jsrailton, (edited ) to hacking
@jsrailton@mastodon.social avatar

deleted_by_author

  • Loading...
  • jsrailton, (edited )
    @jsrailton@mastodon.social avatar

    There's a disgraceful ecosystem of public relations & lobbying firms using hackers for hire.

    Sometimes they are used to silence critics & advocacy groups.

    Like US nonprofits doing climate advocacy.

    Our investigation into a group we christened uncovered a sprawling -based hack-for-hire operation.

    They enabled US corporations to outsource lawbreaking.

    https://citizenlab.ca/2020/06/dark-basin-uncovering-a-massive-hack-for-hire-operation/

    0x58, to infosec

    On Wednesday, October 18, 2023, we @cloudflare] discovered attacks on our system that we were able to trace back to Okta – threat actors were able to leverage an authentication token compromised at Okta to pivot into Cloudflare’s Okta instance.

    .. and they wrap up with recommendations...

    Take any report of compromise seriously and act immediately to limit damage; in this case Okta was first notified on October 2, 2023 by @beyondtrust but the attacker still had access to their support systems at least until October 18, 2023.

    #Okta #breach #infosec #cybersecurity

    https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/

    simplenomad, to blogging
    @simplenomad@rigor-mortis.nmrc.org avatar

    GitLab is hiring for a #redteam position, the position is somewhat unique in that #cicd experience, #blogging, and even #conference speaking would help land this job. Feel free to boost to get many #infosec eyes on it. And if we know each other I could put in a good word for you.

    https://boards.greenhouse.io/gitlab/jobs/7056513002

    majorlinux, to apple
    @majorlinux@toot.majorshouse.com avatar
    iaintshootinmis, to infosec
    @iaintshootinmis@digitaldarkage.cc avatar

    Gonna write this up better later. But thanks to @tbaraki , we found a fluke in Microsoft's SignonLogs table. Sometime in the last few days they made UserPrincipalName case sensitive.

    So our alerts looking for breakglassadmin@CompanyName.onmicrosoft.com started failing because we were using (==) instead of (has).

    Would highly recommend you check your alerting and see which operands you're using in your queries.

    #InfoSec #threatintel #Logging

    kuketzblog, to infosec German
    @kuketzblog@social.tchncs.de avatar

    "Der Diebstahl eines Signatur-Schlüssels wirft weiterhin Fragen auf, die Microsoft nicht beantwortet. Was betroffene Unternehmen jetzt selbst tun können."

    Den Aufruf von @ju916 kann ich nur unterstützen! Stellt bzw. flutet Microsoft so lange mit Fragen, bis endlich aussagekräftige Antworten kommen. heise bietet entsprechende Fragen/Vorlagen, die ihr einfach für eure Anfrage kopieren könnt. 👇

    https://www.heise.de/news/Gestohlener-Cloud-Master-Key-Microsoft-schweigt-so-fragen-Sie-selber-9229395.html

    hack_lu, to infosec

    First version of the @hack_lu 2023 agenda is now online

    https://2023.hack.lu/agenda/

    The agenda will be extended in the next days with latest speaker acceptances or updates.

    #hacklu #conference #infosec #luxembourg

    tinker, to infosec

    If your first instinct is to try and find blame when a security vulnerability is pointed out...

    ...you have already created an environment where everyone will hide issues from you.

    You currently live in a fake reality where you think everything is fine and you have no idea the rot that is underneath you.

    If you fire or punish a person every time a vulnerability is found, you will have no one left. Hell, fire yourself first to save us all the trouble.

    Vulnerabilities exist. The world changes. Software changes. Attacks change. Business needs change.

    Life is fucking impermanence.

    So create an environment where folks come to you quickly and tell you what needs to be fixed as they find it.

    How do you do that?! Reward vulnerability discovery. Reward mitigations. Reward patch management. Reward security improvement. Reward safety improvement.

    #informationsecurity #infosec #operationalsecurity #opsec #ics #ot

    Arataka, to mastodon
    @Arataka@esper.lol avatar

    Pretty cool interview here with @jerry on #Mastodon and the challenges of scaling an instance with a mass user influx, def recommend checking it out! - https://www.youtube.com/watch?v=vTEC6Gl7l2c

    #infosec #video

    happygeek, to infosec

    My article at Forbes has been updated as the WebP zero-day issue is moving fast. 1Password and Signal join web browsers including Chrome, Edge, Brave, Firefox, Opera and Vivaldi in issuing emergency security updates. I expect a lot more non-web browser applications will follow…

    #Infosec

    https://www.forbes.com/sites/daveywinder/2023/09/14/new-emergency-chrome-security-update-after-critical-ios-1661-release/

    tinker, to infosec

    This is your Public Service Announcement: Today is the first day of Fall (in the upper hemisphere).

    All users should now rotate their passwords to:

    • Fall2023
    • Fall2023! (If they're secure.)

    If they are fancy, they can rotate their passwords to:

    • Autumn2023
    • Autumn2023! (If they're secure.)

    Note, users should change their passwords to their local language, eg:

    • Autunno2023
    • Autunno2023! (Se sono sicuri.)
    • Осень2023
    • Осень2023! (Если они в безопасности.)

    Further Note, if users are in the southern hemisphere, please use the corresponding terms for Spring.

    ankit_anubhav, to microsoft
    infosecsidekick, to infosec

    It was super fun to interview @jerry for this week's episode of the Infosec Sidekick Podcast!

    I had wanted to do this a while back; when the heat of the twitter migration was taking place, but I almost feel like now was a better time.

