enno, to random German
@enno@nafo.army avatar

deleted_by_author

  • Loading...
  • kkarhan,

    @enno not that surprising given that every #SingleVendor / #SingleProvider "solution" for communications will inherently have #Govware #backdoors, otherwise they'd be illegal!

    That's why noone who takes #ITsec, #InfoSec, #OpSec & #comSec 100% seriously will use them for anything but posting public info.

    That's how the drug dealers using #EncroChat & #ANØM got caught and why noone should trust any #VPN or #Messenger!

    https://www.youtube.com/watch?v=WVDQEoe6ZWY
    https://twitter.com/thegrugq/status/1085614812581715968

    sabogato, to random
    @sabogato@sunbeam.city avatar

    deleted_by_author

  • Loading...
  • kkarhan,

    @sabogato izt's not just #OpSec, but #ITsec, #InfoSec & #ComSec.

    If I had even attempted such a fuckup, I'd be in prison!

    kkarhan, to infosec

    @kvuzet no.

    Exercise #ITsec, #InfoSec, #OpSec & #ComSec always rigorously, because #metadata will be used against you...

    AufstandLastGen, to random German

    Komm zum 💯 für Bayern Vorbereitungstreffen!

    Im August werden wir in Bayern protestieren und Widerstand gegen den tödlichen gesellschaftlichen Kurs leisten. Egal wie der Staat reagiert, auch wenn er uns einsperrt!

    Dafür suchen wir 💯 Menschen

    https://uni-passau.zoom.us/j/61193381542?pwd=dW1jdWZVdk9FeVhIS3lFTjhTUXllQT09

    kkarhan,

    @AufstandLastGen Und was dann?

    Ich bezweifle dass dabei was rauskommt aus gut ausschlachtbare Propaganda die zur eurer Kriminalisierung genutzt werden kann...

    Aber hey, überrascht micht gern positiv damit, dass ihr mal #ITsec, #InfoSec, #OpSec & #ComSec ernst nehmt und nicht euch und eure Unterstützer*innen so heftig self-d0xxed, dass es ein #WontAttend bleibt?

    PogoWasRight, to random

    Mount Desert Island Hospital notifies 24,180 patients of April network attack:

    https://www.databreaches.net/mount-desert-island-hospital-notifies-24180-patients-of-april-network-attack/

    So, they call it a "data security incident" and haven't updated their June 5 notice. Yet there's a listing on a leak site that may be populated at some point....

    @brett @amvinfe @allan

    #databreach #hack #HealthSec #ITsec #cyberattack #HIPAA #extortion #transparency #incidentresponse

    kkarhan, to languagelearning

    So that's how the cracked shit...

    Thanks @tails for the info:
    https://tails.boum.org/security/argon2id/index.en.html

    I guess a lot of people now have their weekends f**ked because they gonna need to re-encrypt shit.

    Gladly I'm not affected as I user 128-digit passwords wherever possible...
    https://github.com/kkarhan/misc-scripts/blob/260f087c8337417c69f94787358abf4faf5090f9/bash/.bash_aliases#L5

    But a lot of you folks may be!

    Please check your crypto settings NOW!

    PogoWasRight, (edited ) to Cybersecurity

    Peters Township School District in Pennsylvania just notified the Maine AG's office of a breach from 2/22 - 4/22 that affected 12,692.

    What took them so long to notify, you wonder? Well, tl;dr version is they couldn't figure out what had been accessed or acquired so, wait for it.....

    IN AN ABUNDANCE OF CAUTION... they blahblahblahblah

    @brett @douglevin @funnymonkey
    https://apps.web.maine.gov/online/aeviewer/ME/40/59627aa2-a5e8-4c73-9158-f812f89022fb.shtml

    #databreach #hack #EduSec #ITsec #IncidentResponse #cybersecurity

    SpaceGeek, to fediverse German
    @SpaceGeek@chaos.social avatar

    Hallo
    ich bin auf der Suche nach ein paar interessanten und aktiven* Blogs aus folgenden Bereichen.

    • Astronomie (eher privater Bereich)

    • Fotografie (eher privater Bereich)

    • Infosec/ITsec/Hacking (Binary Exploitation, Reverse Engineneering)

    • Linux (Linux im Alltag, Sysadmin)

    Könnt ihr den ein oder anderen Blog empfehlen?

    • Aktiv: min. 2-3 Beiträge in 3 Monaten wären nett.

    :BoostOK:

    PogoWasRight, to random

    So is this listing by AlphV aka BlackCat about Barts NHS Trust related to the U. of Manchester report the other day about 1.1 million patients, etc.?

