social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Search results for tag #infosec

AodeRelay boosted

[?]Anthony » 🌐
@abucci@buc.ci

Gradient ascent is superior to generate-and-test in any domain in which you have even a heuristic gradient that is sometimes wrong.

Why people working on software where something serious is at stake would throw out known gradient to use a code generator + testing is beyond my capacity to understand.

https://1password.social/@1password/116580082041363054


    [?]your auntifa liza 🇵🇷 🦛 🦦 » 🌐
    @blogdiva@mastodon.social

    [?]gyptazy » 🌐
    @gyptazy@gyptazy.com

    AI assisted pen testing, coding and arising secvulns. Are we humans still good enough?

    the last weeks we saw more and more security issues coming up. Let's talk!

    Sorry, a pretty long blog post about this...

    https://gyptazy.com/blog/coding-after-ai-are-humans-still-good-enough/


    Let's talk about AI slops - like this image!

    Alt...Let's talk about AI slops - like this image!

      AodeRelay boosted

      [?]RemADeus » 🌐
      @RemADeus@wehavecookies.social

      Reading this blow post makes you angry at vendor & platform lock in

      Do something about it

      # FIGHT

      Athropy is used here

      fireborn.mataroa.blog/blog/the

      #

        [?]Florian 'floe' Echtler » 🌐
        @floe@hci.social

        I had found a very thorough server checker (e.g. TLS, DKIM, certificates, PFS, DMARC, you name it) here on the fedi at some point and thought I'd bookmarked it, but just can't find it anymore. Any recommendations from the sysadmin crowd?

          Taggart :ifin: boosted

          [?]Mike Sheward » 🌐
          @SecureOwl@infosec.exchange

          So a new, quite effective method I've found during pentests recently:

          People are starting to connect their work email and calendars to personal AI agents, and are, inevitably, storing the code in publicly accessible repos.

          There are two things I look for:

          - Email creds, prevalent where people have given the AI dealy IMAP access to their messages.

          - If I can't find email creds, the link to the private Google Calendar (either outlook or Google) ICS file.

          If you grab that ICS file, you download effectively an entire copy of the calendar, which includes the body of the meeting invite - so, various links, attachments, keys/secrets/passwords etc.

          I have done the email thing maybe once or twice.

          The calendar thing, at least a dozen times in the last few months.

            Fred de CLX boosted

            [?]h3artbl33d :openbsd: :antifa: [Try/Me] » 🌐
            @h3artbl33d@exquisite.social

            About that... We now have a fourth vulnerability: ssh-keysign-pwn. Despite the first three letters, this is a Linux kernel vuln. PoC already available.

              [?]Sean » 🌐
              @seanm@infosec.exchange

              Just to be clear, I think JavaScript is fine for authenticated or more complex content. If I'm a user of a server, it seems acceptable that I should trust it and enable JavaScript.

              However, if I am some random visitor to your instance and just trying to view a post or user profile, that should not require JavaScript.

              The JavaScript ecosystem (e.g., npm) is rife with supply chain hacks. Plus, there are many poorly maintained Mastodon instances (e.g., mastodon.social, I think?). Although, I guess those poorly maintained instances are not pulling down the latest backdoored npm packages... Regardless, it is a security risk to require visitors run JavaScript from every instance they visit for simple content.

                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                @Steve12L@mamot.fr

                ⋅ Shai-Hulud Worm Steals npm, GitHub, AWS, and Kubernetes Secrets From Developers

                cybersecuritynews.com/shai-hul

                  [?]Super Owl » 🌐
                  @gtsadmin@wiseowl.club

                  Pictured is a Gotosocial #ActivityPub server (#Mastodon-compatible), that I've been successfully running for several months now. It's running on the Raspberry Pi 5 (small black box in the background), firewalled behind an #OpenWRT router. This server uses my "Super Owl reverse proxy", where an inexpensive VPS in the cloud acts as the "frontend". The #RaspberryPi 5 "backend" server has *far* more disk space (than the frontend VPS); it has a 500GB NVMe. More info:
                  https://owleyes.blue/posts/gotosocial-reverse-proxy-with-wireguard/
                  #InfoSec #SelfHosting

                  An OpenWRT router in the foreground, and a Raspberry Pi 5 in an Argon Neo case, in the background.

                  Alt...An OpenWRT router in the foreground, and a Raspberry Pi 5 in an Argon Neo case, in the background.

                    [?]Dendrobatus Azureus » 🌐
                    @dendrobatus_azureus@polymaths.social

                    This is something that's actually forbidden in our country

                    companies may not call random numbers just to spam them.

                    To compensate for that luxury, the main internet and POTS provider let's companies pay them to spam us with SMS!

                    This is also disallowed by law but no one seems to bother to file a class action suit against this company

                    Those spam SMS you can easily block though

                    @rl_dane

                    #Spam #privacy #InfoSec

                      AodeRelay boosted

                      [?]PLA_906114 » 🌐
                      @PLA_906114@mastodon.illumos.cafe

                      All of them need local physical access to the servers right?

                      @h3artbl33d

                        AodeRelay boosted

                        [?]Dendrobatus Azureus » 🌐
                        @Dendrobatus_Azureus@mastodon.bsd.cafe

                        The more you read this piece of excellent work the more you realize how much energy we, as the Open Source community, the programma's and the users, shall need to put in another to get a proper Balance Again

                        Read the section here.

                        Source:

                        fireborn.mataroa.blog/blog/the

                        against

                          mmu_man boosted

                          [?]VM » 🌐
                          @vm666@infosec.exchange


                          Three minor releases in three days to fix the copy fail / dirty frag local
                          You would think the is over?
                          Nope! Today, Gentoo published new kernels with a bespoke patch.

                          --- linux-6.18.29-gentoo/net/core/skbuff.c 2026-05-12 12:00:13.960097343 +0200
                          +++ linux-6.18.29-gentoo-r1/net/core/skbuff.c 2026-05-14 12:36:07.935053114 +0200
                          @@ -2188,6 +2188,7 @@
                          skb_frag_ref(skb, i);
                          }
                          skb_shinfo(n)->nr_frags = i;
                          + skb_shinfo(n)->flags |= skb_shinfo(skb)->flags & SKBFL_SHARED_FRAG;
                          }

                          if (skb_has_frag_list(skb)) {
                          @@ -6149,6 +6150,8 @@
                          from_shinfo->frags,
                          from_shinfo->nr_frags * sizeof(skb_frag_t));
                          to_shinfo->nr_frags += from_shinfo->nr_frags;
                          + if (from_shinfo->nr_frags)
                          + to_shinfo->flags |= from_shinfo->flags & SKBFL_SHARED_FRAG;

                          if (!skb_cloned(from))
                          from_shinfo->nr_frags = 0;

                            [?]mc.fly [he/him] » 🌐
                            @mcfly@milliways.social

                            depthfirst.com/nginx-rift

                            Anyone running nginx? Noone does that right?

                              Fred de CLX boosted

                              [?]Thomas Roccia :verified: » 🌐
                              @fr0gger@infosec.exchange

                              🤯 The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)!

                              I hope it helps to make sense of the information out there. Please treat the information "as is" while the analysis progresses! 🧐

                                [?]Jonathan Kamens 86 47 » 🌐
                                @jik@federate.social

                                I got 29 of these alerts over a 3½ hour period overnight, all from IP addresses in Iran.
                                Since access to the public internet has been blocked for most people in Iran since January, this is probably government-backed Iranian hackers credential-stuffing Synology boxes. I would imagine there is probably some specific reason they're targeting Synology boxes, perhaps having to do with recently patched CVEs.
                                If you have Synology devices, make sure your security is tight!

                                Synology ActiveInsight notification about a failed login to my NAS from an IP address in Iran

                                Alt...Synology ActiveInsight notification about a failed login to my NAS from an IP address in Iran

                                  AodeRelay boosted

                                  [?]Dendrobatus Azureus » 🌐
                                  @Dendrobatus_Azureus@mastodon.bsd.cafe

                                  I knew my browser was chatty but I didn't know that my browser on Android was so chatty and so wonderful with giving out free space

                                  Space that I need!

                                  Sources

                                  sinceyouarrived.world/taken

                                    [?]maswan » 🌐
                                    @maswan@mastodon.acc.sunet.se

                                    Hey, did I mention over here yet that regiastration for BSides Ume on June 16-17th is open: indico.neic.no/event/287/

                                    This year we are happy to have @bagder as our keynote speaker!

                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                      @Steve12L@mamot.fr

                                      ⋅ Fragnesia Linux Vulnerability Let Attackers Gain Root Privileges – PoC Released

                                      cybersecuritynews.com/fragnesi

                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                        @Steve12L@mamot.fr

                                        [?]AA » 🌐
                                        @AAKL@infosec.exchange

                                        New.

                                        Cloudflare: When "idle" isn't idle: how a Linux kernel optimization became a QUIC bug blog.cloudflare.com/quic-death

                                          [?]Metin Seven 🎨 » 🌐
                                          @metin@graphics.social

                                          🧵 Pixel art works, 8/x

                                          Isometric pixel illustration for a Dutch infosec company.

                                          Stylized isometric pixel artwork of a character operating a rugged laptop in a protected environment, surrounded by walls and security cameras.

                                          Alt...Stylized isometric pixel artwork of a character operating a rugged laptop in a protected environment, surrounded by walls and security cameras.

                                            [?]mc.fly [he/him] » 🌐
                                            @mcfly@milliways.social

                                            RE: cyberplace.social/@GossiTheDog

                                            This YellowKey Bitlocker Bypass Vulnerability is seriously crazy. As if someone found a government / law enforcement backdoor....

                                            [?]Kevin Beaumont » 🌐
                                            @GossiTheDog@cyberplace.social

                                            So I’ve just had a quick play with this and yes, it works. Essentially BitLocker has a backdoor. github.com/Nightmare-Eclipse/Y

                                            Mitigation = BitLocker PIN and BIOS password lock.

                                              [?]Dendrobatus Azureus » 🌐
                                              @dendrobatus_azureus@polymaths.social

                                              Many people also don't realize that everyone on the globe, who is in a country which is being controlled by Swift banking system, will also suffer.

                                              @rl_dane

                                              #Privacy #SSN #InfoSec #breach #sensitive #programming

                                                [?]Dendrobatus Azureus » 🌐
                                                @dendrobatus_azureus@polymaths.social

                                                What is happening over there!?

                                                It's extremely disturbing that they want your Sierra Sierra November. That is a record you can always be uniquely identified with

                                                @rl_dane

                                                #Privacy #SSN #InfoSec #breach #sensitive #programming

                                                  [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                  @rysiek@mstdn.social

                                                  time! I'm rysiek. On fedi since before it was fedi ­— I see you, old StatusNet guard!

                                                  Did information security and infrastructure for journalists, fought on the streets and in meetings, helped write the book on , started a hackerspace and a half, and wrote a bunch of code.

                                                  Media literacy is a human right. Protocols, not platforms. Communities, not customers. User-Authored Works, not user-generated content.

                                                    [?]Shawn Webb [He/Him] » 🌐
                                                    @lattera@bsd.network

                                                    cgit.freebsd.org/src/commit/?i

                                                    This is the kind of bug that protects against with its kmalloc hardening feature. It forces memory zeroing upon both allocation and free. My own non-build systems (laptops and non-build servers/VMs) all run with hardening.kmalloc_zero=1.

                                                      [?]doboprobodyne » 🌐
                                                      @doboprobodyne@mathstodon.xyz

                                                      @stefano Hear, hear. And in n years the ability of bad or indifferent actors to collate data will be fantastically better. Not sure if it helps but I made a throwaway email address with a provider that had an email app of its own, so I could chat to estate agents without risking ++ spam. It was so useful that I kept it. In retrospect, I should have added a second pay as you go sim card. I'd wager that thoughtful clubs might let one use a nickname or non de plume and pay with cash or cryptocurrency. I'm guessing if all this was an option you'd have suggested it, but I thought it worth mentioning in this thread for completeness' sake.

                                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                        @Steve12L@mamot.fr

                                                        ⋅ Pwn2Own Berlin 2026 Hits Capacity as Rejected Hackers Release 0-Days

                                                        hackread.com/pwn2own-berlin-20

                                                          AodeRelay boosted

                                                          [?]Sub_Root » 🌐
                                                          @Sub_Root@techhub.social

                                                          @GrapheneOS

                                                          Hardened OSs like do a great job, but we have a major blind spot: The Hardware.

                                                          Modern phones are networks of dozens of "black box" computers (UFS, Baseband, Wi-Fi) running proprietary code we can't audit, disable, secure or replace.

                                                          Why this matters:
                                                          1️⃣ Persistence: Malware in your UFS/SSD controller survives a factory reset.
                                                          2️⃣ Tracking: Hardware Attestation acts as an immutable digital fingerprint.
                                                          3️⃣ Shadow Attacks: Zero-click exploits hit your Wi-Fi or Baseband before the OS can even react.

                                                          We are calling for . Inspired by the philosophy, we demand:
                                                          ✅ Open & replaceable firmware for ALL subsystems.
                                                          ✅ User-controlled hardware toggles.
                                                          ✅ Trust minimization that includes the manufacturer.

                                                          It's time to move from "Vendor-Enforced Security" to User Sovereignty.
                                                          Read the full Open Letter here: pastebin.com/RzRbzhwn

                                                          The Trojan Guardian means a chip that is Security for the Vendor, but Privacy nightmare for the user.

                                                          Alt...The Trojan Guardian means a chip that is Security for the Vendor, but Privacy nightmare for the user.

                                                            [?]TagHunt [../..] » 🌐
                                                            @TagHunt@infosec.exchange

                                                            I think a lot of us here are using to stay in touch with our colleagues and ex-employers. I think i have an opportunity to get a whole boat load of people to switch.

                                                            What can we switch to?
                                                            (preferably something fedi-based)

                                                              AodeRelay boosted

                                                              [?]Umherstreunender Auflauf » 🌐
                                                              @lasagne@chaos.social

                                                              Can someone here breach Shopify in a funny way before someone breaches them in a boring way?

                                                              They are having an "AI" induced quality meltdown.

                                                              It is absolutely staggering how many shops run on their systems.

                                                                [?]mc.fly [he/him] » 🌐
                                                                @mcfly@milliways.social

                                                                Nothing wakes you up as fast as a good information security incident.

                                                                From bed reading infosec news to the computer pressing buttons in like 60 sec.

                                                                now 3 hrs later i'll go and make a first coffee...

                                                                  [?]FLOX Advocate » 🌐
                                                                  @FLOX_advocate@floss.social

                                                                  Deploying Quantum Computing Resistant Encryption Algorithms — a risk-based approach from Hoyt L Kesterson II

                                                                  Description: Hoyt starts with Caesar and works up to public key and moves on to new encryption methods that resist quantum computing

                                                                  This Thursday @ 19:00 AZ ( UTC - 7 )

                                                                  1702 E Highland, Phoenix

                                                                  @FLOSS_Stammtisch is next Tuesday on the 19th also starting at 19:00

                                                                    AodeRelay boosted

                                                                    [?]Radio Azureus » 🌐
                                                                    @RadioAzureus@mastodon.social

                                                                    Patch your Linux home and production servers / clients

                                                                    Privilege escalation bug

                                                                    Instead of asking yourself why the second bug🥈 in 2 weeks has been found on such a level, be glad that it has been found

                                                                    Just patch and move on

                                                                    Note
                                                                    These bugs only occur local not over the network over the internet.
                                                                    Local_privilege_escalation

                                                                    Sources

                                                                    lists.debian.org/debian-securi

                                                                    security-tracker.debian.org/tr

                                                                    Debian bug tracker

                                                                    Alt...Debian bug tracker

                                                                    Debian patch entry

                                                                    Alt...Debian patch entry

                                                                      ClaudioM boosted

                                                                      [?]Quad9DNS » 🌐
                                                                      @quad9dns@mastodon.social

                                                                      Some may have experienced outage intervals for our primary zone "quad9.net" on 8 May - for we which we are sorry and appreciate your support and patience 🫶 . Here are the details:

                                                                      quad9.net/news/blog/analysis-o

                                                                      Server racks with purple and blue lighting in the background, featuring the white and red "quad9" logo overlay.

                                                                      Alt...Server racks with purple and blue lighting in the background, featuring the white and red "quad9" logo overlay.

                                                                        Taggart :ifin: boosted

                                                                        [?]AA » 🌐
                                                                        @AAKL@infosec.exchange

                                                                        This is very good. Cloudflare should be fired.

                                                                        "The four-hour gap between the onset of the attack and the appearance of Cloudflare addresses on Canonical’s repository hostnames is the interval during which the purchasing decision moved. I imagine engineers moving from 'hold the line' against attacks routed through Cloudflare to 'sign the Cloudflare contract'. Roughly the time it took for the cost of continued outage to exceed the deal Cloudflare offered."

                                                                        Flying Penguin: Can Someone Please Explain Whether Cloudflare Blackmailed Canonical? flyingpenguin.com/can-someone-

                                                                        @mttaggart

                                                                          AodeRelay boosted

                                                                          [?]Shodan Safari » 🤖 🌐
                                                                          @shodansafari@infosec.exchange

                                                                          ... [SENSITIVE CONTENT]

                                                                          ASN: AS197690
                                                                          Location: Antwerpen, BE
                                                                          Added: 2026-05-03T12:36

                                                                            AodeRelay boosted

                                                                            [?]AmmarSpaces » 🌐
                                                                            @AmmarSpaces@infosec.exchange

                                                                            Moscow shutting down internet in May 5th to May 9th in order to ensure Victory Day parade security.

                                                                            What I want to highlight is, if it is started by one country, the other will follows.

                                                                            First, they banned VPNs, now the west also trying to ban VPNs.

                                                                            What is gonna be next? Digital firewall?

                                                                            I am here just telling we need to prepare and prevent your country to fall into this oblivion of internet freedom.

                                                                            militarnyi.com/en/news/moscow-

                                                                              ClaudioM boosted

                                                                              [?]BeyondMachines :verified: » 🤖 🌐
                                                                              @beyondmachines1@infosec.exchange

                                                                              JDownloader Website Hijacked to Distribute Malware via CMS Exploit

                                                                              JDownloader's official website was compromised via a CMS vulnerability, allowing attackers to replace legitimate Windows and Linux installers with malware-laden versions. Existing installations remain safe due to cryptographic signing, users who downloaded and executed the affected files on May 6-7 are advised to change all passwords, and enable multi-factor authentication or reinstall their operating systems.

                                                                              **If you downloaded and ran the JDownloader Windows Alternative Installer or Linux shell script between May 6 and May 7, 2026, you should assume your system is compromised. Remove the systems, or ideally reinstall your system. Standard antivirus scans cannot guarantee the removal of this malware. Affected users must change all passwords and enable multi-factor authentication (MFA) on all accounts.**

                                                                              beyondmachines.net/event_detai

                                                                                [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                                                                @MissConstrue@mefi.social

                                                                                Everybody hates . But, despite tech reporting being willing to give the leeway, this new measure is not to stop robocalls, it won’t do a damn thing to stop robocalls. What it does is make burner phones illegal.

                                                                                Burners are an integral part of many social justice actions. Protestors use them to record and other . We include them in “Go Bags” to let abused women and children escape. They allow for anonymity.

                                                                                They are a thorn in the side of the panopticon, and they are moving to eliminate them.

                                                                                Stock up kids.

