Hi friends,
Here's this week's attempt to keep up with security news! :-) Enjoy the read and have a good end of the week!
Cheers,
Supported by 1Password.
Hi friends,
Here's this week's attempt to keep up with security news! :-) Enjoy the read and have a good end of the week!
Cheers,
Interesting write-up of a ransomware attack, that first failed because the company's EDR solution detected and blocked the encryption malware on their Windows machines. The attackers then pivoted to a vulnerable webcam, which didn't have EDR installed and ran Linux, and proceeded to mount the company files as SMB shares and encrypt them from there. Not something you see every day.
Related, here are two other "mind your camera's" articles from last week, it seemed to be a theme:
This made some headlines this week, but doesn't seem to be as bad as you'd think. It's about how the ubiquitous ESP32 microchip, made by Chinese manufacturer Espressif and used by over 1 billion IoT devices, contains undocumented commands that could be leveraged for attacks. Not for actual remote attacks though, but rather ways to maintain a presence on the devices once you already hacked into them. Good Hackernews thread on this here.
A software developer has been found guilty of sabotaging his ex-employer's systems by running custom malware and installing a "kill switch" after being demoted at the company.
For those running PHP on Windows, this is worth double checking your patch cycle for. It affects Windows PHP installations with PHP running in CGI mode. Successful exploitation enables unauthenticated attackers to execute arbitrary code.
Good cautionary tale against running end-of-life network equipment.
I don't think most developers realise how valuable 1Password can be. It doesn't just hold passwords, it also hold your SSH keys, signs your Git commits, injects token and other secrets in CLI scripts when you want, and much more. (Sponsored)