![]() |
| Product Page |
If you're in software development, raise some awareness around the office of the OWASP Top 10 vulnerabilities. They're still being found in software even after all this time, which means not enough effort is being made to avoid them.
![]() |
| Product Page |
If you're in software development, raise some awareness around the office of the OWASP Top 10 vulnerabilities. They're still being found in software even after all this time, which means not enough effort is being made to avoid them.
![]() |
| from here and here (image source) |
The MOVEit vulnerability has been exploited far and wide, but this latest one involving the DMV seems particularly far reaching.
![]() |
| from here and here |
There's a security vulnerability in the secure boot feature of modern computers. While the patch for this 0-day was already released, it won't be enabled by default until Q1 2024. That's a long time to wait for a fix. In theory you can probably enable this fix sooner than that, but most people aren't even going to be aware of it, so most of the vulnerable computer population will remain vulnerable for basically a year, giving attackers ample opportunity to take advantage of it.
![]() |
| found on Izismile |
You might think that the only way they could get into your WiFi is by guessing your super powerful secret password, but not only is your password probably not as strong as you think it is, it's also probably not the only way in. WiFi routers have vulnerabilities just like other computerized systems.
![]() |
| from here and here |
I'm not saying there's anything wrong with wanting something in return for your efforts, but be honest about your motivations and be more curious about how that process works. Don't just assume everyone hands out bug bounties, because they don't, and if the company in question doesn't then it's best to not even mention it.
Frankly, when you approach a company with a report that mentions a deadline to act and payment they never agreed to, quite a few are going to interpret it as some sort of shakedown or blackmail. One of the best indicators that a company won't do that is if they do in fact have a documented bug bounty program.
![]() |
| from here and here |
When the advice to deal with a vulnerable Internet of Things device is to unplug it (effectively returning you to the dumb way of doing things), that's when you know "smart" isn't worth it.
![]() |
| from here and here |
I can't resist a pun, and I suppose some attackers can't either, so keep that in mind when you're naming your products. And if you happen to be a GoAnywhere user, patch it, or your org might be the next place the attackers wind up.
![]() |
| from here and here |
I imagine if you can still get Internet on your phone, a digital snow day while you wait for 83 patches to be applied to your PC might actually be a good thing. No work and all play. It's almost enough to make me wish I had a phone.
![]() |
| from here and here |
Withholding security patches for over a year is not a good look on anyone, regardless of how well loved your products are.
![]() |
| from here and here |
It's hard to believe, but the year is 2023 and people are still creating products with SQL injection vulnerabilities. I can only guess that the Q in QNAP doesn't stand for quality. It might stand for quick, because that's how fast you can get pwned with a vulnerability like that.
![]() |
| from here and here |
It's honestly kind of shocking how many cars are vulnerable to hackers and how much they can do to them. Makes me glad I use public transit.
![]() |
| from here and here |
I think the people who make updates need to put more thought into the user experience of applying updates. Otherwise the updates are just going to get delayed over and over again.
![]() |
| from here and here |
Thanks to Microsoft's misguided efforts to make their inferior browser an integral part of the Windows platform, the IE rendering engine was stuck into all sorts of things - and now, even though the browser has long since been deprecated, governmental hackers are still using IE exploits to break into systems because IE is embedded into MS Office products. Thanks for nothing, Microsoft.
![]() |
| from here and here |
Gotta love malware that doesn't validate its own inputs. Especially when it goes out of it's way to be non-persistent, so that when it crashes it's effectively gone and the previously infected machines are now clean until someone comes along to reinfect them.
![]() |
| from here and here |
Log4j is still out there after an entire year. It's hardly the first time a vulnerability has been left unpatched within the online world, but an easy to exploit vulnerability with the highest severity possible still being unpatched after a year? That's not a good precedent to set.
![]() |
| from here and here |
There is certainly a delicious irony in Google getting called out by none other than Google for taking to long to patch their shit. Seemingly the patch has been available for more than the 90 days that Google's Project Zero usually gives vendors. They didn't even need to develop the patch themselves, just apply it to their product, but apparently it's gotten held up in testing.
Kinda makes you wonder, if Google can't even adhere to their own 90 day policy, why is it reasonable to expect it from others?
![]() |
| from here and here |
Even though the security company that discovered the malware vulnerability aren't publishing it, I have high hopes that people less scrupulous than them will use it to take the criminals down. That's not to say that I don't want the criminals in question to face justice, but rather I have my doubts whether most of them will, and in the absence of legal consequences, the increased cost due to business disruptions could conceivably make the operation less financially viable. Also, if the hack forces them to re-infect people or to infect even more people then that probably will increase their exposure with regards to law enforcement and might be the thing that gets them caught.
![]() |
| from here and here |
Apparently Chrome has more than twice as many vulns this year as the next leading browser. I know more vulnerabilities doesn't necessarily mean Chrome is less secure than it's competitors. It has the most market share so it gets the most attention from people trying to find vulnerabilities. However, while that doesn't make it less secure, it does make it less safe. More attention from attackers (successful attention at that it appears) means that users of the software face more attacks than users of the alternative browser - and that has been the rationale behind using alternative software for a long time. If you're using something that has a smaller target on it's back, you're less likely to fall victim.
![]() |
| from here and here |