slack

Disney 1.2 TB Slack Hack: NullBulge Claims Leak is its Own
Richi Jennings | | Disney, hacktivism, Hacktivist, Hacktivists, hacktivity, NullBulge, SB Blogwatch, slack, Slack breach
Steamboat bloat: Hacktivist group wields infostealer Trojan, leaks 1,200 GB of mouse droppings ...
Security Boulevard

Microsoft’s Copilot+ Recall Feature, Slack’s AI Training Controversy
Tom Eston | | AI, AI training, chat, Copilot, Cyber Security, Cybersecurity, Data Privacy, Digital Privacy, Episodes, Information Security, Infosec, LLM, machine learning, Microsoft, ML, Podcast, Podcasts, policy, Privacy, Recall, security, slack, technology, Weekly Edition, Windows
Episode 331 of the Shared Security Podcast discusses privacy and security concerns related to two major technological developments: the introduction of Windows PC’s new feature ‘Recall,’ part of Microsoft’s Copilot+, which captures ...

Why Smart SOAR is the Best SOAR for Slack
Pierre Noujeim | | Automated Incident Alerting, Integration Guide, Post-Incident Review, Real-time Incident Discussion, slack, Smart SOAR, SOAR, SOAR Integration
Effective communication is a critical component in incident response, often making the difference between rapid resolution and prolonged impact. This article explores how the integration between Smart SOAR and Slack provides a ...

Patch EVERYTHING: Widely Used ‘WebP’ Code has Critical Bug
Richi Jennings | | Buffer Overflow, buffer overflow attack, Buffer Overflow Vulnerabilities, buffer overflows, Chrome, Chromium, edge, Electron, Exploitable Vulnerabilities, Firefox, google, Heap Overflow, libwebp, Open Source and Software Supply Chain Risks, open source software supply chain, open source software supply chain security, opera, SB Blogwatch, secure software supply chain, slack, software supply chain, software supply chain hygiene, software supply chain risk, Software Supply Chain risks, software supply chain security, Software Supply Chain Security Risks, thunderbird, WebP
WebP FAIL. Critical vuln in libwebp: Go get updates to Chrome, Firefox, Edge, Slack and more ...
Security Boulevard

Slack Security Breach Highlights Risks of SaaS Session Hijacking
Emile Antone | | CrowdStrike, FEATURED, Incident Response, SaaS Security, SaaS threat detection, Security Advisories, slack, Slack breach
Slack Attack: Employee Tokens Stolen On December 29, 2022, workforce collaboration application, Slack posted a security update that announced the discovery of unauthorized access to some of its code repositories. The company ...

CircleCI Rotates GitHub OAuth Tokens After Security Incident
Following a security incident, CircleCI has completed the process of rotating GitHub OAuth tokens for their customers. CircleCI said Saturday that while customers could still rotate their own tokens, it has “confidence ...
Security Boulevard
Slack GitHub Account Hacked via Stolen Employee API Token
Ivanwallarm | | api leak, API security, Cloud Security, Data breach, DEVOPS, Different attack types, Incident, Researcher Corner, security incidents, slack, Token Leak, Web Application Security
On December 29, 2022, Slack was alerted to suspicious activity on their GitHub account. Upon investigation, the company discovered that a limited number of employee tokens had been stolen and misused to ...

Slack App Leaked Hashed User Passwords for 5 YEARS
Richi Jennings | | api, I’m willing to bet someone JSON.stringify’d the entire user object without realizing the password hash is in there, Password, Salesforce, SB Blogwatch, slack, slack technologies, Slack Vulnerability
Since 2017, if you’ve invited anyone to a Slack workspace, your password has leaked. How could this have happened? ...
Security Boulevard

Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code
BrianKrebs | | A Little Sunshine, Amtrak, Apple, BitBucket, Breadcrumbs, Dan Goodin, Doxbin, Electronic Arts, emergency data request, Everlynn, Flashpoint, Genesis, Globant, Iqor, KT, Lapsus$, Lapsus$ Jobs, Michelin, Microsoft, Mobile Device Management, Mox, Ne'er-Do-Well News, Nvidia, Recursion Team, Russian Market, Samsung, SASCAR, SIM swapping, slack, source code theft, swatting, T-Mobile, T-Mobile Atlas, WhiteDoxbin
KrebsOnSecurity recently reviewed a copy of the private chat messages between members of the LAPSUS$ cybercrime group in the week leading up to the arrest of its most active members last month ...

Bolster Playbooks get the hookup with new API connector
Bolster has recently added the availability of a Playbook API connector that can help streamline the incredibly important work needed to analyze suspicious and fraudulent sites ...