احذر استعمال الراوتر القديم يزيد من فرص الاختراق almasryalyoum.com - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from almasryalyoum.com Daily Mail and Mail on Sunday newspapers.
Peloton’s Leaky API Potentially Exposed Riders’ Personal Information May 6, 2021 06:36 GMT
· Comment
Peloton s Leaky API
According to a report from TechCrunch, an outdated version of Peloton’s API, the program that enables the company’s bikes and recall treadmills to communicate with its servers, might have revealed private customer profiles. Peloton claims to have over 3 million subscribers and over 1 million connected fitness profiles, so the leak may be massive.
Jan Masters, a security researcher at Pen Test Partners, discovered the bug on January 20th and reported it to Peloton, but the company is only now confirming that it has been patched.
BBC News
By Jane Wakefield
image captionModems need crucial software updates and secure passwords
Millions of people could be using outdated routers that put them at risk of being hacked, Which? has warned.
The consumer watchdog examined 13 models provided to customers by internet-service companies such as EE, Sky and Virgin Media and found more than two-thirds had flaws.
It estimated about six million people could have a device not updated since 2018 or earlier.
So, in some cases, they would not have received crucial security updates.
Weak passwords
weak default passwords cyber-criminals could hack were found on most of the modems
Have I Been Pwned founder’s keynote offered a sobering counterpoint to the well-meaning ‘World Password Day’
Imagine a parent’s terror when the geolocation of their child’s smart watch suddenly switches from tennis practice to the middle of the ocean.
This was precisely the scenario simulated by Ken Munro of UK infosec firm Pen Test Partners via exploitation of an insecure direct object reference (IDOR) vulnerability in an IoT device, and with help from Troy Hunt, creator of data breach record index Have I Been Pwned, and his daughter.
This was one of many eye-opening tales of shoddy security behind the “endless flow of data” into Have I Been Pwned recounted today (May 6) during Hunt’s keynote address at the all-virtual Black Hat Asia 2021.