LowEndBox - Cheap VPS, Hosting and Dedicated Server Deals

Here Come the RackSpace Lawsuits

"That Rackspace offered opaque updates for days, then admitted to a ransomware event without further customer assistance is outrageous," according to one attorney. Class-action lawsuits against Rackspace are popping up around the country.

Read More
Here Come the RackSpace Lawsuits

Just Stop Using LastPass: They've Been Hacked for the 9th Time

LastPass had security incidents in 2011, 2015, 2016, 2017 (twice), 2019, 2021, and twice now in 2022. Are you still using them? Why?

Read More
Just Stop Using LastPass: They've Been Hacked for the 9th Time

WHMCS Won't Tell You About What The Vulnerability Is, But Will Say "Patch ASAP!"

There's an important security vulnerability in WHMCS 8.5.x and 8.6.x. WHMCS won't tell you what it is, but will tell you that you need to patch ASAP. No earlier versions are affected.

Read More
WHMCS Won't Tell You About What The Vulnerability Is, But Will Say

Getting Scans From 18.171.7.246 and 35.177.10.231? It's the UK Government

If you're seeing weird things in your logs, it's because the UK National Cyber Security Center has decided to scan all UK systems as part of their "Scanning the Internet for Fun and Profit" (their term). Click to learn how to opt-out.

Read More
Getting Scans From 18.171.7.246 and 35.177.10.231?  It's the UK Government

Is This the Future of Passwordless Authentication?

Biometrics? So last decade.

Read More
Is This the Future of Passwordless Authentication?

Internap Loses Customer Data, Shrugs, Doesn't Apologize

"We lost your data. It's your problem. OKTHXBYE - Internap."

Read More
Internap Loses Customer Data, Shrugs, Doesn't Apologize

BRING YOUR OWN JOKE: Uber Has Many Openings in IT Security

As of this morning, Uber has the following positions open: Senior Security Engineer - Application Security Security Engineer - Penetration Testing Security Engineer II Security Incident Commander II T...

Read More
BRING YOUR OWN JOKE: Uber Has Many Openings in IT Security

This Week's Initial Ransomware Offering (IRO) Calendar

Check out this sentence: "For the author, this business model enables them to scale their earnings from their software with less risk." I slightly modified the original, but we're not talking about a...

Read More
This Week's Initial Ransomware Offering (IRO) Calendar

LastPass Releases Its Security Incident for 2022

Sometimes you see stuff in the media and wonder if it's really news.  Some celebrity broke up with some other celebrity.  Some tech company released version X.Y which is .0001% better.  LastPass was h...

Read More
LastPass Releases Its Security Incident for 2022

More Vulnerabilities, Poorer Patches: TrendMicro Is Bummed

Presenting at the Black Hat USA conference this week, Trend Micro had an interesting comment: Over the last few years, we’ve noticed a disturbing trend – a decrease in patch quality and a reduction in...

Read More
More Vulnerabilities, Poorer Patches: TrendMicro Is Bummed

Those Spam Texts Are Coming From Twilio: They've Been Hacked

Twilio has suffered a data breach and the attackers "used the stolen credentials to gain access to some of our internal systems". Twilio is a messaging platform with a nice API.  I used it last year t...

Read More
Those Spam Texts Are Coming From Twilio: They've Been Hacked

Why It May Be Illegal to Pay Ransomeware and Why a Ban on Payments Won't Work

If your organization's data is being held for ransom by hackers, should you pay up?  The universal consensus is that you shouldn't because it encourages criminals.  But an earlier question needs to be...

Read More
Why It May Be Illegal to Pay Ransomeware and Why a Ban on Payments Won't Work

Your Wordpress Has Been Scanned. Hope You Weren't Hacked.

Wordfence reports that hackers are widely attempting to exploit a vulnerability that they reported over three months ago.  According to The Register: Wordfence disclosed the flaw almost three months a...

Read More
Your Wordpress Has Been Scanned.  Hope You Weren't Hacked.

ALMOST GONE: Save 90% on Shodan.io! Only $5 Lifetime!

LowEndTalk member @Chuck alerted the community to a terrific deal: you can get a full access lifetime membership for Shodan.io for only $5 - that's 90% off the list price! However the deal expires at...

