720-891-1663

Yet Another IoT Device with Hardcoded Credentials

Last month the Mirai botnet took down Twitter, Amazon and hundreds of other web sites by compromising cheap Chinese web cams and weaponizing them.  While the attack was very interesting and could have been a lot worse, I attributed it to it being a cheap Chinese web cam.  Hundreds of thousands of them. Now an […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Iran (?) Attacks Saudi Central Bank and Other Saudi Agencies

Starting in mid November, someone, possibly Iran, wiped many computers at a number of Saudi government agencies, including the Saudi Civil Aviation Agency .  A total of 6 agencies were attacked; 4 were compromised; 2 agencies repelled the attack. The attack was made to look identical to an attack attributed to Iran in 2012 where […]

Continue reading → [DISPLAY_ACURAX_ICONS]

The Safety Of Using Your Facebook ID To Sign On To Other Websites

UPDATE:  Apparently Paypal was one of the companies affected by some of these OAuth security holes and they just released a fix (Dec 1,2016) for a bug that would allow hackers to steal OAuth tokens from payment apps of third party developers. Many web sites encourage you to sign on with your social media userid […]

Continue reading → [DISPLAY_ACURAX_ICONS]