#SBBlogwatch
Researchers are warning of an alarming uptick in #DDoS activity. Two separate research groups are showing scary stats about the network-melting capabilities of botnets.

It’s obviously a big worry for critical infrastructure. In #SBBlogwatch, we’re in denial. At #TechstrongGroup⁠’s #SecurityBlvd
Biggest Ever DDoS is Threat to OT Critical Infrastructure
Egyptian River Floods: Operational technology (OT) targeted in “world record” 3.8 Tb/s distributed denial of service (DDoS).
securityboulevard.com
October 4, 2024 at 4:24 PM
Big debate over using #Rust in #Linux kernel continues. After one of Linus’s ALL CAPS rants, kernel 2IC gkh wades in.

In case we were in doubt, it’s clear Rust is really happening in the #Linux kernel. In #SBBlogwatch, we walk off sideways.

@futurumgroup.bsky.social @techstronggroup.bsky.social
Rust vs. C — Linux’s Uncivil War
Kernel Panic in the Rust Belt. Memory safety: GOOD. Cheese motion: BAD.
securityboulevard.com
February 25, 2025 at 6:49 PM
Hacker claims to have breached #OracleCloud (OCI), stealing 6M records. But #Oracle says it’s not true.

Many customers confirm data is genuine. But Oracle keeps up the pretense.

“No breach,” the PR flaks cry. In #SBBlogwatch, we cry too.

@futurumgroup.bsky.social @techstronggroup.bsky.social
Oracle Hack PR Drama: Deny, Deny, Deny — Despite Damning Data
OCI dokey then: Larry Ellison’s PR pukes desperately follow the script.
securityboulevard.com
March 28, 2025 at 7:18 PM
35 data brokers employed #DarkPatterns to discourage #Californian​s from exercising privacy rights. Hid legally required web pages from Google—so we can’t find them.

Senator unhappy, accuses firms of “requiring people to navigate byzantine labyrinths.” In #SBBlogwatch, we join her trisyllabic diss.
Act Surprised: Data Brokers Seem to Scoff at California Privacy Act
Privacy Rights Crushed by robots.txt: Sen. Hassan is on the warpath.
securityboulevard.com
August 14, 2025 at 6:44 PM
#DLink #NAS boxes are obsolete. Even the youngest has been out of support for four years. That’s why D-Link says it’s not going to patch the latest flaw in its old range of network storage devices.

In fact, it claims it’s “prohibited” from doing so. In #SBBlogwatch, we find that bit kinda odd.
These 20 D-Link Devices Have Critical RCE Bug — but NO Patch NEVER
‘Bobby’ flaw flagged WONTFIX: Company doesn’t make storage devices now; has zero interest in fixing this catastrophic vulnerability.
securityboulevard.com
November 13, 2024 at 5:34 PM
#Stoli Group USA filed for #Chapter11 bankruptcy last week. But now its leaders have come out swinging: They’re blaming #ransomware and #Russia.

Seems to be an unspoken assumption the hackers were state sponsored. In #SBBlogwatch, we wonder what Patsy Stone would have thought. For #TechstrongGroup
Stoli Vodka: Bankrupt After Ransomware Attack
Absolutely un-fabulous: Smells like Russia is responsible, but reality is a bit more complicated.
securityboulevard.com
December 6, 2024 at 6:07 PM
Apple to limit website certificate validity to 45 days. Cupertino proposes Safari should reject HTTPS sites whose certs expire “too far” into the future.

First Google wants 90 days, now this? In #SBBlogwatch, we wonder why they don’t just drop it to an hour. At #TechstrongGroup⁠’s #SecurityBlvd
Apple Enrages IT — 45-Day Cert Expiration Fury
CA/B testing: Ludicrous proposal draws ire from “furious” systems administrators.
securityboulevard.com
October 16, 2024 at 3:27 PM
U.S. Immigration and Customs Enforcement (ICE) agents are using a new phone app: #MobileFortify puts “instant, #AI powered” #FacialRecognition in their hands. What could possibly go wrong?

A major risk is inaccurate recognition. In #SBBlogwatch, the French want their statue back:
ICE’s Shiny New ‘AI’ Facial Recognition App: False Positives Ahoy!
Mobile Fortify: Liberty’s existential threat, or sensible way to ID illegal immigrants?
securityboulevard.com
June 30, 2025 at 5:50 PM
Scammers pretended to be FCC. This seems to have been enough to awaken the sleeping government giant. It proposes to fine #Telnyx.

