<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>InfoSec on Musings by Eliza Ng</title>
		<link>https://www.eliza-ng.me/tags/infosec/</link>
		<description>Recent content in InfoSec on Musings by Eliza Ng</description>
		<generator>Hugo</generator>
		<language>en</language>
		
		
		
		
			<lastBuildDate>Sat, 21 Jan 2023 16:43:50 +0500</lastBuildDate>
		
			<atom:link href="https://www.eliza-ng.me/tags/infosec/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Norton Password Manager Accounts breached in Credential Stuffing Attack</title>
				<link>https://www.eliza-ng.me/post/nortoncredentialstuffing/nortoncredentialstuffing/</link>
				<pubDate>Sat, 21 Jan 2023 16:43:50 +0500</pubDate>
				<guid>https://www.eliza-ng.me/post/nortoncredentialstuffing/nortoncredentialstuffing/</guid>
				<description>&lt;p&gt;The news of a recent cyberattack on Norton Password Manager accounts is alarming. In December 2022, hackers successfully hacked some accounts using a credential-stuffing attack. This type of attack involves the use of stolen usernames and passwords to gain access to accounts.&lt;div class=&#39;align-center&#39;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;../nortoncredentialstuffing.png&#34; alt=&#34;img&#34; title=&#34;img&#34;&gt;&lt;/p&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;This attack is particularly concerning because it highlights a major security flaw in the way many online services store and manage passwords. Many services, including Norton Password Manager, rely on users to create strong passwords and then store them in a secure location. Unfortunately, this is not always the case.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Malicious code embedded on LCBO website</title>
				<link>https://www.eliza-ng.me/post/lcbo/lcbo/</link>
				<pubDate>Fri, 13 Jan 2023 15:43:48 +0800</pubDate>
				<guid>https://www.eliza-ng.me/post/lcbo/lcbo/</guid>
				<description>&lt;p&gt;Recently, LCBO, a popular Canadian liquor store, was the victim of a cybersecurity incident. On April 16th, LCBO discovered that malicious code had been embedded on its checkout page, allowing hackers to steal customer information.&lt;/p&gt;&#xA;&lt;div class=&#39;align-center&#39;&gt;&#xA;&lt;p&gt;&lt;img src=&#34;../DALLE-MaliciousLCBO_256.png&#34; alt=&#34;img&#34; title=&#34;img&#34;&gt;&lt;/p&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;The malicious code was designed to steal customer data, such as names, addresses, and credit card information. It is believed that the hackers were able to gain access to the website through a vulnerability in the e-commerce platform.&lt;/p&gt;</description>
			</item>
			<item>
				<title>TrustCor and Untrustworthy Certificate Authorities</title>
				<link>https://www.eliza-ng.me/post/trustcor/trustcor/</link>
				<pubDate>Thu, 15 Dec 2022 15:43:48 +0800</pubDate>
				<guid>https://www.eliza-ng.me/post/trustcor/trustcor/</guid>
				<description>&lt;p&gt;Untrustworthy certificate authorities like TrustCor can pose a serious threat to online security. TrustCor, a certificate authority that operated during the early 2010s, was responsible for issuing fraudulent digital certificates. These certificates are used to verify the identity of websites and establish secure connections between users and those websites.&lt;/p&gt;&#xA;&lt;div class=&#39;align-center&#39;&gt;&#xA;&lt;p&gt;&lt;img src=&#34;../DALLE-TrustCorSm.png&#34; alt=&#34;img&#34; title=&#34;img&#34;&gt;&lt;/p&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;TrustCor was able to issue fraudulent certificates because it was part of a network of trusted certificate authorities. These organizations are trusted by web browsers and operating systems to issue digital certificates, so when TrustCor issued a fraudulent certificate, it was automatically trusted by most users&amp;rsquo; devices.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
