Oddbean new post about | logout

Notes by 41c7b836 | export

 Sony confirms data breach that affects 6800 former employees & their family members. It appears to be another breach involving the MoveIt managed file transfer solution.

https://www.bleepingcomputer.com/news/security/sony-confirms-data-breach-impacting-thousands-in-the-us/

#infosec #cybersecurity #Sony #databreach #MoveIt #Cl0p 
 New "Looney Tunables" bug allows attackers to gain root access to major Linux distros due to a vulnerability found in the GLIBC_TUNABLES environment variable.

https://www.bleepingcomputer.com/news/security/new-looney-tunables-linux-bug-gives-root-on-major-distros/

#infosec #cybersecurity #Linux #LooneyTunables #vulnerability #CVE_2023_4911 
 Wow, #Pixel8 will come with 7 years of guaranteed OS, security & feature drop updates through to 2030. Turns out the rumours are true. Hope this pushes other manufacturers to follow suit.

#GooglePixel 
 nostr:npub1fq0gfrhyl3lk8z3vpxkupqu77andnsxt7rjvuhzl064vk0h0m65svx6t28 What is not clear is why Te... 
 @663e5b60 Interesting, just looked into this further in Microsoft's own guidance here: https://msrc.microsoft.com/blog/2023/10/microsofts-response-to-open-source-vulnerabilities-cve-2023-4863-and-cve-2023-5217/

It does indeed list Edge as the only product patched, maybe Microsoft uses their own VP codec for their video conferencing products & not the open source libvpx codec? 
 Looks like Microsoft has released patches against CVE-2023-4863 and CVE-2023-5217 vulnerabilities for Microsoft Edge, Teams and Skype. The patches revolve around the vulnerable the libvpx & libwebp open source libraries used by these products. Update now!

https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-teams-get-fixes-for-zero-days-in-open-source-libraries/

#infosec #cybersecurity #Microsoft #Edge #Skype #MSTeams #patchnow #CVE_2023_4863 #CVE_2023_5217 
 Looks like Microsoft has released patches for CVE-2023-4863 and CVE-2023-5217. Update now!

https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-teams-get-fixes-for-zero-days-in-open-source-libraries/

#infosec #cybersecurity #Microsoft #Edge #Skype #MSTeams #patchnow #CVE_2023_4863 #CVE_2023_5217 
 Looks like Microsoft has released patches for CVE-2023-4863 and CVE-2023-5217. Update now!

https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-teams-get-fixes-for-zero-days-in-open-source-libraries/

#infosec #cybersecurity #Microsoft #Edge #Skype #MSTeams #patchnow 
 nostr:npub1vcl9kcqwwsk536z8s4h6k48qrfkm7mahzrk5mz0v04j94507d20s6hk6t3 nostr:npub1hyp0snlqyw66uwue... 
 @eb1cf42f @f7c84b7b @b902f84f 

Ya definitely needs to be updated, have a feeling that Microsoft is focusing the Teams 2.0 launch so they haven't updated the Electron version underneath... though still not sure why they're using an Electron version that's a year old by now...

Hopefully they'll update it soon due to this vulnerability.

https://media.infosec.town/media/72cd92dc-4991-463c-ae69-8590e220677f.png 
 The Better Outcomes Registry & Network (BORN), a healthcare organization funded by the Government of Ontario has disclosed that they were among the victims of the MOVEIt hacking spree by the Cl0p ransomware gang.

The organization is a perinatal & child registry that collects, interprets, shares & protects critical data about pregnancy, birth and childhood in the Province of Ontario.

BORN disclosed that the attackers made off with data containing sensitive patient data affecting over 3.4 million people. The data stolen included: 
- full name
- home address
- postal code
- date of birth 
- health card number. 

Depending on the type of care received by BORN, additional data may have been exposed, these included: dates of service/care, lab test results, pregnancy risk factors, type of birth, procedures, & pregnancy and birth outcomes.

To determine whether or not you've been affected, the organization states on the website if you answer "YES" to the following questions, you may be affected:
- Did you give birth or was your child born in Ontario between April 2010 and May 2023?
- Did you receive pregnancy care in Ontario between January 2012 and May 2023?
- Did you have in-vitro fertilization or egg banking in Ontario between January 2013 and May 2023?

https://www.bleepingcomputer.com/news/security/born-ontario-child-registry-data-breach-affects-34-million-people/

https://www.bornincident.ca/

#infosec #cybersecurity #databreach #moveit #cl0p #BORN #Ontario #Canada 
 The Better Outcomes Registry & Network (BORN), a healthcare organization funded by the Government of Ontario has disclosed that they were among the victims of the MOVEIt hacking spree by the Cl0p ransomware gang.