But #FCC only acted after scammers tried to scam its own staff. In #SBBlogwatch, we don’t know your customer. @futurumgroup.bsky.social @techstronggroup.bsky.social
FINALLY! FCC Gets Tough on Robocall Fraud
KYC isn’t a Thing, claims telco: Commissioner Brendan Carr (pictured) wants $4.5 million fine on Telnyx, for enabling “illegal robocall scheme.”
securityboulevard.com
February 7, 2025 at 3:57 PM
Big #OpenSource projects are being hammered with stupid #security bug reports. It appears that dim people are relying on dumb #AI chatbots to generate “spammy, hallucinated” #vulnerability reports.

@sethmlarson.dev is as mad as hell. In #SBBlogwatch, we’re not gonna take this any more:
AI Slop is Hurting Security — LLMs are Dumb and People are Dim
Artificial stupidity: Large language models are terrible if you need reasoning or actual understanding.
securityboulevard.com
December 12, 2024 at 6:36 PM
#Apple appeals UK government order to create back door in #iCloud. (We only know this because secret sources revealed secret complaint appealing the secret order—in secret.)

As always with attempts to break #E2EE, the math ain’t mathing. In #SBBlogwatch, we worry about dumb pols.
Apple vs. UK — ADP E2EE Back Door Faceoff
Won’t Tim Think of the Children? End-to-end encryption battle continues.
securityboulevard.com
March 5, 2025 at 7:17 PM
U.S. sen #RonWyden demanding #FTC do something about #Microsoft already. Says Satya’s crew to blame for some awful #ransomware attacks, via vuln 10+ years old.

#Kerberoasting exploit affects #ActiveDirectory installs not configured to modern specs. In #SBBlogwatch, we wonder where to point fingers:
Microsoft’s ‘Gross Cybersecurity Negligence Threatens National Security’
Roasting Redmond for Kerberoasting: “Like an arsonist selling firefighting services,” quips this 76-year-old.
securityboulevard.com
September 11, 2025 at 4:21 PM
Workplace surveillance system #WorkComposer is under fire for storing sensitive data with ZERO #security. Firm saved 21M screenshots of users’ PC screens in open #AWS #S3 bucket.

Hackers could have easily stolen company secrets—and personal ones, too. In #SBBlogwatch, we can’t quite believe it.
200,000 Workers’ PII at Risk in WorkComposer S3 SNAFU
Don’t say ‘spyware’—21 million screenshots in one open bucket.
securityboulevard.com
April 25, 2025 at 4:23 PM
Biden #WhiteHouse executive order on #cybersecurity causing kerfuffle. Requires sweeping changes to how federal agencies work, aiming to improve U.S. govt’s security.

And, by extension, ours. In #SBBlogwatch, we wait to see what happens next. @futurumgroup.bsky.social @techstronggroup.bsky.social
This is HUGE: Biden’s Cybersecurity Exec. Order — Big Parting Gift to Trump
Wow. Just Wow: Joseph Robinette Biden Jr. hits the emergency “do something” button.
securityboulevard.com
January 17, 2025 at 6:36 PM
Today, we learned two incredible things: That this type of rapid update isn’t tested by people; and that #CrowdStrike doesn’t dogfood them, nor do staged, “canary” deployment.

In #SBBlogwatch, we sit slack jawed in horror. At #TechstrongGroup​’s #SecurityBlvd: securityboulevard.com/2024/07/crow...
CrowdStrike Admits it Doesn’t ‘Canary’ Test all Updates
Corporate incompetence: Beleaguered security firm issues initial post-mortem on Friday’s faux pas.
securityboulevard.com
July 24, 2024 at 1:20 PM
Storage queens #QNAP squashed some vulns last week, but cure was worse than disease. After applying update, users found they couldn’t log in to arrays.

Firm stresses problems only affected some products. In #SBBlogwatch, we’re thankful for small mercies. At #TechstrongGroup⁠’s Security Blvd:
QNAP’s Buggy Security Fix Causes Chaos
RAID FAIL: NAS Maker does a CrowdStrike—cleanup on /dev/dsk/c1t2d3s4 please
securityboulevard.com
November 26, 2024 at 3:08 PM
Pair of ethical hackers discover “catastrophic” vulns in code running #BurgerKing, etc. sites. Owner quickly fixed flaws, but then #Cyble issued sus-seeming #DMCA takedown.

Tale as old as time: Poor, unfortunate $8½ billion corp vs. evil, vindictive, millennial hackers. In #SBBlogwatch, we rule:
Burger King’s ‘Very Bad’ Bugs Leaked Your Data, Claim Gagged Hackers
Streisand Effect in full effect: Restaurant Brands International (RBI) “assistant” platform riddled with terrible security flaws.
securityboulevard.com
September 9, 2025 at 4:49 PM
One notorious center for the grotesquely evil practice of #PigButchering is #Myanmar.

