Security Newsletter

Issue #221 · 27 October 2023

Okta breached. Safari iLeakage attack. Security Copilot early access.

Supported by 1Password and GlitchSecure.

News

Hi folks!

The main item this week is Okta's breach. You can tell from my description below that I'm less than impressed with them at the moment. I hope you find the summary, and the rest of the news, interesting at least :-)

Have a good one!

Breaches and leaks

  • European govt email servers hacked using Roundcube zero-day: link.
  • International Criminal Court systems breached for cyber espionage: link.
  • American Family Insurance confirms cyberattack is behind IT outages: link.
  • D.C. Board of Elections: Hackers may have breached entire voter roll: link.
  • City of Philadelphia discloses data breach after five months: link.
  • University of Michigan breached, employee and student data stolen: link.
  • Cyberattack on health services provider impacts 5 Canadian hospitals: link.
  • Philadelphia: Hackers spent three months accessing city gov’t email accounts: link.
  • Seiko says ransomware attack led to leak of 60,000 ‘items’ of personal data: link.
  • US energy firm shares how Akira ransomware hacked its systems: link.

Issues and fixes

  • Critical RCE flaws found in SolarWinds access audit solution: link.
  • Citrix Bleed exploit lets hackers hijack NetScaler accounts: link.
  • Cisco discloses new IOS XE zero-day exploited to deploy malware implant: link.
  • VMWare fixes critical vulnerability: link.