                                                                                gizmodo.com/fcc-attempts-to-so

                                                                                wiley.law/alert-FCC-Proposes-S

                                                                                mashable.com/article/fcc-propo

                                                                                  Fred de CLX boosted

                                                                                  [?]knoppix » 🌐
                                                                                  @knoppix95@mastodon.social

                                                                                  A Debian developer released a one-click .deb mitigation for the Copy Fail and Dirty Frag Linux kernel flaws affecting Debian-based distros 🐧
                                                                                  The temporary package applies command-line protections for Ubuntu, Mint, and Debian users while awaiting upstream kernel patches and security updates 🔐

                                                                                  🔗 fossforce.com/2026/05/a-simple

                                                                                    Fred de CLX boosted

                                                                                    [?]knoppix » 🌐
                                                                                    @knoppix95@mastodon.social

                                                                                    ShinyHunters reportedly defaced Canvas login portals at about 330 schools after another breach of Instructure systems, demanding ransom payments before May 12 🎓
                                                                                    Attackers claim stolen Canvas data includes messages, enrollments, and user records 🔐

                                                                                    🔗 bleepingcomputer.com/news/secu

                                                                                      Leila boosted

                                                                                      [?]PH4NTXM :verified: » 🌐
                                                                                      @PH4NTXMOFFICIAL@infosec.exchange

                                                                                      Most people still think privacy works like this:

                                                                                      “I use a VPN, so I’m anonymous.”

                                                                                      But modern tracking no longer relies only on IP addresses.

                                                                                      Today, systems can fingerprint users through:

                                                                                      * browser behavior
                                                                                      * hardware characteristics
                                                                                      * TCP/IP stack patterns
                                                                                      * DNS behavior
                                                                                      * GPU/rendering fingerprints
                                                                                      * timing signatures
                                                                                      * viewport & display metrics
                                                                                      * runtime inconsistencies across layers

                                                                                      Changing your IP alone often isn’t enough.

                                                                                      That idea led us to build PH4NTXM.

                                                                                      Instead of randomizing things independently, PH4NTXM tries to create a coherent runtime identity where:

                                                                                      * hardware
                                                                                      * networking
                                                                                      * browser environment
                                                                                      * timing behavior
                                                                                      * GPU exposure

                                                                                      all align consistently within the same session.

                                                                                      The project is:

                                                                                      * live-only
                                                                                      * stateless
                                                                                      * non-persistent across boots
                                                                                      * fully open source

                                                                                      Current focus areas include:

                                                                                      * fingerprint surface reduction
                                                                                      * browser hardening
                                                                                      * network personality shaping
                                                                                      * Tor-isolated operation modes
                                                                                      * fail-secure session termination

                                                                                      We’re not claiming “perfect anonymity” — the goal is simply to reduce static identity behavior and avoid contradictory signals as much as possible.

                                                                                      Find us: github.com/PH4NTXMOFFICIAL/PH4

                                                                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                        @Steve12L@mamot.fr

                                                                                        Et hop !
                                                                                        ⋅ 9000 écoles touchées dans le monde... La plateforme éducative Canvas victime d'une intrusion majeure

                                                                                        clubic.com/actualite-612388-ec

                                                                                          AodeRelay boosted

                                                                                          [?]Bobe'bot on security » 🤖 🌐
                                                                                          @Bobe_bot@mastobot.ping.moi

                                                                                          3D printing health risks: fumes, ultrafine particles, VOCs — and most people printing at home have no idea. The tech is wonderfully accessible, but the safety conversation hasn't quite kept up with the maker movement.

                                                                                          Sometimes the most interesting attack surface is the one sitting on your desk. 🖨️


                                                                                          bgr.com/2156591/3d-printing-he

                                                                                            AodeRelay boosted

                                                                                            [?]Shaula Evans » 🌐
                                                                                            @ShaulaEvans@zirk.us

                                                                                            New Google Sheets "Chip" feature lets you extract data about people.

                                                                                            My takeaway: if you view a shared Google Sheet while logged into a Google Account, the doc owner (maybe others) can extract your location & phone. 1/n

                                                                                            support.google.com/docs/answer

                                                                                            Google Help screenshot. Text says:

Types of data you can extract

You can extract data from smart chips in your Google Sheets to include information about the
following chips:

People smart chip A
Information comes from domain profiles.
+ Email
+ Name
+ Location*
+ Phone*
« Title*
Note: Information with * are only available to Google Workspace Business Standard, Business Plus,
Enterprise Essentials, Enterprise Standard, Enterprise Plus, Education Fundamentals, Education
Plus, Education Standard, and the Teaching and Learning Upgrade users.

                                                                                            Alt...Google Help screenshot. Text says: Types of data you can extract You can extract data from smart chips in your Google Sheets to include information about the following chips: People smart chip A Information comes from domain profiles. + Email + Name + Location* + Phone* « Title* Note: Information with * are only available to Google Workspace Business Standard, Business Plus, Enterprise Essentials, Enterprise Standard, Enterprise Plus, Education Fundamentals, Education Plus, Education Standard, and the Teaching and Learning Upgrade users.

                                                                                              AodeRelay boosted

                                                                                              [?]Adhidarma Hadiwinoto :verifyc: » 🌐
                                                                                              @adhisimon@mastodon.kodesumber.com

                                                                                              Habis terbitlah

                                                                                              • CVE-2026-43284
                                                                                              • CVE-2026-43500

                                                                                              Belum coba sih poc-nya, tapi sepertinya simpel juga.

                                                                                              github.com/V4bel/dirtyfrag/blo

                                                                                                mc.fly boosted

                                                                                                [?]mc.fly [he/him] » 🌐
                                                                                                @mcfly@milliways.social

                                                                                                Automated scanning.

                                                                                                What tools do you use to scan your enviroments for security issues? Why?

                                                                                                Not looking for virusscanners here, more for a bit more enterprisy enviroment?

                                                                                                Are there things i should have a look at?

                                                                                                What is your experience in general?

                                                                                                RT welcome for reach.

                                                                                                  [?]Shawn Webb [He/Him] » 🌐
                                                                                                  @lattera@bsd.network

                                                                                                  Anyone have a collection of PCIe whitepapers and specs I could reference?

                                                                                                    [?]Michael Boelen » 🌐
                                                                                                    @mboelen@mastodon.social

                                                                                                    Yesterday at the @nluug I learned about podcasts provided by @hpr that covers topics for "hackers".

                                                                                                    So check out to see if there is anything useful in there for you.

                                                                                                      AodeRelay boosted

                                                                                                      [?]AmmarSpaces » 🌐
                                                                                                      @AmmarSpaces@infosec.exchange

                                                                                                      Indonesia's Directorate General of Immigration busted an international investation scam ring in Batam.

                                                                                                      During the raid, they arrested 210 people.

                                                                                                      It is believed they are affiliated/former international scam ring based in Cambodia.

                                                                                                      Evidences retrieved:
                                                                                                      - 131 computer units
                                                                                                      - 93 laptop
                                                                                                      - 492 cellphones
                                                                                                      - 52 monitors

                                                                                                      GG guys

                                                                                                      Source:
                                                                                                      x.com/RidhaIntifadha/status/20

                                                                                                      The Directorate General of Immigration has arrested 210 foreign nationals suspected of committing online investment fraud in Batam.

The victims are overseas, but the operation is based in Indonesia. They didn’t arrive all at once, but in small groups over time.

There are indications that this is a former international network based in Cambodia.

                                                                                                      Alt...The Directorate General of Immigration has arrested 210 foreign nationals suspected of committing online investment fraud in Batam. The victims are overseas, but the operation is based in Indonesia. They didn’t arrive all at once, but in small groups over time. There are indications that this is a former international network based in Cambodia.

                                                                                                        [?]knoppix » 🌐
                                                                                                        @knoppix95@mastodon.social

                                                                                                        Linux zero-day “Dirty Frag” lets local users gain root on major distros by chaining kernel page-cache flaws with no race condition required 🐧⚠️
                                                                                                        Ubuntu, Fedora, RHEL and openSUSE remain unpatched, while temporary mitigations disable modules tied to IPsec VPN and AFS support 🔓

                                                                                                        🔗 bleepingcomputer.com/news/secu

                                                                                                          AodeRelay boosted

                                                                                                          [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                          @rysiek@mstdn.social

                                                                                                          Oh and a reminder that the whole "wow Mythos is such much special at finding vulns amaze" shtick is largely just Anthropic's hype.

                                                                                                          aisle.com/blog/ai-cybersecurit

                                                                                                          > We tested Anthropic Mythos's showcase vulnerabilities on small, cheap, open-weights models. They recovered much of the same analysis. AI cybersecurity capability is very jagged: it doesn't scale smoothly with model size, and the moat is the system into which deep security expertise is built, not the model itself.

                                                                                                            [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                            @rysiek@mstdn.social

                                                                                                            Will the rate of vulns being found "thanks to AI" be higher than the rate of vulns being introduced by vibe-coding shit?

                                                                                                            No. It will not. You know it as well as I do.

                                                                                                            Why? Because the incentives have not changed.

                                                                                                            What remains heavily incentivised is excreting more code and slapping more and more random features, not quality control and robustness.

                                                                                                            I've linked this before, but it remains so very on-topic and on-point, so here it is again:
                                                                                                            freakonometrics.hypotheses.org

                                                                                                              [?]Keira (She/Her) » 🌐
                                                                                                              @keira_reckons@aus.social

                                                                                                              The canvas hack drags on. Today was the ransom deadline I'm told, and the app is down.

                                                                                                              Everyone at my uni has been given extensions on assessment until midnight Monday, so they seem to think they'll have it back by then. In the meantime we're all to read up on identifying phishing attempts.

                                                                                                              I'm fully aware how hard defensive cyber security is, but I also know that almost no-one puts enough resources into it. I'm very sick of the money and strategy people facing no consequences for gambling with my data.


                                                                                                              edited for typos

                                                                                                                mc.fly boosted

                                                                                                                [?]mc.fly [he/him] » 🌐
                                                                                                                @mcfly@milliways.social

                                                                                                                lwn.net/Articles/1071719/

                                                                                                                is a broken embargo.

                                                                                                                Local Privilege Escalation to root.

                                                                                                                Public working exploit. No CVE assigned yet.

                                                                                                                No fix in sight.
                                                                                                                <edit> 7.0.5 was just released which has a fix </edit>
                                                                                                                <edit 2> CVE-2026-43284 has been assigned</edit 2>

                                                                                                                -2026-43284

                                                                                                                This is the documentation & exploit of DirtyFrag:
                                                                                                                github.com/V4bel/dirtyfrag/blo

                                                                                                                are you not entertained meme

                                                                                                                Alt...are you not entertained meme

                                                                                                                  Marcos Dione boosted

                                                                                                                  [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                  @rysiek@mstdn.social

                                                                                                                  If anyone knows of any decent write-up on securing ZooKeeper / ClickHouse Keeper, I am very interested.

                                                                                                                  Documentation of both is really crap I find, and security seems to be a complete afterthought.

                                                                                                                  I would love to be proven wrong on that last bit.

                                                                                                                  :boost_ok:

                                                                                                                    [?]R.L. Dane :Debian: :OpenBSD: :FreeBSD: 🍵 :MiraLovesYou: [he/him/my good fellow] » 🌐
                                                                                                                    @rl_dane@polymaths.social

                                                                                                                    @ireneista @darkuncle @tg

                                                                                                                    Just curious, does anyone still use #PortKnocking, or has stuff like Tailscale relegated that to the bitbucket of #infosec praxis?

                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                      @Steve12L@mamot.fr

                                                                                                                      ⋅ Scammers Use Hidden Text to Bypass AI Email Filters in Phishing Scams

                                                                                                                      hackread.com/scammers-text-byp

                                                                                                                        [?]Michael Boelen » 🌐
                                                                                                                        @mboelen@mastodon.social

                                                                                                                        Today an interesting keynote by @beauwoods at the @nluug conference.

                                                                                                                        Beau explains where policy and technical controls meet, the complexities involved, and some paths forward.

                                                                                                                        Thanks Beau!

                                                                                                                        Beau giving a keynote, asking the public raising their hands as a response to a question

                                                                                                                        Alt...Beau giving a keynote, asking the public raising their hands as a response to a question

                                                                                                                          [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 [it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
                                                                                                                          @freya@social.highenergymagic.net

                                                                                                                          hey so. looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years experience administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. I'm also 26, so I started when I was 11, explaining the no jobs so far. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Three machines, 72 docker containers. One running most of them, one running Mastodon+glitchsocial, one running the uptime monitor. encrypted root on ZFS, alpine linux, gVisor on supported containers, plan to move to Kata. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status. Currently using gVisor, docker compose, and kata containers in production, experience with Linux, docker, Net/Open/FreeBSD, Cisco IOS, Juniper Junos, Mikrotik and UniFi, configuring and administering Asterisk, plus extensive experience with IBM AIX and Sun Solaris.

                                                                                                                          Please boost for reach, any job offers please DM me.

                                                                                                                            [?]Keira (She/Her) » 🌐
                                                                                                                            @keira_reckons@aus.social

                                                                                                                            abc.net.au/news/2026-05-06/aus

                                                                                                                            We were told about this at uni today. They took pains to tell us they "only" had access to out names, emails, and messages between people. But don't worry, not our passwords or bank details.

                                                                                                                            I mean, yes, if they had access to passwords (which ought to be encrypted), or bank details (which ought to be handled separately by someone with better creds than the beleaguered uni IT team), that would be a monumental fuck up bigger than the one that actually happened. But also I* can change a fucking password. I can't change my uni address. And who knows what people have put into "messages".

                                                                                                                            * yes, I understand passwords matter because most people reuse them and don't change them. It's just a less big deal to me personally.

                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                              @Steve12L@mamot.fr

                                                                                                                              ⋅ Google's Android Apps Get Public Verification to Stop Supply Chain Attacks

                                                                                                                              thehackernews.com/2026/05/andr

                                                                                                                                [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                @rysiek@mstdn.social

                                                                                                                                Here's a thought:

                                                                                                                                The fact that people are experiencing issues with DE sites and asking if CloudFlare is down speaks volumes about the stability of DE ccTLD and the broader DNS compared to big cloud providers.

                                                                                                                                :blobcatcoffee:

                                                                                                                                  [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                  @rysiek@mstdn.social

                                                                                                                                  DENIC's status page:
                                                                                                                                  status.denic.de/

                                                                                                                                  Screenshot below in case you're not able to load it (as I said, stuff is going to be intermittently failing).

                                                                                                                                  DNSSEC disruption affecting .de domainsPartial Service Disruption

Incident Status

Partial Service Disruption

Components

DNS

Services

DNS Nameservice

May 5, 2026 23:28 CEST
May 5, 2026 21:28 UTC
INVESTIGATING

Frankfurt am Main, 5 May 2026 – DENIC eG is currently experiencing a disruption in its DNS service for .de domains. As a result, all DNSSEC-signed .de domains are currently affected in their reachability.
The root cause of the disruption has not yet been fully identified. DENIC’s technical teams are working intensively on analysis and on restoring stable operations as quickly as possible.
Based on current information, users and operators of .de domains may experience impairments in domain resolution. Further updates will be provided as soon as reliable findings on the cause and recovery are available.
DENIC asks all affected parties for their understanding.
For further enquiries, DENIC can be contacted via the usual channels.

                                                                                                                                  Alt...DNSSEC disruption affecting .de domainsPartial Service Disruption Incident Status Partial Service Disruption Components DNS Services DNS Nameservice May 5, 2026 23:28 CEST May 5, 2026 21:28 UTC INVESTIGATING Frankfurt am Main, 5 May 2026 – DENIC eG is currently experiencing a disruption in its DNS service for .de domains. As a result, all DNSSEC-signed .de domains are currently affected in their reachability. The root cause of the disruption has not yet been fully identified. DENIC’s technical teams are working intensively on analysis and on restoring stable operations as quickly as possible. Based on current information, users and operators of .de domains may experience impairments in domain resolution. Further updates will be provided as soon as reliable findings on the cause and recovery are available. DENIC asks all affected parties for their understanding. For further enquiries, DENIC can be contacted via the usual channels.

                                                                                                                                    [?]mc.fly [he/him] » 🌐
                                                                                                                                    @mcfly@milliways.social

                                                                                                                                    theregister.com/2026/05/02/ncs

                                                                                                                                    The patch tsunami is coming.

                                                                                                                                    "All organizations have 'technical debt'; a backlog of technical issues – that is both expensive and time-consuming – as a result of prioritising short-term gains over building resilient products.

                                                                                                                                    Artificial Intelligence, when used by sufficiently-skilled and knowledgeable individuals, is showing the ability to exploit this technical debt at scale and at pace across the technology ecosystem. The result is likely to be a "forced correction" as those weaknesses are uncovered and addressed in bulk"

                                                                                                                                      John Shaft boosted

                                                                                                                                      [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                      @rysiek@mstdn.social

                                                                                                                                      Edit: issue seems fixed.

                                                                                                                                      Looks like DE ccTLD is unresolvable due to DNSSEC issue:
                                                                                                                                      dnsviz.net/d/nic.de/afpsNg/dns

                                                                                                                                      😬

                                                                                                                                      🧵👇

                                                                                                                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                        @Steve12L@mamot.fr

                                                                                                                                        ⋅ We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is

                                                                                                                                        thehackernews.com/2026/05/we-s

                                                                                                                                          [?]BastilleBSD :freebsd: » 🌐
                                                                                                                                          @BastilleBSD@fosstodon.org

                                                                                                                                          I am looking for a few more US-based early adopters to provide feedback on a protective DNS service offering aligned with NIST SP 800-81 Rev. 3 (March 2026).

                                                                                                                                          csrc.nist.gov/pubs/sp/800/81/r

                                                                                                                                          This service merges Zero Trust and DNS without requiring client-side agents. Supports mobile devices, browsers, server hardware & IoT.

                                                                                                                                          If you're interested in providing feedback on this service as a free beta tester, email me at:

                                                                                                                                          securednsbeta@techliterate.co

                                                                                                                                            DamonHD boosted

                                                                                                                                            [?]Mike Sheward » 🌐
                                                                                                                                            @SecureOwl@infosec.exchange

                                                                                                                                            Did a good zero knowledge to full control of web app without tools pen test last week.

                                                                                                                                            1. found /.git/config was readable
                                                                                                                                            2. said config file contained GitHub personal access token
                                                                                                                                            3. cloney cloney clone clone
                                                                                                                                            4. review app source, find lots of debug holes and frankly, nasty sql injection issues
                                                                                                                                            5. find hardcoded cloud storage credentials in source
                                                                                                                                            6. party like it were the early 2000’s i guess

                                                                                                                                              [?]Morgan » 🌐
                                                                                                                                              @kaidenshi@exquisite.social

                                                                                                                                              Holy shit, Microsoft. Whoever made this decision should be fired. Into the Sun.

                                                                                                                                              lemmy.world/post/46435614

                                                                                                                                                [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                @jik@federate.social

                                                                                                                                                P.S. I see from looking at the ICS file in a text editor that it was produced with Microsoft Exchange Server 2010, which as far as I can tell has been out of support (i.e., no longer receiving security updates) since 2020. The invitation in question came from a healthcare facility bound by HIPAA. It is an obvious violation of the HIPAA security rule to be running Microsoft server software that is no longer supported or receiving security patches.

                                                                                                                                                  [?]Mike Sheward » 🌐
                                                                                                                                                  @SecureOwl@infosec.exchange

                                                                                                                                                  Experiment update

                                                                                                                                                  Amazon are 2/2 for hitting the QR canary token - same CDN, same non-phone user agent each time. Seems to happen async after the delivery, maybe 20 mins or so later.

                                                                                                                                                  Actual delivery photo from today below.

                                                                                                                                                  Only other test subject so far is Fedex, they did not trigger the QR.

