This week in cybersecurity with the Code Curmudgeon March 13, 2020

Опубликовано: 03 Август 2026
на канале: CodeCurmudgeon
22
2

Lots of interesting things happened in cybersecurity this week. Here’s 5 interesting stories that are mostly connected to companies making bad decisions.
Accounts not use multi-factor authentication are compromised
Companies threaten security researchers rather than fix vulnerabilities
Google has a flaw in two-factor authentication they could have fixed long ago
Medical devices are vulnerable because they’re running ancient operating systems
And Hackers are getting hacked through trojanized tools. Which is kind of funny.
All this on this week in cybersecurity with me, the Code Curmudgeon.

Intro this week filmed just for fun using my Infrared GoPro Hero 7 using the “IR Chrome” filter from Kolari Vision https://kolarivision.com/product/kola...

Shortcuts:
Missing multi-factor authentication: 00:40    • This week in cybersecurity with the Code C...  
Researcher threatened: 04:43    • This week in cybersecurity with the Code C...  
Google 2FA flaw: 07:50    • This week in cybersecurity with the Code C...  
Medical devices: 10:00    • This week in cybersecurity with the Code C...  
Hackers hacked: 13:09    • This week in cybersecurity with the Code C...  

Compromised accounts not used multi-factor authentication – Microsoft report
https://www.zdnet.com/google-amp/arti...

We have talked about passwords before…
FBI advice    • This week in cybersecurity with the Code C...  
Last week as well    • This week in cybersecurity with the Code C...  

Talkspace threatened to sue a security research over bug report.
A research approached Talkspace to tell them of a vulnerability, they ignored him, so he wrote a blog, upon which Talkspace sicced their lawyers on him.
They should have been saying “thank you” and looking into the problem.

https://cybersguards.com/talkspace-th...

Google flaw in 2FA that they could have fixed years ago – other apps can “screen capture” the authenticator and get the codes. Reported to Google many times over the years.
Microsoft authenticator on android has the same flaw.

https://www.zdnet.com/google-amp/arti...

Medical imaging devices run outdated OS

Over 80% of medical devices running ancient unsupported operating systems. Leads to extreme hackability. Hacked devices become the method for further deeper attacks – see my presentation “JUMPING the fishtank” from Cybersecure LA    • Jumping the Goldfish : The Impact of IoT I...  

Story: https://www.wired.com/story/most-medi...
research: https://unit42.paloaltonetworks.com/i...

Hackers getting hacked via trojanized hacking tools
It turns out someone has been hacking the tools hackers use and putting them on common internet tool distribution sites. So hackers getting hacked by hacking tools.
https://www.helpnetsecurity.com/2020/...

See also
SQLi Hall-of-shame http://sqlihallofshame.com for SQL Injection
IoT Hall-of-shame http://iothallofshame.com
IoT Hall-of-shame Reddit   / iothallofshame  
My blog: http://codecurmudgeon.com
Twitter: @Codecurmudgeon   / codecurmudgeon  
Facebook:   / codecurmudgeon  
My photography channel:    / @backsideofblue3163