Happy 14th Birthday, KrebsOnSecurity!

Nor do I wish to hold forth about whatever cyber horrors may await us in 2024.
I do want to thank you all for your continued readership, encouragement and support, without which I could not do what I do.
As of this birthday, I've officially been an independent investigative journalist for longer than I was a reporter for The Washington Post.
Of course, not if you count the many years I worked as a paperboy schlepping The Washington Post to dozens of homes in Springfield, Va. True story: At the time I was hired as a lowly copy aide by The Washington Post, all new hires - everyone from the mailroom and janitors on up to the executives - were invited to a formal dinner in the Executive Suite with the publisher Don Graham.
On the evening of my new hires dinner, I was feeling underdressed, undershowered and out of place.
After wolfing down some food, I tried to slink away to the elevator with another copy aide, but was pulled aside by the guy who hired me.
I was 23 years old, and I had no clue what to say except to tell him that paper route story, and that I'd already been working for him for half my life.
Mr. Graham laughed and told me that was the best thing he'd heard all day.
Which of course made my week, and made me feel more at ease among the suits.
I remain grateful to WaPo for instilling many skills, such as how to distill technobabble into plain English for a general audience.
How to make people the focus of highly technical stories.
Because people - and their eternal struggles - are imminently relatable, regardless of whether one has a full grasp of the technical details.
Words fail me when trying to describe how grateful I am that this whole independent reporter thing still works, financially and otherwise.
I mostly just keep my head down researching stuff and sharing what I find, and somehow loads of people keep coming back to the site.
Another milestone of sorts: We've now amassed more than 52,000 subscribers to our email newsletter, which is a fancy term for a plain text email that goes out immediately whenever a new story is published here.
Subscribing is free, we never share anyone's email address, and we don't send emails other than new story notifications.
A friendly reminder that while you may see ads at the top of this website, all two-dozen or so ad creatives we run are vetted by me and served in-house.
Our advertising partners are how we keep the lights on over here.
In case you missed any of them, here are some of the most-read stories published by KrebsOnSecurity in 2023.


This Cyber News was published on krebsonsecurity.com. Publication date: Fri, 29 Dec 2023 22:25:25 +0000


Cyber News related to Happy 14th Birthday, KrebsOnSecurity!

Happy 14th Birthday, KrebsOnSecurity! - Nor do I wish to hold forth about whatever cyber horrors may await us in 2024. I do want to thank you all for your continued readership, encouragement and support, without which I could not do what I do. As of this birthday, I've officially been an ...
11 months ago Krebsonsecurity.com
ID Theft Service Resold Access to USInfoSearch Data - One of the cybercrime underground's more active sellers of Social Security numbers, background and credit reports has been pulling data from hacked accounts at the U.S. consumer data broker USinfoSearch, KrebsOnSecurity has learned. Since at least ...
1 year ago Krebsonsecurity.com
Ten Years Later, New Clues in the Target Breach - On Dec. 18, 2013, KrebsOnSecurity broke the news that U.S. retail giant Target was battling a wide-ranging computer intrusion that compromised more than 40 million customer payment cards over the previous month. Ten years later, KrebsOnSecurity has ...
1 year ago Krebsonsecurity.com
Juniper Support Portal Exposed Customer Device Info - Until earlier this week, the support website for networking equipment vendor Juniper Networks was exposing potentially sensitive information tied to customer products, including which devices customers bought, as well as each product's warranty ...
10 months ago Krebsonsecurity.com
CEO of Data Privacy Company Onerep.com Founded Dozens of People-Search Firms - The data privacy company Onerep.com bills itself as a Virginia-based service for helping people remove their personal information from almost 200 people-search websites. An investigation into the history of onerep.com finds this company is operating ...
9 months ago Krebsonsecurity.com
Arrests in $400M SIM-Swap Tied to Heist at FTX? - Three Americans were charged this week with stealing more than $400 million in a November 2022 SIM-swapping attack. The U.S. government did not name the victim organization, but there is every indication that the money was stolen from the now-defunct ...
10 months ago Krebsonsecurity.com
Treasury Sanctions Creators of 911 S5 Proxy Botnet - The U.S. Department of the Treasury today unveiled sanctions against three Chinese nationals for allegedly operating 911 S5, an online anonymity service that for many years was the easiest and cheapest way to route one's Web traffic through ...
6 months ago Krebsonsecurity.com
CVE-2024-51757 - happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the host via a script tag. This would execute code in the user context of happy-dom. Users are ...
1 month ago Tenable.com
CVE-2016-2183 - The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a ...
1 year ago
CVE-2013-6241 - The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, in certain user-id sharing scenarios, does not properly construct a SQL statement for next-year birthdays, which allows remote ...
9 years ago
CVE-2021-24292 - The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.17.0 have a number of widgets that are vulnerable to stored Cross-Site Scripting(XSS) by lower-privileged users such as ...
3 years ago
CVE-2023-41236 - Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Happy addons Happy Elementor Addons Pro plugin < 2.8.0 versions. ...
1 year ago
CVE-2023-51676 - Server-Side Request Forgery (SSRF) vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.9.1.1. ...
11 months ago
CVE-2023-6632 - The Happy Addons for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via DOM in all versions up to and including 3.9.1.1 (versions up to 2.9.1.1 in Happy Addons for Elementor Pro) due to insufficient input sanitization ...
11 months ago Tenable.com
CVE-2024-29108 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.1. ...
9 months ago Tenable.com
CVE-2024-32698 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.10.4. ...
7 months ago
Happy Holidays and Happy New Year Cisco Distributors - We have found ourselves in this wonderful season again. A season of giving, sharing, and remembering-a unique opportunity to slow down and be with those who bring you immense joy and peace. We have worked hard this year and we've all exhibited ...
1 year ago Feedpress.me
CVE-2024-24833 - Missing Authorization vulnerability in Leevio Happy Addons for Elementor.This issue affects Happy Addons for Elementor: from n/a through 3.10.1. ...
7 months ago
CVE-2024-47357 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Leevio Happy Addons for Elementor allows Stored XSS.This issue affects Happy Addons for Elementor: from n/a through 3.12.0. ...
2 months ago
CVE-2024-48045 - Missing Authorization vulnerability in Leevio Happy Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Happy Addons for Elementor: from n/a through 3.12.3. ...
1 month ago Tenable.com
CVE-2024-53269 - Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and ...
3 days ago Tenable.com
No one's happy with latest US cyber incident reporting plan The Register - Organizations that sell IT services to Uncle Sam are peeved at proposed changes to procurement rules that would require them to allow US government agencies full access to their systems in the event of a security incident. The rules were unveiled in ...
10 months ago Go.theregister.com
Wordfence Intelligence Weekly WordPress Vulnerability Report (September 23, 2024 to September 29, 2024) - Software Name Software Slug 012 Ps Multi Languages 012-ps-multi-languages ABC APP CREATOR abcapp-creator Absolute Reviews absolute-reviews Accordion accordions Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads quick-adsense-reloaded Advanced File ...
2 months ago Wordfence.com
Okta: Breach Affected All Customer Support Users - When KrebsOnSecurity broke the news on Oct. 20, 2023 that identity and authentication giant Okta had suffered a breach in its customer support department, Okta said the intrusion allowed hackers to steal sensitive data from fewer than one percent of ...
1 year ago Krebsonsecurity.com
The Fake Browser Update Scam Gets a Makeover - One of the oldest malware tricks in the book - hacked websites claiming visitors need to update their Web browser before they can view any content - has roared back to life in the past few months. New research shows the attackers behind one such ...
1 year ago Krebsonsecurity.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)