Securing the Cloud

Okta Screws Up (Yet Again) — ALL Customers’ Data Hacked, not just 1%
Richi Jennings | | 2 factor auth, 2-fa authentication, 2-factor authentication, 2fa, 2FA Authenticator, 2FA/MFA, auth, Authentication, CIAM, ciam authentication, ciam solution, ciam solutions, ciam vs iam, cloud IAM, Cloud IAM architecture, Cloud IAM as a Service, cloud IAM platform, Cloud IAM Solution, hosted single sign-on, iam, Identity as a service and single sign on, Identity management and Single sign-on, MFA, MFA rollout, Multi-Factor Authentication (MFA), Okta, okta alternative, Okta replacements, Okta SSO, replace okta, Saasure, SB Blogwatch, single sign on, Single Sign On (SSO), sso, two-factor-authentication.2fa, web application single sign on
You had one job: Last month’s sheer incompetence descends this week into UTTER FARCE ...
Security Boulevard

Meta Sued for Ignoring its Underage Kids Problem (Because Money)
Richi Jennings | | child, child identity theft, child online privacy, Child Online Safety, Child protection, Child Safety, child security online, children, children online, Children's Online Privacy Protection Act, Children's Online Privacy Protection Act (COPPA), children's privacy, Coppa, facebook, Instagram, Meta, online safety for children, Privacy, privacy children, Rights of Children, Safety Of Children, SB Blogwatch, Won’t somebody think of the children?
Don’t be square: Newly-unsealed COPPA suit says Zuck’s mob knows full well there are loads of users under the age of 13, but did nothing ...
Security Boulevard

FCC’s Got New Rules for SIM-Swap and Port-Out Fraud
Richi Jennings | | 2 factor, 2 factor auth, 2-factor authentication, 2FA apps, 2FA bypass, 2FA Flaws, 2FA phishing, 2FA policies, 2FA/MFA, Cloud MFA, DUAL FACTOR AUTHENTICATION, fcc, FCC Failures, FCC Follies, hacking two factor, Jessica Rosenworcel, MFA, MFA hacks, mfasecurity, Multi-Factor Authentication (MFA), number port-out fraud, number port-out scams, Number Portability Administration Center, port-out scams, SB Blogwatch, SIM swap, sim swap fraud, SIM swap scams, SIM swapping, SMS, SMS messages, SMS phishing, sms scam, SMS scams, smshing, two-factor-authentication.2fa
Too many times: Federal Communications Commission shuts stable door after horse bolted. But chairwoman Jessica Rosenworcel (pictured) was hoping it would save us ...
Security Boulevard

Google to Force-Block Ad Blockers — Time to Get Firefox?
Richi Jennings | | ad blockers, ad-blocker, ad-blocking, adblock, adblockers, adblocking, adblocks, adtech, Advertising and AdTech, Chrome, Chrome extension, chrome extensions, google, Manifest V3, SB Blogwatch, uBlock Origin
Manifest V3: Destiny. Huge advertising monopoly flexes muscles: “Manifest V2” extensions to be nuked, but “V3” cripples ad blockers ...
Security Boulevard

FBI’s Warrantless Spying on US Must Continue, Says FBI
Richi Jennings | | 4th Amendment, Democracy, FBI, FBI Director Christopher Wray, Federal Government, FISA, Fourth Amendment, government, government access, government surveillance, Government Surveillance Reform Act (GSRA), lawful surveillance, mass surveillance, nsa, police surveillance, Privacy, SB Blogwatch, Section 702, surveillance, US Constitution, US FBI, warrantless search
Privacy, schmivacy: FBI head Christopher Wray (pictured) doesn’t see what all the fuss is about. Just renew FISA section 702 already! ...
Security Boulevard

HALT! I am Reptar! Intel CPU Bug Panics Cloud Providers
Richi Jennings | | Cloud, Cloud IaaS, cpu, CPU attack, CPU flaw, CPU microcode, cpu vulnerability, Denial of Service, denial-of-service attack, DoS, IaaS, IaaS Security, Infrastructure as a Service (IaaS), Intel, Intel CPU, INTEL-SA-00950, Microcode Flaws, Redundant Prefix Issue, Reptar, SB Blogwatch, x86, x86_64
IaaS Catch Fire: Google and Intel fuzz, find and fix a fabulous bug. Next up: More of the same ...
Security Boulevard

LockBit Crashes Boeing Dark Web Data — No Ransom Paid
7oops7: Seattle plane maker tries to tell us the 50GB dump is ever so boring and not worth spinning up Tor for ...
Security Boulevard

World’s Biggest Bank Hacked: ICBC Walks Trades on USBs
Richi Jennings | | china, Citrix, Citrix Bleed, Citrix Systems, CVE-2023-4966, ICBC, Industrial and Commercial Bank of China, Lockbit, Lockbit 3.0, LockBit ransomware, Ransomware, Russia, SB Blogwatch, Treasury, Treasury Department, U.S. Department of Treasury, U.S. Treasury Department
Plan B is sneakernet: After Industrial and Commercial Bank of China ransomware attack, U.S. Treasury trades settled by bike messengers with flash drives ...
Security Boulevard

VICTORY: Google WEI ‘Stealth DRM’ Plan is Dead (or is it?)
Richi Jennings | | adtech, attestation, Chrome, digital rights management, DRM, environment attestation, freedom to tinker, google, IntegrityToken, SB Blogwatch, Web Environment Integrity, WebView Media Integrity API, WEI, wmi
WEI is dead — long live WMI: Google backs down on Web Environment Integrity API, but its replacement is also problematic ...
Security Boulevard

We Won’t Pay Ransomware Crims — 40 Nations Promise Biden’s WH
Richi Jennings | | Anne Neuberger, Biden, Biden administration, Biden cybersecurity summit, Biden National Cybersecurity Strategy, Biden-Harris, International Counter Ransomware Initiative, International Security, Joe Biden, President Biden, Ransomware, SB Blogwatch, White House
Will CRI pledge work? International Counter Ransomware Initiative (CRI) hopes to pull rug from under scrotes ...
Security Boulevard