Security Newsletter

Issue #122 · 29 March 2019

Facebook logged passwords in plaintext. Asus software updates hijacked.

Supported by 1Password.

Sponsorships

News

Breaches and leaks

  • FEMA: exposed personal information of 2.3 million people by needlessly sharing it with a third-party contractor.
  • Family Locator: an app where you can "share your location with your loved ones" had an unsecured MongoDB instance, showing plaintext passwords and the precise locations of over 238.000 people.
  • Another consumer spyware vendor has left a database unsecured full of highly sensitive contents, including over 95.000 images and 25.000 phone recordings: link.

If you are using the Social Warfare plugin or the Easy WP SMTP plugin, you'll want to update quickly. Both are being actively exploited.