This week, #SpaceX is crowing about how it’s blocked 2,500 #Starlink satellite internet terminals being used by these scumbags to reach their victims. In #SBBlogwatch, we wonder what took Elon so long.
Elon Musk’s SpaceX ‘is Facilitating’ Scams via Starlink
Low Earth Pork: Pig-butchering scammers in Myanmar lose use of 2,500 Starlink terminals.
securityboulevard.com
October 23, 2025 at 5:09 PM
#ENISA has brought #EUVD out of beta. Born from a 2022 EU law, it’ll work alongside MITRE’s #CVE database—the future of which is still hazy after April’s last-minute reprieve.

ENISA’s Juhan Lepassaar (pictured) is keen to get on with the job. In #SBBlogwatch, we take this kiss throughout the world:
As US CVE Database Fumbles, EU ‘Replacement’ Goes Live
Diesen Kuß der ganzen Welt! European Union Vulnerability Database (EUVD) launches this week. And not a moment too soon.
securityboulevard.com
May 14, 2025 at 4:06 PM
#OpenWrt project scrambles to fix critical vuln: Built-in firmware updater could be persuaded to install malicious code.

Japanese researcher discovered #OpenWrt used incredibly weak hash; it also failed to sanitize inputs. In #SBBlogwatch, we make code not war. At #TechstrongGroup⁠’s SecurityBlvd:
Critical OpenWrt Bug: Update Your Gear!
ASU 48-bit trash hash: Open source router firmware project fixes dusty old code.
securityboulevard.com
December 10, 2024 at 4:43 PM
Airlines, stock markets, TV networks, banks and more suffered huge outages this morning. A security service from #CrowdStrike is to blame, apparently.

Seems to affect #Microsoft365 and #Azure cloud services, too. In #SBBlogwatch, we look for the silver lining. At #TechstrongGroup​’s #SecurityBlvd:
Worldwide Outages Caused by CrowdStrike Security Tool
BSODs beyond belief: A buggy update to CrowdStrike Falcon made Windows PCs and servers crash—globally.
securityboulevard.com
July 19, 2024 at 10:13 AM
#Microsoft VPs David “dwizzzle” Weston (pictured) and Pavan Davuluri (not) are making noise about preventing a repeat of July’s #CrowdStrike débâcle.

#MicrosoftIgnite 2024 is their nexus of (ahem) “learnings.” In #SBBlogwatch, we hunker down in the windy city. At #TechstrongGroup⁠’s #SecurityBlvd:
Microsoft Veeps Ignite Fire Under CrowdStrike
BSODs begone! Redmond business leaders line up to say what’s new in Windows security.
securityboulevard.com
November 20, 2024 at 5:19 PM
A new paper puts a fire under DevOps, IT teams and anyone else using modern RSA—or similar cryptosystems. Factoring big primes now seems much, much easier for #QuantumComputers than thought even a few years ago.

Of course, the Devil is in the details. In #SBBlogwatch, we never shy away from detail.
RSA and Bitcoin at BIG Risk from Quantum Compute
PQC PDQ: Researchers find we’ll need 20 times fewer qubits to break conventional encryption than previously believed.
securityboulevard.com
May 27, 2025 at 5:08 PM
Many dual-boot #Linux PCs have been failing—and it’s Microsoft’s fault. The problem is caused by an errant #SecureBoot #security bugfix.

But, as we revealed last month, Secure Boot is basically broken, anyway. In #SBBlogwatch, we might as well turn it off. At #TechstrongGroup⁠’s #SecurityBlvd:
Patch Tuesday not Done ’til LINUX Won’t Run?
Redmond reboot redux: “Something has gone seriously wrong.” You can say that again, Microsoft.
securityboulevard.com
August 21, 2024 at 2:43 PM
#NATO and #European nations are calling out #Russia for #cyberattacks on government systems last year. Putin’s #GRU is said to have been behind it.

Attack vector said to be Outlook vuln. In #SBBlogwatch, we wonder why gov’t IT teams didn’t patch it in time. At #TechstrongGroup’s #SecurityBlvd:
Germany Warns Russia: Hacking Will Have Consequences
War of the words: Fancy Bear actions are “intolerable and unacceptable,” complains German foreign minister Annalena Baerbock.
securityboulevard.com
May 6, 2024 at 6:23 PM