And Now For Something Completely Different

It’s the last Thursday of the month, which means it’s the day I post something completely different. Included below are a few topics and articles that I found interesting this month.

DEF CON

This story from a Delta flight from Las Vegas to Atlanta following DEF CON doesn’t necessarily bring up a new concept in hacking, though the timing definitely leaves a lot to be desired. It would seem doing something illegal while on a plane with no exit strategy isn’t the smartest idea, unless their name is DB Cooper.

Still, the story allowed me to reminisce about attending DEF CON in 2017 with some coworkers, which was an experience both during and after-hours. Most of the conference was over my head, but I did learn how to pick locks and still have a lock picking set stored somewhere.

https://arstechnica.com/information-technology/2026/08/def-con-crowd-suspected-in-fake-hotspot-attack-on-delta-flight/


Apple

Apple will send a push notification to your phone if it detects “mercenary spyware attacks” based on who you are or what you do. This is a feature Apple has had in place since 2001, but popped into the mainstream once again this past month.

Security awareness training (including phishing, vishing, and smishing) usually recommend being cautious when an email, text, or phone call comes with a sense of urgency or pressure, so this would require some thought before taking next steps if it popped on my screen.

https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/


Infrastructure

Bear with me as I go in a little circle here regarding the cyber attacks on water infrastructure in various states.

Chesterton’s Fence is “the principle that you should not remove or change a rule, system, or object until you understand why it was put there in the first place”. I learned about this principle recently, mostly because it applies to so many things happening around us.

With my prior employer, an aspect of my job responsibilities was to complete IT risk and general controls assessments for local (small) municipal and public sector entities. Something I always had to keep in mind while performing these assessment was their resource limitations, which directly affected what types of recommendations could be made.

The Cybersecurity and Infrastructure Security Agency (CISA) is a federal agency under the Department of Homeland Security (DHS) responsible for protecting the nation’s critical infrastructure and cyber defenses. CISA provides additional support for local entities, including infrastructure, that don’t have the resources to do everything on their own.

CISA’s staff dropped from roughly 3,300 to about 2,389 employees last year (2025), which is a loss of about a third of the agency. Proposed budget plans for 2027 target the elimination of ~900 additional positions.

Job cuts at CISA, limited resources at the local level, and constantly increasing cyber threats is a recipe for disaster and could make cyberattacks on our infrastructure more common and potentially successful.

This is a long winded way of noting the job cuts at CISA are not a good idea.

https://www.securityweek.com/us-water-cyberattacks-extend-beyond-minnesota-to-at-least-6-other-states/

And Now For Something Completely Different

Last month I asked some friends to come up with a title for the monthly post of topics outside the normal focus of the blog. One of them gave me the idea of naming it “And Now For Something Completely Different”, which is taken from Monty Python’s Flying Circus, or so I’m told. I liked the idea, but should also note I didn’t know where the phrase came from and never actually watched the show outside of a few skits on YouTube. Feel free to use that against me. 😀


WordPress

Let’s start things off with a topic related to this blog and millions of sites on the interweb. A WordPress vulnerability was found in the wild affecting versions 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. The vulnerabilities affect self-hosed WordPress.org sites, not sites hosted by WordPress.com.

I self-hosted my personal blog for a while, leasing server space with GoDaddy, but then transferred it to WordPress.com in 2012. Self-hosting was fun for a while as it allowed me to make unlimited changes to the look and feel of the site, without restrictions. It also put me in a position to learn a little more about how things work on the backend, but as life got busy it just turned into more of a hassle. It was worth moving to a hosted site with WordPress.com for its ease of use.

