Analysis of Leaked AWS Keys in Python Package Index

We’ve been seeing a lot of python related security issues of late, including the leaking of secrets. When python developer Tom Forbes of London heard that Infosys had leaked their AWS keys, he got intrigued. The key that was leaked was not just any AWS key, it...

Slack’s GitHub repository Compromised

Slack recently disclosed that it had a security incident involving unauthorised access to a subset of their code repository. They have observed suspicious activities on their GitHub code repository account, and upon investigation, discovered that a limited number of...

CircleCI security incident immediate actions

CircleCI recently announced that they are investigating a security incident. While they haven’t yet provided any details of the incident or their responses, they have requested two immediate actions to be taken by their customers. The first is to rotate any and all...

Queensland University of Technology suffers Ransomware Attack

The Queensland University of Technology has disclosed that it had suffered a cyberattack. The University had to shut down their IT systems in response and they expect some of those systems to be disrupted for some weeks. Students who are currently enrolled will be...

Google Home Smart Speaker Wiretap vulnerability

Matt from down right niffy dot me recently released an article detailing how he discovered an interesting vulnerability in Google’s Home smart speaker. He discovered that you can link a google account to a smart speaker without any authentication. The vulnerability...