Security News

U.S. Sanctions 6 Iranian Officials for Critical Infrastructure Cyber Attacks
2024-02-03 07:33

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) announced sanctions against six officials associated with the Iranian intelligence agency for attacking critical...

Mastodon Vulnerability Allows Hackers to Hijack Any Decentralized Account
2024-02-03 06:51

The decentralized social network Mastodon has disclosed a critical security flaw that enables malicious actors to impersonate and take over any account. "Due to insufficient origin validation in...

AnyDesk Hacked: Popular Remote Desktop Software Mandates Password Reset
2024-02-03 03:55

Remote desktop software maker AnyDesk disclosed on Friday that it suffered a cyber attack that led to a compromise of its production systems. The German company said the incident, which it...

The Week in Ransomware - February 2nd 2024 - No honor among thieves
2024-02-02 23:33

An Ottawa man convicted on charges related to a ransomware attack affecting hundreds of victims was sentenced to two years behind bars on Friday. The number of ransomware victims paying ransom demands has dropped to a record low of 29% in the final quarter of 2023, according to ransomware negotiation firm Coveware.

AnyDesk says hackers breached its production servers, reset passwords
2024-02-02 22:16

AnyDesk confirmed today that it suffered a recent cyberattack that allowed hackers to gain access to the company's production systems. In a statement shared with BleepingComputer late Friday afternoon, AnyDesk says they first learned of the attack after detecting indications of an incident on their product servers.

AnyDesk says hackers breached its production servers, resets passwords
2024-02-02 22:16

AnyDesk confirmed today that it suffered a recent cyberattack that allowed hackers to gain access to the company's production systems. In a statement shared with BleepingComputer, AnyDesk says they first learned of the attack after detecting indications of an incident on their product servers.

Friday Squid Blogging: Illex Squid in Argentina Waters
2024-02-02 22:03

Post on the Friday Squid a topic you would like to see, in the form of a "Starter seed". Many of the threads on this blog can be found to have come from topics raised and talked about in the Friday Squid by many different people.

Blackbaud settles with FTC after that IT breach exposed millions of people's info
2024-02-02 21:12

Blackbaud, which had data on millions of people stolen from it by one or more crooks, has promised to shore up its IT defenses in a proposed deal with the FTC. In announcing the draft settlement, the US watchdog's boss Lina Khan, Commissioner Rebecca Slaughter, and Commissioner Alvaro Bedoya blasted Blackbaud - a cloud software provider for schools, charities, and other orgs - for its "Unfair and deceptive data security practices" in a statement [PDF]. "The FTC charges that Blackbaud's reckless data retention practices rendered its security failures much more costly: by hoarding reams of data that it did not reasonably need, Blackbaud's breach exposed far more data," they said.

David Kahn
2024-02-02 20:06

His groundbreaking book, The Codebreakers was the first serious book I read about codebreaking, and one of the primary reasons I entered this field. Tags: books, cryptanalysis, history of cryptography.

Critical vulnerability in Mastodon is pounced upon by fast-acting admins
2024-02-02 18:32

Mastodon has called admins to action following the disclosure of a critical vulnerability affecting the decentralized social network favored by erstwhile Twitter lovers. "Every Mastodon version prior to 3.5.17 is vulnerable, as well as 4.0.x versions prior to 4.0.13, 4.1.x version prior to 4.1.13, and 4.2.x versions prior to 4.2.5.".