Hackers are bypassing Twitch's 2FA by stealing the user's cookie and changing streamers' payment methods to steal their money: https://thecybersecguru.com/news/twi...ck-2fa-bypass/
Even BG Forum validates user cookies against their partial IP and user agent before doing anything important. INB4 Ksandra complains about this![]()
"Sophisticated" my ass lol, it's Twitch not even doing the bare minimum for security. What the ever living fuck. It's a basic tenant of Zero Trust, just enabling 2FA and SAML doesn't suddenly make you impervious. It's like these companies that "encrypt" their data in base64 text files on a web accessible site but oh hey it's not plaintext!A sophisticated new wave of cyberattacks is targeting Twitch streamers, successfully bypassing Two-Factor Authentication (2FA) to drain earnings.
Like Ragns said, if user agent or IP change you have to reauth.... 2FA via SMS isn't fully dead, you can't suddenly expect everyone to get a hardware token. Just handle shit better. Don't allow your 2FA SMS to spam a user to the point they just accept out of frustration...don't let your 2FA via web app to trust everything because a user authenticated one time 5hrs ago and has since seemingly moved to a different country with a new IP.The 2FA Crisis This event is a wake-up call for the entire tech industry. 2FA via SMS is dead. 2FA via App is vulnerable to cookie theft. The only true defense remaining is Hardware Security Keys (FIDO2/WebAuthn) like YubiKeys, which require a physical touch to authenticate a new session.
You can send whatever you want as the user agent string, so it doesn't increase security notably to include it, but I guess it doesn't hurt. IP isn't completely foolproof either but it's at least harder to spoof. You're basically checking for hacker incompetence, but most of them are incompetent.
IMO it's so stupid that Twitch, a company backed by AWS, has the same security failures as PHP-Nuke in the early 2000s.
Nike - 1.4TB, 200k of the files have been leaked to the dark web
https://arstechnica.com/security/202...-chain-attack/
Notepad++ said that officials with the unnamed provider hosting the update infrastructure consulted with incident responders and found that it remained compromised until September 2. Even then, the attackers maintained credentials to the internal services until December 2, a capability that allowed them to continue redirecting selected update traffic to malicious servers. The threat actor “specifically targeted Notepad++ domain with the goal of exploiting insufficient update verification controls that existed in older versions of Notepad++.” Event logs indicate that the hackers tried to re-exploit one of the weaknesses after it was fixed but that the attempt failed.
According to independent researcher Kevin Beaumont, three organizations told him that devices inside their networks that had Notepad++ installed experienced “security incidents” that “resulted in hands on keyboard threat actors,” meaning the hackers were able to take direct control using a Web-based interface. All three of the organizations, Beaumont said, have interests in East Asia.
This is hilariously bad...like wipe your system bad but it's too late now anyways
suppose I'm lucky that I never reinstalled it after I reinstalled windows
Still the best notepad program around so hopefully they're alright in the long run
The auto updater is what got compromised. Installing through the website was/is fine
Lol. thank goodness for a while I was updating manually. It's still one of my go tos for a lot of script stuff. Thank heaven for Patch My PC, which I use once a week.
I'm gonna keep to updating manually for now.
Haven't used it in forever. Looks like I'm on 8.7.4.0
If you were on version 8.8.2 through 8.8.8 you'd need to be concerned
8.6.x lol it is and always has been one of my biggest procrastinated updates as far as apps are concerned. Lucky me
I wonder how this could have happened?
cough:trumpexecutiveorder14306:cough
https://venturebeat.com/security/cla...security-stack
The Mexican government via Claude and ChatGPT. 150GB of data including 195M taxpayer records, voter records, government credentials, & civil registry files. Despite both chat bots having guardrails against such actions, users used prompts that gave a detailed step by step guide on how to carry out the attacks, which is something that the programmers hadn't considered.
Claude accidentally posted their entire source code during an update and now it's all over the internet for free; someone rewrote it from scratch so their version isn't subject to DMCA strikes and is presumably available forever.
Sent from my SM-S938U using Tapatalk