6 hours ago · 10 min read2023 words · Tech · hide · 0 comments

OverviewThis week put exposed edge systems, trusted login paths, and internet-facing business software back at the front of the queue. SonicWall and Sangoma confirmed exploitation against remote-access and phone-system products, Google patched another Chrome zero-day, and CISA added seven flaws spanning appliances, developer infrastructure, Python services, and AI tooling to its exploited-vulnerability catalog.The incident side showed the same trust problem from a different angle. A Lenovo identity path opened Dropbox accounts without their normal passwords, a dark-web service offered an enormous collection of identity-document scans, and court backup data was accessed through a vendor cloud environment. My practical takeaway is to verify every inherited trust path, not just the product name on the contract or the asset name in the inventory.Reality check: A patch closes the documented entry point. It does not erase sessions, shells, tokens, or data access that may have happened…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.