Content Paint
Edward Targett

Edward Targett

Ed is a co-founder of The Stack. He previously edited Computer Business Review. He has also covered energy markets. He started his journalism career on local papers. He left school at 15 and has made a living asking "but why?" ever since.

Hackers could have taken over every single .ai domain

"It is clear that the internet is so, so brittle" and possibly held together with duct tape

VMware zero day used to hack defence, tech companies

The threat group has also used a wide range of attacker scripts to get vpxuser credentials, enumerate ESXi hosts and their guest VMs, and manipulate connected ESXi host firewall rules in order to steal data.

MFA is no protection against this critical new Fortinet vulnerability, CVE-2023-27997

"It is a pre-auth RCE [and] has been proven to be exploitable in a consistent manner; we found it during a Red Team engagement and have exploited it remotely..."

HMG eyes £800 million new Open Banking framework

HMG makes a lot of payments: The Department for Work and Pensions alone makes 2.5 million+ daily that are worth £3.7 billion per week.

Zoom Europe data storage privacy settings

Careful now, read the small print: Account, diagnostic data will stay in the US and Zoom can't promise calls and recordings won't pass through data centres you opted out of...

Tech services firm Persistent is rolling out an AI coding companion to 16,000 engineers. Its CTO recognises the risk

“The legal structure of contracts between a services company and customers simply doesn't allow us to unilaterally activate this kind of tooling. We have to have customer buy-in."

BBC, BA suffer data breaches in wake of MOVEit attacks

The Stack is seeing exposed instances associated with scores of high profile blue chips

There’s yet another CVSS 10, sandbox escape vulnerability in this widely used software library

23 million downloads last month. Four CVSS 10 vulnerabilities reported within weeks. Public exploits shared...

UPDATED: File transfer software under active attack. Banks, gov't hit as CVE, new IOCs released

Admins should urgently modify firewall rules to deny HTTP and HTTPs traffic to MOVEit Transfer on ports 80 and 443. (Also, can we start fuzzing for SQL Injection properly, please?)

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.