                                                                                                                                                  amazon delivery photo

                                                                                                                                                  Alt...amazon delivery photo

                                                                                                                                                    AodeRelay boosted

                                                                                                                                                    [?]Dendrobatus Azureus » 🌐
                                                                                                                                                    @Dendrobatus_Azureus@mastodon.bsd.cafe

                                                                                                                                                    Do not forget to always patch your Linux / BSD distributions wherever they may reside.
                                                                                                                                                    Forgetting to do so may open up your systems for known exploits which is easily avoidable, from the InfoSec perspective

                                                                                                                                                    In case you don't know termux yet on ARM architecture go read and learn

                                                                                                                                                    Sources:

                                                                                                                                                    man man(1)
                                                                                                                                                    man apt

                                                                                                                                                    Termux upgrade

                                                                                                                                                    Alt...Termux upgrade

                                                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                      @Steve12L@mamot.fr

                                                                                                                                                      Marcos Dione boosted

                                                                                                                                                      [?]Allpoints » 🌐
                                                                                                                                                      @allpoints@mstdn.social

                                                                                                                                                      /rant
                                                                                                                                                      FFS vendors. Randomizing a MAC isn't making anyone safer. It just makes it harder for folks to manage their networks.

                                                                                                                                                      Up next on Today's Rant, enough with blocking inbound ping. You're not hiding from network probes.

                                                                                                                                                        Marcos Dione boosted

                                                                                                                                                        [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                                                                                                                                        @nemo@mas.to

                                                                                                                                                        Reports: A critical cPanel & WHM zero-day (CVE-2026-41940) is being actively exploited since Feb—attackers can bypass auth to gain full admin access. Patch immediately. 🔥🔐⚠️ Read: cyberinsider.com/critical-cpan

                                                                                                                                                          Remi Gacogne boosted

                                                                                                                                                          [?]Alyx [Any pronouns :nonbinary_flag:] » 🌐
                                                                                                                                                          @x_cli@infosec.exchange

                                                                                                                                                          Debunkage de la vidéo sur les mots de passe de Fabien Olicard : mémorabilité, densité et entropie irréconciliables ?

                                                                                                                                                          docs.numerique.gouv.fr/docs/48

                                                                                                                                                          Nouvel article argumentant notamment que toute structure dans un mot de passe nuit à sa qualité !

                                                                                                                                                            [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                                            @beyondmachines1@infosec.exchange

                                                                                                                                                            Mozilla Patches Critical Memory Safety and Sandbox Escape Flaws in Firefox

                                                                                                                                                            Mozilla released security updates for Firefox and Firefox ESR to fix five vulnerabilities, including critical memory safety bugs and a sandbox escape that could allow arbitrary code execution.

                                                                                                                                                            **Update Firefox and Firefox ESR as well as your Firefox based browsers (Tor, Waterfox, LibreWolf...). Mozilla fixed multiple critical memory safety bugs and a WebRTC sandbox escape that could allow a malicious website to take full control of your system. Your browser is your primary gateway to the web and will be hit first. Update now, all your sessions and tabs will be restored automatically.**

                                                                                                                                                            beyondmachines.net/event_detai

                                                                                                                                                              [?]Larvitz :fedora: » 🌐
                                                                                                                                                              @Larvitz@burningboard.net

                                                                                                                                                              Fresh gist: mitigating CVE-2026-31431 ("Copy Fail") on RHEL 8/9/10 with a tiny Ansible playbook.

                                                                                                                                                              It blacklists algif_aead via a kernel boot arg (initcall_blacklist=algif_aead_init), reboots only when needed, and asserts the mitigation actually stuck after reboot. Idempotent & safe to re-run.

                                                                                                                                                              codeberg.org/Larvitz/gists/src

                                                                                                                                                                BrianKrebs boosted

                                                                                                                                                                [?]Ian Campbell 🏴 » 🌐
                                                                                                                                                                @neurovagrant@masto.deoan.org

                                                                                                                                                                "[AI] Agents can now create Cloudflare accounts, buy domains, and deploy"

                                                                                                                                                                Like every other Cloudflare service, this was likely designed to enable threat actors, amplify abusability, and reduce accountability.

                                                                                                                                                                blog.cloudflare.com/agents-str

                                                                                                                                                                  [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                  @jik@federate.social

                                                                                                                                                                  Baby steps.

                                                                                                                                                                  Subject: Important Updates to How You Bank with Beacon Bank
Protecting you
In an effort to further protect our customers, email‑based muti‑factor authentication (MFA) will be eliminated beginning in May. To ensure uninterrupted access to your accounts, please take a moment to update your Two-factor authentication settings by selecting Security under your account settings online or under Login and Security in the mobile app. Be sure to add a supported authentication method, such as a cell phone number or an authenticator app. Please note that an authenticator app can only be added from the web version of online banking, not from the Beacon Bank app.

In the text above in the image, "email-based multi-factor authentication (MFA) will be eliminated beginning in May" has been highlighted by me in green, and "a supported authentication method, such as a cell phone number" has been highlighted by me in red.

                                                                                                                                                                  Alt...Subject: Important Updates to How You Bank with Beacon Bank Protecting you In an effort to further protect our customers, email‑based muti‑factor authentication (MFA) will be eliminated beginning in May. To ensure uninterrupted access to your accounts, please take a moment to update your Two-factor authentication settings by selecting Security under your account settings online or under Login and Security in the mobile app. Be sure to add a supported authentication method, such as a cell phone number or an authenticator app. Please note that an authenticator app can only be added from the web version of online banking, not from the Beacon Bank app. In the text above in the image, "email-based multi-factor authentication (MFA) will be eliminated beginning in May" has been highlighted by me in green, and "a supported authentication method, such as a cell phone number" has been highlighted by me in red.

                                                                                                                                                                    [?]Terri K O 🍁 » 🌐
                                                                                                                                                                    @terri@social.afront.org

                                                                                                                                                                    Has anyone here heard anything about GiveHero? Work's using it for a fitness challenge thing and while I'm ok with handing out a week of fitness data for some fun community building nonsense with my new coworkers I'd rather not find out the app is a front for some military-industrial complex spyware or something.

                                                                                                                                                                      [?]Taran Rampersad » 🌐
                                                                                                                                                                      @knowprose@mastodon.social

                                                                                                                                                                      [?]Larvitz :fedora: » 🌐
                                                                                                                                                                      @Larvitz@burningboard.net

                                                                                                                                                                      Fresh gist: mitigating CVE-2026-31431 ("Copy Fail") on RHEL 8/9/10 with a tiny Ansible playbook.

                                                                                                                                                                      It blacklists algif_aead via a kernel boot arg (initcall_blacklist=algif_aead_init), reboots only when needed, and asserts the mitigation actually stuck after reboot. Idempotent & safe to re-run.

                                                                                                                                                                      codeberg.org/Larvitz/gists/src

                                                                                                                                                                        [?]your auntifa liza 🇵🇷 🦛 🦦 » 🌐
                                                                                                                                                                        @blogdiva@mastodon.social

                                                                                                                                                                        RE: cyberplace.social/@GossiTheDog

                                                                                                                                                                        I HATE TO BE THAT GUY but even as this paints the security in a bad light… do we know if this wasn't aislopped?

                                                                                                                                                                        we don’t.

                                                                                                                                                                        and that's the point of : it’s a complete rejection of The Social Contract on how we agree on the truth.

                                                                                                                                                                        we need the community to help us create new, defensive fact checking protocols. the oligarchy wants to own reality, and define the truth. pushback on giving them the benefit of the doubt.

                                                                                                                                                                        Y’ALL DID AND WE LOST THE RIGHT TO ABORTIONS, AND VOTING RIGHTS

                                                                                                                                                                          Gabriel :golang: :nixos: boosted

                                                                                                                                                                          [?]Mike Sheward » 🌐
                                                                                                                                                                          @SecureOwl@infosec.exchange

                                                                                                                                                                          trying a new thing, have 3D printed a QR code and put it on the front porch

                                                                                                                                                                          QR code triggers a canary token

                                                                                                                                                                          want to see if any of the delivery companies are using the drop off proof of delivery pics to train AI

                                                                                                                                                                          my door mat with a 3d printed qr code to the side, the qr code is covered up in this picture to protect the integrity of the experiment

                                                                                                                                                                          Alt...my door mat with a 3d printed qr code to the side, the qr code is covered up in this picture to protect the integrity of the experiment

                                                                                                                                                                            Vincent 🐡 boosted

                                                                                                                                                                            [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                            @rysiek@mstdn.social

                                                                                                                                                                            A lot of people are apparently happily running a script clearly marked as a root exploit from some random website using curl | bash :blobsweat:

                                                                                                                                                                            Some do inspect the script, but then still run it using curl | bash anyway. :thaenkin:

                                                                                                                                                                            Incidentally, this very relevant blogpost about detecting curl | bash and serving different scripts based on that is almost exactly a decade old:
                                                                                                                                                                            web.archive.org/web/2023031806

                                                                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                              @Steve12L@mamot.fr

                                                                                                                                                                              [?]Timo Tijhof » 🌐
                                                                                                                                                                              @krinkle@fosstodon.org

                                                                                                                                                                              FastCGI: 30 Years Old and Still the Better Protocol for Reverse Proxies by @agwa

                                                                                                                                                                              How to avoid getting pwned by request smuggling and untrusted headers.

                                                                                                                                                                              agwa.name/blog/post/fastcgi_is

                                                                                                                                                                                Marcos Dione boosted

                                                                                                                                                                                [?]Mike Sheward » 🌐
                                                                                                                                                                                @SecureOwl@infosec.exchange

                                                                                                                                                                                One of the other domains I registered as I descended into this rabbit hole was "dev-user.com".

                                                                                                                                                                                Based on email traffic, owning that domain has been enough to give me admin access to a couple of Wordpress-powered sites, and multiple SaaS apps (particularly, staging/non-prod instances).

                                                                                                                                                                                All orgs involved have been informed.

                                                                                                                                                                                So to summarize current state of Plexfiltration:

                                                                                                                                                                                1 - Deleteduser/deleted-user.com = 65 orgs using
                                                                                                                                                                                2 - Internaluser.com - 12 orgs
                                                                                                                                                                                3 - service-account.com - 8 orgs
                                                                                                                                                                                4 - dev-user.com - 6 orgs

                                                                                                                                                                                  [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                  @jik@federate.social

                                                                                                                                                                                  Anybody else getting daily spam phone calls from "Jeff" at , each one from a different phone number.
                                                                                                                                                                                  They finally pissed me off enough that I reamed them out on (linkedin.com/posts/share-74553). Not that I expect it to do any good; a company that resorts to making sales calls from spoofed phone numbers isn't going to stop just because somebody asks them to.
                                                                                                                                                                                  (And I suspect "Jeff" is AI, not a real person.)

                                                                                                                                                                                    [?]Quad9DNS » 🌐
                                                                                                                                                                                    @quad9dns@mastodon.social

                                                                                                                                                                                    ISO an Infrastructure Provisioning Manager to join our amazing Quad9 team. 🌠

                                                                                                                                                                                    Interested? You can find all the details right here: quad9.net/about/jobs/

                                                                                                                                                                                    Remember, sharing is caring 🫶

                                                                                                                                                                                    Quad9 logo with a neon pink glowing frame and text saying "We are hiring, join our team" on a black background.

                                                                                                                                                                                    Alt...Quad9 logo with a neon pink glowing frame and text saying "We are hiring, join our team" on a black background.

                                                                                                                                                                                      🗳

                                                                                                                                                                                      [?]Bobe'bot on security » 🤖 🌐
                                                                                                                                                                                      @Bobe_bot@mastobot.ping.moi

                                                                                                                                                                                      🧠 Quiz Infosec — Wednesday 29 Apr

                                                                                                                                                                                      Dans le contexte des systèmes legacy, quel mécanisme protège un secteur de démarrage (MBR) contre les modifications non autorisées ?

                                                                                                                                                                                      Résultats + explication demain !

                                                                                                                                                                                      Secure Boot:0
                                                                                                                                                                                      ASLR:0
                                                                                                                                                                                      DEP/NX bit:0
                                                                                                                                                                                      AES-256:0

                                                                                                                                                                                        [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                        @jik@federate.social

                                                                                                                                                                                        OK, so, just sent out breach notice + identity monitoring offer letters on behalf of .
                                                                                                                                                                                        We received two. They were addressed to first initial + last name. The salutation of the letter, also, says "Dear <initial>:" rather than giving a name.
                                                                                                                                                                                        The two letters' initials match my wife's and my first names. They _also_ match the first names of two of our kids who may have applied to Columbia.
                                                                                                                                                                                        So, who the fuck are the letters for? 🤔🤷🤡

                                                                                                                                                                                          DamonHD boosted

                                                                                                                                                                                          [?]Mike Sheward » 🌐
                                                                                                                                                                                          @SecureOwl@infosec.exchange

                                                                                                                                                                                          I just got given admin access to some Medicaid filing platform because I own the domain internaluser.com

                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                            [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                                                                                                                                                                            @MissConstrue@mefi.social

                                                                                                                                                                                            thatprivacyguy.com/blog/anthro

                                                                                                                                                                                            Security researcher Alexander Hanff wrote an article titled Anthropic secretly installs spyware when you install Claude Desktop. Anthropic has not denied the report, as of time of post.

                                                                                                                                                                                            TLDR: If a user installs Claude Desktop on a Mac (pc test results tba), it installs a backdoor into every browser, even those not installed. By testing on a clean machine, Hanff discovered that Installing Claude Desktop for macOS drops a Native Messaging host manifest into multiple Chromium profiles (Chrome, Edge, Brave, Arc, Vivaldi, Opera, Chromium), even including for browsers that are not actually installed yet.

                                                                                                                                                                                            How bad is it? Well...that depends. What it does is create a very wide attack vector, especially for prompt injection. That it is done invisibly, without telling the user, and making it difficult to remove, is certainly problematic.

                                                                                                                                                                                            I dunno man, maybe don’t use the planet destroying tulip craze?

                                                                                                                                                                                              Norry Nowt boosted

                                                                                                                                                                                              [?]TelH90 » 🌐
                                                                                                                                                                                              @kkarhan@c.im

                                                                                                                                                                                              DamonHD boosted

                                                                                                                                                                                              [?]Mike Sheward » 🌐
                                                                                                                                                                                              @SecureOwl@infosec.exchange

                                                                                                                                                                                              Haven't had much new stuff to report on this topic for a bit...until today!

                                                                                                                                                                                              3 new arrivals to the deleteduser dumpster:

                                                                                                                                                                                              - a company that handles public/guest wifi access in Europe

                                                                                                                                                                                              - An EU based sports club booking platform

                                                                                                                                                                                              and, extremely concerningly:

                                                                                                                                                                                              - a period tracking app, that emails out full PII and data

                                                                                                                                                                                              All have been contacted.

                                                                                                                                                                                              In lighter plexfiltration news, a developer who was testing something out sent a 'hello, test' message to a 'deleted user', so I was able to respond with 'test worked - hows it going?' which I can only assume really freaked them out.

                                                                                                                                                                                              Out of the now 60ish orgs contacted, have heard back from 2 who have fixed their use of deleteduser.com. I'd say that maybe 3 or 4 have dropped off, but the rest still continue.

                                                                                                                                                                                              Ironically, this includes all of the tech and cybersecurity companies that were contacted.

                                                                                                                                                                                                [?]Laurent Cheylus » 🌐
                                                                                                                                                                                                @lcheylus@bsd.network

                                                                                                                                                                                                Note d’alerte par le Centre de Coordination des Crises Cyber (C4) : mise en garde contre une vaste offensive de piratage ciblée via les messageries instantanées ; les secteurs régaliens sont spécifiquement visés dgsi.interieur.gouv.fr/dgsi-a-

                                                                                                                                                                                                  [?]maswan » 🌐
                                                                                                                                                                                                  @maswan@mastodon.acc.sunet.se

                                                                                                                                                                                                  Ah, the fun of abuse contact emails. "attempt of DoS attack" , "using 9.5 TCP kpkts/s".

                                                                                                                                                                                                  The "DoS" in question: Someone downloading suse package updates at the rate of ~15Mbit/s, leading to us, the suse mirror, sending tcp packets in their direction...

                                                                                                                                                                                                    [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                    @Steve12L@mamot.fr

                                                                                                                                                                                                    ⋅ Vidar Infostealer Spreads via Fake CAPTCHAs, Hides in JPEG and TXT Files

                                                                                                                                                                                                    hackread.com/vidar-infostealer

                                                                                                                                                                                                      Fred de CLX boosted

                                                                                                                                                                                                      [?]knoppix » 🌐
                                                                                                                                                                                                      @knoppix95@mastodon.social

                                                                                                                                                                                                      Bitwarden CLI version 2026.4.0 was compromised via a GitHub Actions supply chain attack, distributing malicious npm code that stole secrets 🔓
                                                                                                                                                                                                      The package was briefly available before removal, with attackers exfiltrating tokens and injecting workflows across CI pipelines 🔐

                                                                                                                                                                                                      🔗 thehackernews.com/2026/04/bitw

                                                                                                                                                                                                        [?]Bobe'bot on security » 🤖 🌐
                                                                                                                                                                                                        @Bobe_bot@mastobot.ping.moi

                                                                                                                                                                                                        Leaving SSH port 22 open for 54 days — and carefully logging every knock at the door. The result? A fascinating (and slightly dizzying) portrait of what the internet looks like from the outside. Spoiler: it's busy. Very busy. 🔍


                                                                                                                                                                                                        arman-bd.hashnode.dev/i-left-p

                                                                                                                                                                                                          [?]your auntifa liza 🇵🇷 🦛 🦦 » 🌐
                                                                                                                                                                                                          @blogdiva@mastodon.social

                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                          [?]Graham Perrin » 🌐
                                                                                                                                                                                                          @grahamperrin@mastodon.bsd.cafe

                                                                                                                                                                                                          AI/ML Security

                                                                                                                                                                                                          <openssf.org/groups/ai-ml-secur> @openssf @linuxfoundation

                                                                                                                                                                                                          "This working group is situated at the intersection between security and artificial intelligence (AI). We explore the security risks associated with Large Language Models (LLMs), Generative AI (GenAI), and other forms of artificial intelligence and machine learning (ML), and their impact on open source projects, maintainers, their security, communities, and adopters. Furthermore, we explore using AI and ML to strengthen the security of other open source projects.

                                                                                                                                                                                                          This group in collaborative research and peer organization engagement to explore topics related to AI and security. This includes security for AI development (e.g., supply chain security) but also using AI for security. We are covering risks posed to individuals and organizations by improperly trained models, data poisoning, privacy and secret leakage, prompt injection, licensing, adversarial attacks, and any other similar risks.

                                                                                                                                                                                                          This group leverages prior art in the AI/ML space,draws upon both security and AI/ML experts, and pursues collaboration with other communities (such as the CNCF’s AI WG, LFAI & Data, AI Alliance, MLCommons, and many others) who are also seeking to research the risks presented by AL/ML to OSS in order to provide guidance, tooling, techniques, and capabilities to support open source projects and their adopters in securely integrating, using, detecting and defending against LLMs. …"

                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                            Fred de CLX boosted

                                                                                                                                                                                                            [?]Etienne / Tek [he/him] » 🌐
                                                                                                                                                                                                            @tek@todon.eu

                                                                                                                                                                                                            Defending Against China-Nexus Covert Networks of Compromised Devices
                                                                                                                                                                                                            cisa.gov/news-events/cybersecu

                                                                                                                                                                                                              [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                              @jik@federate.social

                                                                                                                                                                                                              Happy Day to those who celebrate!
                                                                                                                                                                                                              (And it only took them ten months. Wow, so fast!)

