Sans News Bites for April 16, 2024

Hello everyone. I know I’ve done reading on some of these items, and I found one article that I’ll get to post a at some point since it missed its schedule.

One of the articles I did read from Krebs on Security and its titled Crickets from Chirp Systems in Smart Lock Key Leak.

The fact of the matter is, any silence on a breach may not necessarily be good, although I understand why they want to say nothing. By not saying anything, it won’t hurt their bottom line, and that’s the most important thing.

Let’s get started with what is at the top of the news and work our way forward.

The top of the news

  • • Critical RCE Vulnerability in Palo Alto Networks’ GlobalProtect
  • • Chirp Systems Silent on Chirp Access Hard-Coded Credentials

The Churp thing has a bunch of articles including the one that I linked from Krebs.

RCE stuff is never good, so make sure you’re as secure as possible.

The Rest of the news

  • • Delinea Updates Secret Server to Fix Critical Vulnerability
  • • Cisco Duo SMS MFA Logs Stolen from Telephony Provider
  • • Smishing Campaign Focuses on Unpaid Tolls
  • • Roku Mandates 2FA Following Data Breach
  • • Telegram Fixes Vulnerability in Windows Desktop App
  • • Juniper Publishes Multiple Security Bulletins
  • • Nexperia IT Systems Breached
  • • US Cybercom and Hunt Forward Operations

Telegram and their desktop app, if you’re using it, be prepared to read it. Some of the other items I’ve read in passing and don’t know why I didn’t blog it unless they missed their schedules. If they have, I’ll be sure to get those blog posts up.

Want to read sans news bites for the 16th? Click on the reading link, and learn.


Discover more from The Technology blog and podcast

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.