/
Navigation
C
Chronicles
Browse all articles
C
E
Explore
Semantic exploration
E
R
Research
Entity momentum
R
N
Nexus
Correlations & relationships
N
~
Story Arc
Topic evolution
S
Drift Map
Semantic trajectory animation
D
P
Posts
Analysis & commentary
P
Browse
@
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
?
Concept Search
Semantic similarity search
!
High Impact Stories
Top coverage by position
+
Sentiment Analysis
Positive/negative coverage
*
Anomaly Detection
Unusual coverage patterns
Analysis
vs
Rivalry Report
Compare two entities head-to-head
/\
Semantic Pivots
Narrative discontinuities
!!
Crisis Response
Event recovery patterns
Connected
Nav: C E R N
Search: /
Command: ⌘K
Embeddings: large
VOICE ARCHIVE

Sean Wright

@seanwrightsec
30 posts
2024-02-12
Still trying to find an answer, has there been any confirmed case of a Flipper Zero being use to steal a car?
2024-02-12 View on X
Gizmodo

A Canadian minister says the government plans to ban devices that copy wireless signals for remote keyless entry, like the Flipper Zero, to combat auto theft

2024-02-11
Still trying to find an answer, has there been any confirmed case of a Flipper Zero being use to steal a car?
2024-02-11 View on X
Gizmodo

A Canadian minister says the government plans to ban devices that copy wireless signals for remote keyless entry, like the Flipper Zero, to combat auto theft

🤨  —  https://www.bleepingcomputer.com/ ...  #security #pentesting #flipperzero #canada Matti Aleve / @maleve@zeroes.ca : Sigh where to even begin with this.  —  The subhead pretty...

2023-11-09
If you are running Confluence on-prem and haven't already updated, drop what you doing and update ASAP. This is a really nasty one, especially if you have this publicly exposed. https://www.theregister.com/ ...
2023-11-09 View on X
The Register

Atlassian raises the severity rating of a vulnerability in its Confluence Data Center and Server to maximum, and confirms the flaw is being actively exploited

Connor Jones / The Register :

2023-10-22
Looks like it took Okta over a week to respond in any meaningful way. That's quite concerning if that was the case!
2023-10-22 View on X
CNBC

Okta's stock closed down 11.57% on October 20 after the cybersecurity firm said a hacker used a stolen credential to access its support system and client files

- Cybersecurity firm Okta said an unidentified hacker had accessed the company's support system and viewed client files.

2023-10-21
Looks like it took Okta over a week to respond in any meaningful way. That's quite concerning if that was the case!
2023-10-21 View on X
CNBC

Okta's stock closes down 11.57% after the cybersecurity company said a hacker accessed its support system using a stolen credential and viewed client files

- Cybersecurity firm Okta said an unidentified hacker had accessed the company's support system and viewed client files.

2023-06-15
Always make sure that you review what you install and run! Don't just blindly run something. https://twitter.com/...
2023-06-15 View on X
BleepingComputer

Some hackers are impersonating cybersecurity researchers on Twitter and GitHub to post fake zero-day proof-of-concept exploits that push Windows/Linux malware

Hackers are impersonating cybersecurity researchers on Twitter and GitHub to publish fake proof-of-concept exploits for zero …

2023-03-27
I agree, most social media apps are all pretty much the same. So if you going to ban one then you should ban them all! https://twitter.com/...
2023-03-27 View on X
The Register

The French government bans TikTok and all other recreational apps from staff phones, claiming none have sufficiently robust security for government devices

Meanwhile the US contemplates drastic action  —  The government of France has banned TikTok - and all other recreational apps - from phones issued to its employees.

2023-03-16
Just to clarify, I meant if you using O365 service. If you still connecting to any non-0365 service (e.g. on prem exchange) then the client is still vulnerable. And regardless of which version you using, I'd still recommend patching. https://twitter.com/...
2023-03-16 View on X
BleepingComputer

Microsoft patches an Outlook zero-day, exploitable without user interaction, and says Russian hackers used the flaw to target European organizations in 2022

Sergiu Gatlan / BleepingComputer :

2023-02-28
A good example why allowing home devices without appropriate controls in place could cause potential issues: https://www.securityweek.com/ ... And by controls I mean things that allow you to enforce minimum requirements (such as OS patching, end point protection, etc).
2023-02-28 View on X
BleepingComputer

LastPass says hackers stole password vault data in 2022 by exploiting an RCE flaw in third-party software to install a keylogger on a DevOps engineer's computer

LastPass revealed more information on a “coordinated second attack,” where a threat actor accessed and stole data …

