Information Security Sharing Group Hong Kong

Information Security Sharing Group Hong Kong This group is originally named "CISSP Hong Kong Study Group" , starting from Mar 7, 2016, it is renamed as "Information Security Sharing Group Hong Kong"

To motivate interests on Information Security, we will also post Security News or Information in this page. (All commercial adv will be deleted immediately and user will be blocked to post any message and reported to Facebook as well). Commercial advertisement is strictly prohibited in the page and will be deleted immediately.

22/02/2025

呢單嘢可以講充滿花生味,究竟係無間道?定係黑客牛B?

https://www.securitymagazine.com/articles/101343-vulnerability-discovered-in-subarus-connected-vehicle-serviceResearch f...
01/02/2025

https://www.securitymagazine.com/articles/101343-vulnerability-discovered-in-subarus-connected-vehicle-service

Research from Shubham Shah and Sam Curry reveals Subaru’s STARLINK connected vehicle service contains a vulnerability that permits unrestricted, targeted access to all user accounts and vehicles in the United States, Canada, and Japan.

By exploiting this vulnerability, a malicious actor could obtain sensitive data and control if they also had the victim’s surname and ZIP code, phone number, email address, or license plate. With the listed information, a malicious actor could:

- Retrieve the location of a vehicle
- Remotely lock, unlock, start or stop a vehicle
- Obtain a vehicle’s location history from the past year
- Retrieve miscellaneous data (such as odometer reading, previous owners, call history, sales history, and more)

“Researchers Shubham Shah and Sam Curry identified hardcoded credentials within JavaScript files and then allowed them to replace employee email addresses, reset passwords without confirmation tokens, and bypass 2FA by modifying the UI, thus giving them access to the admin panel. Once inside the admin panel they essentially gained ‘God Mode’ access, enabling them to search for any STARLINK-connected vehicle.

Subaru’s STARLINK connected vehicle service contains a vulnerability that permits access to user accounts and vehicles.

https://unwire.hk/2025/01/26/oppo-fineasy-app/fun-tech/
29/01/2025

https://unwire.hk/2025/01/26/oppo-fineasy-app/fun-tech/

由廠商推出的手機系統更新通常都值得安裝,不過最近泰國的 Oppo 和 Realme 推出的系統更新,就竟然包含了一款貸款 App,而且擁有大量權限又無法移除,在當地引起很大爭議,最近才終於陸續平息。

https://www.facebook.com/share/18hU5QfkM5/?mibextid=WC7FNe
10/12/2024

https://www.facebook.com/share/18hU5QfkM5/?mibextid=WC7FNe

📣 DEVCORE CONFERENCE 回歸 —— 售票開跑 🔥

攻擊導向資安技術研討會—— DEVCORE CONFERENCE 將在 2025/03/15(六)登場!

我們深信,󠀠厚實的技術是攻擊及防禦的根本,最佳的防禦策略更需要從駭客視角出發,理解攻擊者的思路,搶先掌握新型攻擊手法。
一起聚焦技術核心,一探網路安全在各領域的不同應用,包含但不限於 、 #開源衛星、 大賽,更有這些年來超過 100 場 #紅隊演練 的洞察分享,無論你是紅隊或藍隊,一定都會有所收穫!

-
󠀠【關於 DEVCORE CONFERENCE 2025】
時間:2025/03/15(六)
地點:TICC 台北國際會議中心 201 會議室(台北市信義區信義路五段 1 號)
現正販售中:
✨ 早鳥票 $5,500 - 限時販售
✨ 學生票 $2,000 - 限量 50 名
✨ 夥伴專享票,將依團購票券張數享有不同優惠 - 若您為政府機關、資通訊/資安經銷廠商,並有購買 3 張以上票券需求,敬請聯繫 [email protected]

-
購票請至 KKTIX 活動頁面
👉 https://devcore.kktix.cc/events/devcoreconf2025

更即時及完整的議程資訊,請參考 DEVCORE CONFERENCE 官方網站 󠀠
👉 https://conf.devco.re/2025/
󠀠󠀠


#資安研討會
#紅隊演練

04/11/2024

唯聽香港聽覺及言語中心,以及聽健言語及聽覺中心發生資料外洩事故,受影響人數近15萬人,大部分是病人,亦有數十位現職及前員工,外洩的資料

Gmail Security—Viral AI Hack Poses Critical Question For 2.5 Billion Users (forbes.com)https://www.forbes.com/sites/dave...
22/10/2024

Gmail Security—Viral AI Hack Poses Critical Question For 2.5 Billion Users (forbes.com)

https://www.forbes.com/sites/daveywinder/2024/10/21/gmail-security-viral-ai-hack-poses-critical-question-for-25-billion-users/

Ten days ago, I wrote an article warning Gmail users about a newly uncovered security threat powered by AI that was convincing enough almost to fool a professional security consultant. That story captured the imagination of more than two million readers as it quickly went viral. In its wake, a question remains: does AI make Gmail a safer email service or a more dangerous one? As is often the case, the answer is complicated and nuanced, but it’s important nonetheless, so let’s try and clarify it.

As I reported at the time, in what would become a viral news story about Gmail security, it all started when a professional security consultant, Sam Mitrovic, posted an innocent enough reply to a message on X saying that he’d come close to getting fooled by a “super realistic AI scam call” designed to hack his Gmail account. I’d recommend reading the original article for the full details of what happened, but here’s the TL;DR version. A notification requesting a Google account recovery approval is received, followed by a missed phone call. Seven days later another such notification and call were made, but the telephone was answered this time. What followed was a convincing conversation with what appeared to be a genuine Google number and a real support technician. Long story short, it was neither: it was an AI-powered voice on the other end of the call and one that nearly fooled Mitrovic.

Ultimately, then, this was a phishing attack. Phishing is nothing new. AI deepfakes are nothing new. However, combining the two to target Gmail users in such a convincing way is fast becoming the new normal. “The main reason social engineering is so effective is that it keeps evolving,” Anna Collard, a cybersecurity evangelist at KnowBe4, said. “The rise of deepfakes, convincingly real images and videos artificially generated, has further exacerbated the potential for misinformation and manipulation.”

According to the newly published Cybersecurity Survey Report 2024: Navigating the New Frontier of Cyber Challenges from Kaseya, hackers are leveraging advances in AI technology to “launch more sophisticated cyberattacks at a faster pace than ever before.” That much, I think, we can all agree upon. Where things start to get a bit more nuanced is when we look at how AI can help on the defensive side of the cybersecurity fence. “More than half of survey participants say they believe AI will help them be more secure,” Chris Mckie, vice president of product marketing at Kaseya, said, adding that “more research and clarity around the benefits and limitations of AI as a cybersecurity tool is needed.”

As a new Gmail security warning goes viral, all users should ask whether AI is an email threat or a safety shield.

Address

Mong Kong
Kung Tong
00000

Website

Alerts

Be the first to know and let us send you an email when Information Security Sharing Group Hong Kong posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share