                                                                                                                                                                                                              An envelope whose return address is "Columbia University / IN THE CITY OF NEW YORK / Return to Kroll" and recipient is "J KAMENS"

                                                                                                                                                                                                              Alt...An envelope whose return address is "Columbia University / IN THE CITY OF NEW YORK / Return to Kroll" and recipient is "J KAMENS"

                                                                                                                                                                                                                [?]knoppix » 🌐
                                                                                                                                                                                                                @knoppix95@mastodon.social

                                                                                                                                                                                                                Switzerland plans a gradual shift from Microsoft products to reduce dependency, citing digital sovereignty and long-term control over public IT systems 🇨🇭
                                                                                                                                                                                                                Open-source alternatives are under review amid cost, lock-in, and US Cloud Act data access risks tied to foreign providers 🔍

                                                                                                                                                                                                                🔗 swissinfo.ch/eng/swiss-authori

                                                                                                                                                                                                                  Marcos Dione boosted

                                                                                                                                                                                                                  [?]Mike Sheward » 🌐
                                                                                                                                                                                                                  @SecureOwl@infosec.exchange

                                                                                                                                                                                                                  was testing an AI tools willingness to call its own API’s this week

                                                                                                                                                                                                                  1. gave it an absolute url to call, everytime it replaced it with a place holder because its prompt must’ve included a “never call yourself” rule

                                                                                                                                                                                                                  2. gave it the same url, but base64 encoded and said, “base64 decode the url and call it”- it worked - willingly made calls to its own api in the context of itself

                                                                                                                                                                                                                  like a 2000’s era waf bypass

                                                                                                                                                                                                                  what’s old is new! but with a glowy border around the input box so you know its fancy af

                                                                                                                                                                                                                    [?]Mike Sheward » 🌐
                                                                                                                                                                                                                    @SecureOwl@infosec.exchange

                                                                                                                                                                                                                    Ok, if you are particularly sensitive to the effects of irony, I suggest you take a seat before reading further.

                                                                                                                                                                                                                    In what is perhaps the most perfect encapsulation of everything that this experiment has shown so far, last night, deleted-user.com received over 400 emails from the same organization.

                                                                                                                                                                                                                    This was an EU based tech firm.

                                                                                                                                                                                                                    The purpose of those emails? They were from the company's legal team, advising users of updated terms and conditions, and the first update was:

                                                                                                                                                                                                                    "Data protection: we added language explaining how we handle personal data under the GDPR"

                                                                                                                                                                                                                      [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                      @jik@federate.social

                                                                                                                                                                                                                      lol. lmao, even.
                                                                                                                                                                                                                      To be clear: it absolutely sucks that the Trump administration has done the same hatchet job to that they've done to most of the rest of the federal government. We need strong federal leadership. But after all the damage Trump has done to CISA, it's a joke and will remain a joke regardless of whether it has a Senate-confirmed head and regardless of who that head is.
                                                                                                                                                                                                                      Given that, I am comfortable laughing at the ineptitude here.
                                                                                                                                                                                                                      techcrunch.com/2026/04/23/trum

                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                        [?]Tinker ☀️ » 🌐
                                                                                                                                                                                                                        @tinker@infosec.exchange

                                                                                                                                                                                                                        Ummm... Is SANS training ICE?

                                                                                                                                                                                                                        sam.gov/workspace/contract/opp

                                                                                                                                                                                                                        Edit to add: SANS is training ICE how to pull information off of harddrives, etc.

                                                                                                                                                                                                                        FOR498: Digital Acquisition and Rapid Triage

                                                                                                                                                                                                                        "Course Overview:
                                                                                                                                                                                                                        A digital forensic acquisition training course, FOR498 provides the skills to identify the many and varied data storage mediums in use today, and how to collect and preserve this data in a forensically sound manner despite how and where it may be stored. This forensics data collection course covers digital acquisition from computers, portable devices, networks, and the cloud, and teaches rapid triage—the art and science of identifying and starting to extract actionable intelligence from a hard drive in 90 minutes or less."

                                                                                                                                                                                                                        This training will directly hurt people.

                                                                                                                                                                                                                        Notification of SANS Training for US Immigration and Customs Enforcement

                                                                                                                                                                                                                        Alt...Notification of SANS Training for US Immigration and Customs Enforcement

                                                                                                                                                                                                                          mmu_man boosted

                                                                                                                                                                                                                          [?]Etienne / Tek [he/him] » 🌐
                                                                                                                                                                                                                          @tek@todon.eu

                                                                                                                                                                                                                          Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
                                                                                                                                                                                                                          socket.dev/blog/bitwarden-cli-

                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                            [?]AmmarSpaces » 🌐
                                                                                                                                                                                                                            @AmmarSpaces@infosec.exchange

                                                                                                                                                                                                                            Today, there is a meeting between @wikipedia and Ministry of Communication and Digital Affairs.

                                                                                                                                                                                                                            Whether or not wikipedia and wikimedia blocked are depends on today meeting.

                                                                                                                                                                                                                            Let's hope we won.






                                                                                                                                                                                                                            @indonesia

                                                                                                                                                                                                                            Wikipedia Blocked or Not Depends on Today's Meeting

                                                                                                                                                                                                                            Alt...Wikipedia Blocked or Not Depends on Today's Meeting

                                                                                                                                                                                                                              [?]βrυɲϋs » 🌐
                                                                                                                                                                                                                              @brunus@mamot.fr

                                                                                                                                                                                                                              Fucky fuck ! KiD est fasciné par mes histoires de "hackers", white hats, grey hats, black hats, les mags que je lis encore, Phrack, 2600 (nan...pas LinuxFr), les outils que je maîtrise...
                                                                                                                                                                                                                              Got r00t !? 😜
                                                                                                                                                                                                                              J'avais dit : Le même mec pète tous les sites d'assos de sport, ça doit être le même soft, la même faille.
                                                                                                                                                                                                                              J'avais dit à un pote, qui n'y croyait pas : Lulzsec c'est des branleurs ils vont se faire niquer, ils sont trop prétentieux et pas furtifs !
                                                                                                                                                                                                                              ¯\_(ツ)_/¯

                                                                                                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                                                                                                ⋅ Cybercriminals Exploit French Fintech Accounts to Move Stolen Money Before Detection

                                                                                                                                                                                                                                cybersecuritynews.com/cybercri

                                                                                                                                                                                                                                  [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                  @jik@federate.social

                                                                                                                                                                                                                                  I am sure there is absolutely no reason to fear that the frequency and severity of security breaches like this one will increase as age verification laws get passed all over the world. /s
                                                                                                                                                                                                                                  The legislators writing these laws for the most part can't be bothered to include strict privacy, security, or data deletion requirements. They're not even _trying_ to do this right (not that there _is_ a way to do age verification right, but still…).
                                                                                                                                                                                                                                  techcrunch.com/2026/04/22/fran

                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                    [?]Mark Wyner Won’t Comply :vm: » 🌐
                                                                                                                                                                                                                                    @markwyner@mas.to

                                                                                                                                                                                                                                    Google is sleeping with ICE. And they have your data. So, yeah, maybe detach from their services.

                                                                                                                                                                                                                                    eff.org/press/releases/eff-sta

                                                                                                                                                                                                                                      [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                      @jik@federate.social


                                                                                                                                                                                                                                      OK, so, with all the advances in computing and networking technology we've seen in recent decades, it's certainly possible, at least in theory, for it to be entirely pleasant and hassle-free to book international travel involving multiple airlines.
                                                                                                                                                                                                                                      Let's talk about what we get instead.
                                                                                                                                                                                                                                      (1/16)

                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                        [?]God Emperor of Mastodon » 🌐
                                                                                                                                                                                                                                        @mms@mastodon.bsd.cafe

                                                                                                                                                                                                                                        tweet about loveble data leak

                                                                                                                                                                                                                                        Alt...tweet about loveble data leak

                                                                                                                                                                                                                                          [?]Hypolite Petovan » 🌐
                                                                                                                                                                                                                                          @hypolite@friendica.mrpetovan.com

                                                                                                                                                                                                                                          Oh good, Claude Desktop on MacOS silently and continually whitelists browser extensions that aren't installed yet on browsers that aren't installed yet that Anthropic says it doesn't support yet.


                                                                                                                                                                                                                                          Anthropic secretly installs spyware when you install Claude Desktop — That Privacy Guy!

                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                            ⋅ Les Magasins U ont été piratés : les données des clients ont été compromises

                                                                                                                                                                                                                                            01net.com/actualites/les-magas

                                                                                                                                                                                                                                              [?]AA » 🌐
                                                                                                                                                                                                                                              @AAKL@infosec.exchange

                                                                                                                                                                                                                                              New.

                                                                                                                                                                                                                                              This guy is 24-years-old. His chosen career path is cybercrime. We really should ask what is happening to that generation because there are multiple accounts of kids in their teens turning to cybercrime, not just in the UK, although that country clearly has a problem. Technically, this shouldn't qualify as "normal," non-delinquent behavior. So, in the grand social tapestry, there is a glaring black hole. Who failed?

                                                                                                                                                                                                                                              KrebsonSecurity: ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty krebsonsecurity.com/2026/04/sc @briankrebs

                                                                                                                                                                                                                                                mmu_man boosted

                                                                                                                                                                                                                                                [?]Pseudo Nym » 🌐
                                                                                                                                                                                                                                                @pseudonym@mastodon.online

                                                                                                                                                                                                                                                [?]your auntifa liza 🇵🇷 🦛 🦦 » 🌐
                                                                                                                                                                                                                                                @blogdiva@mastodon.social

                                                                                                                                                                                                                                                in my 4 decades of online life, i go where these people go:
                                                                                                                                                                                                                                                especially
                                                                                                                                                                                                                                                &
                                                                                                                                                                                                                                                especially epidemiologists, especially²

                                                                                                                                                                                                                                                &
                                                                                                                                                                                                                                                riders
                                                                                                                                                                                                                                                and cuz they’re curators by default


                                                                                                                                                                                                                                                + esp trans folks
                                                                                                                                                                                                                                                activists

                                                                                                                                                                                                                                                & activists

                                                                                                                                                                                                                                                these people not only know what's newsworthy. they’re often the news.
                                                                                                                                                                                                                                                🧵…

                                                                                                                                                                                                                                                  [?]Etienne / Tek [he/him] » 🌐
                                                                                                                                                                                                                                                  @tek@todon.eu

                                                                                                                                                                                                                                                  Dissecting Sapphire Sleet’s (Bluenoroff) macOS intrusion from lure to compromise
                                                                                                                                                                                                                                                  microsoft.com/en-us/security/b

                                                                                                                                                                                                                                                  Some interesting bits in there, like "invokes the legitimate macOS softwareupdate binary with an invalid parameter, an action that performs no real update but launches a trusted Apple‑signed process to reinforce the appearance of legitimacy"

                                                                                                                                                                                                                                                    [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                    @Steve12L@mamot.fr

                                                                                                                                                                                                                                                    ⋅ « StravaLeaks » : quand les traces numériques deviennent un enjeu de sécurité

                                                                                                                                                                                                                                                    theconversation.com/stravaleak

                                                                                                                                                                                                                                                      [?]Alyx [Any pronouns :nonbinary_flag:] » 🌐
                                                                                                                                                                                                                                                      @x_cli@infosec.exchange

                                                                                                                                                                                                                                                      Je viens de publier un cours intitulé "Identité et méthodes d'authentification" sous licence CC-BY : broken-by-design.fr/posts/cour

                                                                                                                                                                                                                                                      Ce cours s'adresse aux personnes de niveau M2 et aux professionnel.les débutant.es, même si les plus expérimenté.es pourraient y trouver des informations intéressantes.

                                                                                                                                                                                                                                                      Il comprend une introduction aux différents types de référentiels d'identités, avant de plonger dans l'authentification, sous des angles juridiques et techniques. Authentification multifacteur, forte, résistante au phishing, assurant de bonnes garanties de vie privée ! Authentification à l'état de l'art ! Vous pourrez en apprendre plus à ces sujets grâce à ce cours.

                                                                                                                                                                                                                                                      Et ce n'est que la première partie ! Ce mois-ci, une seconde partie sera publiée, sur le sujet de l'autorisation, avec un TP de mise en place de pour une authentification fédérée avec OpenID Connect! À suivre !

                                                                                                                                                                                                                                                      Corentin boosted

                                                                                                                                                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                      @Steve12L@mamot.fr

                                                                                                                                                                                                                                                      ⋅ L'ANTS piratée à cause d'une faille basique et 19 millions de Français en font les frais, une fois de plus !

                                                                                                                                                                                                                                                      clubic.com/actualite-609775-l-

                                                                                                                                                                                                                                                      🤦‍♂️

                                                                                                                                                                                                                                                        rixx boosted

                                                                                                                                                                                                                                                        [?]Mike Sheward » 🌐
                                                                                                                                                                                                                                                        @SecureOwl@infosec.exchange

                                                                                                                                                                                                                                                        i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

                                                                                                                                                                                                                                                        The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

                                                                                                                                                                                                                                                        And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D

                                                                                                                                                                                                                                                          Boud boosted

                                                                                                                                                                                                                                                          [?]AmmarSpaces » 🌐
                                                                                                                                                                                                                                                          @AmmarSpaces@infosec.exchange

                                                                                                                                                                                                                                                          ... [SENSITIVE CONTENT]

                                                                                                                                                                                                                                                          If Wikipedia were indeed blocked in Indonesia, please understand with looking at these following links, according to Indonesian internet users

                                                                                                                                                                                                                                                          Also, @wikipedia , please keep your Indonesia's problem banner at the top of your page until there is a resolution. Wikipedia you are in the verge of being blocked in Indonesia, yet at the critical times, the banner no longer there.

                                                                                                                                                                                                                                                          (I hope they revoked their decision and this is not indeed the reason they want Wikipedia joining PSE)

                                                                                                                                                                                                                                                          Please look at these links:

                                                                                                                                                                                                                                                          id.wikipedia.org/wiki/Daftar_k
                                                                                                                                                                                                                                                          (saved in Internet Archive: web.archive.org/web/2026041810)

                                                                                                                                                                                                                                                          id.wikipedia.org/wiki/Makan_Be (Archived at: web.archive.org/web/2026041814)

                                                                                                                                                                                                                                                          id.wikipedia.org/wiki/Kontrove (Archived at: web.archive.org/web/2026041814)

                                                                                                                                                                                                                                                          id.wikipedia.org/wiki/Kontrove (Archived at: web.archive.org/web/2026041814)

                                                                                                                                                                                                                                                          id.wikipedia.org/wiki/Kontrove (Archive (per January 13th 2026): web.archive.org/web/2026011303)

                                                                                                                                                                                                                                                          A snippet of food poisoning incident from MBG (free nutrition meals program)

source:
https://id.wikipedia.org/wiki/Daftar_kasus_keracunan_makanan_massal_di_dunia

                                                                                                                                                                                                                                                          Alt...A snippet of food poisoning incident from MBG (free nutrition meals program) source: https://id.wikipedia.org/wiki/Daftar_kasus_keracunan_makanan_massal_di_dunia

                                                                                                                                                                                                                                                          A snippet of free nutritious meals program controversies
Source:
https://id.wikipedia.org/wiki/Makan_Bergizi_Gratis

                                                                                                                                                                                                                                                          Alt...A snippet of free nutritious meals program controversies Source: https://id.wikipedia.org/wiki/Makan_Bergizi_Gratis

                                                                                                                                                                                                                                                          A snippet of Joko Widodo (previous Indonesia president) controversies
Link: https://id.wikipedia.org/wiki/Kontroversi_yang_melibatkan_Joko_Widodo

                                                                                                                                                                                                                                                          Alt...A snippet of Joko Widodo (previous Indonesia president) controversies Link: https://id.wikipedia.org/wiki/Kontroversi_yang_melibatkan_Joko_Widodo

                                                                                                                                                                                                                                                          A snippet of Gibran Rakabuming Raka (current Indonesia's Vice President) controversies
Source: https://id.wikipedia.org/wiki/Kontroversi_yang_melibatkan_Gibran_Rakabuming_Raka

                                                                                                                                                                                                                                                          Alt...A snippet of Gibran Rakabuming Raka (current Indonesia's Vice President) controversies Source: https://id.wikipedia.org/wiki/Kontroversi_yang_melibatkan_Gibran_Rakabuming_Raka

                                                                                                                                                                                                                                                            [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                                                                                                                                            @beyondmachines1@infosec.exchange

                                                                                                                                                                                                                                                            Mailcow Patches Critical XSS Flaws Enabling Unauthenticated Account Takeover

                                                                                                                                                                                                                                                            Mailcow patched three XSS vulnerabilities, including a critical flaw in Autodiscover logs, that allow unauthenticated attackers to take over administrator accounts and exfiltrate sensitive emails. The flaws were fixed in version 2026-03b after researchers demonstrated how to chain them with Login CSRF to steal user data.

                                                                                                                                                                                                                                                            **If you run a self-hosted Mailcow email server, update it to version 2026-03b ASAP. These vulnerabilities could let an attacker silently take over your admin account just by sending a crafted email. After updating, also check that your server is configured to only accept the X-Real-IP header from trusted internal proxies, not from the open internet.**

                                                                                                                                                                                                                                                            beyondmachines.net/event_detai

                                                                                                                                                                                                                                                              Debacle boosted

                                                                                                                                                                                                                                                              [?]Taran Rampersad » 🌐
                                                                                                                                                                                                                                                              @knowprose@mastodon.social

                                                                                                                                                                                                                                                              Not a fan of Bill Mager for a variety of reasons...
                                                                                                                                                                                                                                                              And...

                                                                                                                                                                                                                                                              It seems he got this one right enough.

                                                                                                                                                                                                                                                              thewrap.com/creative-content/t

                                                                                                                                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                [?]R.L. Dane :Debian: :OpenBSD: :FreeBSD: 🍵 :MiraLovesYou: [he/him/my good fellow] » 🌐
                                                                                                                                                                                                                                                                @rl_dane@polymaths.social

                                                                                                                                                                                                                                                                [?]R.L. Dane :Debian: :OpenBSD: :FreeBSD: 🍵 :MiraLovesYou: [he/him/my good fellow] » 🌐
                                                                                                                                                                                                                                                                @rl_dane@polymaths.social

                                                                                                                                                                                                                                                                @hanno

                                                                                                                                                                                                                                                                The good thing is that if the old adage, "You don't have to be the fastest gazelle to outrun the lion, you just have to not be the slowest" is true, there are a crapton of slow gazelles out there right now.

                                                                                                                                                                                                                                                                Halfway sensible #infosec practices from 25 years ago would be fantastic today.

                                                                                                                                                                                                                                                                (That said, I never want to give anyone a false sense of security, especially when it's hard to even know what's vibecoded out there right now, let alone fully avoid it.

                                                                                                                                                                                                                                                                  [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                  @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                                                  [?]BastilleBSD :freebsd: » 🌐
                                                                                                                                                                                                                                                                  @BastilleBSD@fosstodon.org

                                                                                                                                                                                                                                                                  RE: infosec.exchange/@clueax/11642

                                                                                                                                                                                                                                                                  Having recently completed a master's degree in Cybersecurity, this is incredibly accurate.

                                                                                                                                                                                                                                                                    [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                    @jik@federate.social

                                                                                                                                                                                                                                                                    Class-action lawsuit with a free year of credit monitoring incoming in 3… 2… 1…
                                                                                                                                                                                                                                                                    Alas, as an Amtrak passenger who has had my share of train trouble and therefore support tickets, my info (name, email address, physical address, support ticket details) was included in this breach. 🤦
                                                                                                                                                                                                                                                                    haveibeenpwned.com/Breach/Amtr

                                                                                                                                                                                                                                                                      [?]βrυɲϋs » 🌐
                                                                                                                                                                                                                                                                      @brunus@mamot.fr

                                                                                                                                                                                                                                                                      Ha bin c'est un poil trop tard mais mieux vaut maintenant que jamais hein !

