Sat.Apr 05, 2025

article thumbnail

Weekly Update 446

Troy Hunt

After an unusually long day of travelling from Iceland, we've finally made it to the land of Guinness, Leprechauns, and a tax haven for tech companies. This week, there are a few more lessons from the successful phish against me the previous week, and in happier news, there is some really solid progress on the HIBP UX rebuild. We spent a bunch of time with Stefan and Ingiber (the guy rebuilding the front end) whilst in Reykjavik and now have a very clear plan mapped out to get this finished

Phishing 159
article thumbnail

Learning from Troy Hunt’s Sneaky Phish

Adam Shostack

Troy Hunt has a good post about being phished. Good on Troy for being transparent, and he talks about being tired and jet lagged, and that deserves sympathy. Attackers are sneaky. Troy honorably admits that he overrode 1Password and filled out the phishing site. In this post, I want to share why I think I wouldnt fall for this, even jet lagged. That defense is intensive sorting into folders, enabled by custom email addresses.

Phishing 130
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

A flaw in Verizon’s iOS Call Filter app exposed call records of millions

Security Affairs

A now-patched flaw in Verizon s iOS Call Filter app exposed call records of millions. No abuse found. Only phone numbers and timestamps were at risk. A now-patched vulnerability in Verizon s iOS Call Filter app could have been exploited to harvest the call records of millions of Americans. Verizon’s Call Filter app allows users to identify and manage unwanted calls, such as spam and robocalls.

Wireless 105
article thumbnail

Smart Strategies for Managing Machine Identities

Security Boulevard

Why is Smart Machine Identity Management Crucial? What comes to your mind when you think about cybersecurity? Most often, we conceptualize cybersecurity as a measure to protect user data, financial information, and other forms of human-associated identities. While these are certainly significant, there is an underlying and often underestimated area of cybersecurity the management [] The post Smart Strategies for Managing Machine Identities appeared first on Entro.

article thumbnail

Why Giant Content Libraries Do Nothing for Your Employees’ Cyber Resilience

Many cybersecurity awareness platforms offer massive content libraries, yet they fail to enhance employees’ cyber resilience. Without structured, engaging, and personalized training, employees struggle to retain and apply key cybersecurity principles. Phished.io explains why organizations should focus on interactive, scenario-based learning rather than overwhelming employees with excessive content.

article thumbnail

Port of Seattle ‘s August data breach impacted 90,000 people

Security Affairs

Port of Seattle is notifying 90,000 people of a data breach after personal data was stolen in a ransomware attack in August 2024. In August 2024, a cyber attack hit the Port of Seattle , which also operates the Seattle-Tacoma International Airport. The attack impacted websites and phone systems. According to The Seattle Times, the cyber attack disrupted travel plans.

article thumbnail

Crafting Impenetrable Defenses for Your NHIs

Security Boulevard

Why the Buzz about Impenetrable NHIs? You might have heard quite the buzz around impenetrable Non-Human Identities (NHIs). Its the cornerstone of next-generation cybersecurity. So, is this truly the game-changing approach toward secure defenses we have been looking for? Mastering the Art of Securing Non-Human Identities Seamlessly managing Non-Human Identities is akin to playing a [] The post Crafting Impenetrable Defenses for Your NHIs appeared first on Entro.

LifeWorks

More Trending

article thumbnail

Optimistic About the Future of Secrets Vaulting?

Security Boulevard

Are You Ready to Embrace the Future of Secrets Vaulting? I often get asked: What does the future hold for secrets vaulting? Its a valid question. With organizations continuously transitioning to the cloud and the prevalence of digital identities growing, secrets management is becoming the cornerstone of any robust cybersecurity strategy. But why should we [] The post Optimistic About the Future of Secrets Vaulting?

article thumbnail

Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data

The Hacker News

Cybersecurity researchers have uncovered malicious libraries in the Python Package Index (PyPI) repository that are designed to steal sensitive information. Two of the packages, bitcoinlibdbfix and bitcoinlib-dev, masquerade as fixes for recent issues detected in a legitimate Python module called bitcoinlib, according to ReversingLabs.

article thumbnail

BSidesLV24 – HireGround – Tracking And Hacking Your Career

Security Boulevard

Authors/Presenters: Misha Yalavarthy, Leif Dreizler Our sincere appreciation to BSidesLV , and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conferences events located at the Tuscany Suites & Casino ; and via the organizations YouTube channel. Permalink The post BSidesLV24 – HireGround – Tracking And Hacking Your Career appeared first on Security Boulevard.

