Enterprises can use CIS RAM v2.1 for IG3 to demonstrate that a risk is reasonable upon experiencing a breach.
Monthly Archives: May 2022
Pro-Russian Hackers Hit Critical Government Websites in Italy
Hacker group Killnet has targeted approximately 50 Italian institutions, including the council of judiciary
Bank refuses to pay ransom to hackers, sends dick pics instead
I’m not sure if it would be enough for me to switch bank accounts, but I have something of a sneaking respect for the Bank of Zambia…
CVE-2021-30028
SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.
DoJ: White Hat Hackers Will No Longer Face Prosecution
rubygem-git-1.3.0-2.el7
FEDORA-EPEL-2022-d1317f7176
Packages in this update:
rubygem-git-1.3.0-2.el7
Update description:
Security fix for CVE-2022-25648
rubygem-git-1.11.0-1.el8
FEDORA-EPEL-2022-81ce78cd62
Packages in this update:
rubygem-git-1.11.0-1.el8
Update description:
Security fix for CVE-2022-25648
Bluetooth Flaw Allows Remote Unlocking of Digital Locks
Locks that use Bluetooth Low Energy to authenticate keys are vulnerable to remote unlocking. The research focused on Teslas, but the exploit is generalizable.
In a video shared with Reuters, NCC Group researcher Sultan Qasim Khan was able to open and then drive a Tesla using a small relay device attached to a laptop which bridged a large gap between the Tesla and the Tesla owner’s phone.
“This proves that any product relying on a trusted BLE connection is vulnerable to attacks even from the other side of the world,” the UK-based firm said in a statement, referring to the Bluetooth Low Energy (BLE) protocol—technology used in millions of cars and smart locks which automatically open when in close proximity to an authorised device.
Although Khan demonstrated the hack on a 2021 Tesla Model Y, NCC Group said any smart locks using BLE technology, including residential smart locks, could be unlocked in the same way.
Another news article.
Modern “Smart” Farm Machinery Vulnerable to Cyber-Attackers
A new report warns hackers could exploit flaws in agricultural hardware used to plant and harvest crops
UK Sextortion Cases Doubled in 2021
The UK’s Revenge Porn Helpline received 1124 reports of sextortion last year, compared to 593 in 2020