#SecurityBlvd
Researchers are warning of an alarming uptick in #DDoS activity. Two separate research groups are showing scary stats about the network-melting capabilities of botnets.

It’s obviously a big worry for critical infrastructure. In #SBBlogwatch, we’re in denial. At #TechstrongGroup⁠’s #SecurityBlvd
Biggest Ever DDoS is Threat to OT Critical Infrastructure
Egyptian River Floods: Operational technology (OT) targeted in “world record” 3.8 Tb/s distributed denial of service (DDoS).
securityboulevard.com
October 4, 2024 at 4:24 PM
Apple to limit website certificate validity to 45 days. Cupertino proposes Safari should reject HTTPS sites whose certs expire “too far” into the future.

First Google wants 90 days, now this? In #SBBlogwatch, we wonder why they don’t just drop it to an hour. At #TechstrongGroup⁠’s #SecurityBlvd
Apple Enrages IT — 45-Day Cert Expiration Fury
CA/B testing: Ludicrous proposal draws ire from “furious” systems administrators.
securityboulevard.com
October 16, 2024 at 3:27 PM
Today, we learned two incredible things: That this type of rapid update isn’t tested by people; and that #CrowdStrike doesn’t dogfood them, nor do staged, “canary” deployment.

In #SBBlogwatch, we sit slack jawed in horror. At #TechstrongGroup​’s #SecurityBlvd: securityboulevard.com/2024/07/crow...
CrowdStrike Admits it Doesn’t ‘Canary’ Test all Updates
Corporate incompetence: Beleaguered security firm issues initial post-mortem on Friday’s faux pas.
securityboulevard.com
July 24, 2024 at 1:20 PM
What happens when AI uncovers zero-day exploits before developers can fix them?

On Security Boulevard, Tom Hollingsworth & Fernando Montenegro discuss the "Exploitarium" GitHub code drop, where AI exposed zero-day vulnerabilities in critical open-source software. #SecurityBlvd #Cybersecurity
July 24, 2026 at 5:49 PM
#OpenWrt project scrambles to fix critical vuln: Built-in firmware updater could be persuaded to install malicious code.

Japanese researcher discovered #OpenWrt used incredibly weak hash; it also failed to sanitize inputs. In #SBBlogwatch, we make code not war. At #TechstrongGroup⁠’s SecurityBlvd:
Critical OpenWrt Bug: Update Your Gear!
ASU 48-bit trash hash: Open source router firmware project fixes dusty old code.
securityboulevard.com
December 10, 2024 at 4:43 PM
Airlines, stock markets, TV networks, banks and more suffered huge outages this morning. A security service from #CrowdStrike is to blame, apparently.

Seems to affect #Microsoft365 and #Azure cloud services, too. In #SBBlogwatch, we look for the silver lining. At #TechstrongGroup​’s #SecurityBlvd:
Worldwide Outages Caused by CrowdStrike Security Tool
BSODs beyond belief: A buggy update to CrowdStrike Falcon made Windows PCs and servers crash—globally.
securityboulevard.com
July 19, 2024 at 10:13 AM
#Microsoft VPs David “dwizzzle” Weston (pictured) and Pavan Davuluri (not) are making noise about preventing a repeat of July’s #CrowdStrike débâcle.

#MicrosoftIgnite 2024 is their nexus of (ahem) “learnings.” In #SBBlogwatch, we hunker down in the windy city. At #TechstrongGroup⁠’s #SecurityBlvd:
Microsoft Veeps Ignite Fire Under CrowdStrike
BSODs begone! Redmond business leaders line up to say what’s new in Windows security.
securityboulevard.com
November 20, 2024 at 5:19 PM
Is the era of “wild west” AI development ending—or just getting more controlled?

On #SecurityBlvd Podcast, @NetworkingNerd.net, Mitch Ashley, and @FSMontenegro.bsky.social explore how AI regulation has rapidly evolved into a critical cybersecurity priority.

#Cybersecurity #SecurityBoulevard
March 20, 2026 at 10:56 PM
Many dual-boot #Linux PCs have been failing—and it’s Microsoft’s fault. The problem is caused by an errant #SecureBoot #security bugfix.

