TLDR

TLDR Information Security 2024-02-12

Fake LastPass App spotted in Apple App Store 🎭, Supply Chain Vulnerability in Bazel πŸ› οΈ, Infiltrating Attacker Telegram Bots πŸ€–

πŸ”“
Attacks & Vulnerabilities

Phishception - SendGrid is Abused to Host Phishing Attacks Impersonating Itself (7 minute read)

Juniper Support Portal Exposed Customer Device Info (3 minute read)

Fake LastPass Password Manager Spotted on Apple’s App Store (3 minute read)

🧠
Strategies & Tactics

Cycode Discovers a Supply Chain Vulnerability in Bazel (9 minute read)

How We Were Able to Infiltrate Attacker Telegram Bots (5 minute read)

Secure Authentication and Authorisation in React Native (6 minute read)

πŸ§‘β€πŸ’»
Launches & Tools

StunCheck (GitHub Repo)

Jira-Lens (GitHub Repo)

MetaRadar (GitHub Repo)

🎁
Miscellaneous

Raspberry Robin Keeps Riding The Wave Of Endless 1-Days (10 minute read)

New macOS Backdoor Written in Rust Shows Possible Link with Windows Ransomware Group (6 minute read)

BGPWatch β€” A comprehensive platform for detecting and diagnosing hijacking incidents (7 minute read)

⚑️
Quick Links

Google to pay $350 million to settle shareholders' data privacy lawsuit (3 minute read)

Cyber Security Funding Insights Q4 2023: Soft landing for the economy, a bit bumpier for startups (10 minute read)

QR Codes - What’s the Real Risk? (3 minute read)

Curated news πŸ“°, research πŸ§‘β€πŸ”¬, and tools πŸ”’ for information security professionals
Join 300,000 readers for one daily email