ 340,000 Jason’s Deli Customers Potentially Impacted by Credential Stuffing Attack
Jason’s Deli says hackers targeted users in credential stuffing attacks, likely compromising their personal information.
-
Security Week ☛ PoC Code Published for Just-Disclosed Fortra GoAnywhere Vulnerability
PoC code exploiting a critical Fortra GoAnywhere MFT vulnerability gets published one day after public disclosure.
-
Security Week ☛ Pwn2Own Automotive: Hackers Earn Over $700k for Tesla, EV Charger, Infotainment Exploits
On the first day of Pwn2Own Automotive participants earned over $700,000 for hacking Tesla, EV chargers and infotainment systems.
-
Security Week ☛ Chrome 121 Patches 17 Vulnerabilities
Google releases Chrome 121 to the stable channel with 17 security fixes, including 11 reported by external researchers.
The post Chrome 121 Patches 17 Vulnerabilities appeared first on SecurityWeek.
-
Neowin ☛ Microsoft confirms backdoored Windows 10 Sysprep.exe error 0x80073cf2 after installing KB5032278
Following the release of this month’s optional non-security updates, Abusive Monopolist Microsoft published a notification about backdoored Windows 10 version 22H2 having a hard time completing preparations using Sysprep.exe (System Preparation Tool).
-
SANS ☛ How Bad User Interfaces Make Security Tools Harmful, (Wed, Jan 24th)
User interface design is one of those often overlooked aspects in software design in general. A bad user interface can quickly become a vulnerability regarding security.