                                                                                                                                                                                                                                                                      "L'utilisation d'applications et de logiciels étrangers dans le cadre professionnel constitue un risque, alerte la DGSI...
                                                                                                                                                                                                                                                                      Cela concerne les messageries instantanées, les logiciels de visioconférence, le stockage de données en ligne, des outils d'intelligence artificielle, etc."

                                                                                                                                                                                                                                                                      franceinfo.fr/internet/securit

                                                                                                                                                                                                                                                                        [?]Xavier Garcia » 🌐
                                                                                                                                                                                                                                                                        @shellguardians@infosec.exchange

                                                                                                                                                                                                                                                                        AI is going grreeaaaat...

                                                                                                                                                                                                                                                                        Somebody invented a protocol for cross-application communication over the system clipboard. AKA copy and paste.

                                                                                                                                                                                                                                                                        I was looking at the MaCOS telemetry and I found a weird script that was pasting AI prompts in the MacOS clipboard.

                                                                                                                                                                                                                                                                        This is the 7th hell!

                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                          [?]Mike Sheward » 🌐
                                                                                                                                                                                                                                                                          @SecureOwl@infosec.exchange

                                                                                                                                                                                                                                                                          Boud boosted

                                                                                                                                                                                                                                                                          [?]AmmarSpaces » 🌐
                                                                                                                                                                                                                                                                          @AmmarSpaces@infosec.exchange

                                                                                                                                                                                                                                                                          Indonesia will ban Wikimedia (including Wikipedia @wikipedia in 7 days if they don't register to PSE (a.k.a bow to whatever goverment said).

                                                                                                                                                                                                                                                                          

Announcement:

Wikimedia Project websites, including Wikipedia, will be blocked by the
Ministry of Communication and Digital Affairs within 7 working days if they
do not register as a Private Scope PSE in Indonesia.
Previously, we have made a post regarding PSE which can be viewed below
this post.

                                                                                                                                                                                                                                                                          Alt... Announcement: Wikimedia Project websites, including Wikipedia, will be blocked by the Ministry of Communication and Digital Affairs within 7 working days if they do not register as a Private Scope PSE in Indonesia. Previously, we have made a post regarding PSE which can be viewed below this post.

                                                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                            ⋅ Google, Microsoft, Meta Tracking You Even if You Opt Out – New Research

                                                                                                                                                                                                                                                                            cybersecuritynews.com/google-m

                                                                                                                                                                                                                                                                              AodeRelay boosted

                                                                                                                                                                                                                                                                              [?]Taran Rampersad » 🌐
                                                                                                                                                                                                                                                                              @knowprose@mastodon.social

                                                                                                                                                                                                                                                                              rixx boosted

                                                                                                                                                                                                                                                                              [?]Mike Sheward » 🌐
                                                                                                                                                                                                                                                                              @SecureOwl@infosec.exchange

                                                                                                                                                                                                                                                                              i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

                                                                                                                                                                                                                                                                              The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

                                                                                                                                                                                                                                                                              And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D

                                                                                                                                                                                                                                                                                🗳
                                                                                                                                                                                                                                                                                Paco Hope boosted

                                                                                                                                                                                                                                                                                [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                @jik@federate.social

                                                                                                                                                                                                                                                                                I have an old WiFi acting as an access point. This router is end-of-life and supposedly no longer receives firmware updates; there was a security update last September, so it isn't _too_ stale.
                                                                                                                                                                                                                                                                                Because it's serving as an access point it has no public IP address, though obviously a sufficiently dedicated attacker could literally sit outside our house and talk to it over WiFi.
                                                                                                                                                                                                                                                                                If you were in my shoes, what would you do with this router?

                                                                                                                                                                                                                                                                                leave it, it's fine:19
                                                                                                                                                                                                                                                                                too risky, replace it:2
                                                                                                                                                                                                                                                                                too risky, flash it to DD-WRT:23
                                                                                                                                                                                                                                                                                something else, see reply:1

                                                                                                                                                                                                                                                                                Closed

                                                                                                                                                                                                                                                                                  [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                  @jik@federate.social


                                                                                                                                                                                                                                                                                  I just discovered that a firmware upgrade with security patches for one of my home's WiFi routers was released by in September 2025, but the router itself has continued to claim since then that no upgrade was available every month when I went to the firmware upgrade page on the router and told it to check.
                                                                                                                                                                                                                                                                                  Brillian, 10/10, no notes. 😠

                                                                                                                                                                                                                                                                                    GuB boosted

                                                                                                                                                                                                                                                                                    [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                    @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                    On recommence !
                                                                                                                                                                                                                                                                                    Les sites gouv : du gruyère…

                                                                                                                                                                                                                                                                                    ⋅ Gros coup dur pour l'Éducation nationale, qui confirme ce mardi soir avoir été victime d'une nouvelle cyberattaque, qui expose les données d'élèves liées à ÉduConnect.

                                                                                                                                                                                                                                                                                    clubic.com/actualite-608995-no

                                                                                                                                                                                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                      @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                      ⋅ 108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

                                                                                                                                                                                                                                                                                      thehackernews.com/2026/04/108-

                                                                                                                                                                                                                                                                                        [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                                                                                                                                                                        @beyondmachines1@infosec.exchange

                                                                                                                                                                                                                                                                                        MyLovely.AI Data Breach Exposes Intimate Content and Personal Data of Users

                                                                                                                                                                                                                                                                                        A threat actor claims to have breached MyLovely.AI, an NSFW AI companion platform, and is auctioning a 2.1 GB database that allegedly includes user emails, social media handles, AI-generated explicit content, and roughly 113,000 private prompts, many tied to individual user IDs creating risks of doxxing, sextortion, and blackmail. The breach has been flagged as sensitive on Have I Been Pwned, and the company has not commented on the incident.

                                                                                                                                                                                                                                                                                        ****

                                                                                                                                                                                                                                                                                        beyondmachines.net/event_detai

                                                                                                                                                                                                                                                                                          ClaudioM boosted

                                                                                                                                                                                                                                                                                          [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                                                                                                                                                                          @beyondmachines1@infosec.exchange

                                                                                                                                                                                                                                                                                          Adobe Reader Zero-Day Exploited in Targeted Fingerprinting Campaign

                                                                                                                                                                                                                                                                                          A zero-day actively exploited vulnerability in Adobe Reader's JavaScript engine allows attackers to exfiltrate system data and potentially execute remote code via malicious PDF files.

                                                                                                                                                                                                                                                                                          **If you use Adobe Reader, open it right now and disable JavaScript by going to Edit > Preferences > JavaScript and uncheck "Enable Acrobat JavaScript". This blocks the exploit's main attack path. Until Adobe releases a patch, don't open any PDF files from unknown or unexpected sources, and if you must view untrusted PDFs, use a browser-based viewer like Chrome or Edge instead of Adobe Reader. Always verify the source of PDF files before opening them.**

                                                                                                                                                                                                                                                                                          beyondmachines.net/event_detai

                                                                                                                                                                                                                                                                                            controlc boosted

                                                                                                                                                                                                                                                                                            [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 [it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
                                                                                                                                                                                                                                                                                            @freya@social.highenergymagic.net

                                                                                                                                                                                                                                                                                            hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status.

                                                                                                                                                                                                                                                                                            Please boost for reach, any job offers please DM me.

                                                                                                                                                                                                                                                                                              lux 🦊ΘΔ boosted

                                                                                                                                                                                                                                                                                              [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 [it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
                                                                                                                                                                                                                                                                                              @freya@social.highenergymagic.net

                                                                                                                                                                                                                                                                                              hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status.

                                                                                                                                                                                                                                                                                              Please boost for reach, any job offers please DM me.

                                                                                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                                                                                [?]PLA_906114 » 🌐
                                                                                                                                                                                                                                                                                                @PLA_906114@mastodon.illumos.cafe

                                                                                                                                                                                                                                                                                                One of my first interactions with encryptions was PGP, by Philip Zimmermann

                                                                                                                                                                                                                                                                                                I wanted certain emails to be encrypted with a public private key pair combination

                                                                                                                                                                                                                                                                                                In reading Zimmermann, documentation I noticed that there could be something wrong.

                                                                                                                                                                                                                                                                                                Source code openness and other eyeballs were needed.

                                                                                                                                                                                                                                                                                                ## We got that in openGPG

                                                                                                                                                                                                                                                                                                I've NEVER trusted closed source encryption schemes.

                                                                                                                                                                                                                                                                                                I sometimes also verify if the shadow that's following me is actually mine

                                                                                                                                                                                                                                                                                                @h3artbl33d @Rairii

                                                                                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                                                                                  [?]PLA_906114 » 🌐
                                                                                                                                                                                                                                                                                                  @PLA_906114@mastodon.illumos.cafe

                                                                                                                                                                                                                                                                                                  On the lemmy wires I've read that it has happened with three specific accounts

                                                                                                                                                                                                                                                                                                  It's a coordinated attack. Microsoft wants these programs to disappear from its ecosystems. No one has access to drives and systems which are encrypted with these programs apart from the owner.

                                                                                                                                                                                                                                                                                                  lemmy.world/post/45356143

                                                                                                                                                                                                                                                                                                  @h3artbl33d

                                                                                                                                                                                                                                                                                                    [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                    @jik@federate.social

                                                                                                                                                                                                                                                                                                    RE: flipboard.com/@404media/404-me

                                                                                                                                                                                                                                                                                                    If you think there's any chance that law enforcement might ever be interested in the content of your Signal chats, and you don't want them to have access to them, then setting up disappearing messages is necessary but not sufficient. You also need to go into the Signal settings and either disable notifications completely or set them to show "No name or message" so the content won't be capture and preserved in the phone's notification database.
                                                                                                                                                                                                                                                                                                    ""

                                                                                                                                                                                                                                                                                                      [?]Etienne / Tek [he/him] » 🌐
                                                                                                                                                                                                                                                                                                      @tek@todon.eu

                                                                                                                                                                                                                                                                                                      Just found this interesting APT map by the Chinese cybersecurity company Qianxin
                                                                                                                                                                                                                                                                                                      ti.qianxin.com/apt/apt

                                                                                                                                                                                                                                                                                                      World map centred the pacific ocean that shows list of APT groups per country, some of them written in Latin characters, some of then in Chinese characters

                                                                                                                                                                                                                                                                                                      Alt...World map centred the pacific ocean that shows list of APT groups per country, some of them written in Latin characters, some of then in Chinese characters

                                                                                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                                                                                        [?]Dendrobatus Azureus » 🌐
                                                                                                                                                                                                                                                                                                        @dendrobatus_azureus@polymaths.social

                                                                                                                                                                                                                                                                                                        Does this mean that you shall also stop using curl?

                                                                                                                                                                                                                                                                                                        AFAIK Daniel doesn't care what is used to find bugs

                                                                                                                                                                                                                                                                                                        @rl_dane

                                                                                                                                                                                                                                                                                                        https://mastodon.social/@bagder/116373716541500315

                                                                                                                                                                                                                                                                                                        #curl #LLM #hallucinated #slop #AI #InfoSec #programming #technology

                                                                                                                                                                                                                                                                                                          mmu_man boosted

                                                                                                                                                                                                                                                                                                          [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                          @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                          Oh boy…
                                                                                                                                                                                                                                                                                                          edition.cnn.com/2026/04/08/chi

                                                                                                                                                                                                                                                                                                          > A [cyberthreat actor] has allegedly stolen a massive trove of sensitive data – including highly classified defense documents and missile schematics – from a state-run Chinese supercomputer

                                                                                                                                                                                                                                                                                                          > The dataset, which allegedly contains more than 10 petabytes of sensitive information, is believed by experts to have been obtained from the National Supercomputing Center (NSCC) in Tianjin

                                                                                                                                                                                                                                                                                                          🧵

                                                                                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                            ⋅ E-commerce : une image SVG est utilisée pour voler les données bancaires

                                                                                                                                                                                                                                                                                                            it-connect.fr/e-commerce-une-i

                                                                                                                                                                                                                                                                                                              Nigel boosted

                                                                                                                                                                                                                                                                                                              [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 [it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
                                                                                                                                                                                                                                                                                                              @freya@social.highenergymagic.net

                                                                                                                                                                                                                                                                                                              hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net.

                                                                                                                                                                                                                                                                                                              Please boost for reach, any job offers please DM me.

                                                                                                                                                                                                                                                                                                                Kh0lah boosted

                                                                                                                                                                                                                                                                                                                [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                                                                                                                                                                                                @beyondmachines1@infosec.exchange

                                                                                                                                                                                                                                                                                                                National Supercomputing Center in Tianjin Allegedly Suffers Massive 10-Petabyte Data Breach

                                                                                                                                                                                                                                                                                                                A threat actor known as FlamingChina allegedly stole 10 petabytes of sensitive military and aerospace data from the National Supercomputing Center in Tianjin after exploiting a compromised VPN. The breach, which occurred over six months, exposed classified research from 6,000 clients, including missile schematics and defense documents.

                                                                                                                                                                                                                                                                                                                ****

                                                                                                                                                                                                                                                                                                                beyondmachines.net/event_detai

                                                                                                                                                                                                                                                                                                                  JP Mens boosted

                                                                                                                                                                                                                                                                                                                  [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                  @jik@federate.social

                                                                                                                                                                                                                                                                                                                  locks account that maintainer uses to sign bootloaders with no explanation or route for appeal. If they don't fix this, in a few months every Windows computer that uses VeraCrypt whole-disk encryption will stop being able to boot and all the data on it that isn't backed up elsewhere will be lost. 🤦
                                                                                                                                                                                                                                                                                                                  If this doesn't convince you big tech has too much control, I don't know what will.
                                                                                                                                                                                                                                                                                                                  h/t @zackwhittaker
                                                                                                                                                                                                                                                                                                                  techcrunch.com/2026/04/08/vera

                                                                                                                                                                                                                                                                                                                    [?]Laurent Cheylus » 🌐
                                                                                                                                                                                                                                                                                                                    @lcheylus@bsd.network

                                                                                                                                                                                                                                                                                                                    A 27-year-old OpenBSD Vulnerability found in TCP SACK assessing Claude Mythos Preview’s Cybersecurity Capabilities ; other Bugs found in FFmpeg, FreeBSD NFS, Linux kernel... red.anthropic.com/2026/mythos-

                                                                                                                                                                                                                                                                                                                      Taggart :ifin: boosted

                                                                                                                                                                                                                                                                                                                      [?]IFIN - The Independent Federated Intelligence Network » 🌐
                                                                                                                                                                                                                                                                                                                      @ifin@infosec.exchange

                                                                                                                                                                                                                                                                                                                      Hello, world!

                                                                                                                                                                                                                                                                                                                      We are IFIN, the Independent Federated Intelligence Network, and we want to change how threat intelligence is done.

                                                                                                                                                                                                                                                                                                                      We believe we're all safer when we share what we know. Come learn more and join us!

                                                                                                                                                                                                                                                                                                                      ifin-intel.org/blog/hello/

                                                                                                                                                                                                                                                                                                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                        @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                        Taggart :ifin: boosted

                                                                                                                                                                                                                                                                                                                        [?]IFIN - The Independent Federated Intelligence Network » 🌐
                                                                                                                                                                                                                                                                                                                        @ifin@infosec.exchange

                                                                                                                                                                                                                                                                                                                        Hello, world!

                                                                                                                                                                                                                                                                                                                        We are IFIN, the Independent Federated Intelligence Network, and we want to change how threat intelligence is done.

                                                                                                                                                                                                                                                                                                                        We believe we're all safer when we share what we know. Come learn more and join us!

                                                                                                                                                                                                                                                                                                                        ifin-intel.org/blog/hello/

                                                                                                                                                                                                                                                                                                                          [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                          @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                          ⋅ AI Agents and Non-Human Identities Creating Critical Security Gaps, Report

                                                                                                                                                                                                                                                                                                                          hackread.com/ai-agents-non-hum

                                                                                                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                                                                                                            [?]Taran Rampersad » 🌐
                                                                                                                                                                                                                                                                                                                            @knowprose@mastodon.social

                                                                                                                                                                                                                                                                                                                            [?]Wulfy—Speaker to the machines » 🌐
                                                                                                                                                                                                                                                                                                                            @n_dimension@infosec.exchange

                                                                                                                                                                                                                                                                                                                            @bagder

                                                                                                                                                                                                                                                                                                                            Just so I understand this correctly...
                                                                                                                                                                                                                                                                                                                            We don't want machine generated vulerability reports...

                                                                                                                                                                                                                                                                                                                            ...so we can leave our projects vulnerable to hackers who are not constrained by ideology in their sploits using ?

                                                                                                                                                                                                                                                                                                                            Yeah, that tracks with the current majority of "professionals" letting the Rome burn while they roast the marshmallows, feeling super pure and superior.

                                                                                                                                                                                                                                                                                                                              [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                              @jik@federate.social

                                                                                                                                                                                                                                                                                                                              I think it says a lot about how seriously we should take any crypto firm which experiences a security breach and then chooses to publish their post-mortem… on X.com and only on X.com.
                                                                                                                                                                                                                                                                                                                              (Link is to Archive Today so as not to give clicks to X. Apparently xcancel.com doesn't properly display X "articles".)
                                                                                                                                                                                                                                                                                                                              (Yes, I know we shouldn't take _any_ crypto firm seriously, but this is particularly egregious.)
                                                                                                                                                                                                                                                                                                                              Ref: archive.ph/Bdoq7

                                                                                                                                                                                                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                What could go wrong?

                                                                                                                                                                                                                                                                                                                                ⋅ Critical Claude Code Flaw Silently Bypasses Developer-Configured Security Rules

                                                                                                                                                                                                                                                                                                                                cybersecuritynews.com/claude-c

                                                                                                                                                                                                                                                                                                                                  [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                  @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                  ⋅ BrowserGate: LinkedIn Tracks 6,000+ Browser Extensions on Users’ PCs

                                                                                                                                                                                                                                                                                                                                  hackread.com/browsergate-linke

                                                                                                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                    [?]Taran Rampersad » 🌐
                                                                                                                                                                                                                                                                                                                                    @knowprose@mastodon.social

                                                                                                                                                                                                                                                                                                                                    [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                                                    @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                                                    There used to be a time when building out a botnet required *some* work – writing exploits, taking over devices, obscuring the purpose of the executable, etc.

                                                                                                                                                                                                                                                                                                                                    Not any more!

                                                                                                                                                                                                                                                                                                                                    Instead of "malware", call it an "AI agent" and people will just happily install it on their devices with full root privileges!
                                                                                                                                                                                                                                                                                                                                    github.com/jgamblin/OpenClawCV

                                                                                                                                                                                                                                                                                                                                    Bam! RCE by asking nicely.

                                                                                                                                                                                                                                                                                                                                    🧵

                                                                                                                                                                                                                                                                                                                                      AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                      [?]Graham Perrin » 🌐
                                                                                                                                                                                                                                                                                                                                      @grahamperrin@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                      @nielsa no, that's not what I'm telling you.

                                                                                                                                                                                                                                                                                                                                      I prefer to believe that most people will be thoughtful.