The organization is a perinatal & child registry that collects, interprets, shares & protects critical data about pregnancy, birth and childhood in the Province of Ontario.

BORN disclosed that the attackers made off with data containing sensitive patient data affecting over 3.4 million people. The data stolen included: 
- full name
- home address
- postal code
- date of birth 
- health card number. 

Depending on the type of care received by BORN, additional data may have been exposed, these included: dates of service/care, lab test results, pregnancy risk factors, type of birth, procedures, & pregnancy and birth outcomes.

The organization advises individuals to not take other actions at this time apart from treating incoming communication with caution & be suspicious of unsolicited messaging requesting sensitive data.

https://www.bleepingcomputer.com/news/security/born-ontario-child-registry-data-breach-affects-34-million-people/

#infosec #cybersecurity #databreach #moveit #cl0p #BORN #Ontario #Canada 
 The Better Outcomes Registry & Network (BORN), a healthcare organization funded by the Government of Ontario has disclosed that they were among the victims of the MOVEIt hacking spree by the Cl0p ransomware gang.

The organization is a perinatal & child registry that collects, interprets, shares & protects critical data about pregnancy, birth and childhood in the Province of Ontario.

BORN disclosed that the attackers made off with data containing sensitive patient data affecting over 3.4 million people. The data stolen included: 
- full name
- home address
- postal code
- date of birth 
- health card number. 

Depending on the type of care received by BORN, additional data may have been exposed, these included: dates of service/care, lab test results, pregnancy risk factors, type of birth, procedures & pregnancy and birth outcomes.

The organization advises individuals to not take other actions at this time apart from treating incoming communication with caution & be suspicious of unsolicited messaging requesting sensitive data.

https://www.bleepingcomputer.com/news/security/born-ontario-child-registry-data-breach-affects-34-million-people/

#infosec #cybersecurity #databreach #moveit #cl0p #BORN #Ontario #Canada 
 i'm tired of name.com, anyone know a good domain name registrar? i want it to be cheap and respec... 
 @77f3b09f For my different domains I've used CloudFlare Registrar and OVH Domains. However, I also used Hover previously. All of these registrars have been pretty good.

I know CloudFlare is controversial for some, but they have some of the best pricing if you're not the type that wants to jump from a registrar to the next chasing transfer promos. 
 A new actively exploited zero-day vulnerability in iOS has been disclosed by researchers from @beb4ab43.

This vulnerability is being used by the "BLASTPASS" exploit to deploy NSO Group's Pegasus mercenary spyware. The exploit involves a PassKit attachment that contains malicious images sent from an attacker iMessage account to its victim. The researchers also note that no user interaction is required by the victim for this exploit to work.

Apple has since released patches for this zero-day vulnerability. Both Apple & Citizen Lab urges iPhone users to update as soon as possible.

https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/

Apple security advisory: https://support.apple.com/en-us/HT213905

#infosec #cybersecurity #zeroday #blastpass #citizenlab #nsogroup #pegasus #spyware #iOS #iPhone #iMessage #patchnow 
 Infosec.town has now achieved its 500th user w00t!

#Firefish #fediverse

https://media.infosec.town/media/862bab5b-8ccd-4545-ad4e-2674f770c16e.png 
Event not found
 @b1650f17 Oracle Cloud Free Tier gives you 4 ARM-based vCPU, 24GB RAM & 200GB free. However, you need to keep it active or else they will claim the resources back.

https://www.oracle.com/cloud/free/

Alternatively, you can get dirt cheap hosting if you check out LowEndTalk forums.

I've had pretty good experience with GreenCloudVPS. These hosts do oversubscribe but these guys aren't too bad. You're not gonna get Hetzner or DigitalOcean quality but for bargain basement pricing, hard to beat: https://greencloudvps.com/billing/store/budget-kvm-sale. Their 2 vCPU + 4GB RAM option should be enough for something like an #Akkoma install or maybe even a #Firefish install. Not a ton of drive space though so you have to be very careful of how many relays you use.

Hope this helps! 
Event not found
 @66087130 @f8d9bc1c 

It's kinda interesting how Mastodon has resisted adding full text search when other ActivityPub microblogging implementations like #Akkoma & #Firefish already have these for a while.

I'm currently replying from a Firefish instance and the full text search works pretty well...