Hi folks,
I hope you're doing well. We've got a nice balance of interesting articles and plenty of breaches this week :-) Enjoy the read!
Cheers,
Supported by 1Password.
Hi folks,
I hope you're doing well. We've got a nice balance of interesting articles and plenty of breaches this week :-) Enjoy the read!
Cheers,
The Chinese state-sponsored hacker group Salt Typhoon has impacted at least eight telecoms in the US and more in other countries as well, in a campaign that has been going for over two years.
Apparently a manufacturer of satellite receivers from South Korea pre-loaded 240,000 receivers with DDoS attack capabilities, at the request of the (unnamed) client. Building in such capability is illegal, so the manufacturer now had their CEO and five employees arrested, and assets being seized. No mention of what happens to the client. I presume they're from a different country and thus can't be directly charged.
Good to be aware of that pages.dev and workers.dev, which are operated by Cloudflare, are frequently used in phishing attacks because most security applications consider those domains to have a good reputation. Most of the time they are used for hosting legit things, but not always.
Alarm bells are being raised about an increased usage of Chinese-made components for lidar technology, similar to previously raised issues with Huawei and DJI drones.
It's a sponsored post (on bleepingcomputer, not here), but it's actually a great list of things that really should be common knowledge by now but still aren't. Like password length beats complexity rules, password rotation is a bad idea, etc. Easy to share with folks who haven't gotten the memo yet after all these years.
I'm not going to write a long marketing-heavy paragraph on this one. I just love using 1Password. The UX, the support, the integrations, it all works wonderfully. Highly recommended. (Sponsored)