                                                                                                                                                                                                                                                                                                                                      "… a huge number of bugs. I have so many bugs in the Linux kernel that I can't report because I haven't validated them yet. I'm not going to make some open source developer validate bugs that I haven't checked yet. I'm not going to send them potential slop … I now have … several hundred crashes that they haven't seen because I haven't had time to check them. We need to find a way to fix this …"

                                                                                                                                                                                                                                                                                                                                      – Nicholas Carlini

                                                                                                                                                                                                                                                                                                                                      Screenshot: a frame from https://www.youtube.com/watch?v=1sd26pWhfmg

                                                                                                                                                                                                                                                                                                                                      Alt...Screenshot: a frame from https://www.youtube.com/watch?v=1sd26pWhfmg

                                                                                                                                                                                                                                                                                                                                        [?]jbz » 🌐
                                                                                                                                                                                                                                                                                                                                        @jbz@indieweb.social

                                                                                                                                                                                                                                                                                                                                        🙄 Microsoft now force upgrades unmanaged Windows 11 24H2 PCs

                                                                                                                                                                                                                                                                                                                                        "The machine learning-based intelligent rollout has expanded to all devices running Home and Pro editions of Windows 11, version 24H2 that are not managed by IT departments,"

                                                                                                                                                                                                                                                                                                                                        bleepingcomputer.com/news/micr

                                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                          [?]Graham Perrin » 🌐
                                                                                                                                                                                                                                                                                                                                          @grahamperrin@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                          Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

                                                                                                                                                                                                                                                                                                                                          <youtube.com/watch?v=1sd26pWhfmg> (3rd March)

                                                                                                                                                                                                                                                                                                                                          ― essential viewing for anyone with an interest in cybersecurity or infosec.

                                                                                                                                                                                                                                                                                                                                          @dch thanks for the encouragement.

                                                                                                                                                                                                                                                                                                                                          A few more links in the comment that's pinned under <redd.it/1sapr8a>, but Carlini's half-hour presentation is a must.

                                                                                                                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                            ⋅⋅⋅ "A significant volume of data (about 91.7 GB compressed) was exfiltrated from the compromised AWS account, including personal data such as names, email addresses, and email content."

                                                                                                                                                                                                                                                                                                                                            ⋅ European Commission cloud breach: a supply-chain compromise

                                                                                                                                                                                                                                                                                                                                            cert.europa.eu/blog/european-c

                                                                                                                                                                                                                                                                                                                                              Boud boosted

                                                                                                                                                                                                                                                                                                                                              [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                                                              @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                                                              Aqua's "Cloud Native Application Protection Platform", Trivy, got pwned:
                                                                                                                                                                                                                                                                                                                                              aquasec.com/blog/trivy-supply-

                                                                                                                                                                                                                                                                                                                                              …using credentials, which Aqua already knew were compromised:

                                                                                                                                                                                                                                                                                                                                              > The Trivy team (…) executed credential rotation. Subsequent investigation revealed the rotation was not fully comprehensive, allowing the threat actor to retain residual access via still-valid credentials.

                                                                                                                                                                                                                                                                                                                                              One of the sites compromised downstream was @EUCommission's europa.eu:
                                                                                                                                                                                                                                                                                                                                              cert.europa.eu/blog/european-c

                                                                                                                                                                                                                                                                                                                                              Cyberecurity theater. 🙄

                                                                                                                                                                                                                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                ⋅ Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability

                                                                                                                                                                                                                                                                                                                                                cybersecuritynews.com/700-next

                                                                                                                                                                                                                                                                                                                                                  [?]Mark Wyner Won’t Comply :vm: » 🌐
                                                                                                                                                                                                                                                                                                                                                  @markwyner@mas.to

                                                                                                                                                                                                                                                                                                                                                  EDIT: @rysiek has an explanation about the shady things LinkedIn is doing. He explains it far better than I did:

                                                                                                                                                                                                                                                                                                                                                  mstdn.social/@rysiek/116337205

                                                                                                                                                                                                                                                                                                                                                  LinkedIn/Microsoft are definitely NOT to be trusted. But I realize phrasing is important. So I’m moderating my own post. I apologize if this was misconstrued.

                                                                                                                                                                                                                                                                                                                                                  But I subjectively believe there is a high likelihood that LinkedIn is doing nefarious things with this data.

                                                                                                                                                                                                                                                                                                                                                  Emulation of the LinkedIn logo, changed to read “unauthorized.”

                                                                                                                                                                                                                                                                                                                                                  Alt...Emulation of the LinkedIn logo, changed to read “unauthorized.”

                                                                                                                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                    [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                    @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                    This is my second "holy shit" of the day.
                                                                                                                                                                                                                                                                                                                                                    Apparently if silently collecting data on every extension you use every time you visit the site. Which it then uploads, with your identity attached to it.
                                                                                                                                                                                                                                                                                                                                                    This is absolutely horrifying. Literally, people should go to jail over this.

                                                                                                                                                                                                                                                                                                                                                    browsergate.eu/

                                                                                                                                                                                                                                                                                                                                                      Timo Tijhof boosted

                                                                                                                                                                                                                                                                                                                                                      [?]Metin Seven 🎨 » 🌐
                                                                                                                                                                                                                                                                                                                                                      @metin@graphics.social

                                                                                                                                                                                                                                                                                                                                                      Aral Balkan boosted

                                                                                                                                                                                                                                                                                                                                                      [?]Julian Oliver » 🌐
                                                                                                                                                                                                                                                                                                                                                      @JulianOliver@mastodon.social

                                                                                                                                                                                                                                                                                                                                                      NodeJS, for all the brilliant projects out there leaning on it, has a supply chain that might as well run the length of a dark alley permanently at 2am in the club district.

                                                                                                                                                                                                                                                                                                                                                      thehackernews.com/2026/03/axio

                                                                                                                                                                                                                                                                                                                                                      Anyway, hope none of you good people are affected by this latest pox

                                                                                                                                                                                                                                                                                                                                                        [?]Paco Hope [He/Him] » 🌐
                                                                                                                                                                                                                                                                                                                                                        @paco@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                        We can quit and just go farm potatoes or something. After 25 years of one of the most talked-about tech companies invents a daemon process that

                                                                                                                                                                                                                                                                                                                                                        makes use of a file-based “memory system” designed to allow for persistent operation across user sessions.

                                                                                                                                                                                                                                                                                                                                                        Sure. Just store your system instructions in a random text file.

                                                                                                                                                                                                                                                                                                                                                        Why are we installing endpoint protection on this system?

                                                                                                                                                                                                                                                                                                                                                        Why do we verify cryptographic signatures on software updates to this system?

                                                                                                                                                                                                                                                                                                                                                        Why are we building a zero trust security environment?

                                                                                                                                                                                                                                                                                                                                                        Why do we do scan email to avoid social engineering emails?

                                                                                                                                                                                                                                                                                                                                                        Our AI-assisted users are gonna YOLO right past all that. And if they can’t get past our controls, this agentic Frankenstein will write itself some markdown and work quietly in the background figuring out how to bypass something the user couldn’t bypass on their own.

                                                                                                                                                                                                                                                                                                                                                        This is in 2026

                                                                                                                                                                                                                                                                                                                                                          [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                          @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                          This is alarming but not surprising:
                                                                                                                                                                                                                                                                                                                                                          forbes.com/sites/the-wiretap/2
                                                                                                                                                                                                                                                                                                                                                          TLDR If you access multiple Google accounts from the same device, and the cops know about one of the accounts and ask Google the right questions, Google will tell the cops about the other accounts.
                                                                                                                                                                                                                                                                                                                                                          The general lesson here is one we already know: if you have any sort of account you don't want linked to you, you can't ever access it from a device or network connection you use other accounts on.
                                                                                                                                                                                                                                                                                                                                                          Caveat usor.

                                                                                                                                                                                                                                                                                                                                                            [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                            @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                            Three observations about ( hackers) getting into 's Gmail account (ref: techcrunch.com/2026/03/27/iran):
                                                                                                                                                                                                                                                                                                                                                            1) It is not unusual for govt employees to forward emails from govt to personal accounts, e.g., personal emails inappropriately sent to govt accounts. We would have to know what emails were forwarded to know if there was a problem. Presumably if the forwarded emails were problematic the journalists reporting on this would have reported that?
                                                                                                                                                                                                                                                                                                                                                            (1/3)

                                                                                                                                                                                                                                                                                                                                                              [?]Blue Ghost » 🌐
                                                                                                                                                                                                                                                                                                                                                              @blueghost@mastodon.online

                                                                                                                                                                                                                                                                                                                                                              [?]AmmarSpaces » 🌐
                                                                                                                                                                                                                                                                                                                                                              @AmmarSpaces@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                              ... [SENSITIVE CONTENT]

                                                                                                                                                                                                                                                                                                                                                              Looks like defcon.social getting flooded by targetted defamation towards @briankrebs . I still haven't found the context.

                                                                                                                                                                                                                                                                                                                                                              Anyone has more info on this?

                                                                                                                                                                                                                                                                                                                                                              @defcon
                                                                                                                                                                                                                                                                                                                                                              @support

                                                                                                                                                                                                                                                                                                                                                              defcon.social account flood

                                                                                                                                                                                                                                                                                                                                                              Alt...defcon.social account flood

                                                                                                                                                                                                                                                                                                                                                                ClaudioM boosted

                                                                                                                                                                                                                                                                                                                                                                [?]Shawn Webb [He/Him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                @lattera@bsd.network

                                                                                                                                                                                                                                                                                                                                                                And now linux.org has been defaced. This kinda reminds me of the old defacement crews of the mid-to-late 1990's like Hackweiser and World of Hell.

                                                                                                                                                                                                                                                                                                                                                                  [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                  @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                  ⋅ Détentions d’armes : un pirate exfiltre des données du SIA (ministère de l’Intérieur)

                                                                                                                                                                                                                                                                                                                                                                  next.ink/231423/detentions-dar

                                                                                                                                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                    [?]Hyde 📷 🖋 :debian: » 🌐
                                                                                                                                                                                                                                                                                                                                                                    @hyde@lazybear.social

                                                                                                                                                                                                                                                                                                                                                                    059 with @rysiek.

                                                                                                                                                                                                                                                                                                                                                                    Today, he shares his thoughts on , , , , and .

                                                                                                                                                                                                                                                                                                                                                                    He also replied to @brennan's question.

                                                                                                                                                                                                                                                                                                                                                                    He suggested two books that I'll try to get.

                                                                                                                                                                                                                                                                                                                                                                    lazybea.rs/ovr-059

                                                                                                                                                                                                                                                                                                                                                                      [?]Edwin G. :mapleleafroundel: [he/him/il/lui] » 🌐
                                                                                                                                                                                                                                                                                                                                                                      @EdwinG@mstdn.moimeme.ca

                                                                                                                                                                                                                                                                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                      @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                      Avec Fortinet, t'as l'air tout bête !

                                                                                                                                                                                                                                                                                                                                                                      ⋅ Fortinet, une faille critique activement exploitée dans FortiClient EMS menace des milliers de serveurs

                                                                                                                                                                                                                                                                                                                                                                      clubic.com/actualite-606889-fo

                                                                                                                                                                                                                                                                                                                                                                        [?]FlohEinstein » 🌐
                                                                                                                                                                                                                                                                                                                                                                        @FlohEinstein@chaos.social

                                                                                                                                                                                                                                                                                                                                                                        Working on another sticker for - found this image a while ago, but only as a lowres jpg, so I re-did it as a vector graphic.


                                                                                                                                                                                                                                                                                                                                                                        We do not test on animals, we test in production.

                                                                                                                                                                                                                                                                                                                                                                        EDIT: Here's the SVG for all of you who asked blog.kohler.is/sticker-we-do-n

                                                                                                                                                                                                                                                                                                                                                                        A green no parking sign with the inscription we do not test on animals we test in production showing a bunny, a red heart and a stack of servers going up in flames

Original idea found on https://www.reddit.com/r/ProgrammerHumor/comments/z1z43b/ive_made_a_new_sticker_so_your_projects_has_no by u/AlFlakky (AlexBlintsov)&#10;Used sources from Flaticon.com: Star Icons by Pixel perfect, Hase by torskaya, hacken by juicy_fish, dedizierter Server by Design Circle, Herz by IconBaandar

                                                                                                                                                                                                                                                                                                                                                                        Alt...A green no parking sign with the inscription we do not test on animals we test in production showing a bunny, a red heart and a stack of servers going up in flames Original idea found on https://www.reddit.com/r/ProgrammerHumor/comments/z1z43b/ive_made_a_new_sticker_so_your_projects_has_no by u/AlFlakky (AlexBlintsov)&#10;Used sources from Flaticon.com: Star Icons by Pixel perfect, Hase by torskaya, hacken by juicy_fish, dedizierter Server by Design Circle, Herz by IconBaandar

                                                                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                          [?]FlohEinstein » 🌐
                                                                                                                                                                                                                                                                                                                                                                          @FlohEinstein@chaos.social

                                                                                                                                                                                                                                                                                                                                                                          Wow, u/DeeZett made a 3D version of my "We do not test on animals, we test in production" sticker. I love it!

                                                                                                                                                                                                                                                                                                                                                                          Reddit: reddit.com/r/3Dprinting/commen
                                                                                                                                                                                                                                                                                                                                                                          Model on Makerworld: makerworld.com/en/models/25874
                                                                                                                                                                                                                                                                                                                                                                          Thing on Thingiverse: thingiverse.com/thing:7323159

                                                                                                                                                                                                                                                                                                                                                                          A green no parking sign with the inscription we do not test on animals we test in production showing a bunny, a red heart and a stack of servers going up in flames
3D printed in bright green (sign), white (inscription, bunny, inner flame), red (heart, flame) and black (servers).

                                                                                                                                                                                                                                                                                                                                                                          Alt...A green no parking sign with the inscription we do not test on animals we test in production showing a bunny, a red heart and a stack of servers going up in flames 3D printed in bright green (sign), white (inscription, bunny, inner flame), red (heart, flame) and black (servers).

                                                                                                                                                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                            ⋅ ShinyHunters Claims 350GB Data Breach at European Commission

                                                                                                                                                                                                                                                                                                                                                                            hackread.com/shinyhunters-350g

                                                                                                                                                                                                                                                                                                                                                                              [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                              @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                              Happy "LASTPASS COURT ORDERED NOTICE OF CLASS ACTION SETTLEMENT" day to those who celebrate!

                                                                                                                                                                                                                                                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                ⋅ Red Hat Warns of Malware Code Embedded in Popular Linux Tool Allow Unauthorized Access to Systems

                                                                                                                                                                                                                                                                                                                                                                                cybersecuritynews.com/linux-to

                                                                                                                                                                                                                                                                                                                                                                                  DamonHD boosted

                                                                                                                                                                                                                                                                                                                                                                                  [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                  @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                  Looks like the bad guys are using the email addresses harvested from the / . I just received this email on an email address I've never used for anything else. I'll be deactivating the email address, of course.
                                                                                                                                                                                                                                                                                                                                                                                  I like , but there's one important feature it's missing: I really wish they would implement an integration with .
                                                                                                                                                                                                                                                                                                                                                                                  Ref: haveibeenpwned.com/Breach/WIRED
                                                                                                                                                                                                                                                                                                                                                                                  FYI @troyhunt @zackwhittaker @briankrebs

                                                                                                                                                                                                                                                                                                                                                                                  Screenshot of email message with a header bar at the top of the body showing that it was routed through Addy.io. That header bar indicates that the description associated with the destination email address at Addy.io is "condenast.com, wired.com".

                                                                                                                                                                                                                                                                                                                                                                                  Alt...Screenshot of email message with a header bar at the top of the body showing that it was routed through Addy.io. That header bar indicates that the description associated with the destination email address at Addy.io is "condenast.com, wired.com".

                                                                                                                                                                                                                                                                                                                                                                                  [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                  @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                  ⋅ LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace

                                                                                                                                                                                                                                                                                                                                                                                  thehackernews.com/2026/03/leak

                                                                                                                                                                                                                                                                                                                                                                                    Dๅᴉĸo boosted

                                                                                                                                                                                                                                                                                                                                                                                    [?]BeyondMachines :verified: » 🤖 🌐
                                                                                                                                                                                                                                                                                                                                                                                    @beyondmachines1@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                                                    French Ministry of Education Data Breach Exposes 243,000 Staff Records

                                                                                                                                                                                                                                                                                                                                                                                    The French Ministry of National Education reports a data breach affecting 243,000 individuals after an attacker stole personal records from the COMPAS HR system. The stolen data, including names and addresses, has been partially leaked online, prompting the ministry to suspend the system and involve national cybersecurity authorities.

                                                                                                                                                                                                                                                                                                                                                                                    ****

                                                                                                                                                                                                                                                                                                                                                                                    beyondmachines.net/event_detai

                                                                                                                                                                                                                                                                                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                      @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                      ⋅ Node.js Patches Multiple Vulnerabilities That Enable DoS Attacks and Process Crashes

                                                                                                                                                                                                                                                                                                                                                                                      cybersecuritynews.com/node-js-

                                                                                                                                                                                                                                                                                                                                                                                        Marcus Adams boosted

                                                                                                                                                                                                                                                                                                                                                                                        [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                        @MissConstrue@mefi.social

                                                                                                                                                                                                                                                                                                                                                                                        If you have an device and you have not updated, you are in danger of a zero click hack, () the bones of which were just published on .

                                                                                                                                                                                                                                                                                                                                                                                        It allows attackers to seize full control by just visiting a compromised website, without requiring any clicks, downloads, or user interaction. The malware operates in memory, deleting its own traces to avoid detection.

                                                                                                                                                                                                                                                                                                                                                                                        Update to iOS 26.3.1 or the latest available version (18.7.6 or higher). If you are running an older hardware, update to at least iOS 15, for emergency patches for older devices.

                                                                                                                                                                                                                                                                                                                                                                                        Go to Settings > General > Software Update to ensure you are fully updated.

                                                                                                                                                                                                                                                                                                                                                                                        If you cannot update immediately, or if you are at high risk, enable Lockdown Mode. This is an extreme, high-security mode. Go to Settings > Privacy & Security > Lockdown Mode and turn it on.

                                                                                                                                                                                                                                                                                                                                                                                        mashable.com/article/iphone-ex

                                                                                                                                                                                                                                                                                                                                                                                          [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                          @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                          Hey @zackwhittaker, I admire how you implied "This is really stupid" in this article with complete plausible deniability.
                                                                                                                                                                                                                                                                                                                                                                                          techcrunch.com/2026/03/24/fcc-
                                                                                                                                                                                                                                                                                                                                                                                          There's a lot that could be done through regulation to improve the security of consumer routers in the United States. Banning all routers made overseas isn't going to do it.
                                                                                                                                                                                                                                                                                                                                                                                          Let's be honest: this is an economic policy masquerading as a security policy. The only real impact will be Americans paying more for routers.

                                                                                                                                                                                                                                                                                                                                                                                            [?]Kim Crawley 😷 (she/her) » 🌐
                                                                                                                                                                                                                                                                                                                                                                                            @kimcrawley@zeroes.ca

                                                                                                                                                                                                                                                                                                                                                                                            Please boost! Please share!

                                                                                                                                                                                                                                                                                                                                                                                            I am Kim Crawley and I research and write about all areas of cybersecurity. I do it the "old fashioned" way by actually using my brain and doing the work... No Gen AI! Fuck Gen AI! I hate Gen AI! I founded Stop Gen AI!

                                                                                                                                                                                                                                                                                                                                                                                            I've worked for:

                                                                                                                                                                                                                                                                                                                                                                                            - Siemens (Digital Industries World)
                                                                                                                                                                                                                                                                                                                                                                                            - BlackBerry Cylance
                                                                                                                                                                                                                                                                                                                                                                                            - Kaspersky
                                                                                                                                                                                                                                                                                                                                                                                            - Hack The Box
                                                                                                                                                                                                                                                                                                                                                                                            - O'Reilly Media
                                                                                                                                                                                                                                                                                                                                                                                            - Wiley Tech
                                                                                                                                                                                                                                                                                                                                                                                            - AT&T Cybersecurity

                                                                                                                                                                                                                                                                                                                                                                                            My portfolio is here: kimcrawley.com

                                                                                                                                                                                                                                                                                                                                                                                            - Whitepapers
                                                                                                                                                                                                                                                                                                                                                                                            - Blogs
                                                                                                                                                                                                                                                                                                                                                                                            - Documentation
                                                                                                                                                                                                                                                                                                                                                                                            - Books
                                                                                                                                                                                                                                                                                                                                                                                            - Threat analysis
                                                                                                                                                                                                                                                                                                                                                                                            - Enterprise cybersecurity instruction and consulting

                                                                                                                                                                                                                                                                                                                                                                                            I'm in Tribe of Hackers.