Hacking 52
article thumbnail

Microsoft Credits EncryptHub, Hacker Behind 618+ Breaches, for Disclosing Windows Flaws

The Hacker News

A likely lone wolf actor behind the EncryptHub persona was acknowledged by Microsoft for discovering and reporting two security flaws in Windows last month, painting a picture of a "conflicted" individual straddling a legitimate career in cybersecurity and pursuing cybercrime.

article thumbnail

Zero Trust Mandate: The Realities, Requirements and Roadmap

The DHS compliance audit clock is ticking on Zero Trust. Government agencies can no longer ignore or delay their Zero Trust initiatives. During this virtual panel discussion—featuring Kelly Fuller Gordon, Founder and CEO of RisX, Chris Wild, Zero Trust subject matter expert at Zermount, Inc., and Principal of Cybersecurity Practice at Eliassen Group, Trey Gannon—you’ll gain a detailed understanding of the Federal Zero Trust mandate, its requirements, milestones, and deadlines.

article thumbnail

Speaking the Board’s Language: A CISO’s Guide to Securing Cybersecurity Budget

Security Boulevard

The biggest challenge CISOs face isnt just securing budget its making sure decision-makers understand why they need it. The post Speaking the Boards Language: A CISO’s Guide to Securing Cybersecurity Budget appeared first on Security Boulevard.

CISO 96
article thumbnail

Apple's latest iPad Mini model has hit its lowest price of the year

Zero Day

While I wouldn't buy the iPad Mini 7 solely for its AI features, its ultraportability still reigns supreme among Apple's tablet lineup - especially with this new deal.

86
article thumbnail

AI-Powered ‘Buy for Me’ Feature Turns Amazon App Into Personal Shopping Assistant

Penetration Testing

Amazon has recently announced the testing of a new feature called Buy for Me, a button within its mobile app that allows users to delegate shopping tasks to an AI-powered agent, streamlining the purchasing process. Powered by Amazons proprietary AI model, Nova, the Buy for Me function enables users to effortlessly purchase items via the […] The post AI-Powered Buy for Me Feature Turns Amazon App Into Personal Shopping Assistant appeared first on Daily CyberSecurity.

Mobile 55
article thumbnail

I wasn't planning to upgrade, but the Pixel 9 Pro XL changed my mind

Zero Day

The Google Pixel 9 Pro series looks, feels, and performs as well as it should for its price. But this new Amazon deal makes it even more enticing.

78
article thumbnail

Prevent Data Breaches With Zero-Trust Enterprise Password Management

Keeper Security is transforming cybersecurity for people and organizations around the world. Keeper’s affordable and easy-to-use solutions are built on a foundation of zero-trust and zero-knowledge security to protect every user on every device. Our next-generation privileged access management solution deploys in minutes and seamlessly integrates with any tech stack to prevent breaches, reduce help desk costs and ensure compliance.

article thumbnail

AMD Ryzen AI Software Update Addresses Multi Security Vulnerabilities

Penetration Testing

AMD has released an update to its Ryzen AI software to address several high-severity security vulnerabilities. The Ryzen AI software is designed to optimize and deploy AI inference on PCs powered by AMD Ryzen AI processors, enabling applications to run on the Neural Processing Unit (NPU) built into the AMD XDNA architecture. The vulnerabilities, if […] The post AMD Ryzen AI Software Update Addresses Multi Security Vulnerabilities appeared first on Daily CyberSecurity.

article thumbnail

This Lenovo ThinkPad is my go-to laptop for remote work - especially with these specs

Zero Day

The Lenovo ThinkPad T14s Gen 5 is among the most durable laptops I've tested, and its strong battery life and sharp webcam make it a smart choice for getting work done.

76
article thumbnail

Trump EO Presses States to Bear the Weight of CI Resilience

Security Boulevard

States, the EO suggests, are best positioned to own and manage preparedness and make risk-informed decisions that increase infrastructure resilience. And theres some truth to that. The post Trump EO Presses States to Bear the Weight of CI Resilience appeared first on Security Boulevard.

