Oh, what a tangled web we weave.
— @Richi 🤓 Jennings (@RiCHi) August 15, 2022
In today’s #SBBlogwatch, we order the lobster Thermidor au crevette with a Mornay sauce, served in a Provencale manner, with shallots and aubergines, etc., etc. …
At @TechstrongGroup’s @SecurityBlvd: https://t.co/DnKlTnyyo8 @ShaeFlorentine
Monday, 15 August 2022
Gmail Lets Candidates Spam You — FEC FAIL - Security Boulevard
Email is a Mass Noun: Politicians convinced the Federal Election Commission (FEC) that Google must give them a free pass through Gmail’s spam filters. They want la GOOG to ignore user preferences and deliver their “delightful” fundraising missives direct to your inbox.
Friday, 12 August 2022
Cisco Pwned by ‘Russian’ Gang — Data Leaked, Egg on Face - Security Boulevard
MFA FAIL: Cisco got hacked by a ransomware gang—a broker for the UNC2447 threat actor, linked to the Yanluowang crew (pictured). This was way back at the end of May, but Cisco’s only now talking about it.
What a mess.
— @Richi 🤓 Jennings (@RiCHi) August 12, 2022
In today’s #SBBlogwatch, we try to learn from Cisco’s mistakes.
At @TechstrongGroup’s @SecurityBlvd: https://t.co/F3WgYaRi9c
Thursday, 11 August 2022
We Must Kill ‘Dinosaur’ JavaScript | Microsoft Open Sources 3D Emoji - DevOps.com
The moral of the story: The Devil hath power to assume a pleasing shape
In this week’s #TheLongView:
— @Richi 🤓 Jennings (@RiCHi) August 11, 2022
1⃣ #JavaScript is a bloated barrier to progress, and
2⃣ @Microsoft’s #emoji are on @GitHub.
At @TechstrongGroup’s @DevOpsDotCom: https://t.co/Bfcjp7bHbE #DevOps
DevOps: Fix your dangerous redirects! Amex shows how - ReversingLabs
And Snap shows how not: Recent ‘LogoKit’ spear phishing campaigns have misused open redirect URLs in web apps from Snapchat and American Express. When alerted, Amex quickly fixed the hole, but Snap’s is still open after more than a year.
Be better netizens, #DevOps teams.
— @Richi 🤓 Jennings (@RiCHi) August 11, 2022
In this week’s #SSBlogwatch we audit our URLs.
For @ReversingLabs’ @SecuredSoftware: https://t.co/MPBjV6uFjn
Tuesday, 9 August 2022
Twilio Fails Simple Test — Leaks Private Data via Phishing - Security Boulevard
“Sophisticated” Sophistry: Twilio (NYSE:TWLO) customer data has leaked—after a simple phishing attack on employees. The firm isn’t saying how many end-users are affected, but it could run into the millions.
… Twilio PR is spinning it as a “sophisticated” attack.
— @Richi 🤓 Jennings (@RiCHi) August 9, 2022
In today’s #SBBlogwatch, we just point and laugh.
At @TechstrongGroup’s @SecurityBlvd: https://t.co/nRi20mV3u7
Subscribe to:
Posts (Atom)