On this week’s SURPRISE edition, Patrick Gray and Adam Boileau discuss the week’s security news. They cover:
Their disappointment over last week’s SEC Twitter hackChina rainbow-tables AirdropEnterprise bugs galore…… and why patching fast is hard when there isn’t even a patch yetUEFI flaws get trad-BIOS-era vendor responseand much, much more…This week’s show is unsponsored, we’re just here for the fun of it.
Show notes
The SEC’s Official X Account Was ‘Compromised’ and Used to Post Fake Bitcoin News | WIREDApple AirDrop leaks user data like a sieve. Chinese authorities say they’re scooping it up. | Ars TechnicaFireChat – the messaging app that’s powering the Hong Kong protestsEnd-of-life Cisco routers targeted by China’s Volt Typhoon groupIvanti Connect Secure attacks part of deliberate espionage operation | Cybersecurity DiveIvanti Connect Secure VPN Exploitation Goes GlobalNetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2023-6548 and CVE-2023-6549Aria Automation Missing Access Control Vulnerability (CVE-2023-34063)Security Bulletin - January 16 2024Stable Channel Update for Desktop“MyFlaw” — Cross Platform 0-Day RCE Vulnerability Discovered in Opera’s BrowserPixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack.LeftoverLocals: Listening to LLM responses through leaked GPU local memoryBigpanzi TV BotnetSoutheast Asian casino industry supercharging cyber fraud, UN says