Jessica Haworth
24 February 2023 at 13:09 UTC
Updated: 27 February 2023 at 15:32 UTC
Your fortnightly rundown of AppSec vulnerabilities, new hacking techniques, and other cybersecurity news
Twitter faced further criticism this week when Elon Musk’s social networking platform announced SMS-based 2FA will only be available to paying customers going forward.
The social media site historically enabled two-factor authentication (2FA) to all users, providing they connected their mobile phone number to their account.
This week, however, users were warned that this security option would no longer be available to users who did not pay for verification.
Of course, this sparked huge backlash online, particularly among the majority of those with non-paid accounts.
It’s worth noting, though, that users can still use 2FA with third-party authentication apps such as Google Authenticate.
Want the latest web security news straight to your inbox? Sign up to our newsletter here
Elsewhere, web hosting provider GoDaddy announced it had fallen victim to a cyber-attack… and this was part of a campaign lasting almost three years.
The company announced in a statement that it had evidence of an intrusion that took place back in December 2022, when “a small number of customers” complained about their websites being intermittently redirected.
In a filing to the US Securities and Exchange Commission (PDF), the American domain registrar also divulged that it had evidence this attack was linked to an earlier incident in March 2020, when an attacker “compromised the hosting login credentials of approximately 28,000 hosting customers to their hosting accounts as well as the login credentials of a small number of our personnel”.
GoDaddy says it believes these attacks, together with a 2021 compromise of its hosted WordPress service, “are part of a multi-year campaign by a sophisticated threat actor group”.
BACKGROUND Truffle Security relaunches XSS Hunter tool with new features
Finally, the maintainers of newly resurfaced tool XSS Hunter announced the introduction of optional end-to-end (e2e) encryption to its fork after a backlash from privacy-conscious users.
Truffle Security, which launched a new fork of the open source utility after its deprecation by original creator Matthew Bryant, were criticized earlier this month for inspecting potentially sensitive data generated by users after they shared anonymized statistics about the vulnerabilities unearthed.
As reported by The Daily Swig, users have now been reassured that e2e encryption has been added to the fork in a statement given by Truffle Security’s founder.
We also recently reported that Belgium has become the first European country to adopt a national, comprehensive safe harbor framework for ethical hackers, and how Frans Rosén topped PortSwigger’s top 10 web hacking techniques of 2022 with his research ‘Account hijacking using dirty dancing in sign-in OAuth-flows’.
You can catch up with the full range of our recent news coverage by visiting The Daily Swig’s homepage.
Here are some more web security stories and other cybersecurity news that caught our attention in the last fortnight:
A security researcher has praised the merits of hacking on Apple’s bug bounty program
*PortSwigger is the parent company of The Daily Swig.
PREVIOUS EDITION Deserialized web security roundup: KeePass dismisses ‘vulnerability’ report, OpenSSL gets patched, and Reddit admits phishing hack