Security News > 2023 > October

Hacking Gas Pumps via Bluetooth
2023-10-03 11:01

Turns out pumps at gas stations are controlled via Bluetooth, and that the connections are insecure. No details in the article, but it seems that it's easy to take control of the pump and have it dispense gas without requiring payment.

Browse Safer and Faster Around the World with JellyVPN — Now Just $34.99
2023-10-03 10:02

Browse Safer and Faster Around the World with JellyVPN - Now Just $34.99 This high-speed, unlimited VPN offers quality connections all over the globe. Beyond keeping your network traffic secure, VPNs like JellyVPN are great for keeping you connected and entertained while you're traveling abroad. Right now, you can snag a lifetime subscription for just $34.99 - a huge saving on its regular price of $329. JellyVPN has been serving customers for more than a decade.

Researcher Reveals New Techniques to Bypass Cloudflare's Firewall and DDoS Protection
2023-10-03 09:29

Firewall and distributed denial-of-service (DDoS) attack prevention mechanisms in Cloudflare can be circumvented by exploiting gaps in cross-tenant security controls, defeating the very purpose of...

Evolving conversations: Cybersecurity as a business risk
2023-10-03 05:00

Considering the above, this article examines the current relationship between the CISO and the rest of the board and best practices for navigating conversations with the board when discussing cybersecurity priorities. Frequent collaboration between the CISO and the rest of the board is vital to building trust and rapport as it guarantees that relevant cybersecurity concerns are being brought up with the right people and being addressed in a timely manner.

Arm Issues Patch for Mali GPU Kernel Driver Vulnerability Amidst Ongoing Exploitation
2023-10-03 04:58

Arm has released security patches to contain a security flaw in the Mali GPU Kernel Driver that has come under active exploitation in the wild. Tracked as CVE-2023-4211, the shortcoming impacts...

CISO’s compass: Mastering tech, inspiring teams, and confronting risk
2023-10-03 04:30

In this Help Net Security interview, Okey Obudulu, CISO at Skillsoft, talks about the increasing complexity of the CISO role and challenges they face. With the increasing complexity of the CISO role, what are the top three challenges you believe they face, and how can they best address these?

GenAI in software surges despite risks
2023-10-03 04:00

In this Help Net Security video, Ilkka Turunen, Field CTO at Sonatype, discusses how generative AI influences and impacts software engineers' work and the software development lifecycle. According to a recent Sonatype survey of 800 developers and application security leaders, 97% are using the technology today, with 74% reporting pressure to use it despite identified security risks.

Chalk: Open-source software security and infrastructure visibility tool
2023-10-03 03:30

Chalk is a free, open-source tool that helps improve software security. You add a single line to your build script, and it will automatically collect and inject metadata into every build artifact: source code, binaries, and containers.

Barriers preventing organizations from DevOps automation
2023-10-03 03:00

Organizations prioritize DevOps automation investments. The biggest barriers preventing organizations from automating new DevOps use cases are security concerns, difficulty operationalizing data, and toolchain complexity.

Co-founder of collapsed crypto biz Three Arrows cuffed at airport
2023-10-03 01:30

Asia in brief Zhu Su, co-founder of fallen crypto business Three Arrows Capital, was arrested last Friday at Changi Airport in Singapore as he attempted to leave the country. Zhu is expected to spend four months in jail for failing to comply with investigations into his ill-fated company, according to the 3AC's liquidators, consultancy firm Teneo.