seanthegeek, to infosec
PogoWasRight, to infosec
YourAnonRiots, to infosec Japanese

ScarCruft, the North Korean threat group behind , has adapted to the blocking of macros by using oversized LNK files.

https://thehackernews.com/2023/05/north-koreas-scarcruft-deploys-rokrat.html

chiefgyk3d, to infosec
@chiefgyk3d@social.chiefgyk3d.com avatar

My @\flipper_zero came in yesterday so I reused the foam it shipped with to make a nice hard case in PETG #sync #3dprinting #cybersecurity #infosec

image/jpeg

0xor0ne, to infosec

Great blog post for beginners on bitwise operations in C by Andrei Ciobanu

https://andreinc.net/2023/02/01/demystifying-bitwise-ops

#infotech #infosec #cybersecurity #learning

image/jpeg
image/jpeg
image/png

0x58, to infosec

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes, but not only:

‣ Hackers target vulnerable servers exposed online
queries for Americans’ digital data drops, yet advocates for surveillance reform remain undeterred
: Back in After Meeting Watchdog Demands
‣ Many Public Sites are Leaking Private Data
CSF 2.0 Core discussion draft released, stakeholder feedback invited
Attack: New Politically-Motivated Surveillance Campaign in
version of RTM Locker targets ESXi servers
‣ New Atomic info-stealing targets 50 crypto wallets
Gets Court Order to Take Down That Infected Over 670,000 Computers
restricted in after refusal to supply user data to authorities
discloses XSS zero-day flaw in server management tool
‣ Ukrainian arrested for selling data of 300M people to Russians
‣ Hackers are breaking into AT&T email accounts to steal
, , join Elite Cyber Defenders Program to secure critical infrastructure
‣ ATT&CK v13 April Updates
‣ New Data Sharing Platform Serves as Early Warning System for Threats
‣ North Korean Hackers Target Mac Users With New ‘’ Malware
‣ New All-in-One "" Stealer for Systems Surfaces on the Dark Web

📚 This week's recommended book is: "This Is How They Tell Me the World Ends: The Cyberweapons Arms Race" by Nicole Perlroth

Subscribe to the to have it piping hot in your inbox every Sunday ⬇️

https://0x58.substack.com/p/infosec-mashup-week-172023

infosec_jobs, to infosec
Randyy, to infosec

I really Don't understand why people still Don't take seriously nowadays.

"It's just hard to remember 25k different passwords".

And then they are shocked they getting .

Saren42, to infosec

Well, the Oklahoma governor Stitt did it. He signed SB 613 into law, after saying he will veto all bills until he gets his way on other bills. Thankfully the Senate removed the language banning trans healthcare from being covered by private insurance in the state, it still is banning all sorts of gender affirming care for anyone under 18. Will be forcibly de-transitioning children now, with a bullshit 6 month "wind down".

Me and my wife have been trying to get out of Oklahoma for a while now, but... it's getting more and more risky and dangerous for us here. I've been trying to find a new job, since I've been unable to perform my current job, since at least August (been on a medical LOA, but the short term disability company is ghosting me, and has not paid be since November 1st). I'm at a point, where I'm really not sure what to do at this point. Struggling to find a new job, and my wife doesn't have enough income for us to save money to move.

That being said, I have been trying to find my first infosec role for near 2 years now. In that time, I began working on a degree in Cybersecurity & Digital Forensics, but after I contracted COVID at work, I had to drop mid-semester, and the board at the school, denied my request for retro-active withdraw, with refund for the classes, which ended with me owing the school almost 4 grand for the semester, since they had to return student loan funds. Which has lead me to being unable to re-enroll. Began to work on studying for the Sec+ exam, while also continuing to work with my homelab on things, as well as doing work on TryHackMe learning paths.

I've spent the better part of my adult life working in industrial equipment maintenance since I got out of the USAF, where I was an Aircraft Electrician. Due to various reasons, I've had to step away from industrial equipment maintenance, and been trying to figure out how to make my career switch since my last role doing that ended in 2018.

