Skip to main content

Security

Data belonging to 500 million LinkedIn users found for sale on hacker marketplace

posted onApril 8, 2021
by l33tdawg
Credit: IT Pro

The scraped data of over 500 million LinkedIn profiles has been put up for sale on a popular hacker forum.

The post's author has leaked two million records already as proof of the existence of the much larger data trove, as reported by Cybernews. The data, which is spread across four files, is said to include full names, email addresses, phone numbers, and information related to their place of work.

How to use Docker Bench for Security to audit your container deployments

posted onApril 8, 2021
by l33tdawg
Credit: Tech Republic

One of the biggest issues surrounding container deployments is security. This is such an issue because there are so many moving parts to be checked. You might have your container manifests perfectly secure, but what about your host? Or maybe your host is sound, but your YAML files are riddled with security holes.

Hackers Are Exploiting Discord and Slack Links to Serve Up Malware

posted onApril 8, 2021
by l33tdawg
Credit: Wired

Thanks in large part to the global pandemic, collaboration platforms like Discord and Slack have taken up intimate positions in our lives, helping maintain personal ties despite physical isolation. But their increasingly integral role has also made them a powerful avenue for delivering malware to unwitting victims—sometimes in unexpected ways.

Critical Cloud Bug in VMWare Carbon Black Allows Takeover

posted onApril 7, 2021
by l33tdawg
Credit: Threat Post

A critical security vulnerability in the VMware Carbon Black Cloud Workload appliance would allow privilege escalation and the ability to take over the administrative rights for the solution.

The bug (CVE-2021-21982) ranks 9.1 out of 10 on the CVSS vulnerability-severity scale.

Malaysia Airlines suffers data security 'incident' spanning nine years

posted onMarch 2, 2021
by l33tdawg
Credit: Flickr

Malaysia Airlines has suffered a data security "incident" that compromised personal information belonging to members of its frequent flyer programme, Enrich. The breach is purported to have occurred at some point during a period that spans almost a decade and involves a third-party IT service provider.