    With the dust somewhat settled, @jerry and I talk about Information Sharing, Community Building, and how Mastadon plays a role in that.

    I genuinely appreciate this conversation and hope it can provide you some value and entertainment throughout your week.

    You will be sure to find gems in this episode, such as the unlikely comparison to twitter vs mastadon as Monsters Inc. Power Generation (don't ask, just listen lol)

    To Listen -> https://www.infosecsidekick.com/p/building-a-cyber-security-community#details

    #infosec #infosecurity #podcast #news #community #intelligence #informationsecurity

    nixCraft, to linux
    @nixCraft@mastodon.social avatar

    With firefox on X11 (#Linux and #Unix machines), any page can pastejack you anytime https://www.openwall.com/lists/oss-security/2023/10/17/1 #security #infosec

    monkeyflower, to opsec
    timbray, to infosec
    @timbray@cosocial.ca avatar

    It dawns on me that many of you youngster developers out there probably don’t know about the Ken Thompson hack. If you’re one of them, reading this should make you shudder:
    https://wiki.c2.com/?TheKenThompsonHack
    https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf

    #infosec

    pseudonym, to infosec
    @pseudonym@mastodon.online avatar

    Left here without further comment.

    https://id.uni-lj.si/DigitalnaIdentiteta/PonastavitevGesla?culture=en-GB

    quote:

    Your password must also not contain the following character combinations: script, select, insert, update, delete, drop, --, ', /*, */.

    juliewebgirl, to Seattle
    @juliewebgirl@mstdn.social avatar

    I'm kinda speechless.

    Ok so because of Covid, there was no for 3yrs. Then Cheq bought it & are the new owners. (I didn't realize anyone "owned" it.)

    They launched an app 6mo ago.

    Here's the appalling rundown of how to ruin a beloved local event (since 1982) in one fell swoop:

    Vendors:

    ✓ required to use the app
    ✓ paid ~$5k for a spot
    ✓ had to pay 16% of all sales to Cheq
    ✓ forbidden from taking cash or use their own POS systems


    *fun links to follow

    1/

    ImPureMotion, to infosec

    Can we do that thing where we recommend people to follow? Trying to find all the good Infosec accounts #infosec #blueteam #cybersecurity

    j_opdenakker, to infosec

    Security by removal.

    Remove all

    • user accounts you no longer use.
    • software you no longer use on your pc.
    • redundant apps on your mobile devices.
    • unnecessary third party apps that have access to other apps.
    • files or documents that contain sensitive information.

    #Infosec

    rye, to infosec
    @rye@ioc.exchange avatar

    Hi, Mastadon, I’m a Sr. Security Engineer with more than 15 Years of experience building reliable telecommunication infrasturcutre at global scale.

    I’m looking for work one of these domains.
    Cyber Threat Intelligence (CTI)
    Detection Engineering
    Jr. Software Engineering
    Pre-sales engineer (B2B SaaS)

    Here’s a sample of a training presentation.

    https://www.youtube.com/watch?feature=shared&v=V9MvelMEeHw

    accidentalciso, to Cybersecurity

    A few years ago, I was burned out to the point where I had nothing left for myself or my family. I was forced to make drastic changes in my life.

    Does that sound like you?

    I made a series of short videos talking about my experience with burnout and recovering from it. The first video is just an intro to the series, so start with the second video in the playlist. The sixth video is important.

    I hope that by talking openly about mental health and burnout in #CyberSecurity #infosec, we will be able to help folks understand that they are not alone. If you are struggling, please talk to friends or loved ones about it. I'm always willing to listen, too. My DMs aren't wide open, but I look at every reply and will always follow back on request to switch to DM. Please don't be shy.

    https://www.youtube.com/playlist?list=PLwdctyJSeCzOoRzfcMVLUbItKM15yLmPj

    avoidthehack, to iOS

    iOS 17.3 adds multiple features originally planned for 17

    Adds “Stolen Device Protection” + a handful of . Update ASAP.

    Stolen Device Protection limits passcode fallback for some actions and adds security delay functions to sensitive changes, such as changing the device pin.

    https://arstechnica.com/gadgets/2024/01/ios-17-3-adds-multiple-features-originally-planned-for-ios-17/

    RichiH, to mastodon
    @RichiH@chaos.social avatar

    On a whim, I tested a hypothesis: "infosec happens on Mastodon." Consider :

    is surfacing a lot of primary and secondary technical sources. Not exclusively, but with high signal to noise.

    seems to have a huge portion of Japanese discourse (might be bad search filters) but nothing groundbreaking

    is very meta, pulling the topic into whatever context the author cares about, with no primary and few secondary sources

    The bubble really did migrate here. Nice.

    blueghost, to infosec
    @blueghost@mastodon.online avatar

    LibreOffice supports digital signatures via GnuPG for OpenDocument Format (ODF) files.

    Digital Signature: https://en.wikipedia.org/wiki/Digital_signature
    GnuPG: https://mastodon.online/@blueghost/111974048270035570
    ODF: https://mastodon.online/@blueghost/111936020896554127

    Select: File > Digital Signatures > Digital Signatures > Sign Document > Select Certificate > Sign > Enter Password > OK > Close

    A banner will appear stating the document is digitally signed.

    Website: https://www.libreoffice.org
    Mastodon: @libreoffice

    #LibreOffice #DigitalSignature #GnuPG #GPG #InfoSec #ODF

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • GTA5RPClips
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • provamag3
  • Leos
  • cisconetworking
  • lostlight
  • All magazines