News

Hi folks,

It has been a while :-)

After the last issue I took some more time for myself. Not all for bad reasons though, in fact life is pretty sweet right now. My family is doing great, we're settling into the new house, and I went ahead and started a non-profit!

It's still early days, there's barely even a website, but I'm having so much fun. I haven't felt this driven and motivated in a long while, and it feels goood :-)

It's essentially a non-profit digital engineering company, where we focus on reliable, robust software for critical infrastructure and (real-world) incident response. It's exciting and maybe a little over-ambitious, but I've got a couple of projects going, and am even starting to pull in some help! We'll see where it goes :-) More to come later, I'm sure, but I won't drag this out for now.

I'm not sure what the frequency of securitynewsletter.co will be for the foreseeable future. I'll probably send, well, when I feel like it. Which I've only recently learned how much of a privilege that is, indeed.

I've gathered the news below that stood out to me from the last few weeks and months. As always, I hope you get value out of it.

Thank you for reading, thank you for waiting, and as always, thank you to 1Password for their support.

Cheers to all,

Dieter








And some more news, but shorter:

  • Chinese state attackers going after Dell zero-day since mid-2024: link.
  • Aisuru botnet sets new record with 31.4 Tbps DDoS attack: link.
  • Critical n8n flaws disclosed along with public exploits: link.
  • CISA seeks infrastructure sector consultation on incident reporting rule: link.
  • Majority of Ivanti EPMM threat activity linked to hidden IP: link.

Some noteworthy breaches

  • Have I Been Pwned: SoundCloud data breach impacts 29.8 million accounts: link.
  • Newsletter platform Substack notifies users of data breach: link.
  • European Commission discloses breach that exposed staff data: link.
  • Hackers access Odido customer info, 6.2 million hit: link.