• Cyber Sizzler
  • Posts
  • There’s 1 Thing That Gun Owners Universally Hate

There’s 1 Thing That Gun Owners Universally Hate

ESET confirms 1st UEFI boot kit; this is a big...big deal

Welcome to the Cyber Sizzler - the only cybersecurity newsletter that helps industry professionals get 2% better every day.

We’re the weathermen of cybersecurity newsletters, but instead of predictions we bring the heat; news & tools you can use.

New format worked well for us, so we’re going to keep it for a while. Instead of the repacked crap you find elsewhere, we’ll dig up links to original reporting (with a summary if it’s a dense report), and tools you can use. We hope you enjoy and share with your friends.

🌶️

ON DECK FOR TODAY

  • HEATING UP - USSS & ICE conduct warrantless surveillance

  • DUMPSTER FIRE - There’s 1 Thing That Gun Owners Universally Hate

  • JALA-MEME-ÑOS: 🌶️ 🤣

HEATING UP

Spicy links of original reporting

one / News

  • USSS & ICE conduct warrantless surveillance (summary) (report)

  • National Cybersecurity Strategy released; Panda & Bear named top threats (krebs summary)(report)

  • CrowdStrike 2023 Global Threat Report - no email needed (report)

  • US Cyber Command to establish its own cyber intel center (link)

  • Boston loves cybersecurity companies (link)

  • Zero-day used to steal SSN from Hatch Bank (link)

two / Nerdy

  • BlackLotus renders Secure Boot useless (link)

    • ESET confirms 1st UEFI boot kit; this is a big…big deal

  • ESET opens Mustang Panda’s backdoor (link)

  • Mapping ATT&CK made simple (link)

  • Heimdal Security compiles ethical hacking tool list (link)

three / Money

  • HPE secures the cloud with Axis Security acquisition (link)

  • Momentum Cyber releases 2023 Cybersecurity Almanac (report)

DUMPSTER FIRE

Eyebrow raising breaches that you already know about, but with our 🌶️ added

  • Affected: 565K

  • Dwell time: Unknown

  • Notification time: None, seriously…none.

  • Identity monitoring: None 🙄

There’s 1 Thing That Gun Owners Universally Hate

Gun owners hate being on lists.

Announced yesterday, Gun Auctions was hacked in December which exposed PII and login information (with passwords) of roughly 565,000 people. Troy Hunt broke the story and TechCrunch finally reached the site owner, Manny Delacruz, who was proving elusive to Hunt’s attempts. Delacruz responded with a rather rosy take on the situation, “…we want to reassure our customers that we have no reason to believe that any financial information was accessed during the breach.”

And now, there’s a list of gun owners, with addresses and purchase history, floating around the internet, but Manny’s big takeaway was tone-deaf.

When you run a website that auctions guns, and the website is hacked, you should act like you give a shit, because you better believe that gun owners sure as hell do.

Jala-meme-ños

🌶️ 🤣

TALL GLASS OF MILK

Time to cool down with a tall glass of milk. Thanks for reading! We'll be back tomorrow. In the meantime, feel free to reach out if you have any questions or feedback. Keep crushing it!

What'd you think of today's edition?

Login or Subscribe to participate in polls.

AFTERBURN

#bribery

If you made it this far could you help us out? 

If you found this fun and interesting, could you share this with your team? We’re grassrootsing this thing and would love extra help spreading the word.

🌶️ 🙌