Archive
Are you sure you don’t want a Capital One card now?
In one of the largest breaches that affects over 6 million Canadians and potentially 100 million US customers, Capital One has revealed that it lost customer data and it was related to Security Misconfiguration. A suspect has been arrested, charged with computer fraud and abuse.
https://globalnews.ca/news/5700226/capital-one-data-breach-canada/amp/
Goodbye Docker: Purging is Such Sweet Sorrow – zwischenzugs
Now that IBM has thrown its hat in the cloud with the $34B purchase of Redhat, you should expect more innovation. This article from another WordPress site helps answer the question of why running docker is not necessary to have containerized solutions. You can minimize the attack surface and remove docker by using open source tools available to use today. https://zwischenzugs.com/2019/07/27/goodbye-docker-purging-is-such-sweet-sorrow/amp/
Honest, it was like that when I drove up?
It can be comforting to know that McD’s is still running Windows XP for their drive up kiosks…

and is still having logic based software problems like the rest of big enterprise isn’t it?
WebInspect has 3 great new features – Micro Focus Community – 1796294
Malicious Python libraries targeting Linux servers removed from PyPI | ZDNet
3 malicious libraries used in many open source packages. https://www.zdnet.com/google-amp/article/malicious-python-libraries-targeting-linux-servers-removed-from-pypi/
How to Gain Access to Domain Credentials Without Being on a Target’s Network
A two part series on password spraying that can help to illustrate the dangers with web based authentication sites.
This is a good read for those in development that are not familiar with how hackers are gaining access.
TD customers question how Visa Debit chequing accounts were compromised | CBC News
https://www.cbc.ca/news/canada/nova-scotia/spotify-charges-td-accounts-virtual-debit-cards-1.5213569
Slack resets thousands of user passwords four years after hack – The Verge
Google joins Microsoft and deprecates XSS Auditor for Chrome
In an effort to remove overhead and avoid the backlash, Chromium devs have decided to remove xss filtering from future versions of chrome.
https://portswigger.net/daily-swig/google-deprecates-xss-auditor-for-chrome