    #databreach #extortion #NHS #healthcare #ITsec #healthsec

    @brett @GossiTheDog @amvinfe

    D64eV, to random German
    @D64eV@d-64.social avatar

    Aus Fehlern das Falsche gelernt. Der Bundestag hat auf Wunsch des BMI & Nancy Faeser das Beamtengesetz geändert, damit die neue Präsidentin des BSI, Claudia Plattner, jederzeit in den Ruhestand versetzt werden kann. Eine beunruhigende Entwicklung. Das BSI steht unter Fachaufsicht des BMI. Das ist ein Problem. Denn Sicherheitsbehörden haben oft ein Interesse daran, IT-Sicherheitslücken offenzuhalten, zum Beispiel um Staatstrojaner einzusetzen. 1/

    kkarhan,

    @D64eV Allein deshalb muss das @bsi vom @bmi entkoppelt werden denn der #Interessenskonflikt schadet der #NatSec genauso wie #ITsec, #InfoSec, #OpSec & #ComSec!

    vowe, to random German

    deleted_by_author

  • Loading...
  • kkarhan,

    @vowe #DESHALB immer alle #Metadaten u.a. [#EXIF] entfernen und idealerweise anonym via z.B. #ExifRecherche u.ä. #antifaschistisch|e Gruppen leaken lassen...

    #ITsec #InfoSec #OpSec #ComSec

    #FilmNazis

    PogoWasRight, to random

    So an investigator from #HHSOCR contacted me to ask if I still had unredacted data from a breach I reported last year and if I did, could I share it with them?

    And to my shock, they told me they still have no way for folks to upload databases. They could take fax or postal mail or an encrypted email.

    I was told last year that they were getting an upload system. Where is it?

    Luckily, what they requested wasn't too big and could be attached to an encrypted email. But if it was a database.... ?

    I really hope they get the resources they need to investigate data security breaches. They've issued a few settlements involving data security very recently and I hope that's a good sign of more to come.

    #databreach #leak #HIPAA #HHSOCR #RiskAssessment #SecurityRule #HITECH #Enforcement

    Heck, I don't even know who to tag on this one. :(

    PogoWasRight,

    @thomrstrom

    Holy heck! I just found out that yes, HHS was a victim of the MOVEit incident. They've notified Congress that more than 100,000 have been affected.

    #databreach #HHS #MOVEit #infosec #businessassociate #thirdparty #ITsec

    PogoWasRight, to infosec

    Here’s your reminder for today about the insider threat:

    Lawyer censured for using TeamViewer to snoop on former firm’s business activity:
    https://www.abajournal.com/web/article/lawyer-is-censured-for-using-teamviewer-to-snoop-on-former-firms-business-activity

    Direct link to Disciplinary Review Board's findings and recommendations in 2022: https://drblookupportal.judiciary.state.nj.us/DocumentHandler.ashx?document_id=1161175

    Do you think he got off too lightly or did censure seem right to you?

    #Infosec #InsiderThreat #Insider #ITsec #cybersecurity

    PogoWasRight, to infosec

    National Student Clearinghouse notifies schools of MOVEit breach: https://www.databreaches.net/national-student-clearinghouse-notifies-schools-of-moveit-breach/

    They still haven't answered the question as to whether they paid Clop or not.

    #DataBreach #MOVEit #infosec #ITsec #EduSec #transparency #incidentresponse

    @douglevin @brett @allan @funnymonkey @mkeierleber

    PogoWasRight, to random

    HHS Office for Civil Rights Settles HIPAA Investigation with iHealth Solutions Regarding Disclosure of Protected Health Information on an Unsecured Server for $75,000

    Interesting context to this one. Read some of the history at https://www.databreaches.net/hhs-office-for-civil-rights-settles-hipaa-investigation-with-ihealth-solutions-regarding-disclosure-of-protected-health-information-on-an-unsecured-server-for-75000/

    #HIPAA #databreach #HealthSec #SecurityRule #unsecured #ITsec

    @jgreig @zackwhittaker

    PogoWasRight, to hacking

    I can't remember offhand if we had this one already, so:

    "LUMBERTON, Texas — The Lumberton Independent School District was the victim of a cyberattack earlier this month.

