Monthly Shaarli

All links of one month in a single page.

March, 2024

Million Dollar Dissidents and the Rest of Us - Bill Marczak and John Scott-Railton - 33rd Chaos Communication Congress (33C3)
thumbnail

In August 2016, Apple issued updates to iOS and macOS that patched three zero-day vulnerabilities that were being exploited in the wild to remotely install persistent malcode on a target’s device if they tapped on a specially crafted link. We linked the vulnerabilities and malcode to US-owned, Israel-based NSO Group, a government-exclusive surveillance vendor described by one of its founders as “a complete ghost”.

How Spoutible’s Leaky API Spurted out a Deluge of Personal Data - Troy Hunt
thumbnail

Ever hear one of those stories where as it unravels, you lean in ever closer and mutter “No way! No way! NO WAY!” This one, as far as infosec stories go, had me leaning and muttering like never before. Here goes:
Last week, someone reached out to me with what they claimed was a Spoutible data breach obtained by exploiting an enumerable API. Just your classic case of putting someone else's username in the URL and getting back data about them, which at first glance I assumed was another scraping situation like we recently saw with Trello. They sent me a file with 207k scraped records and a URL that looked like this...

npm install everything, and the complete and utter chaos that follows - Evan Boehs

how one little joke can get so, so out of hand