Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. πΊπΈ We’ve known, unofficially, that the US government uses commercial data brokers to by-pass the 4th amendment and get geolocation data on US citizens for some time, but now it’s on the record: FBI […]
Continue readingCategory: Security Bits
Security Bits β 15 March 2026
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. A timely reminder to keep your routers patched and to bin un-supported models via listener BG in the Podfeet Slack: 14,000 routers are infected by malware thatβs highly resistant to takedowns β arstechnica.com/β¦ (ASUS […]
Continue readingSecurity Bits β 1 March 2026
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Notepad++ boosts update security with βdouble-lockβ mechanism β www.bleepingcomputer.com/β¦ (Following the embarrassing compromise of their update infrastructure that required all users to do a manual upgrade late last year) π¬π§ A little movement on […]
Continue readingSecurity Bits – 15 February 2026
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Both a good reminder that it’s important to be careful where you get your software from, and an illustration of how the residential proxy networks we recently talked about are built: Laced 7-Zip installers […]
Continue readingSecurity Bits β 1 February 2026
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. A timely reminder both that malicious ads remain a big problem, and that Mac users are not immune to malware: Mac malware is sneaking into some sponsored Google ads β appleinsider.com/β¦ Deep Dive β […]
Continue readingSecurity Bits β 18 January 2026
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Some context for a story we covered many times in 2025: Amazon blocked 1,800 employment attempts by North Korean agents β cyberinsider.com/β¦ Yet another reason to steer clear of VS Code forks: VSCode IDE […]
Continue readingSecurity Bits β 18 December 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Yet another real-world example of the dangers of poor secret hygiene: Over 10,000 Docker Hub images found leaking credentials, auth keys β www.bleepingcomputer.com/β¦ π¬π§ UK fines LastPass Β£1.2M over 2022 data breach impacting 1.6 […]
Continue readingSecurity Bits β 6 December 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. A good example of why Bart has been going on and on about secret management in recent conversations with Allison: Massive GitLab scan finds 17,000+ valid secrets in public repositories β cyberinsider.com/β¦ A nice […]
Continue readingSecurity Bits β 23 November 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Google backpedals on new Android developer registration rules β www.bleepingcomputer.com/β¦ (Android is not becoming quite as Apple-like after all β better for Linux geeks, worse for regular folks) Deep Dive β that Cloudflare Outage […]
Continue readingSecurity Bits β 9 November 2025
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. More evidence of the dangers of Agentic Browsers: ChatGPT Atlas Browser Can Be Tricked by Fake URLs into Executing Hidden Commands β thehackernews.com/β¦ Related Article: Be Cautious with Agentic Web Browsers β tidbits.com/β¦ (by […]
Continue reading