    Officials at Lumberton ISD discovered a "cybersecurity incident" at the district on Tuesday, June 13, 2023 according to a statement from Mary Johnson, Director Of Communication And Community Relations for the district."

    https://www.12newsnow.com/article/news/local/lumberton-isd-hit-by-cyberattack/502-16792d36-c6f1-42c8-aefd-e995b7b97654

    #databreach #EduSec #ITsec #hacking

    @douglevin @brett @funnymonkey

    PogoWasRight, to infosec

    It looks like 1,558 employees' at Braintree Schools in Massachusetts had their PII acquired by a bad actor in May:

    https://apps.web.maine.gov/online/aeviewer/ME/40/8d5fdbcf-008d-4fb1-9e87-34c54935042e.shtml

    #databreach #infosec #ITsec #EduSec #hacking

    @douglevin @brett @funnymonkey

    nzakas, to random
    @nzakas@fosstodon.org avatar

    Repeat after me: Blocking paste on a form textbox is not a security feature.

    kkarhan,

    @ShadSterling @nzakas well, I just block all but whitelisted Cookies and JS.

    And Yes, is a problem in general...

    Needless to say users can't be made liable for shitty of the company who's website they log in.

    Point is: are the most secure option - period.

    aral, to security
    @aral@mastodon.ar.al avatar

    Wow, Bank of Ireland are completely clueless about .

    “BOI: We need to speak to you about your credit card application…

    Me: Sure…

    BOI: First, let’s verify you…full name, date of birth…

    Me: …

    BOI: Mother’s maiden name?

    Me: LjwOtrNGIgpJlJE

    BOI: So this is the problem: We need your mother’s maiden name.

    Me: I just gave it. This is a security question and I provided you with a password.

    BOI: No, that won’t work, we need her name.

    Me: Wow… OK… Please cancel my application.”

    kkarhan,

    @aral Eeyupp - I'd do the same!

    And THIS is why I neither use #OnlineBanking nor have any #CreditCard:

    Because I won't compromise my #ITsec for their shitty bs.

    Also my mother's maiden name is none of their business and that's why they legally can't ask for it in Germany!

    yuki2501, to random

    Atn admins:

    Time to start working on allow lists and authorized fetch, folks.

    We cannot stop Meta from trying to federate and control some instances. What we can do is establish new rules for federation.

    The time to block unknown instances by default has come.

    Start preparing.

    kkarhan, (edited )

    @yuki2501 I know, but I also know how the internet works and that blocking PRISM snitches like all the #GAFAM|s is more realistic than manually allow-listing.
    https://github.com/greyhat-academy/lists.d/blob/main/activitypub.domains.block.list.tsv

    #Reputation-based systems failed due to universal blockade by corporate interests - espechally the #GAFAMs...
    Otherwise #CAcert would've rightfully taken the place that #LetsEncrypt has, because #AllowListing as the norm of CAs has nothing to do with #ITsec at all...
    https://en.wikipedia.org/wiki/CAcert.org

    YourAnonRiots, to Cybersecurity Japanese

    #LockBit #ransomware has extorted $91 million from U.S. organizations, conducting hundreds of attacks since 2020. The cyber threat is evolving and disruptive, targeting critical sectors.

    Are you prepared for the next attack?

    https://thehackernews.com/2023/06/lockbit-ransomware-extorts-91-million.html

    #cybersecurity

    kkarhan,

    @YourAnonRiots OFC because I do have proper #ITsec, #OpSec, #InfoSec & #ComSec in place to enshure it doesn't happen...

    PogoWasRight, to random

    LockBit claims to have attacked Bound Brook School District in NJ but has posted no proof of claims. There is nothing on bbrook.org that indicates any attack.

    #databreach #ransomware #ITsec #EdusSec

    I don't know if this one was posted already but in case it wasn't:
    @brett @douglevin @funnymonkey

    PogoWasRight, to infosec
    PogoWasRight, to random

    Some research published in a medical journal:

    Hacking Acute Care: A Qualitative Study on the Health Care Impacts of Ransomware Attacks Against Hospitals

    My comment: This was a small-sample qualitative survey research study that generated some proactive recommendations for hospitals. If you don't have access to Annals of Emergency Medicine, there's a write-up of the research here:

    https://www.auntminnie.com/index.aspx?sec=ser&sub=def&pag=dis&ItemID=140429

    #healthcare #radiology #ransomware #incidentresponse #riskassessment #proactive #ITsec

    PogoWasRight, to infosec

    At least two states' motor vehicle agencies became victims of the MOVEit breach. Oregon says it may be 3.5 million, and no numbers yet for Louisiana.

    https://www.databreaches.net/oregon-dmv-louisiana-omv-warn-residents-of-moveit-data-breach/

    #databreach #MOVEit #hack #extortion #Clop #infosec #ITsec #cybersecurity #filetransfer

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • InstantRegret
  • mdbf
  • ngwrru68w68
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • osvaldo12
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • JUstTest
  • tacticalgear
  • ethstaker
  • provamag3
  • cisconetworking
  • tester
  • GTA5RPClips
  • cubers
  • everett
  • modclub
  • megavids
  • normalnudes
  • Leos
  • lostlight
  • All magazines