Kenn White

@kennwhite
6.6K Followers
631 Following
2.1K Posts
cryptography • neuro • cloud • biscuits
ORD-DCA-NYC-BCN ✈️
twitterhttps://twitter.com/kennwhite
webhttps://opencryptoaudit.org/people

NEW, by me: A hacking campaign targeted high-profile Gmail and WhatsApp users across the Middle East this week, sent as a phishing lure over WhatsApp.

I obtained a copy of the phishing page and analyzed it with the help of experts. The attack aimed to steal passwords, hijack WhatsApp accounts, and grab victims' location data.

But a bug in the code also *exposed* victims' data, allowing us to see dozens of people who had fallen victim.

More: https://techcrunch.com/2026/01/16/how-a-hacking-campaign-targeted-high-profile-gmail-and-whatsapp-users-across-the-middle-east/

How a hacking campaign targeted high-profile Gmail and WhatsApp users across the Middle East | TechCrunch

The phishing campaign targeted users on WhatsApp, including an Iranian-British activist, and stole the credentials of a Lebanese cabinet minister and at least one journalist.

TechCrunch

Day in the life of a Black Hat reviewer

submission #37/219: Here's 2 years of work in which we pwned several Internet exchanges and ISPs, spent 6 mos coordinating disclosure w/ 16 vendors, and a completed 40 slide deck & full whitepaper.

#38: Cybersecurity is a serious concern to CEOs nowadays…

This week saw a scramble to save the CVE Program after federal funding was set to expire. The program's long-term future remains unclear. @lhn dives in.

https://www.wired.com/story/cve-program-cisa-funding-chaos/

‘Stupid and Dangerous’: CISA Funding Chaos Threatens Essential Cybersecurity Program

The CVE Program is the primary way software vulnerabilities are tracked. Its long-term future remains in limbo even after a last-minute renewal of the US government contract that funds it.

WIRED

NEW: U.S. Treasury officials say the department was hacked in early December by Chinese government hackers, which gained remote access to workstations and obtained unclassified documents.

More + Treasury's letter to lawmakers, which we've published: https://techcrunch.com/2024/12/30/us-treasury-says-china-stole-documents-in-major-cyberattack/

US Treasury says China accessed government documents in 'major' cyberattack | TechCrunch

Treasury officials attributed the December theft of unclassified documents to China.

TechCrunch

Grab some coffee, it's ~ this week in security ~

• Cleo software hit by zero-day hacks
• China spying on calls of senior US politicians
• DOJ has a busy week indicting North Korean IT workers
• SEC's cyber disclosure rules are a hot mess
• Yahoo Paranoids loses 25% of staff this year
• Krispy Kreme hacked; Rhode Island, too.
• Plus: brand new cyber cat, the happy corner and more.

Sign up/RSS: https://this.weekinsecurity.com

Read online: https://mailchi.mp/weekinsecurity/this-week-in-security-december-15-2024-edition

Support/donate: https://ko-fi.com/thisweekinsecurity

~this week in security~

a free cybersecurity newsletter by @zackwhittaker, delivered weekly.

Leopold wishes you a happy Saturday.
Why yes, yes I am setting up DKIM & DMARC records on the horrific platform that is Google Workspaces on Thanksgiving morning. As one does.
Popped up on my phone today. Sebastian about 4 years ago.
🚨 Timeline cleanse.