With that said, if you’re using a self-hosted .org site and don’t have it set to automatically update, you should do that now.

https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk


Click to Pray

Bob the Hacker posted another doozy this month related to the Click to Pray app. Click to Pray is the Pope’s official prayer app launched in 2018 that does the things you would think it would do. However, Bob found a vulnerability that made Personally Identifiable Information (PII) available to anyone. He notified various powers that be about the vulnerability during January 2026, but never received a response and it didn’t get fixed. That is, it wasn’t fixed until he posted about it earlier this month. Again, he received no response about the fix, only finding out it was fixed after reading about it online.

https://bobdahacker.com/blog/click-to-pray


META

The more Meta pushes to expand their use of AI, and that doesn’t even include their “glasses”, the more I want to delete all my Meta accounts. As I noted last month, I still have a Facebook account to keep up with things going on in my community / neighborhood and also still have a IG account. The IG account is set to private, limiting it to only friends / contacts I’ve approved, which is a pretty small group. The last picture I posted there was in 2022. There’s still a high probability I’ll delete both FB and IG accounts at some point.

Meta announced they were going to start using pictures from public IG accounts as a basis for other users to create alternate pictures with it’s AI image generator and it was going to be automatically turned on for all public accounts, requiring the user to turn it off. In essence, if you weren’t paying attention to the news, you wouldn’t even know it was happening. The public wasn’t having it and they eventually decided to back off their plan.

https://www.androidcentral.com/apps-software/meta/meta-removes-muse-image-ai-from-instagram-after-users-voiced-major-concerns


That’s it for this month.

And Now For Something Completely Different

I’m going to take a stab at doing something different on the GRC blog so it doesn’t get too stale by posting links to articles I found interesting during the past month or so and adding some thoughts about the articles. Where the focal point of the blog will mostly revolve around Governance, Risk, and Compliance (GRC), these will likely stray from that focus and into the wider IT industry / environment.


FIFA

This post popped into my feed on the infosec.exchange Mastodon instance and, though it can be a little technical to read at times (read: boring), it might be the most interesting read from the last month. Bob the Hacker was able to find a weakness in FIFA’s Agent Platform that allowed him to not only see the backend of the FIFA feeds, but change them if he wanted. Things got worse as he attempted to contact FIFA to report the security flaw. The headline for the post makes it even better, thinking about how funny it would have been if he changed a match feed to Rick Astley’s Never Gonna Give You Up at the most inopportune time.

I Could’ve Rickrolled the Entire FIFA World Cup. All I Needed Was My ID

On that note, why not give the song a watch/listen.


Apple

It didn’t happen overnight, but the devices I use in my personal life are almost entirely in the Apple ecosystem, so articles about them tend to peak my interest. However, the reality of this article headline about an exploit doesn’t really hold up from a risk perspective. Yes, there’s an exploit on millions of iPhones that can’t be patched. However, assuming the information included in the article is accurate, it only affects older iPhones, requires directly connecting to the iPhone via a special USB device, and doesn’t grant access to user data. It’s not something to dismiss, but maybe don’t let someone connect a USB device to your iPhone without your knowledge.

New Exploit Bypasses Apple’s Boot Defenses

Sticking with the Apple ecosystem, Apple is planning to move from @icloud.com to @private.icloud.com for their hide my email address feature. I’ve used this feature a few times when signing up for an online web site/service. I’m not a fan of the change as it would seem to make it easier for web sites to blacklist @private.icloud.com email addresses, nullifying its usefulness.

Apple Plans to Change its Hide My Email Privacy Feature


META

I don’t actively use Meta platforms much anymore, mostly just using Facebook for the community page to keep up with things happening in my neighborhood, but that’s not really the point of the article. The article is about an employee tracking program called MCI.

Meta rolled out the Model Compatibility Initiative (MCI) tool in April to US employees. The tool “collects computer inputs such as mouse movements, click locations and keystrokes, as well as screen content,” according to workers who have been petitioning against it over privacy, security, and personal liberty concerns.

There are obviously a lot of decisions that go into obtaining employment and deciding to stay with that employer over time, but I’m not sure I’d be willing to give up all my privacy to allow an employer to go into this level of monitoring. To make matters worse, Meta failed to protect the data it was gathering in the program… TWICE. Not good.

Meta Pauses Employee-Tracking Program Following Internal Data Leak


That’s it for this month.