But, as we revealed last month, Secure Boot is basically broken, anyway. In #SBBlogwatch, we might as well turn it off. At #TechstrongGroup⁠’s #SecurityBlvd:
Patch Tuesday not Done ’til LINUX Won’t Run?
Redmond reboot redux: “Something has gone seriously wrong.” You can say that again, Microsoft.
securityboulevard.com
August 21, 2024 at 2:43 PM
#NATO and #European nations are calling out #Russia for #cyberattacks on government systems last year. Putin’s #GRU is said to have been behind it.

Attack vector said to be Outlook vuln. In #SBBlogwatch, we wonder why gov’t IT teams didn’t patch it in time. At #TechstrongGroup’s #SecurityBlvd:
Germany Warns Russia: Hacking Will Have Consequences
War of the words: Fancy Bear actions are “intolerable and unacceptable,” complains German foreign minister Annalena Baerbock.
securityboulevard.com
May 6, 2024 at 6:23 PM
Alastair Cooke @DemitasseNZ discusses the evolving attack surface of cloud-based generative AI applications & new security challenges. Adapt your strategies! Catch insights from @Fortinet's #CFD24 presentation via @SecurityBlvd:
The Attack Surface of Cloud-Based Generative AI Applications is Evolving
It is the right time to talk about this. Cloud-based Artificial Intelligence, or specifically those big, powerful Large Language Models we see everywhere,
buff.ly
December 4, 2025 at 6:02 PM
Current logic around cybersecurity is extremely outdated.

In this clip, Tom Hollingsworth argues that companies rely way too much on cold financial math instead of doing what is morally right for their users.

#Cybersecurity #OpenSource #SecurityBlvd
July 23, 2026 at 9:51 PM
Do you have the #Temu app installed on your phone? You might wanna think twice about that. #Arkansas is suing Temu’s owners, accusing them of deeply shady privacy practices.

Not everyone is buying the Natural State’s narrative. In #SBBlogwatch, we see both sides. At #TechstrongGroup’s #SecurityBlvd
Temu is Malware — It Sells Your Info, Accuses Ark. AG
Chinese fast-fashion-cum-junk retailer “is a data-theft business.”
securityboulevard.com
June 29, 2024 at 3:14 PM
The popular #SocialWarfare plugin contains serious malware. And now it’s been joined by four more malicious Trojans.

Should the #WordPress team do more to prevent this? In #SBBlogwatch, we hand coded this HTML for you. At #TechstrongGroup’s #SecurityBlvd: securityboulevard.com/2024/06/word...
WordPress Plugin Supply Chain Attack Gets Worse
30,000 websites at risk: Check yours ASAP! (800 Million Ostriches Can’t Be Wrong.)
securityboulevard.com
June 26, 2024 at 3:39 PM
#DLink again under fire for not patching critical vulns. Like last week, it’s digging in heels because the devices are just past their arbitrary EOL.

This week, it’s a buffer overflow in six router products. In #SBBlogwatch, we wonder what next week’s will be. At #TechstrongGroup⁠’s #SecurityBlvd:
Here’s Yet Another D-Link RCE That Won’t be Fixed
D-Licious: Stubborn network device maker digs in heels and tells you to buy new gear.
securityboulevard.com
November 21, 2024 at 5:44 PM
Republic of #Korea proposes ban on iPhones and #Apple Watches on mil bases. Apple won’t allow them to disable the microphones—and #Android does.

With S. Korea’s huge #Samsung installed base, that’s not a big problem, probably. In #SBBlogwatch, we 북쪽 이웃을 두려워하라. At #TechstrongGroup’s #SecurityBlvd:
South Korean iPhone Ban: MDM DMZ PDQ
MDM Hindered: Android phones are still OK; this is Samsung’s home, after all.
securityboulevard.com
April 29, 2024 at 4:32 PM
French firm #SchneiderElectric was attacked last week. The #Hellcat gang claimed it stole the data of 400,000 customers and employees.

Known as “Grep” or “Greppy,” the hacker’s searching for baguettes in payment. In #SBBlogwatch, we want fries with that. At #TechstrongGroup⁠’s #SecurityBlvd:
Schneider Electric Confirms Ransom Hack — Hellcat Demands French Bread as ‘Joke’
That’s a lot of pain: $125,000 ransom seems small—but why do the scrotes want it paid in baguettes?
securityboulevard.com
November 6, 2024 at 5:39 PM
DoJ says N. Korean hackers are getting remote IT jobs, posing as Americans. They’re funneling their pay into Pyongyang’s nuclear weapons program.

