The US Federal Trade Commission is taking a strong position when it comes to companies fixing any Log4j vulnerabilities. FTC threatens legal action over unpatched Log4j systems • The Register FTC warns legal action against companies who fail to mitigate Log4Shell – The Record by Recorded Future
Another Bluetooth security – this time in a child’s toy
Fisher Price Chatter Special Edition Rather than children using their imagination to make a call with these toys – an adult, with little care for security added Bluetooth for that real call experience on the playschool toy. Bluetooth reboot of pre-school play phone has privacy flaw • The Register
Log4j in China
Chinese regulator pauses partnership with Alibaba – BBC News Alibaba Cloud in trouble with Beijing for Log4J annoucement • The Register I found this video on YouTube that has a good in-depth description of the Log4j problem. It will keep you up speed with all the acronyms, shells, code etc.
Bluetooth security flawed but fixed
The Ellume – COVID-19 Home Test (ellumehealth.com) was tested and found to not be very secure. Worse compromised data was passed onto an agency vetting people entering into the USA depending on their COVID-19 status. Of course a Bluetooth-using home COVID test was cracked to fake results • The Register
Belgian defence ministry systems exploited via Log4j flaw
Belgian defence ministry admits attackers accessed its computer network by exploiting Log4j vulnerability • The Register As if you needed reminding that if the Log4j vulnerability impacts you, you need to take action.
