Security News > 2023 > March

Hackers earn $1,035,000 for 27 zero-days exploited at Pwn2Own Vancouver
2023-03-27 15:23

Pwn2Own Vancouver 2023 has ended with contestants earning $1,035,000 and a Tesla Model 3 car for 27 zero-day exploited between March 22 and 24. The total prize pool for Pwn2Own Vancouver 2023 was over $1,000,000 in cash and a Tesla Model 3, which Team Synacktiv won.

20-Year-Old BreachForums Founder Faces Up to 5 Years in Prison
2023-03-27 15:18

Conor Brian Fitzpatrick, the 20-year-old founder and the administrator of the now-defunct BreachForums has been formally charged in the U.S. with conspiracy to commit access device fraud. If proven guilty, Fitzpatrick, who went by the online moniker "Pompompurin," faces a maximum penalty of up to five years in prison.

Twitter takes down source code leaked online, hunts for downloaders
2023-03-27 14:55

Twitter has taken down internal source code for its platform and tools that was leaked on GitHub for months.On Friday, GitHub complied with a DMCA infringement notice issued by Twitter because the leak exposed proprietary source code and internal tools, which could pose a security risk to Twitter.

Hiring kit: Cybersecurity engineer
2023-03-27 12:00

PURPOSERecruiting a cybersecurity engineer with the right combination of technical and industry experience will require a comprehensive screening process. This hiring kit from TechRepublic Premium provides a flexible framework your business can use to find, recruit and ultimately hire the right person for the job.

BEC scammers are after physical goods, the FBI warns
2023-03-27 11:59

BEC attacks are usually aimed at stealing money or valuable information, but the FBI warns that BEC scammers are increasingly trying to get their hands on physical goods such as construction materials, agricultural supplies, computer technology hardware, and solar energy products. In 2022, the FBI also warned of a BEC scheme aiming to steal shipments of food products and ingredients.

A bug revealed ChatGPT users’ chat history, personal and billing data
2023-03-27 11:41

Not only were some ChatGPT users able to see what other users have been using the AI chatbot for, but limited personal and billing information ended up getting revealed, as well.ChatGPT suffered an outage on March 20 and then problems with making conversation history accessible to users.

Gone in 120 seconds: Tesla Model 3 child's play for hackers
2023-03-27 11:32

In brief A team of hackers from French security shop Synacktiv have won $100,000 and a Tesla Model 3 after subverting the Muskmobile's entertainment system, and from there opening up the car's core management systems. In the US, the Office of Inspector General of General Services Administration, issued a redacted report [PDF] earlier this month that found the government agency had misled its customers and other government agencies by telling them that Login.

Hacks at Pwn2Own Vancouver 2023
2023-03-27 11:03

On the first day of Pwn2Own Vancouver 2023, security researchers successfully demoed Tesla Model 3, Windows 11, and macOS zero-day exploits and exploit chains to win $375,000 and a Tesla Model 3. The first to fall was Adobe Reader in the enterprise applications category after Haboob SA's Abdul Aziz Hariri used an exploit chain targeting a 6-bug logic chain abusing multiple failed patches which escaped the sandbox and bypassed a banned API list on macOS to earn $50,000.

Where SSO Falls Short in Protecting SaaS
2023-03-27 10:56

While SSO is an important step in securing SaaS apps and their data, having just SSOs in place to secure the SaaS stack in its entirety is not enough. SSO alone won't prevent a threat actor from accessing a SaaS app.

New MacStealer macOS Malware Steals iCloud Keychain Data and Passwords
2023-03-27 10:38

A new information-stealing malware has set its sights on Apple's macOS operating system to siphon sensitive information from compromised devices. First advertised on online hacking forums at the start of the month, it is still a work in progress, with the malware authors planning to add features to capture data from Apple's Safari browser and the Notes app.