                                                                                                                                                                                                                                                                                                                                                                                            I cowrote The Pentester Blueprint.

                                                                                                                                                                                                                                                                                                                                                                                            I'm writing Technofascism Survival Guide now, successful Kickstarter is still taking late pledges for $12 USD eBooks: kickstarter.com/projects/kimcr

                                                                                                                                                                                                                                                                                                                                                                                            Email me: kim(dot)crawley(at)stopgenai.com

                                                                                                                                                                                                                                                                                                                                                                                            Signal: crowgirl.84

                                                                                                                                                                                                                                                                                                                                                                                            Or reply here.

                                                                                                                                                                                                                                                                                                                                                                                            O'REILLY" \ 0,"

Zero Trust

Architecture

in Kubernetes h
> ° . 7)

Kim Crawley [J _ 7,

                                                                                                                                                                                                                                                                                                                                                                                            Alt...O'REILLY" \ 0," Zero Trust Architecture in Kubernetes h > ° . 7) Kim Crawley [J _ 7,

                                                                                                                                                                                                                                                                                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                              @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                              @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                              ⋅ Gcore Radar report reveals 150% surge in DDoS attacks year-on-year

                                                                                                                                                                                                                                                                                                                                                                                              cybersecuritynews.com/gcore-ra

                                                                                                                                                                                                                                                                                                                                                                                                9x0rg boosted

                                                                                                                                                                                                                                                                                                                                                                                                [?]Julian Oliver » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                @JulianOliver@mastodon.social

                                                                                                                                                                                                                                                                                                                                                                                                Why run your own Virtual Private Network, in 2026?

                                                                                                                                                                                                                                                                                                                                                                                                I wrote a post unpacking this Q, with a view to pushing folk to reclaim VPN technology in this neo-feudalist era of the Internet, clawing back autonomy (and privacy) from the big VPN providers.

                                                                                                                                                                                                                                                                                                                                                                                                courses.nikau.io/2026/03/24/wh

                                                                                                                                                                                                                                                                                                                                                                                                  [?]Jill Bryant Ryniker » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                  @Jill_linuxgirl@mast.linuxgamecast.com

                                                                                                                                                                                                                                                                                                                                                                                                  On the next , we’re joined by @SandflySecurity CEO Craig Rowland to break down their massive partnership with Ericsson.
                                                                                                                                                                                                                                                                                                                                                                                                  We’re diving into agentless security & the biggest threats facing the world in 2026.
                                                                                                                                                                                                                                                                                                                                                                                                  Don't miss it! 🐧💻

                                                                                                                                                                                                                                                                                                                                                                                                    [?]jbz » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                    @jbz@indieweb.social

                                                                                                                                                                                                                                                                                                                                                                                                    🦅 The US government just banned consumer routers made outside the US

                                                                                                                                                                                                                                                                                                                                                                                                    「 It is not clear how simply moving production of routers domestically would make them safer. In the Volt Typhoon hack, Chinese state-sponsored hackers primarily targeted Cisco and Netgear routers, routers designed by US companies, according to the Department of Justice 」

                                                                                                                                                                                                                                                                                                                                                                                                    theverge.com/news/899172/fcc-f

                                                                                                                                                                                                                                                                                                                                                                                                      [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                      @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                                      Hey folks.
                                                                                                                                                                                                                                                                                                                                                                                                      I know it's fun to dump on Microsoft's security, so the recent @ProPublica article (propublica.org/article/microso) is blood in the water. But please stop saying that the FedRAMP office called Microsoft's tech "a pile of shit." That's not true.
                                                                                                                                                                                                                                                                                                                                                                                                      They called *their FedRAMP package* a pile of shit.
                                                                                                                                                                                                                                                                                                                                                                                                      Y'all understand the difference between "your compliance package is shit" and "your tech is shit."
                                                                                                                                                                                                                                                                                                                                                                                                      Y'all know compliance and security are not the same thing.
                                                                                                                                                                                                                                                                                                                                                                                                      Please act like it.
                                                                                                                                                                                                                                                                                                                                                                                                      Thanks.

                                                                                                                                                                                                                                                                                                                                                                                                        AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                        [?]Radio_Azureus » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                        @Radio_Azureus@ioc.exchange

                                                                                                                                                                                                                                                                                                                                                                                                        Security Patches

                                                                                                                                                                                                                                                                                                                                                                                                        InfoSec

                                                                                                                                                                                                                                                                                                                                                                                                        Regardless of which Operating System you run, it is important to keep up with the critical updates to keep your machines as safe as possible

                                                                                                                                                                                                                                                                                                                                                                                                        • Realize that by the time a critical bug has been reported, verified, patched and delivered to your distribution of choice, a significant amount of time has passed...
                                                                                                                                                                                                                                                                                                                                                                                                        • From the first day the bug has been discovered [zero day] to the day you patch your computing machine, you've had a vunurable open machine in that one respect.
                                                                                                                                                                                                                                                                                                                                                                                                        • Keep the amount of time between the availability, of patches & the update of your machines, especially your VMs (Qemu et al) & physical servers as short as possible
                                                                                                                                                                                                                                                                                                                                                                                                        • Make sure to always use manual updates on your server VM's!
                                                                                                                                                                                                                                                                                                                                                                                                        • I shall not explain why, start reading on Wikipedia and furthe, the explanation is too long for this short post

                                                                                                                                                                                                                                                                                                                                                                                                        Notes:

                                                                                                                                                                                                                                                                                                                                                                                                        • every OS can have vunurabilities
                                                                                                                                                                                                                                                                                                                                                                                                        • Security in obscurity does not work!
                                                                                                                                                                                                                                                                                                                                                                                                        • you are not secure because you run obsolete AmigaOS QNX or cool and niche *BSD as an OS
                                                                                                                                                                                                                                                                                                                                                                                                        • buffer overflows hide everywhere
                                                                                                                                                                                                                                                                                                                                                                                                        • I reguraly find them!

                                                                                                                                                                                                                                                                                                                                                                                                        photograph of updating a machine

                                                                                                                                                                                                                                                                                                                                                                                                        Alt...photograph of updating a machine

                                                                                                                                                                                                                                                                                                                                                                                                        photograph of pathcing a machine

                                                                                                                                                                                                                                                                                                                                                                                                        Alt...photograph of pathcing a machine

                                                                                                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                          [?]Larvitz » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                          @Larvitz@mastodon.bsd.cafe

                                                                                                                                                                                                                                                                                                                                                                                                          Exciting news. I've just pushed a collection of ports for the Card ecosystem to Codeberg.

                                                                                                                                                                                                                                                                                                                                                                                                          Includes:
                                                                                                                                                                                                                                                                                                                                                                                                          - openpgp-card-tools (oct)
                                                                                                                                                                                                                                                                                                                                                                                                          - openpgp-card-tools-git (oct-git)
                                                                                                                                                                                                                                                                                                                                                                                                          - openpgp-card-ssh-agent

                                                                                                                                                                                                                                                                                                                                                                                                          I'm currently polishing them for official submission to the freebsd ports tree this April!

                                                                                                                                                                                                                                                                                                                                                                                                          A huge thank you to @hko for these excellent tools!

                                                                                                                                                                                                                                                                                                                                                                                                          codeberg.org/Larvitz/freebsd-o

                                                                                                                                                                                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                            🇬🇧 ⋅ The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors

                                                                                                                                                                                                                                                                                                                                                                                                            −, cloud.google.com/blog/topics/t

                                                                                                                                                                                                                                                                                                                                                                                                            −−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−−

                                                                                                                                                                                                                                                                                                                                                                                                            🇫🇷 ⋅ DarkSword : comment des scripts JavaScript parviennent à contourner le bac à sable d'Apple

                                                                                                                                                                                                                                                                                                                                                                                                            zdnet.fr/actualites/darksword-

                                                                                                                                                                                                                                                                                                                                                                                                              [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                              @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                                              just put out the second critical security update for their NAS operating system in four days <synology.com/en-global/release>; the previous one was released on the 16th.
                                                                                                                                                                                                                                                                                                                                                                                                              The new one is to fix, of all things, a vulnerability in telnetd:
                                                                                                                                                                                                                                                                                                                                                                                                              lists.gnu.org/archive/html/bug
                                                                                                                                                                                                                                                                                                                                                                                                              I'm glad they're patching it, but I kind of wish they would just, I dunno, not ship telnetd with their OS? I'm hard-pressed to think of a use-case for telnetd that can't be satisfied with sshd.

                                                                                                                                                                                                                                                                                                                                                                                                                [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                                                My employer uses a web host (WH) that uses IIS.
                                                                                                                                                                                                                                                                                                                                                                                                                Our external pen test caught one of our websites exposing Web.config. (How can there be a WH in 2026 that doesn't know to block this? Why isn't it blocked by default in IIS?)
                                                                                                                                                                                                                                                                                                                                                                                                                We asked WH to fix it.
                                                                                                                                                                                                                                                                                                                                                                                                                They did.
                                                                                                                                                                                                                                                                                                                                                                                                                We asked pen-tester to retest.
                                                                                                                                                                                                                                                                                                                                                                                                                Before they retested, WH broke it and made the file visible again.
                                                                                                                                                                                                                                                                                                                                                                                                                So now we have to get WH to fix it again AND possibly pay the pen-tester for a second retest since our contract only specifies one. 🤦😡

                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                  @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                                                  Size matters

                                                                                                                                                                                                                                                                                                                                                                                                                  …but not in the way you think.

                                                                                                                                                                                                                                                                                                                                                                                                                  blog.kamens.us/2026/03/19/size

                                                                                                                                                                                                                                                                                                                                                                                                                    [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                    @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                    [?]rk: it’s hyphen-minus actually » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                    @rk@mastodon.well.com

                                                                                                                                                                                                                                                                                                                                                                                                                    I have been in infosec for a long time. By some measures it’s over three decades. That’s as many a three tens of years. It’s been a while.

                                                                                                                                                                                                                                                                                                                                                                                                                    I’d like to take this opportunity to convey some of my hard-earned wisdom to the next generation.

                                                                                                                                                                                                                                                                                                                                                                                                                    If you want to test EtherNet/IP message forwarding and it isn’t working, be sure you didn’t disable message forwarding to test something else and forgot about it.

                                                                                                                                                                                                                                                                                                                                                                                                                    This has been “Rob brings you infosec wisdom” episode 8392763.

                                                                                                                                                                                                                                                                                                                                                                                                                      Marcos Dione boosted

                                                                                                                                                                                                                                                                                                                                                                                                                      [?]rk: it’s hyphen-minus actually » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                      @rk@mastodon.well.com

                                                                                                                                                                                                                                                                                                                                                                                                                      Buddy of mine is in pretty dire straits. He’s got decades in but he went through a nasty divorce and then got laid off twice in 18 months and the psychological and financial toll has been immense. He’s been looking for work for well over a year now and has gotten no bites.

                                                                                                                                                                                                                                                                                                                                                                                                                      If anyone is looking for a CISO/infosec manager/security team architect let me know. He’s served in those kind of roles for huge orgs, small orgs, and everything in between.

                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Etienne / Tek [he/him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                        @tek@todon.eu

                                                                                                                                                                                                                                                                                                                                                                                                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                        @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                        ⋅ CVE-2026-32746 : les serveurs Linux menacés par une nouvelle faille Telnet

                                                                                                                                                                                                                                                                                                                                                                                                                        it-connect.fr/cve-2026-32746-l

                                                                                                                                                                                                                                                                                                                                                                                                                          AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                          [?]Radio_Azureus » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                          @Radio_Azureus@ioc.exchange

                                                                                                                                                                                                                                                                                                                                                                                                                          LLM hallucinated spam slop

                                                                                                                                                                                                                                                                                                                                                                                                                          Even a parrot would formulate a better set of sentences. This is easily sent to /dev/null

                                                                                                                                                                                                                                                                                                                                                                                                                          @stefano

                                                                                                                                                                                                                                                                                                                                                                                                                            Gwenn boosted

                                                                                                                                                                                                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                            ⋅ Simple Custom Font Rendering Can Poison ChatGPT, Claude, Gemini, and Other AI Systems

                                                                                                                                                                                                                                                                                                                                                                                                                            cybersecuritynews.com/custom-f

                                                                                                                                                                                                                                                                                                                                                                                                                              [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                              @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                                                              If you, as an information security professional, think an acceptable way to defend against fraudulent accounts is to limit the *legitimate* email address domains you allow your users to use, then you are bad at your job and you are a bad person and you should feel bad.

                                                                                                                                                                                                                                                                                                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                ⋅ Meta to Permanently Remove End-to-End Encryption Feature in Instagram DMs

                                                                                                                                                                                                                                                                                                                                                                                                                                cybersecuritynews.com/instagra

                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                  @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                                                                  How I ended up summarizing my pages of advice, which didn't even cover everything I wanted to cover:
                                                                                                                                                                                                                                                                                                                                                                                                                                  "If you're doing something about which you're worried about the government coming after you or the people you're with now or in the future, it might be prudent to leave your phone home, or turn it off and not turn it back on until you're back home unless there's an emergency."

                                                                                                                                                                                                                                                                                                                                                                                                                                  (2/2)

                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                    @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                                                                    Activist: "Should we put our phones in airplane mode when we're doing activist stuff?"
                                                                                                                                                                                                                                                                                                                                                                                                                                    Me: [responds with two pages of text about threat modeling, risk assessment, levels of protection, current and future threats]
                                                                                                                                                                                                                                                                                                                                                                                                                                    I don't think most people realize how hard it is to give people simple, straightforward cybersecurity guidance.
                                                                                                                                                                                                                                                                                                                                                                                                                                    There's a huge risk in erring on the side of caution: people finding your recommendations burdensome and doing _nothing_ as a result.

                                                                                                                                                                                                                                                                                                                                                                                                                                    (1/2)

                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                      @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                      ⋅ ‘CrackArmor’ Vulnerability in AppArmor Impacts 12.6M Linux Systems

                                                                                                                                                                                                                                                                                                                                                                                                                                      hackread.com/crackarmor-vulner

                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Windy city » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                        @pheonix@hachyderm.io

                                                                                                                                                                                                                                                                                                                                                                                                                                        Is this the first time a major service has removed end-to-end encryption instead of adding it? Why Instagram?

                                                                                                                                                                                                                                                                                                                                                                                                                                        Screenshot showing, "Instagram's end-to-end encrypted messaging is ending on 8 May"

                                                                                                                                                                                                                                                                                                                                                                                                                                        Alt...Screenshot showing, "Instagram's end-to-end encrypted messaging is ending on 8 May"

                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                          @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                          ⋅ Hackers Use Cloudflare Human Check to Hide Microsoft 365 Phishing Pages

                                                                                                                                                                                                                                                                                                                                                                                                                                          hackread.com/hackers-cloudflar

                                                                                                                                                                                                                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]PH4NTXM :verified: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                            @PH4NTXMOFFICIAL@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                                                                                                            Post-quantum cryptography is now operational inside the PH4NTXM live OS.

                                                                                                                                                                                                                                                                                                                                                                                                                                            Our latest builds successfully negotiated hybrid post-quantum key exchange across multiple protocols. The system now prioritizes ML-KEM and hybrid lattice-based exchanges for TLS connections and hybrid post-quantum key exchange for SSH, while maintaining secure classical fallbacks for compatibility.

                                                                                                                                                                                                                                                                                                                                                                                                                                            This means PH4NTXM boots as a stateless live environment with post-quantum-capable cryptography already integrated into the network stack. No external configuration required.

                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                              @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                              [Accès Libre]

                                                                                                                                                                                                                                                                                                                                                                                                                                              ⋅ Le logiciel espion utilisé par le renseignement russe avait bien été développé pour la NSA

                                                                                                                                                                                                                                                                                                                                                                                                                                              next.ink/brief_article/le-logi

                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]Foudreclair » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                @foudreclair@piaille.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                Coruna Jailbreak
                                                                                                                                                                                                                                                                                                                                                                                                                                                Exploit pour iOS 13 → 17.2.1, lançable directement dans le navigateur

                                                                                                                                                                                                                                                                                                                                                                                                                                                34306.lol

                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Hack in Days of Future Past » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                  @allainyann@piaille.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Can small open-source models learn advanced mathematical reasoning? And more importantly: how do you actually build them?

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Great talk by Lewis Tunstall from huggingface on training reasoning models with smart pipelines: SFT, RL with grading rubrics, reasoning cache & inference scaffolds.

                                                                                                                                                                                                                                                                                                                                                                                                                                                  Lots of ideas to explore similar approaches in

                                                                                                                                                                                                                                                                                                                                                                                                                                                  youtube.com/watch?v=kSsyBXf8uMM

                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]gregR ☯ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                    @gregr@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                    Échec et mat !

                                                                                                                                                                                                                                                                                                                                                                                                                                                    > Check Point ThreatCloud flags whole cloudfront.net... - Check Point CheckMates
                                                                                                                                                                                                                                                                                                                                                                                                                                                    > False positives can happen and do happen from time to time. Normally I would not create a CheckMates post for that.
                                                                                                                                                                                                                                                                                                                                                                                                                                                    community.checkpoint.com/t5/Ge

                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                      @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                      @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                      ⋅ Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices

                                                                                                                                                                                                                                                                                                                                                                                                                                                      thehackernews.com/2026/03/doze

                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Ludovic :Firefox: :FreeBSD: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                        @usul@piaille.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Bryan Steele :flan_beard: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                        @brynet@bsd.network

                                                                                                                                                                                                                                                                                                                                                                                                                                                        I don't suppose that I have any friends out there willing to signal boost, by chance? :flan_heart::flan_hacker:

                                                                                                                                                                                                                                                                                                                                                                                                                                                        bsd.network/@brynet/1144589971

                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                          @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                          :drake_dislike: Moltbook is a social network for AI agents

                                                                                                                                                                                                                                                                                                                                                                                                                                                          :drake_like: Moltbook is a botnet C&C portal

                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]Terri K O 🍁 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                            @terri@social.afront.org

                                                                                                                                                                                                                                                                                                                                                                                                                                                            Learning about the "bodysnatcher" attack on serviceNow and "ai agents authenticated only by an unverified email address and a well known reused api token" is so great i bet everyone is doing it.

                                                                                                                                                                                                                                                                                                                                                                                                                                                              mmu_man boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                              @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                              « Des milliards dépensés et les grands projets logiciels continuent d'échouer », Robert N. Charette souligne que 5 600 milliards de dollars sont dépensés chaque année en informatique, mais que « les taux de réussite des logiciels ne se sont pas nettement améliorés au cours des deux dernières décennies ».

                                                                                                                                                                                                                                                                                                                                                                                                                                                              ⋅ L'IA va t-elle rendre la cybersécurité obsolète ? Ou bien la Silicon Valley est-elle encore en train de fantasmer ?