If you’re feeling some déjà vu, that’s because this is now the third such arrest. In #SBBlogwatch, we get busy. At #TechstrongGroup⁠’s #SecurityBlvd:
WTH? DPRK WFH Ransomware Redux: 3rd Person Charged
North Korean army of remote IT workers enabled by Matthew Isaac Knoot, alleges DoJ.
securityboulevard.com
August 13, 2024 at 6:05 PM
The @eff.org is absolutely livid at GOOG’s volte-face. Switching off 3rd-party cookies was finally going to happen. But, given the “feedback” from #AdTech, it’s not.

Instead, #Google will do something else in #Chrome. In #SBBlogwatch, we’re still unclear what. At #TechstrongGroup​’s #SecurityBlvd:
EFF Angry as Google Keeps 3rd-Party Cookies in Chrome
Regulatory capture by stealth? Google changes its mind about third-party tracking cookies—we’re stuck with them for the foreseeable.
securityboulevard.com
July 23, 2024 at 5:05 PM
Hundreds of domains at #Squarespace were left vulnerable by a gaping security hole: Researchers say $SQSP let anyone claim any domain migrated from #GoogleDomains.

And it’s yet another story of weak #DeFi security. In #SBBlogwatch, nothing of value was lost. At #TechstrongGroup​’s #SecurityBlvd:
Squarespace Hacked — DeFi Wallets Drained (Imaginary Money Stolen)
DeFAIL: Cryptocurrency fans lose their worthless tokens via phishing attacks on decen­tral­ized finance sites.
securityboulevard.com
July 16, 2024 at 4:38 PM
#Cariad, VW Group’s software arm, made this classic error.

Personal data from hundreds of thousands of cars sat unsecured for about six months. #Volkswagen was keeping it in AWS.

The big German firm ist sehr verlegen. In #SBBlogwatch, we hope for a safer 2025. At @TechstrongGroup⁠’s @SecurityBlvd:
VW Cars Leak Private Data of 800,000 — ‘Volksdaten’
Cariad, VW Group’s software arm, made this classic error.
securityboulevard.com
December 30, 2024 at 6:01 PM
It’s no secret that cellular carrier reps are subject to bribery. Here’s a great example. Yes, again with the #SIMswapping.

It’s the soft underbelly of the insider threat model. In #SBBlogwatch, we balk at the three-Benjamin bribes. At #TechstrongGroup’s #SecurityBlvd:
SIM Swappers Try Bribing T-Mobile and Verizon Staff $300
Not OK: SMS 2FA — Widespread spam targets carrier employees, as scrotes try harder to evade two-factor authentication.
securityboulevard.com
April 16, 2024 at 6:25 PM
Widely used DNA sequencer contains several worrying vulns. #Illumina iSeq 100 can be “easily” disabled or rigged to produce false results.

But it’s only the tip of the iceberg: Many other devices are likely affected. In #SBBlogwatch, we spot the weak link in the supply chain. At #SecurityBlvd:
Insecure Medical Devices — Illumina DNA Sequencer Illuminates Risks
IEI-IEI, Oh: Running an obsolete OS, on obsolete hardware, configured with obsolete settings.
securityboulevard.com
January 8, 2025 at 6:23 PM
Huge vuln in #VersaDirector allowed #Chinese state sponsored #APT group to pivot into enterprises: #VoltTyphoon. So, yeah, this is a major problem.

Versa made the classic PR faux pas of blaming its own customers. In #SBBlogwatch, we break out the popcorn. At #TechstrongGroup⁠’s #SecurityBlvd:
China Cyberwar Coming? Versa’s Vice: Volt Typhoon’s Target
Xi whiz: Versa Networks criticized for swerving the blame.
securityboulevard.com
August 28, 2024 at 5:09 PM
#Android and #iOS18 users can communicate better, now that #iMessage supports #RCS. But there’s still no #E2EE.

Body charged with getting this sorted is the GSM Association (#GSMA). In #SBBlogwatch, we enjoy some delicious alphabet soup. At @TechstrongGroup⁠’s @SecurityBlvd
E2EE is MIA in iPhone/Android Chat — GSMA Gonna Fix it
No More Barf-Green Bubbles? GSM Association is “excited” to bring Apple and Google closer together, but encryption is still lacking.
securityboulevard.com
September 18, 2024 at 5:06 PM