No, 'airforce' is Not a Good Password: Check Out This Honeypot
LowEndTalk user htop setup a honeypot to trap ssh passwords. Watch skiddies in real time!
Read MoreLowEndTalk user htop setup a honeypot to trap ssh passwords. Watch skiddies in real time!
Read MoreMSI recently suffered a cyber attack and has issued a warning about dodgy imposter firmware that might be in the wild.
Read MoreEzeelogin is an SSH management platform that provides two factor authentication, SAML Authentication, session recording, IAM, RBAC, PAM, and lots of other important acronyms. Community provider RackNerd recently deployed it and explains the product's benefits to providers and users.
Read More"That Rackspace offered opaque updates for days, then admitted to a ransomware event without further customer assistance is outrageous," according to one attorney. Class-action lawsuits against Rackspace are popping up around the country.
Read MoreLastPass had security incidents in 2011, 2015, 2016, 2017 (twice), 2019, 2021, and twice now in 2022. Are you still using them? Why?
Read MoreThere's an important security vulnerability in WHMCS 8.5.x and 8.6.x. WHMCS won't tell you what it is, but will tell you that you need to patch ASAP. No earlier versions are affected.
Read MoreIf you're seeing weird things in your logs, it's because the UK National Cyber Security Center has decided to scan all UK systems as part of their "Scanning the Internet for Fun and Profit" (their term). Click to learn how to opt-out.
Read More"We lost your data. It's your problem. OKTHXBYE - Internap."
Read MoreAs of this morning, Uber has the following positions open: Senior Security Engineer - Application Security Security Engineer - Penetration Testing Security Engineer II Security Incident Commander II T...
Read MoreCheck out this sentence: "For the author, this business model enables them to scale their earnings from their software with less risk." I slightly modified the original, but we're not talking about a...
Read MoreSometimes you see stuff in the media and wonder if it's really news. Some celebrity broke up with some other celebrity. Some tech company released version X.Y which is .0001% better. LastPass was h...
Read MorePresenting at the Black Hat USA conference this week, Trend Micro had an interesting comment: Over the last few years, we’ve noticed a disturbing trend – a decrease in patch quality and a reduction in...
Read MoreTwilio has suffered a data breach and the attackers "used the stolen credentials to gain access to some of our internal systems". Twilio is a messaging platform with a nice API. I used it last year t...
Read MoreIf your organization's data is being held for ransom by hackers, should you pay up? The universal consensus is that you shouldn't because it encourages criminals. But an earlier question needs to be...
Read MoreWordfence reports that hackers are widely attempting to exploit a vulnerability that they reported over three months ago. According to The Register: Wordfence disclosed the flaw almost three months a...
Read MoreLowEndTalk member @Chuck alerted the community to a terrific deal: you can get a full access lifetime membership for Shodan.io for only $5 - that's 90% off the list price! However the deal expires at...
Read More"Today Intel released two security advisories addressing 2 medium severity vulnerabilities reported by academic researchers from ETH Zurich who have labeled their side-channel attack as “Retbleed” due...
Read MoreThe Phishing Attack On April 9, 2022, some not-so-nice ungentleman went phishing. As announced on Low End Talk, phishing emails were received by several Low End Talk members. The phishing emails false...
Read MoreWord is out of a new vulnerability in Chrome, and it sounds serious. If your browser has an update, you should definitely restart to apply to reach version 99.0.4844.84. New updates are out for Wind...
Read MoreOkta (NASDAQ:OKTA), which provides digital identity authentication services to big companies, confirmed Tuesday that it had suffered a security breach. Their stock plunged nearly 9% as reports piled...
Read MoreA new vulnerability that affects many Linux systems has been revealed: Pwnkit. This attack uses a vulnerability in polkitd to allow any user to escalate his privileges to root. There are patches for...
Read MoreAs a quick followup to our story from a couple days ago about the HostSolutions.ro hack, owner Marius has now commented on LowEndTalk, confirming the breach and adding some details. The entire thread...
Read MoreNews broke on Christmas Eve that HostSolutions.ro has been hacked. Community member @MikaelStrang posted the email below that he received from a hacker claiming to have the HostSolutions WHMCS databa...
Read MoreGartner, one of the world's major IT consulting firms, recently shared their "Top Strategic Predictions for 2022 and Beyond" at a conference. Most of the content concerned economic and technological...
Read MoreVulnerabilities don't get much worse than cases where typing the right characters into a chat box gives you remote access to the world's Minecraft servers. Whoops. It's been termed the worst hack in...
Read MoreNow that (hopefully?) the CentOS Stream debacle and the subsequent rise of Alma and Rocky Linux is behind us, there's news from RedHat that RHEL 9 has gone beta. Is this the love child that will fina...
Read MoreThere are a number of ways you can restrict access to your VPS. Passwords (specifically, good passwords) is the most basic method. Restricting access to ssh keys only is better. You can use Google Aut...
Read MoreSep 25, 2023
Sep 24, 2023
Sep 24, 2023
Sep 24, 2023