I do have a general resume on hand I can supply on request, let me know. Otherwise, I am also trying to raise some funding for me and my wife to be able to escape this state, that is actively hostile to both me and my wife. We've previously faced threats of direct violence from individuals, but now the state is directly targeting us. I have a GoFundMe I have started to try to help us.

https://gofund.me/a1049b09

#transphobia #oklahoma #transhealthcare #fundraising #mutualaid #lgbtqia #getfedihired #infosec #transrescue

juliewebgirl, to infosec
@juliewebgirl@mstdn.social avatar

GASP

Nooooo.... REALLY??

When you call #TMobile support, they ask you what your PIN is ..

Meaning you SAY it...

OUT LOUD!!

To a PERSON!!

How the hell is that secure???

Oh! HEY I know... I'll reset my PIN.

How, you might ask?

By SAYING it...

OUT LOUD!!

To a PERSON!!!

No other options.

My PIN was compromised from the second I created it.

I've been bitching about this for years. Ask @elfin.

#infosec #DataBreach

https://arstechnica.com/information-technology/2023/05/t-mobile-discloses-2nd-data-breach-of-2023-this-one-leaking-account-pins-and-more/

mmguero, to infosec

I'm very proud to announce the release of Malcolm v23.05.0! This was a big release!

This is the first version of Malcolm that can be deployed with Kubernetes, although improvements in this area will continue in coming releases. (Please let us know what issues or suggestions you have via the issue tracker or via email to malcolm@inl.gov.)

The Malcolm documentation has been improved and now includes a detailed End-to-end Malcolm and Hedgehog Linux ISO Installation document.

A new ICSNPP-Synchrophasor parser for Synchrophasor Data Transfer for Power Systems (IEEE C37.118) has been integrated.

We've also got a plethora of component version updates, including Arkime to v4.3.0, Capa to v5.1.0, Fluent Bit to v2.1.2, NetBox to v3.5.0, NGINX to v1.22.1, Supercronic to v0.2.24, Suricata to v6.0.10, Yara to v4.3.0, and Zeek to v5.2.1.

Check out the release on GitHub or grab my ISO builds at malcolm.fyi.

Rairii, to infosec

decided to put all public bitlocker attack research I know of (including mine and others) in one place https://github.com/Wack0/bitlocker-attacks

#BitLocker #infosec

jackscerebellum, to infosec

So, one thing I miss about infosec Twitter was the viral awareness brought to timely issues.
Like the cissp bylaw change vote last year.
Now it's up again, but I don't see the advocacy.
Anyone got an opinion on the petition vote?
#cissp #bylaws #infosec

nixCraft, to infosec
@nixCraft@mastodon.social avatar
0x58, to infosec

I did not have the chance to be at , but the resources I've collected here almost felt that I was there... minus the important social event part :sad_panda:​

https://0x58.substack.com/p/rsa-conference-2023-mashup

biscuit, to infosec

Excited that I can finally talk about this! Last year I discovered a security issue that allowed a third-party iOS application to access a user's location without their consent/knowledge. Not a great writeup, but more details here: https://github.com/biscuitehh/cve-2022-46718-leaky-location

#ios #infosec #security

tinker, to infosec

Dang... all the old methods of hacking work. And they keep working...

One day I'll be 1337... today, I'll just be brute forcing telnet services like I'm the Mirai botnet...

Can't stop, won't stop.

#hacking #infosec

RTP, to internet
@RTP@fosstodon.org avatar
0xor0ne, to infosec
SecureOwl, to infosec
toddheberlein, to infosec

Big push by NSA to hire cybersecurity staff.

#cybersecurity #infosec
https://www.youtube.com/watch?v=pM57nyRdqo0

SecureOwl, to infosec

Listen to a sample of Blue Team Diaries: The Big Phish: https://www.youtube.com/watch?v=0xF-6WSLPuc

#infosec #BlueTeam #DFIR #audiobook

lincolncyber, to infosec

How to get started using the BadUSB feature on your Flipper Zero.

Flipper Zero BadUSB: Getting Started with DuckyScript https://blog.lincolncyber.com/flipper-zero-badusb-getting-started-with-duckyscript-f212fcdd5dec

#flipperzero #infosec #pentest #tech #ethicalhacking

PogoWasRight, to infosec

And I see that the Daixin ransomware leak site is back online after a hiatus. Their spokesperson tells me that they have been working on other projects but will be resuming ransomware work soon.

Hmmm.

#databreach #ransomware #infosec

0xor0ne, to infosec
  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • ethstaker
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • tacticalgear
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • lostlight
  • All magazines