Data wiped in IHG hack for revenge, Vietnamese couple says

Sicherheit (Pexels, allgemeine Nutzung)[German]More information on the hack of InterContinental Hotels Group PLC (IHG) a few weeks ago. What was originally planned as blackmail then led to the deletion of extensive data when the blackmail went wrong. This is what a couple from Vietnam reportedly confessed to the British BBC.

Continue reading

Posted in Security | Tagged | Leave a comment

Chrome & Edge may send personal data (including passwords) to Google and Microsoft respectively

Sicherheit (Pexels, allgemeine Nutzung)[German]Unpleasant discovery that a security researcher has made public the days. The Google Chrome browser, and also the Chromium-based Microsoft Edge browser, may transmit in some cases personal data from forms to Google and Microsoft (in the case of Edge). This also includes passwords, by the way. The Extended Spell Checker in the browser or in the MS Editor is probably responsible for this.

Continue reading

Posted in browser, Linux, macOS, Security, Windows | Tagged , , | Leave a comment

LastPass confirmed: Attackers had access to internal systems for four days

Sicherheit (Pexels, allgemeine Nutzung)[German]The developers of the web-based password manager online service LastPass announced this week that attackers had access in August 2022 to internal systems for four days. Then the unauthorized access has been detected. However, the attackers probably did not succeed in gaining write access to the development environment and modifying code of the LastPass software or accessing sensitive user data.

Continue reading

Posted in Security | Tagged | 2 Comments

Microsoft Teams stores authentication tokens as plain text in Windows, Linux, Macs

Sicherheit (Pexels, allgemeine Nutzung)[German]The desktop app for Microsoft Teams stores authentication tokens as plain text on the Linux, macOS, and Windows platforms. This allows attackers to access accounts using these tokens even if multi-factor authentication (MFA) has been enabled. Customers should rely on Teams web applications or monitor access to MS Teams data through processes, as Microsoft will not close this vulnerability immediately.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

GhostSec targets again water hygiene

Sicherheit (Pexels, allgemeine Nutzung)[German]In early September, OTORIO reported that the GhostSec hacktivist group had penetrated 55 Berghof PLC systems in Israel. Now the hacktivist group published another report claiming to have successfully penetrated more industrial control systems. OTORIA provided me with some information about these attacks, which I publish here on the blog.

Continue reading

Posted in Security | Tagged | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Bitdefender has released a Decryptor for LockerGoga encrypted files

Sicherheit (Pexels, allgemeine Nutzung)[German]Small note for people who have fallen victim to LockerGoga ransomware. Bitdefender has informed me that the company has released a universal decryptor. This allows victims of all previous LockerGoga ransomware attacks to recover their encrypted files.  Europol, the NoMoreRansom Initiative, the Zurich Public Prosecutor's Office and the Zurich Cantonal Police participated in the development of the decryptor, which is freely available for download.

Continue reading

Posted in Security, Software | Tagged | Leave a comment

Google faces up to 25 billion euros in "claims" after lawsuits in UK and EU

Paragraph[German] Google and its parent Alphabet are facing further legal trouble, as lawsuits have been filed in the EU and the UK. It's about "damages" for publishers who feel they have been harmed by Google's actions in the area of advertising technology. In the worst case scenario, the publishers' claims could add up to 25 billion euros if these lawsuits are successful.

Continue reading

Posted in General | Tagged | Leave a comment

Microsoft Edge 105.0.1343.42

EdgeMicrosoft has updated the Edge browser in the stable channel to version 105.0.1343.42 on September 15, 2022. The release notes don't reveal much – Chrome security fixes have been integrated into the new version.

Posted in browser, Software, Update | Tagged , | Leave a comment

Update for Exchange Extended Protection script, but still errors

Exchange Logo[German]August 2022 security updates for Microsoft Exchange (on-premises solution) requires, to enable Extended Protection (EP) to close all vulnerabilities. The activation is done via script, which Microsoft provided – but this script caused isses. Now Microsoft has released an updated script. However, there are also errors in this script, a fix should be made with the "next update".

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Ride share service provider Uber investigates hack (Sept. 2022)

Sicherheit (Pexels, allgemeine Nutzung)[German] U.S. ride share service provider Uber appears to have been the victim of a hack, with an 18-year-old penetrating the provider's system. Uber employees initially thought the whole thing was a joke. The hacker claims to have entered the Uber system "for fun", but then probably found a PowerShell script on a share, which contained administrator credentials. And now the hacker is probably an administrator of the Uber IT systems.

Continue reading

Posted in Security | Tagged | Leave a comment