Critical Vulnerability Threatens SSH Security

A groundbreaking attack named “Terrapin” has been uncovered, posing a significant threat to the security of the (SSH) Secure SHell Protocol. SSH, developed nearly 30 years ago to counter password sniffing attacks, is widely used to secure connections in...

SMTP Smuggling ByPasses Email Security Controls

A recently discovered “SMTP smuggling” technique is allowing cyber attackers to sidestep email security protocols like Domain-based Message Authentication, Reporting, and Conformance (DMARC), posing a significant threat to organizations. The method...

Terminated Employee Sabotages Systems

In a case highlighting the importance of removing access upon termination, a disgruntled employee wreaked havoc with his employer’s systems when he was terminated. A former cloud engineer at a bank was terminated for violating company policies, including...

Ubiquiti User Accounts Suffered Data Breach

Ubiquiti users were reporting last week that they were seeing other people’s notification and had access to their devices. The incident was first reported on Reddit, where a user received a notification from UniFi Protect, including an image from someone...

Apple Beta Testing Stolen Device Protection Feature

Apple will soon be introducing a Stolen Device Protection feature which is aimed at enhancing security if an iPhone is stolen, particularly in scenarios where thieves obtain the device passcode. The feature is currently in beta testing and relies on biometrics via...

Over Half of Insider Attacks Involve Privilege Elevation Exploits

Over 50% of insider attacks involve exploiting elevation of privilege flaws. A research study, based on data from January 2021 to April 2023, shows a rise in insider threats, with 55% relying on privilege escalation exploits and the remaining 45% introducing risks by...

Messenger and Facebook to get Default End to End Encryption

In a significant update, Meta has announced the rollout of default end-to-end encryption for personal messages and calls on Messenger and Facebook. This means that private chats and calls across Messenger will now be automatically encrypted by default, enhancing...

5Ghoul Vulnerabilities Affecting Most 5G Smart Phones

A set of 14 security vulnerabilities named “5Ghoul” has been discovered in the firmware implementation of 5G mobile network modems from major chipset vendors like MediaTek and Qualcomm. The flaws impact USB and IoT modems, along with hundreds of smartphone...