
Peter Robards
2.9K posts

Peter Robards
@PeterRobards
IT Professional. Entertainer. Filmmaker. Writer.


Hackers aren't fooled when you change up your passwords with special characters. SocialProof Security CEO @RachelTobac tells Nightcap's @jonsarlin how to keep your accounts safe. For more, watch the full Nightcap episode: cnn.it/3LukShp






CVE-2022-26766: the CoreTrust bug "For years, macOS allowed any root certificate when checking code signatures, making code signing completely useless." // bug discovered by @LinusHenze // writeup by @zhuowei worthdoingbadly.com/coretrust/




Due to breaches involving MFA bombing (attacker keeps sending MFA requests until accepted) now is the time for organizations with Office 365 to enable MFA number matching in Microsoft Authenticator. You can deploy to a group before configuring for all. docs.microsoft.com/en-us/azure/ac… 1/3


Recently @twilio, which provides SMS verification services for Signal, suffered a phishing attack. Via Twilio, attackers may have accessed phone numbers & SMS registration codes for 1,900 Signal users. 1/

*Update on SMS Phish Methods* Cloudflare saw similar attack as Twilio, stages: 1.SMS phish 2.Cred harvest page (Okta, etc) 3.Creds relayed fast to attacker via Telegram 4.TOTP harvest page 5.TOTP relay to attacker 6.Anydesk payload (remote access tool) blog.cloudflare.com/2022-07-sms-ph…


