(x) Blogwatch—not a bot, nor a parody
@xBlogwatch
Followers
73
Following
2K
Media
0
Statuses
1K
Foolish columns for @SecurityBlvd @ReversingLabs: @RiCHi curates the best bloggy bits, finest forums, and weirdest websites—a/k/a OTOH. Also @DevOpsDotCom’s TLV
Formerly Computerworld, Forbes
Joined August 2016
Former head of #L3Harris’s #Trenchant “offensive cyber” division has admitted to stealing a weapons-grade exploit chain worth $35M and selling it for personal gain. Company’s not on trial, but the feds charged #PeterWilliams last week—and this week he’s decided to ’fess up:
So long and thanks for all the fish: Admits to selling unpatched bugs to a shady Russian broker. Raises important questions about national security risks. In #SBBlogwatch, we go out with a whimper. @TheFuturumGroup @TechstrongGroup @SecurityBlvd: https://t.co/ysHaEKC8Yw $LHX
0
1
2
As we discussed earlier this year, organized crime groups are using slaves to scam people from massive “pig butchering” factories. One notorious center for the grotesquely evil practice is Myanmar.
Low Earth Pork: #PigButchering scammers in #Myanmar lose use of 2,500 Starlink terminals. #SpaceX is crowing about how it’s blocked the scammers’ use. In #SBBlogwatch, we wonder what took Elon so long. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
#Microsoft’s #Windows security update rollup is badly buggy this month. Post-patch, the #WinRE recovery environment doesn’t work with most keyboards and mice. And a fix for a cryptography bypass bug is causing failures, requiring rollbacks or registry edits to resolve.
Satya fiddles while Redmond burns? Bugs with security certs—plus failing USB keyboards and mice—cause QA questions. Leads to concerns about #Windows dev process. In #SBBlogwatch, we grab a Linux ISO. @TheFuturumGroup @TechstrongGroup @SecurityBlvd: https://t.co/QtwrLRY3jp $MSFT
0
1
1
Anything any #Android app can display is vulnerable to the #Pixnapping attack—including #2FA codes. That’s the worrying claim from a group of researchers this week. “It’s like Rowhammer, but for the screen,” quips one wag:
If at first you don’t succeed: Researchers discover a new way to steal secrets from #Android apps: #Pixnapping $GOOG thought it fixed the flaw. But group’s demo says not. In #SBBlogwatch, we blur the pels. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
#Redis (Remote Dictionary Server) and its open source fork #Valkey share a scary flaw that can give an attacker full remote code execution. It’s been assigned a maximum CVSS score of 10.0—which is something you don’t often see.
Redis hell: CVSS 10.0 vulnerability in ubiquitous cloud storage layer. PATCH NOW. #Redis shouldn’t normally be exposed to the internet, but it often is. In #SBBlogwatch, we descend a layer. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
0
0
#Japan’s biggest producer of beer is still not producing any beer this week. #Asahi Group Holdings shut down production Monday after detecting a cyber intruder.
金のうんこ! Breaking: Big #beer brewer belatedly believes bitten by ransomware—and likely a data breach. Today #Asahi confirmed fears of #ransomware. In #SBBlogwatch, we dry out. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
The #Akira #ransomware gang have found a way to override the multifactor authentication in #SonicWall SSL VPN appliances. These scrotes appear to be able to move laterally from the VPN boxes to deploy ransomware.
Strange factors: Yet another security problem plaguing #SonicWall customers. It’s worrying that #ransomware scrotes have broken SonicWall’s #2FA. In #SBBlogwatch, we hear customers’ anger. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
Iconic British brand today warned its business would stay stalled for even longer. And a loose confederation of threat actors, now calling itself Scattered Lapsus$ Hunters, has claimed responsibility for hacking the big car firm—via tedious Telegram trolling:
#JLR vs. SLH: #JaguarLandRover woes worse than previously thought. Yes, it’s those Salesforce vish kiddies again. In #SBBlogwatch, we drive the point home. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
U.S. senator #RonWyden (pictured) is demanding the #FTC do something about #Microsoft $MSFT already. He says Satya’s crew are to blame for some awful #ransomware attacks exploiting a vulnerability that’s more than 10 years old:
Roasting Redmond for #Kerberoasting: “Like an arsonist selling firefighting services,” quips 76-year-old. Exploit affects #ActiveDirectory with old specs. In #SBBlogwatch, we wonder where to point fingers. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
A pair of ethical hackers discovered a bunch of “catastrophic” vulns in the code running 30,000 #BurgerKing, #TimHortons, #Popeyes and #FirehouseSubs locations. Owner #RBI quickly fixed the flaws, but then its contractor #Cyble issued a sus-seeming #DMCA takedown notice:
#StreisandEffect in full effect: #RBI platform riddled with terrible #security flaws. Tale as old as time: Poor, unfortunate $8½B corp vs. evil, vindictive, millennial hackers. In #SBBlogwatch, we rule. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
Four weeks ago, #Google admitted it was hacked by #ShinyHunters and/or #ScatteredSpider—via #vishing. Sadly, this sparked a journalistic game of Telephone: Over the space of four weeks, “This #Salesforce instance got vished,” quickly became, “2.5 billion #Gmail users hacked!!1!”
