Home Artists Posts Import Register

Content

Hey yall! I've collated a bunch of news stories while doing my ThreatWire episode research. These are additional headlines you should know about, along with a few action alerts!

ACTION ALERTS

Patch Adobe ColdFusion now to secure against this critical vulnerability: https://www.bleepingcomputer.com/news/security/critical-code-execution-vulnerability-fixed-in-adobe-coldfusion/

Out of date DTLS servers need to patch to prevent DDoS amplification using their systems:  https://www.bleepingcomputer.com/news/security/ddos-booters-now-abuse-dtls-servers-to-amplify-attacks/

MAC devs are being targeted in this "EggShell" backdoor malware attack: https://www.zdnet.com/article/apple-developers-targeted-by-new-malware-eggshell-backdoor/

US taxpayers are being targeted in trojan campaigns: https://www.zdnet.com/article/us-taxpayers-targeted-in-netwire-remcos-trojan-attack-wave/

Facebook and Twitter are expanding their 2FA hardware token options: https://www.theverge.com/2021/3/15/22332234/twitter-security-key-2fa-authenticator-privacy and https://www.theverge.com/2021/3/18/22337891/facebook-expanding-physical-security-keys-2fa-two-factor-authentication 



INTERNATIONAL NEWS

Australia's House passed the Online Safety Act, which gives the eSafety Commissioner power to remove material that could harm adults and it holds platforms accountable: https://www.zdnet.com/article/house-passes-online-safety-bill-as-senate-shoots-down-big-tech-influence-committee/


WEIRD, NOTEWORTHY, or JUST PLAIN FUNNY

This mom and daughter from Florida hacked into a school voting system to change votes so the 17 year old would win homecoming queen. And they got arrested for it: https://www.cnet.com/news/florida-mother-daughter-charged-with-hacking-homecoming-queen-election/

A security researcher is using steganography to hide ZIP and MP3 files inside PNGs uploaded to Twitter: https://threatpost.com/researcher-hides-files-in-png-twitter/164881/


Keep an eye on the page for tomorrow's ThreatWire episode and more security / privacy news!

Files

Critical code execution vulnerability fixed in Adobe ColdFusion

Adobe has released out-of-band security updates to address a critical vulnerability impacting ColdFusion versions 2021, 2016, and 2018. Today's emergency updates patch an arbitrary code execution security flaw caused by an Improper Input Validation software vulnerability.