Category: Government
-

Today’s Topics: Google’s €403 Million Fine Shows the Cost of Losing Control of Location Data CMMC Phase II Is Paused, but Defense Contractors Still Have Work to Do How can Netizen help? Google’s €403 Million Fine Shows the Cost of Losing Control of Location Data On September 21, Ireland’s Data Protection Commission fined Google €403…
-

The FBI is investigating claims that the ShinyHunters cybercrime group compromised FBIJobs.gov and obtained a large collection of personnel and applicant information, including records that appear to identify employees working in sensitive intelligence, surveillance, and counterintelligence roles. ShinyHunters says it entered through a previously unknown Oracle PeopleSoft vulnerability and ultimately stole between two and three…
-

Today’s Topics: ScreenConnect Flaw Turns a Trusted Remote Session Into a File Execution Path Cisco ISE Zero-Day Turns an Identity Control Point Into Root Access How can Netizen help? ScreenConnect Flaw Turns a Trusted Remote Session Into a File Execution Path Remote support software already occupies an unusually trusted position inside an enterprise. A technician…
-

Today’s Topics: The Twitch Extension That Sent 31,000 OAuth Tokens Through Its Proxy Network When the Firewall Manager Becomes the Foothold How can Netizen help? The Twitch Extension That Sent 31,000 OAuth Tokens Through Its Proxy Network A browser extension promising better Twitch playback quietly created a much larger security problem. Nearly 31,000 Chrome and…
-

Today’s Topics: PaperCut Zero-Days Turn Trusted Print Servers Into a Pre-Auth RCE Path The ATF Breach Shows Why an Isolated System Can Still Hold High-Consequence Risk How can Netizen help? PaperCut Zero-Days Turn Trusted Print Servers Into a Pre-Auth RCE Path PaperCut entered emergency-response mode in late August after confirming active exploitation against PaperCut NG…
-

SynkLoader is a newly identified modular Windows malware family that turns a simple helpdesk impersonation into a full access chain. The operator can profile a host, create persistence, steal a user’s Windows password, proxy traffic through the infected system, run PowerShell commands, and take remote control of the active desktop. Much of the follow-on code…
-

A threat actor can use legitimate credentials, approved administrative tools, trusted cloud services, and normal network paths without ever dropping an obvious piece of malware. In that kind of intrusion, the audit trail may be the only record showing that legitimate access became malicious activity. Security programs tend to treat audit logging as foundational infrastructure…
-

Classified and regulated environments are often built around stronger access restrictions, tighter configuration management, formal authorization processes, segmented networks, controlled software baselines, and stricter handling requirements than conventional enterprise systems. Those measures can reduce exposure and limit the number of paths available to an attacker, but they do not eliminate the possibility of credential theft,…
-

Today’s Topics: 9,308 Live AWS Keys Expose a Persistent Cloud Identity Problem How a Trusted Update Channel Turned Android Car Head Units Into Proxy Nodes How can Netizen help? 9,308 Live AWS Keys Expose a Persistent Cloud Identity Problem Publicly exposed cloud credentials are often treated as a code hygiene problem: a developer commits a…
-

A single file moved between NIPRNet and SIPRNet can become a classification, authorization, malware, information-flow, and audit event at the same time. For Department of Defense organizations, moving information between the Non-classified Internet Protocol Router Network and the Secret Internet Protocol Router Network is fundamentally different from transferring a file between ordinary enterprise networks. The…