Hack
MyFitnessPal Data Breach

n February 2018, the diet and exercise service MyFitnessPal suffered a data breach. The incident exposed 144 million unique email addresses alongside usernames, IP addresses and passwords stored as SHA-1 and bcrypt hashes (the former for earlier accounts, the latter for newer accounts).

Read more
General Security
I’ve Been Hacked – What To Do After You’ve Been Hacked

By Carter Graydon at Hacked.com There’s nothing quite like that feeling of dread that slowly envelops you when you realize you’ve been backed. Regardless if it’s just your social media account or something as serious as your bank account or credit card, you can’t escape those first few moments of confusion, anger, and the overwhelming […]

Read more
Hack
First it was Marriott, now Quora has been Hacked…

100 million Quora users may have had their data accessed by an unauthorized third party. Quora is actively investigating the incident, and has already taken steps to improve its security.

Read more
Hack
Marriott Data Breach and What You Need to Know

Marriott International said its Starwood guest reservation database was breached, exposing the personal info of about 500 million customers.

Read more
The SecurityOrb Show
The SecurityOrb Show – An Interview with Dr. Elizabeth Milovidov, Esq. founder of DigitalParentingCoach.com. – 11/27/2018

I had the opportunity to speak with Dr. Elizabeth Milovidov, Esq. founder of DigitalParentingCoach.com about Internet Safety.

Listen to what Dr. Milovidov has to say here:

Read more
Vulnerability & Threat Report
CVE-2018-15454 (Cisco SIP) Exploit Information

From October 2018, NCCIC analysts have observed network traffic indicating

attempts, by unknown actors against multiple government agencies, to exploit a

vulnerability [CVE-2018-15454] in the Session Initiation Protocol (SIP)

inspection engine of Cisco ASA Software and Cisco FTD Software.

Read more
Cloud Security
Amazon AWS GuardDuty

Amazon GuardDuty is a continuous security monitoring service that analyzes and processes the following data sources: VPC Flow Logs, AWS CloudTrail event logs, and DNS logs.

Read more
Cloud Security
Amazon AWS Inspector

Amazon Inspector is an automated security assessment service that helps you test the network accessibility of your Amazon EC2 instances and the security state of your applications running on those instances.

Read more
Cloud Security
Using Docker To Install OpenVAS On CentOS

An interesting post from Gerry Williams at gerrywilliams.net Description: Saw a post on r/sysadmin the other day with a walkthrough on using Docker for the first time. Thought I would take some notes: To Resolve: 1. On the host computer, open up Hyper V and create a new Virtual Machine. Download the Centos7 iso if […]

Read more
Cloud Security
OpenVAS image for Docker on Ubuntu

A Docker container for OpenVAS on Ubuntu. By default, the latest images includes the OpenVAS Base as well as the NVTs and Certs required to run OpenVAS

Read more