Risk 66
article thumbnail

The viral wireless audio dongle for in-flight entertainment just got a major upgrade - and it's legit

Zero Day

The Twelve South AirFly Pro 2 enhances audio quality, connectivity, and ease of use for in-flight entertainment, letting you enjoy your journey without worrying about weak signals.

article thumbnail

Optimizing The Modern Developer Experience with Coder

Many software teams have migrated their testing and production workloads to the cloud, yet development environments often remain tied to outdated local setups, limiting efficiency and growth. This is where Coder comes in. In our 101 Coder webinar, you’ll explore how cloud-based development environments can unlock new levels of productivity. Discover how to transition from local setups to a secure, cloud-powered ecosystem with ease.

article thumbnail

Convenience Over Security: The Inside Story of How Signalgate Happened

IT Security Guru

In the cybersecurity world, the most sophisticated threats often take a backseat to simple human error. The recent “ Signalgate ” incident involving National Security Adviser Mike Waltz demonstrates how even at the highest levels of government, basic contact management can lead to significant security breaches. The Incident Last month, in what can only be described as a perfect storm of digital mishaps, Waltz inadvertently added Jeffrey Goldberg, editor of The Atlantic, to a Signal g

article thumbnail

This OnePlus tablet handles movies and entertainment better than iPads (it's also on sale)

Zero Day

The OnePlus Pad 2 boasts good hardware, a long-lasting battery, and a brilliant display, making it an affordable multimedia tablet that competes with the best.

73
article thumbnail

NSA Chief Ousted Amid Trump Loyalty Firing Spree

WIRED Threat Level

Plus: Another DOGE operative allegedly has a history in the hacking world, and Donald Trumps national security adviser apparently had way more Signal chats than previously known.

Hacking 111
article thumbnail

The Samsung phone I recommend to most people is not a flagship (and it's on sale)

Zero Day

The Galaxy S24 FE offers all the essentials in a smartphone, and Amazon has dropped the phone's price further by $100.

68
article thumbnail

The Tumultuous IT Landscape Is Making Hiring More Difficult

After a year of sporadic hiring and uncertain investment areas, tech leaders are scrambling to figure out what’s next. This whitepaper reveals how tech leaders are hiring and investing for the future. Download today to learn more!

article thumbnail

Trump Extends TikTok’s U.S. Deadline by 75 Days to Secure American Buyer

Penetration Testing

In addition to the recently announced tariff hikes, the Trump administration has signed a new executive order granting TikTok an additional 75 days to continue operating in the United States, allowing more time to secure a suitable American buyer. Previously, President Trump had indicated that he was considering offering TikTok more time to negotiate a […] The post Trump Extends TikToks U.S.

article thumbnail

I replaced my $3,500 Sony camera with a 200MP Android phone - and the results caught me off guard

Zero Day

When the Xiaomi 15 Ultra launched with its new periscope lens and stacked camera setup earlier this year, I just knew I had to get the device in hand.

59
article thumbnail

I gave away my Kindle and iPad within hours of testing this tablet - and it's easy on the eyes

Zero Day

I've used a Kindle for years, but with the TCL Tab 10 Nxtpaper 5G now on sale, it's become my go-to e-reader tablet (at least until the next model arrives).

49
article thumbnail

Don't ignore this troubling metric that your smart air purifier tracks - here's why

Zero Day

The Levoit Sprout smart air purifiers are designed to actively monitor and improve air quality in the areas that need it most.

45
article thumbnail

The Cloud Development Environment Adoption Report

Cloud Development Environments (CDEs) are changing how software teams work by moving development to the cloud. Our Cloud Development Environment Adoption Report gathers insights from 223 developers and business leaders, uncovering key trends in CDE adoption. With 66% of large organizations already using CDEs, these platforms are quickly becoming essential to modern development practices.

article thumbnail

Apple's cheapest earbuds just got even cheaper thanks to this new deal

Zero Day

Don't let their small size fool you - the Beats Solo Buds deliver big sound and a long battery life. They're currently 25% off at Amazon.

44
article thumbnail

Nintendo Switch 2 preorders delayed: What the US tariffs mean for pricing and availability

Zero Day

Spooked by Trump's new tariffs, Nintendo is pausing console pre-orders in the US. However, the June 5 launch remains unchanged.

57