Security News

Slack admits to leaking hashed passwords for five years
2022-08-08 18:14

Popular collaboration tool Slack has just owned up to a cybersecurity SNAFU. According to a news bulletin entitled Notice about Slack password resets, the company admitted that it had inadvertently been oversharing personal data "When users created or revoked a shared invitation link for their workspace." Slack's security advisory doesn't explain the breach very clearly, saying merely that "[t]his hashed password was not visible to any Slack clients; discovering it required actively monitoring encrypted network traffic coming from Slack's servers.

Slack leaked hashed passwords from its servers for years
2022-08-08 11:45

Did Slack send you a password reset link last week? The company has admitted to accidentally exposing the hashed passwords of workspace users. Slack said only 0.5 percent of users were affected, which doesn't sound too terrible until you consider how many Slack users are out there.

Slack Resets Passwords After a Bug Exposed Hashed Passwords for Some Users
2022-08-06 08:44

Slack said it took the step of resetting passwords for about 0.5% of its users after a flaw exposed salted password hashes when creating or revoking shared invitation links for workspaces. "When a user performed either of these actions, Slack transmitted a hashed version of their password to other workspace members," the enterprise communication and collaboration platform said in an alert on 4th August.

Slack resets passwords after exposing hashes in invitation links
2022-08-05 17:44

Slack notified roughly 0.5% of its users that it reset their passwords after fixing a bug exposing salted password hashes when creating or revoking shared invitation links for workspaces. Luckily, the hashed passwords were not visible to Slack clients, with active monitoring of encrypted network traffic from Slack's servers required to access this exposed information, according to Slack.

How to prepare your organization for a Slack or Office 365 breach
2022-07-18 04:30

Whether it's Slack or Office 365, communication and workflow apps are an essential tool for organizations to collaborate efficiently regardless of geography. Using any of these as a primary communication channel, replacing email and knowledge management repositories, makes it a new target to exploit that contains sensitive information.

Major services including Slack, AWS, Hulu, Imgur facing outages
2021-12-22 13:24

Major services across the internet are currently facing ongoing networking outages. "We are experiencing issues with file uploads, message editing, and other services. We're currently investigating the issue and will provide a status update once we have more information," Slack has confirmed, with its status page continuing to show further disruptions.

State-sponsored hackers abuse Slack API to steal airline data
2021-12-15 17:32

A suspected Iranian state-supported threat actor is deploying a newly discovered backdoor named 'Aclip' that abuses the Slack API for covert communications. Slack is an ideal platform for concealing malicious communications as the data can blend well with regular business traffic due to its widespread deployment in the enterprise.

Slack is down, massive outage blocks user logins and messages
2021-05-20 17:49

Slack is experiencing a worldwide outage preventing users from posting messages, uploading images, or connecting to their servers. May 20, 5:27 PM UTC. Some users may be experiencing issues loading Slack.

A New Slack channel for Cybersecurity Leaders Outside of the Fortune 2000
2021-04-30 03:44

Chris Roberts, Chief Security Strategist at Cynet Security, offers a new Slack-based community for InfoSec leaders as a solution. The new InfoSec Leaders Community will feature several channels and will offer security leaders and decision-makers a fresh opportunity to both get advice and new knowledge and share it with others.

BazarLoader Malware Abuses Slack, BaseCamp Clouds
2021-04-16 20:27

The BazarLoader malware is leveraging worker trust in collaboration tools like Slack and BaseCamp, in email messages with links to malware payloads, researchers said. It's been recently seen being used as a staging malware for ransomware, particularly Ryuk.