2023-02-18
Next big company to suffer a breach and have its source code stolen. Also worth noting they knew about this at the beginning of December last year and only informing about it now! https://www.bleepingcomputer.com/ ...
2023-02-18 View on X
BleepingComputer

GoDaddy discovered a multiyear security breach in early December 2022 in which unknown attackers stole some source code and installed malware on its servers

Web hosting giant GoDaddy says they suffered a breach where unknown attackers have stolen source code and installed malware …

2023-02-03
Remember this story? Well it looks like the law final caught up to the former dev! And rightly so. https://twitter.com/...
2023-02-03 View on X
BleepingComputer

A former employee of IoT manufacturer Ubiquiti pleaded guilty to stealing gigabytes of confidential data in December 2020 and extorting the company for ransom

Nickolas Sharp, a former Ubiquiti employee who managed the networking device maker's cloud team, pled guilty today …

2023-01-19
Unfortunately a second time for Mailchimp, again a social engineering attack targeting an employee or contractor. This now appears to be a really common and lucrative approach for attackers! https://techcrunch.com/...
2023-01-19 View on X
TechCrunch

Mailchimp says a hacker accessed data on 133 accounts via a staff social engineering attack, first detected on January 11, its second breach in six months

Email marketing and newsletter giant Mailchimp says it was hacked and that dozens of customers' data was exposed.

2022-12-24
The LastPass incident is big news. But not for the reason why folk may think. We have a difficult time convincing folk to use password managers. This is most likely to harm that effort, sowing doubt with those who are a bit hesitant about doing so.
2022-12-24 View on X
TechCrunch

LastPass says hackers stole a backup copy of users' encrypted and unencrypted vault data using cloud storage keys stolen from a LastPass employee in August 2022

If you have a LastPass account you should have received … Camila Foster / Sammy Fans : Samsung fans using LastPass should know, hackers stolen cloud data Fabian A. Scherschel / The...

2022-12-23
The LastPass incident is big news. But not for the reason why folk may think. We have a difficult time convincing folk to use password managers. This is most likely to harm that effort, sowing doubt with those who are a bit hesitant about doing so.
2022-12-23 View on X
TechCrunch

LastPass says hackers stole a backup copy of users' encrypted and unencrypted vault data using cloud storage keys stolen from a LastPass employee in August 2022

Password manager giant LastPass has confirmed that cybercriminals stole its customers' encrypted password vaults …

2022-12-21
Not been a good year for Okta! https://twitter.com/...
2022-12-21 View on X
BleepingComputer

Okta tells customers its GitHub repositories were hacked this month and its source code was stolen, but says hackers did not access service or customer data

Okta, a leading provider of authentication services and Identity and Access Management (IAM) solutions, says that its private GitHub …

2022-12-08
This is great news. It might even help drive adoption perhaps? https://9to5mac.com/...
2022-12-08 View on X
Wall Street Journal

Apple plans to launch Advanced Data Protection, offering E2EE on iCloud backups, Notes, Photos, and more, in the US in 2022 and globally including China in 2023

‘Advanced Data Protection’ will offer end-to-end encryption on iCloud backups, Notes, Photos and other services—a step that may draw ire from law enforcement

This is great news. It might even help drive adoption perhaps? https://9to5mac.com/...
2022-12-08 View on X
9to5Mac

Apple announces an iMessage feature letting users “verify they are messaging only with the people they intend” and Apple ID support for hardware security keys

Chance Miller / 9to5Mac :

2022-11-04
Updates are one of the most difficult but relatively easy challenges to solve. This is why MDM is so important for corporate devices and effective barriers for BYOD devices (such as minimum patch versions). https://www.bleepingcomputer.com/ ...
2022-11-04 View on X
BleepingComputer

Lookout: almost 50% of Android phones used by US state and local government staff run outdated versions of the OS, exposing them to hundreds of vulnerabilities

Bill Toulas / BleepingComputer :

2022-11-02
Orgs really need to start liking at giving their employees appropriate tooling when it comes to account authentication. Password managers, encouraging (and in some cases enforcing) MFA, and in higher privileged accounts hardware tokens. https://twitter.com/...
2022-11-02 View on X
BleepingComputer

Dropbox says hackers stole code and some API keys from 130 GitHub repositories via a phishing campaign, but its core apps and infrastructure were unaffected

Sergiu Gatlan / BleepingComputer :

2022-09-17
Kudos to LastPass for being upfront about this. My only criticism is I wonder why it took them 2 weeks to fess up though. https://twitter.com/...
2022-09-17 View on X
BleepingComputer

LastPass says a hacker had access to its systems for four days in August 2022 but there is no evidence they accessed customer data or encrypted password vaults

LastPass says the attacker behind the August security breach had internal access to the company's systems for four days until they were detected and evicted.