News
Personal note - (early) parental leave and minimal edition
Some fun news I hadn't shared yet: my wife and I are expecting our second daughter to arrive within a month! I've decided to make full use of Articulate's (my employer) generous policies and am taking some pro-active time off to get things in order.
There will be quite a few minimal issues the next few weeks and months, and maybe a week or two around the birth itself where I don't send anything. I hope y'all understand, family-first :-)
Breaches and leaks
- Ransomware takes down network of French IT giant Sopra Steria: link.
- Covid-19 vaccine-maker hit with cyberattack, data breach: link.
- Pharma giant Pfizer leaks customer prescription info, call transcripts: link.
- Georgia election data hit in ransomware attack: link.
- Montreal's STM public transport system hit by ransomware attack: link.
- Kleenheat customer names and addresses exposed in system breach: link.
- Albion Online game maker discloses data breach: link.
- WastedLocker ransomware hits Boyne Resorts ski resort operator: link.
Google reveals the most powerful DDoS attack in history… albeit three years late
2.5 Tbps (Terabits per second), damn. Mirai was "only" 623 Gbps.
NSA: Top 25 vulnerabilities actively abused by Chinese hackers
Also gives you a some sense of why ransomware has it so easy right now.
Ransomware gang donates part of ransom demands to charity organizations
Trying to ease the guilt? PR stunt? Misplaced aim for Robinhood status? Interesting to read nonetheless.
Patch 'em if you got 'em
- New Google Chrome version fixes actively exploited zero-day bug: link.
- Seven mobile browsers vulnerable to address bar spoofing attacks: link.
- Nvidia tackles code execution flaws, data leaks in GeForce Experience: link.
- HPE fixes maximum severity remote auth bypass bug in SSMC console: link.
- Discord desktop app vulnerability chain triggered remote code execution attacks: link.