API Security
China Cyberwar Coming? Versa’s Vice: Volt Typhoon’s Target
Richi Jennings | | CenturyLink, china, china espionage, China-linked Hackers, China-nexus cyber attacks, China-nexus cyber espionage, CVE-2024-39717, Lumen, Lumen Technologies, Peoples Republic of China, SB Blogwatch, Versa Director, Versa Neworks, VersaMem, Volt Typhoon
Xi whiz: Versa Networks criticized for swerving the blame ...
Security Boulevard
APIs, Web Applications Under Siege as Attack Surface Expands
Attackers are increasingly targeting web applications and APIs, with a nearly 50% year-over-year growth in web attacks, driven by the increased adoption of these technologies, which significantly expanded organizational attack surfaces, according ...
Security Boulevard
Prisoner Swap: Huge Russian Hackers Freed — Seleznev and Klyushin
Richi Jennings | | cyber attacks russia, Putin, Roman Seleznev, Russia, russia hacker, russia-based, Russian hacker, Russian hackers, Russian hacking, SB Blogwatch, Vladimir Putin, Vladislav Klyushin
Pragmatic politics: Anger as Putin gets back two notorious cybercriminals ...
Security Boulevard
WTH? Google Auth Bug Lets Hackers Login as You
Richi Jennings | | G Suite, Google Apps, Google Apps for Work, Google Workspace, OAuth, oauth 2.0, oauth abuse, Oauth Application Abuse, SB Blogwatch, securing oauth
G Suite Sours: Domain owners flummoxed as strangers get Google for their domains ...
Security Boulevard
PKfail: 800+ Major PC Models have Insecure ‘Secure Boot’
Richi Jennings | | Binarly, BIOS, BIOS update, Certificate and Key Management, hardware supply chain, key management, Key Management Problem, PKfail, Private Key Management, SB Blogwatch, secure boot, UEFI, UEFI Failing, UEFI firmware, UEFI vulnerabilities, Unified Extensible Firmware Interface (UEFI)
Big BIOS bother: Hundreds of PC models from vendors such as HP, Lenovo, Dell, Intel, Acer and Gigabyte shipped with useless boot protection—using private keys that aren’t private ...
Security Boulevard
API Discovery – Common Topics We’re Asked About
This article is the first in a series of six covering key API security topics and provides some answers to common questions we often get when talking to potential customers. This series ...
EFF Angry as Google Keeps 3rd-Party Cookies in Chrome
Richi Jennings | | adtech, Advertising, Advertising and AdTech, adverts, Chrome, CMA, Competition and Markets Authority, cookie, Cookie Consent, cookieconsent, cookies, Data Privacy, EFF, Electronic Frontier Foundation, FLEDGE, FLoC, GOOG, google, Google Chrome, ICO, information commissioner's office, IP Protection, Privacy, Privacy Sandbox, regulatory capture, SB Blogwatch, Surveillance capitalism, Topics, tracking, tracking cookies, web cookie, zero trust
Regulatory capture by stealth? Google changes its mind about third-party tracking cookies—we’re stuck with them for the foreseeable ...
Security Boulevard
API Transformation Cyber Risks and Survival Tactics
As you think about how to ensure your APIs are within your risk tolerance, ensure that you have a sound understanding of your inventory and the data associated with them ...
Security Boulevard
‘Blast-RADIUS’ Critical Bug Blows Up IT Vacation Plans
Richi Jennings | | blast radius, collision-based-hashing-algorithm-disclosure, CVE-2024-3596, hash, hash algorithms, hash function, hash functions, Man In The Middle, man in the middle attack, man in the middle attacks, maninthemiddleattacks, md5 hash, men-in-the-middle attack, mitm, MitM Attack, mitm attacks, RADIUS, SB Blogwatch
MD5 MITM Muddle: Ancient, widely used protocol has CVSS 9.0 vulnerability ...
Security Boulevard
‘Polyfill’ Supply Chain Threat: 4x Worse Than We Thought
Richi Jennings | | App Sec & Supply Chain Security, AppSec & Supply Chain Security, CloudFlare, Funnull, Javascript, Modern Software Supply Chains, Open Source and Software Supply Chain Risks, open source software supply chain, open source software supply chain security, polyfill, SB Blogwatch, secure software supply chain, software supply chain attack, software supply chain attacks, software supply chain hygiene, software supply chain risk, Software Supply Chain risks, Supply-Chain Insecurity
Spackle attack: Chinese company takes over widely used free web service—almost 400,000 websites at risk ...
Security Boulevard