Summer’s lease hath all too short a date: Let’s ask Ian Betteridge. “2.5B #Gmail users hacked!!1!” Sigh. “This is entirely false,” complains Google. In #SBBlogwatch, we bait for clicks during dog days. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
4
A subsidiary of @Zurich Insurance $ZURN admitted to a huge leak: More than one million customers’ data. #FarmersGroup is the latest corporation ’fessing up to its data going AWOL via #Salesforce vishing:
#ShinyHunters Hunt Again: #ScatteredSpider claims another #Salesforce instance—albeit three months ago. In #SBBlogwatch, we wonder what #FarmersGroup’s Swiss masters will think. $ZURN @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
Chinese web users couldn’t access websites outside the People’s Republic yesterday. The outage lasted an hour and a quarter—with no explanation. Nobody’s sure whether it was a mistake or an ominous test of new #censorship capabilities:
Xi Whiz: #HTTPS connections on port 443 received forged replies. Some are linking it to a recent outage in #Pakistan. In #SBBlogwatch, we shave with Hanlon’s razor. @TheFuturumGroup @TechstrongGroup @SecurityBlvd: https://t.co/sv0fX9bSJc
#GreatFirewall #China #censorship
0
1
1
The U.S. administration is celebrating a “mutually beneficial understanding” with the #UK, meaning #Apple won’t need to backdoor #iCloud. National intelligence director Tulsi Gabbard and White House veep JD Vance seem happy about it, anyway.
#ADP #E2EE vs. UK: Brits agree to change course, but Tim still shtum. However, it’s not entirely clear that anything’s really changed. In #SBBlogwatch, we doctor the spin. @TheFuturumGroup @TechstrongGroup @SecurityBlvd: https://t.co/DzGoIMI1u5 $AAPL #Apple #iCloud
0
1
1
At least 35 data brokers employed #DarkPatterns to discourage #Californians from exercising their privacy rights. Researchers say the companies hid legally required web pages from #Google—so people can’t find them:
Privacy rights crushed by robots.txt: @SenatorHassan on the warpath. She accuses them of “requiring people to navigate byzantine labyrinths.” In #SBBlogwatch, we share her trisyllabic dissatisfaction. @TheFuturumGroup @TechstrongGroup @SecurityBlvd
https://t.co/g6tZyRoJMl
#CCPA
0
2
2
Venerable file compression-cum-archiving tool suffers yet another exploited vulnerability, causing the sole developer to issue a patch. Is it time to ditch WinRAR? Yes! Here’s why:
Zero day—zero clue: Old, buggy app relies on you to go look for update files. Eugene Roshal (pictured) doesn’t believe in automatic updates. In #SBBlogwatch, we can’t believe it’s still like that in 2025. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
This week, #Google finally admitted it got socially engineered—leading to a breach of #CRM data. Yes, you read that right: Google got vished. Do the scrotes have your info? We don’t know and Google’s not saying.
$GOOG CRM PII AWOL: #ShinyHunters group stole a load of customer data from a #Salesforce cloud instance. What’s worse: It was MONTHS ago. In #SBBlogwatch, we wonder why it took #Google so long to tell us. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
The company behind the #Bee bracelet is being bought by #Amazon. Think of it as Copilot+ Recall for the real world. It seems like Jeff Bezos (pictured) just can’t get enough of knowing everything about you and your life.
Amazzon Beee Buzzzz: It records everything you say (and what people around you say, too). Naturally, this raises a ton of privacy questions. In #SBBlogwatch, we have more questions than answers. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
2
All Your #UAVs Are Belong to UKR: #Gaskar Group, #Russian designer of drones plaguing #Ukraine’s skies, is in utter disarray. Or, at least, so says Ukrainian military intelligence.
#UkrainianCyberAlliance and #BlackOwl hack maker of #Russian military #drones. Hackers steal and delete 57TB critical data, preventing company from operating. In #SBBlogwatch, we peer through fog of war. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
1
Freight trains in the U.S. use a radio link between front and rear, designed around 40 years ago. It’s emerged that the Flashing Rear End Device (#FRED) can be told to slam on the brakes via an extremely weak wireless protocol.
AAR vs. CISA: #Railroad industry first warned about this nasty vuln in 2005. Latest researcher to signal problem says, “You could shutdown the entire rail system.” In #SBBlogwatch, we get to the points. @TheFuturumGroup @TechstrongGroup @SecurityBlvd:
0
1
2