Risky Bulletin Newsletter
October 12, 2022
Risky Biz News: White House working on cybersecurity labels for IoT products
Presented by

News Editor
STAX Finance hack: DeFi platform STAX Finance said it lost $2.3 million after an attacker exploited a bug in TempleDAO, the backbone of its service.
Forced to delete notebooks and files: Peiter "Mudge" Zatko, Twitter's former head of security, alleged that Twitter management forced him to burn notebooks and delete files in order to get his severance package. According to Bloomberg, citing court documents unsealed this week, this included 10 handwritten notebooks and deleted 100 computer files.
Brute-force protection for local admin accounts now generally available: With yesterday's Patch Tuesday security updates, Microsoft has also enabled a new feature by default for all Windows OS versions that will lock and freeze all local admin accounts for 10 minutes after 10 failed login attempts. The feature is meant to be Microsoft's best protection against brute-force attacks, including those carried out via RDP, that have served as an initial entry for many cybercrime and cyber-espionage operations over the past years. A similar feature to block SMB-based brute-force attacks is also in the works.