Read More
ALMOST GONE: Save 90% on Shodan.io!  Only $5 Lifetime!

Retbleed: Your x86 Speculative Attack Du Jour

"Today Intel released two security advisories addressing 2 medium severity vulnerabilities reported by academic researchers from ETH Zurich who have labeled their side-channel attack as “Retbleed” due...

Read More
Retbleed: Your x86 Speculative Attack Du Jour

Low End Detectives: IP Address of Low End Talk Phishing Attacker Revealed In Just 5 Minutes!

The Phishing Attack On April 9, 2022, some not-so-nice ungentleman went phishing. As announced on Low End Talk, phishing emails were received by several Low End Talk members. The phishing emails false...

Read More
Low End Detectives: IP Address of Low End Talk Phishing Attacker Revealed In Just 5 Minutes!

You Need to Update Chrome ASAP

Word is out of a new vulnerability in Chrome, and it sounds serious.  If your browser has an update, you should definitely restart to apply to reach version 99.0.4844.84.  New updates are out for Wind...

Read More
You Need to Update Chrome ASAP

Okta Hacked, Stock in Flames

Okta (NASDAQ:OKTA), which provides digital identity authentication services to big companies, confirmed Tuesday that it had suffered a security breach.  Their stock plunged nearly 9% as reports piled...

Read More
Okta Hacked, Stock in Flames

FREE Root Shells on Linux Servers Thanks to polkitd Vulnerability

A new vulnerability that affects many Linux systems has been revealed: Pwnkit. This attack uses a vulnerability in polkitd to allow any user to escalate his privileges to root.  There are patches for...

Read More
FREE Root Shells on Linux Servers Thanks to polkitd Vulnerability

HostSolutions.ro Hack Update

As a quick followup to our story from a couple days ago about the HostSolutions.ro hack, owner Marius has now commented on LowEndTalk, confirming the breach and adding some details. The entire thread...

Read More
HostSolutions.ro Hack Update

HostSolutions.ro Hacked

News broke on Christmas Eve that HostSolutions.ro has been hacked.  Community member @MikaelStrang posted the email below that he received from a hacker claiming to have the HostSolutions WHMCS databa...

Read More
HostSolutions.ro Hacked

Gartner Makes Bold Prediction: War in the G20 by 2024

Gartner, one of the world's major IT consulting firms, recently shared their "Top Strategic Predictions for 2022 and Beyond" at a conference.  Most of the content concerned economic and technological...

Read More
Gartner Makes Bold Prediction: War in the G20 by 2024

log4Shell Vulnerability: "Worst Hack in History"

Vulnerabilities don't get much worse than cases where typing the right characters into a chat box gives you remote access to the world's Minecraft servers.  Whoops. It's been termed the worst hack in...

Read More
log4Shell Vulnerability:

RHEL 9 Goes Beta

Now that (hopefully?) the CentOS Stream debacle and the subsequent rise of Alma and Rocky Linux is behind us, there's news from RedHat that RHEL 9 has gone beta.  Is this the love child that will fina...

Read More
RHEL 9 Goes Beta

Locking Down Access to Your VPS

There are a number of ways you can restrict access to your VPS. Passwords (specifically, good passwords) is the most basic method. Restricting access to ssh keys only is better. You can use Google Aut...

Read More
Locking Down Access to Your VPS

How to Audit Every Command Run on Your Linux System

Periodically I've had auditors come to me and say "can you tell me what this user on this system did between such-and-such dates/times" and my answer is usually no. By default, Linux systems don't log...

Read More
How to Audit Every  Command Run on Your Linux System

The Syniverse Hack: Why Using SMS for 2FA is a Bad Idea

Security gurus have suggested for years that relying on SMS for two-factor authentication is a bad idea.   Reasons include Your phone may be stolen Many people allow SMS messages to be displayed on lo...

Read More
The Syniverse Hack: Why Using SMS for 2FA is a Bad Idea

Microsoft Says Passwords are Passé

Are passwords a dying breed? In a blog post published September 15, Microsoft Vice President of Security, Compliance, and Identity Vasu Jakkal entitled "The passwordless future is here for your Micros...

Read More
Microsoft Says Passwords are Passé
Older Posts »

Latest LowEndTalk Hosting Offers

View More