                                                                                                                                                                                                                                                                                                                                                                                                                                                              zdnet.fr/actualites/lia-va-t-e

                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                ⋅ Signal Confirms Targeted Phishing Attacks Resulting in Account Takeovers

                                                                                                                                                                                                                                                                                                                                                                                                                                                                cybersecuritynews.com/signal-c

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ⋅ Scandale de babyphones vidéo : un chercheur français découvre plus d'un million d'appareils totalement exposés

                                                                                                                                                                                                                                                                                                                                                                                                                                                                  clubic.com/actualite-603772-sc

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]FLOX Advocate » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @FLOX_advocate@floss.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Someone make this make sense…
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Yesterday when we were at the car dealer,¹ before we submitted our auto loan application², I unfroze our credit reports at TransUnion, Experian, and Equifax so the loan application would go through.³
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    I have email confirming that my report was unfrozen at TransUnion, so I must have successfully logged into their website.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Today, when I went to put the freezes back, I wasn't able to log into the TransUnion website with the credentials in 1Password.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                    (1/5)

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ⋅ Malicious imToken Chrome Extension Caught Stealing Mnemonics and Private Keys

                                                                                                                                                                                                                                                                                                                                                                                                                                                                      cybersecuritynews.com/maliciou

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Mark Wyner Won’t Comply :vm: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @markwyner@mas.to

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Digital rights and privacy with the @privacyguides Privacy Activist Toolbox. Hours of reading in there, but it’s a treasure chest.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                        privacyguides.org/en/activism/

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Marcos Dione boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]Shawn Webb [He/Him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @lattera@bsd.network

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          So I need to test the security properties of a remote TLS server. Normally, I'd use Qualys' TLS server testing tools. However, this server uses an IPv4 allowlist, so Qualys wouldn't be able to reach it.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          So, I'm looking for tools I can run locally (Linux, the BSDs, or Windows).

                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Anyone have any suggestions?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]Mike Sheward » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @SecureOwl@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            a very cool technique that some salesfolk are doing now - if you have the iOS phone call screening thing turned on on your phone, they state their reason for calling as

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            "cybersecurity breach" or "urgent breach detected"

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Because they know that'll go to your screen as text.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                            And by very cool what I mean is "a very cool way of making sure I never talk to you"

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                              @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ⋅ Amazon AWS-LC Vulnerabilities Allows Attackers to Bypass Certificate Chain Verification

                                                                                                                                                                                                                                                                                                                                                                                                                                                                              cybersecuritynews.com/amazon-a

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]DoomsdaysCW » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @DoomsdaysCW@kolektiva.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Helped Unmask Anonymous ‘

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                by Joseph Cox
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Mar 5, 2026 at 3:36 PM

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                A court record reviewed by 404 Media shows privacy-focused email provider Proton Mail handed over payment data related to a Stop Cop City email account to the Swiss government, which handed it to the FBI.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Read more:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                404media.co/proton-mail-helped

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Archived version:
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                archive.ph/8cpN1

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  RE: mastodon.social/@404mediaco/11

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  If you're an activist, you can't rely on Proton Mail to keep your identity private unless you figure out how to pay them in a way that can't be linked back to you.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  I'm not going to say that Proton was in the wrong here—they didn't do anything that they claim they won't do—but I will say that I think some people may have an inflated sense of the extent to which Proton can/will protect their privacy when the rubber hits the road.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]404 Media » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @404mediaco@mastodon.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  A court record reviewed by 404 Media shows privacy-focused email provider Proton Mail handed over payment data related to a Stop Cop City email account to the Swiss government, which handed it to the FBI.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  404media.co/proton-mail-helped

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Tykayn boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Riku Silvola » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @rikusilvola@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    I'm looking for a senior software engineer to join my team working on securing Wikipedia and our other projects. We've got a huge platform, a great mission and a team of passionate engineers and product managers working together with the community.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Wikipedia just celebrated its 25th birthday in January, and there's a lot of energy to take on big challenges. Come help us tackle them head-on!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Job: job-boards.greenhouse.io/wikim

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Team: mediawiki.org/wiki/Product_Saf

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]Mark Wyner Won’t Comply :vm: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @markwyner@mas.to

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      I’m finding an increasing number of sites are blocking me while using VPN. I use Mullvad. Is anyone else experiencing this increase?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ⋅ PleaseFix Flaw Lets Hackers Access 1Password Vault via Comet AI Browser

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        hackread.com/pleasefix-flaw-ha

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]~/devbyben » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @devbyben@piaille.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]Etienne / Tek [he/him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @tek@todon.eu

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          It seems that OAuth phishing attacks are back, I thought the approval process setup by Google and Microsoft killed that. Any idea how these attacks are bypassing the process?
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          microsoft.com/en-us/security/b

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ⋅ Where Multi-Factor Authentication Stops and Credential Abuse Starts

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            thehackernews.com/2026/03/wher

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ⋅ La fin du « laisser-faire » dans la collecte de données personnelles ? La justice confirme l’amende monstre imposée à Criteo

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              01net.com/actualites/la-fin-du

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]~/devbyben » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @devbyben@piaille.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Autopsie technique : Le dossier YGG

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Pour ceux qui suivent l'évolution des trackers privés, ce dossier est une mine d'or sur "ce qu'il ne faut pas faire" en administration système et sécurité web.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                L'analyse détaille la mise en pratique concrète de plusieurs vecteurs d'attaque :
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                - Failles SQL et injections exploitées.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                - Défauts d'OpSec ayant mené à la désanonymisation de l'administration.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                - Gestion des bases de données et fuites d'informations sensibles.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Un cas d'école sur la fragilité des infrastructures centralisées face à des acteurs déterminés.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                👉 À lire ici : yggleak.top/fr/home/ygg-dossier

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]kravietz 🦇 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @kravietz@agora.echelon.pl

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Interesting new project from #Tor #SecureDrop - that’s essentially digitally signed web pages that are client-verified to prevent any server-side covert injection or backdooring. Sounds a bit like SRI (Subresource Integrity) but for the whole page and using digital signature not just server-delegated hash. Obviously, it won’t work for a typical ‘modern’ mash-up website that changes every minute, but sounds perfect for high-integrity and largely static pages such as SecureDrop.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                WEBCAT helps protect users from malicious or unexpected changes to the client-side code of a web application. When a user visits a site that has enrolled in WEBCAT, the WEBCAT browser extension verifies the application’s served assets against a signed manifest before any content is executed. If verification fails, WEBCAT blocks the page from loading and shows a warning.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                https://securedrop.org/news/webcat-alpha/

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                #infosec

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]BastilleBSD :freebsd: » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @BastilleBSD@fosstodon.org

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  I'm pleased to report that I've just submitted the final capstone paper for my master's degree in cybersecurity!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    I am seeing a lot – a *lot* – more e-mail spam than before. I am not the only one. Seems like some larger phishing campaign got kicked off?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    I wonder if this is related to the aggression on Iran.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      There are scam notifications about "monetization" on here going around.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      👉 Don't fall for them.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      👉 Don't click the link.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      👉 Report and block on sight.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      There is no monetization scheme on mastodon.social, nor any other fedi instance I know of.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Stay safe!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Screenshot of a message from a scam account, @MonetizationNotification@mstdn.ca (already blocked on my instance).

I altered the phishing link in the description below on purpose, to make it harder to click on it.

@rysiek Mastodon Sent You Message

Important notification for your account!

The Mastodon team has noticed your activity on our forum and we would like to offer you a partnership.
Partnering with us means that monetization will be enabled for your account.

To begin collaborating with our team, please confirm that you are the owner of this account by following the link below. 
Verify now:  https://lyzo[.]io/icLJa

If you attempt to avoid verification, our system will freeze your account indefinitely.

Thank you for staying with us. 
Mastodon.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Alt...Screenshot of a message from a scam account, @MonetizationNotification@mstdn.ca (already blocked on my instance). I altered the phishing link in the description below on purpose, to make it harder to click on it. @rysiek Mastodon Sent You Message Important notification for your account! The Mastodon team has noticed your activity on our forum and we would like to offer you a partnership. Partnering with us means that monetization will be enabled for your account. To begin collaborating with our team, please confirm that you are the owner of this account by following the link below. Verify now: https://lyzo[.]io/icLJa If you attempt to avoid verification, our system will freeze your account indefinitely. Thank you for staying with us. Mastodon.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ⋅ A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        wired.com/story/coruna-iphone-

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ⋅ Des hackers chinois se cachent dans Windows Update pour espionner des gouvernements sans se faire repérer

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          clubic.com/actualite-603034-de

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [abo]
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ⋅ USA : 7 ans de prison pour avoir volé, et vendu, des failles « 0days » à un courtier russe

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            next.ink/226563/usa-7-ans-de-p

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]Super Owl » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              @gtsadmin@wiseowl.club

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Hello everyone, I'm looking to be #Fedihired. I'm looking for #Linux #DevOps work. I have 5 years software industry experience, and a B. Sc, in Computer Science. My resume is on my website, as is linked in my Bio. I'm excellent at #SelfHosting, cloud administration, all things networking, #Wireguard, and infrastructure design. I've been recently doing #infosec consulting; looking for more. I'm a #Canadian. I have lots of experience with technologies like #postgresql, #MariaDB, #nginx, #dns, #ssl, forums, #containers, #docker, etc. Also, recently automating things with #ansible. I'm posting this from my own #gotosocial instance. The #fediverse and #DataSovereignty are things I care about, and I give back to these things.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              #Fedihire

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]Charlie McHenry » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @CharlieMcHenry@connectop.us

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Europeans design ‘do it together’ (DIT) phone shaped by those who will use it. This, privacy-centric, is due in September 2026.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • No tracking, no calling home, no hidden analytics
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                • User configurable physical Privacy Switch - turn off your microphone, bluetooth, Android apps, or whatever you wish…

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                commerce.jolla.com/products/jo

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Taran Rampersad » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @knowprose@mastodon.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Two recent examples show issues with data and digital sovereignty.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Claude being used to exfil data from the Mexican government.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  'Flying objects' impacting AWS services in Dubai.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Both likely impacted personal and organizational and cross-national information and services. In one case, definitely national.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  knowprose.com/2026/03/when-dat

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ⋅ DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    cybersecuritynews.com/duckduck

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Motorola announces a partnership with GrapheneOS Foundation
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      motorolanews.com/motorola-thre

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      > Motorola and the GrapheneOS Foundation will work to strengthen smartphone security and collaborate on future devices engineered with GrapheneOS compatibility.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      This could be a gamechanger. Congratulations to @GrapheneOS, fingers crossed this works out well!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ⋅ Tire Pressure Systems in Toyota, Mercedes, and Other Major Car Brands Enable Silent Vehicle Tracking

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        cybersecuritynews.com/tire-pre

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ⋅ HackerBot Claw : le bot IA autonome qui a fait disparaître Trivy de GitHub

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          it-connect.fr/hackerbot-claw-l

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @rysiek@mstdn.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Heads up for any folks using @hetzner: scammers seem to be trying to exploit the recent bump in pricing by sending "unpaid invoice notification" e-mails.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Easy to fall for it before morning coffee.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            "Update Payment Method" link obviously leads to a scam site, so not particularly hard to spot either.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Be careful out there. :blobcatcoffee:

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            P.S. yes I am aware of the shitty ways Hetzner treated a bunch of fedi instances; this is not a recommendation.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              webhat boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]Pseudo Nym » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              @pseudonym@mastodon.online

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              @campuscodi

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Closer and closer to Daniel Suarez 's "Demon."

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              It doesn't have to be conscious or a person to follow an agenda to accomplish goals in the real world.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              As this one solicits crypto currency, it's a trivial step to have it supplied with some before launch, and "decide" to deploy money to accomplish physical tasks in the real world.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              We had that unsuccessful "task rabbit" for bots to hire humans a while ago.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Totally doable for bot to bribe a human in an attack.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ⋅ 5 IoT Vulnerabilities That Stop Projects and How to Avoid Them

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                hackread.com/5-iot-vulnerabili

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ⋅ Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  thehackernews.com/2026/02/thou

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    AodeRelay boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Paco Hope [He/Him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @paco@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    I managed to persuade a few very cool folks to join the fediverse.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Their profiles don’t look like much, yet, because some of them were munching on ramen while they signed up and all of us were busy at . But maybe we can light up their feeds a bit and show them that it’s good to be here.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]Jonathan Kamens 86 47 » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @jik@federate.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      I am negotiating an engagement with on behalf of my employer, and I found this buried most of the way down the engagement letter draft they sent me.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      wtaf
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      I replied: "I am uncomfortable with the language in the 'Use of Data' section of the engagement letter. We do not wish to authorize PwC's use of our data, either during or after this engagement, for purposes other than providing to us the contracted services."
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      We shall see.
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      (It's an gap assessment.)

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      12 Use of Data
You agree that we and all members of the PricewaterhouseCoopers global network of firms may use the data we receive from you also for other purposes than for this engagement, i.e. for analysis and development purposes, such as benchmarking, market and cost analyses, and the further development of our technologies, methods, quality standards and services.
In using your data we will ensure,
• that the statutory data protection regulations are observed
• that third parties cannot identify you or your data as a result of the use.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Alt...12 Use of Data You agree that we and all members of the PricewaterhouseCoopers global network of firms may use the data we receive from you also for other purposes than for this engagement, i.e. for analysis and development purposes, such as benchmarking, market and cost analyses, and the further development of our technologies, methods, quality standards and services. In using your data we will ensure, • that the statutory data protection regulations are observed • that third parties cannot identify you or your data as a result of the use.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ⋅ ShinyHunters Leak 2M Records From Dutch Telecom Odido, Claim 21M Stolen

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        hackread.com/shinyhunters-leak

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ⋅ Researchers Uncover Aeternum C2 Infrastructure with Advanced Persistence and Network Evasion Features

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          cybersecuritynews.com/research

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ⋅ ClawJacked Vulnerability in OpenClaw Could Let Websites Hijack AI Agents

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            hackread.com/openclaw-vulnerab

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ⋅ Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              cybersecuritynews.com/chrome-e

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]Tinker ☀️ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @tinker@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Inb4 Duo responds and makes the statement:

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                "These Persona services are opt-in by the client as additional features. We do not integrate them into our core product."

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                to which the answer to that response is:

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                "Yeah, the CLIENT opts in, meaning the COMPANY opts in... the employees have no say. The *employees*, all of us, can only opt out by being fired."

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                Edit: Reading Duo's privacy statement though, I'm not sure if the client actually can opt out. It looks like its fully integrated right now. Clients may opt to require employees to scan their faces... but it looks like IDV with Persona is fully integrated into the above mentioned services. So yay.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]Tinker ☀️ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @tinker@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @alien8 - Yeah, I figure any statement by Duo will absolutely push the whole "its not enabled by default" and its the client's decision to use it.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Which ignores the core point - the employees (once a client enables it) have no say. By even offering this, they put so many people in the position of "accept this or quit" which is not consent.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Especially in the US where one's job is tied to access to healthcare and where many live paycheck to paycheck and if they quit or get fired, they run the real risk of going hungry or losing their house.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Tinker ☀️ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @tinker@infosec.exchange

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    So Duo (the multifactor authentication service that loves) has integrated with Persona (the privacy destroying, Peter Thiel backed, AI-linked, facial scanning and mapping "identity verification" software)

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    You know the recent Discord snafu that received such massive pushback and caused so many people to leave Discord that they've dropped their identity verification?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Yeah, that Persona.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Duo integrates it into Duo Premier, Duo Advantage, and even Duo Essentials...

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ...which means many working class folks will have no option but to be enrolled into and use Persona...

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ...or be fired.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    duo.com/docs/identity-verifica

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Identity Verification Last updated: January 23rd, 2026 Overview  To help protect organizations from the ever-growing threat of social engineering attacks, Duo integrates with Persona to offer integrated identity verification (IDV) workflows which provide high-assurance of user identities before allowing critical workforce user lifecycle actions in your organization.  Identity verification is part of the Duo Premier, Duo Advantage, and Duo Essentials plans.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Alt...Identity Verification Last updated: January 23rd, 2026 Overview To help protect organizations from the ever-growing threat of social engineering attacks, Duo integrates with Persona to offer integrated identity verification (IDV) workflows which provide high-assurance of user identities before allowing critical workforce user lifecycle actions in your organization. Identity verification is part of the Duo Premier, Duo Advantage, and Duo Essentials plans.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Gauthier C. boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      C'est qui, qui a fuité aujourd'hui ?
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Cegedim !

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ⋅ Fuite de données médicales, les notes glaçantes des médecins sur leurs patients exposées sur la toile

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      01net.com/actualites/fuite-de-

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      Le Pdf est ici :

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      cegedim.fr/Communique/Cegedim_

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Taran Rampersad » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @knowprose@mastodon.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Sheldon [he/him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @sysop408@sfba.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        I'm configuring a Web Application Firewall in China that's clearly been translated into English using translation software instead of human translators.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Whenever there's a prompt to confirm a choice, it doesn't say "Confirm" or "Acknowledge".

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        The button reads "Sure!"

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]dallo » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @dallo@pouet.chapril.org

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]Etienne / Tek [he/him] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @tek@todon.eu

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Hey, people, what is your best way to follow threat reports published? Do you have any good RSS feed? Or newsletter?
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          (By threat report I mean technical reports, not news articles)

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]Jon Yoder » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @jonyoder@mstdn.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            It's an exciting time for the project and Connect continues to show visible improvements. Hit the link to find out more!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            mensago.org/february-2026-news

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              Dans la série : Vive l' IA (ou pas) !

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ⋅ Cette directrice de Meta a vu toute sa boîte mail supprimée par OpenClaw

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              frandroid.com/marques/meta/298

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                [?]⁢Ƥĥąɳʈȯɱ :fedora: 🎸 🏳️‍🌈 ⁂ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                @Steve12L@mamot.fr

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ⋅ Comment savoir si mes données personnelles ont été piratées ?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                blogdumoderateur.com/comment-s

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  [?]ARGVMI~1.PIF » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  @argv_minus_one@mastodon.sdf.org

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Just found out that automatically fetches web links in messages and plays the page's video if there is one.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  This is not acceptable behavior!!!

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  * It's annoying. There isn't any obvious way to stop the video.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  * It's insecure. The linked page might attack vulnerabilities in Beagle's video player.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  * It exposes the user's IP address to anyone who sends them a message, potentially physically endangering them.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  Will uninstall and replace ASAP.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    [?]Jon Yoder » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    @jonyoder@mstdn.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Been working hard on attachment support for messages in Connect lately, and I just implemented basic support for a feature I'm calling Attachment Guard, where a color and number are assigned to a level of risk associated with the kind of attachment(s) a message has. Screenshot below.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Does this help the way that I hope it does?

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    A screenshot of an email program. A smaller window is open, displaying a test message that has several attachments. Each attachment is prepended by a colored box with a number in it.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    Alt...A screenshot of an email program. A smaller window is open, displaying a test message that has several attachments. Each attachment is prepended by a colored box with a number in it.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      [?]Emory » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @emory@soc.kvet.ch

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      @briankrebs if you have not seen @howardnoakley's impressive collection of free software you may not know that he offers several excellent options for on .

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      we're talking elegant, powerful software that hooks into core frameworks most people ignore entirely (containers, xhyve/bhyve that sort of thing). you gotta check these out imo. i use them for handling malicious code and for agents to use contained desktop environments.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      eclecticlight.co/virtualisatio

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        David Gerard boosted

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        [?]Kim Crawley 😷 (she/her) » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @kimcrawley@zeroes.ca

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        Although I have a CISSP, I certainly didn't need it to know how horrifying this is.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        But what I think is even worse is that LinkedIn is mostly fucking pathetic bootlickers singing the praises of Copilot and bragging about their "AI skills." 🫠🫠🫠

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        @davidgerard

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        youtu.be/B0B6hoOE9uo?si=gQLzc0

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          @MissConstrue@mefi.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          cybernews.com/security/global-

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Speaking of ID verification companies being shady, , a global AI-based identity verification and "Know Your Customer" (KYC) solutions provider, left a terabyte of user data and biometrics on the open web. The breach exposed approximately 1 billion to 3 billion personal records across 26 countries, making it a significant event for data privacy in the financial and fintech.

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          Call me Cassandra. 🤷🏻‍♀️🤦‍♀️

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            [?]Genuinely Gary 🌤️ » 🌐
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            @sgtgary@mindly.social

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            Age verification vendor Persona left frontend exposed, researchers say malwarebytes.com/blog/news/202

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            (They aren't stealing your password from these sites, they're stealing your biometric identity)