720-891-1663

T-Mobile Hacked for the Eighth Time Recently

T-Mobile recently admitted yet another data breach. This time it compromised 37 million customers. The attack used – or abused – one of T-Mobile’s APIs. Dedicated readers probably remember that I warned about the abuse of APIs last week. It is a growing problem because companies are not paying enough attention to API security. The […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News for the Week Ending January 13, 2023

What Could Possibly Go Wrong – Cali’s Digital License Plates Hacked A team of security researchers managed to gain “super administrative access” into Reviver, the company behind California’s new digital license plates which launched last year. That access allowed them to track the physical GPS location of all Reviver customers and change a section of […]

Continue reading → [DISPLAY_ACURAX_ICONS]

What is the Message of Rackspace’s Decision Not to Patch Exchange?

Well, the first answer is that it is not going to help Rackspace defend itself against the lawsuits that it is facing for the ransomware attack. Rackspace now admits that it decided to hold off installing a patch for a server side request forgery vulnerability in Exchange (CVE-2022-41080) that Microsoft patched the month before the […]

Continue reading → [DISPLAY_ACURAX_ICONS]