percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
wtfismyip, to infosec
@wtfismyip@gnu.gl avatar

Interesting vulnerability in Tailscale that got fixed last week: https://tailscale.com/security-bulletins#ts-2024-005

chiefgyk3d, to infosec
@chiefgyk3d@social.chiefgyk3d.com avatar
juliewebgirl, to infosec
@juliewebgirl@mstdn.social avatar

checks calendar

Today is May 14, 2024.

Kaiser Permanente TODAY notified users of a breach

...

SIX (6) MONTHS AGO ‼️

mocking voice: "our third party vendors Google, Bing, and Twitter"
/mocking voice

Fuckers.

Family member who has account with them asking advice: "Now what?"

Me: "Nothing"

flailing Kermit arms

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
beardedtechguy, to Cybersecurity
@beardedtechguy@allthingstech.social avatar
  • This includes all Chromium based browsers.

New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation

https://thehackernews.com/2024/05/new-chrome-zero-day-vulnerability-cve.html

simplenomad, to infosec
@simplenomad@rigor-mortis.nmrc.org avatar

I recently deployed Wireguard, and have a blog post about it. It's more of a "real world" blog post than instructional, but I do enclose details about what I did and how I did it.

https://www.markloveless.net/blog/2024/5/14/installing-wireguard

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
johnleonard, to Cybersecurity
@johnleonard@mastodon.social avatar

Why cybersecurity staff burn out, and what to do about it

Based on Computing's research and interviews with two experts, we look at the causes of burnout among cybersecurity professionals and how more attention paid to this issue at board level could help shore up defences.
(Free reg)

https://www.computing.co.uk/feature/4207599/cybersecurity-staff-burn-about

chiefgyk3d, to Twitch
@chiefgyk3d@social.chiefgyk3d.com avatar

My schedule for streaming is going to be weird for the next few weeks as I am taking CISSP classes. So for the time being I will be streaming on Sundays, Mondays, and Wednesdays as I am able to for the time being.

#Twitch #Tiktok #Stream #Infosec #Gaming #Linux #GamingonLinux

mr_oova, to infosec

Question for #infosec crowd. I've always stayed away from TouchID (or similar) due to not wanting Apple (or other companies) to have access to my fingerprint. Am I wrong?

FlohEinstein, to infosec
@FlohEinstein@chaos.social avatar

Discworld fans know the irregular clock in Lord Vetinari's waiting room.
I just found out that there are building instructions out there how to build such a clock yourself - the source code is here https://github.com/akafugu/vetinari_clock

But it made me think: why don't we have a kernel patch that does this? Anyway I'm now reading up on the /dev/rtc class, NTP and PTP, wondering what would be funnier to do.

#infosec #linux #Discworld #projectidea

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
Nonya_Bidniss, to infosec
@Nonya_Bidniss@mas.to avatar

Any folks recommend the best contractor hiring in vicinity of Ft. Eisenhower? (Ft. Gordon). A friend is looking for an established contractor with good benefits hiring people at GS-13 equivalent level to staff CYBERCOM, TRADOC or other major commands.

chiefgyk3d, to infosec
@chiefgyk3d@social.chiefgyk3d.com avatar

Live now on Twitch with I got a surprise in the mail | Fallout 4 | Cybersecurity and Gaming on Linux. Join in: https://twitch.tv/chiefgyk3d

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
TehPenguin, to random
@TehPenguin@hachyderm.io avatar

I've been helping to investigate a few LLVM and Rust bugs recently, and I keep running into pet peeves with how these bugs are reported, so I'm going to put together some

I don't want to discourage anyone from filing a bug, please do! But... be aware with how you represent the issue that you're seeing.

I also know that there are folks on here who are vastly more knowledgeable than I am, so feel free to suggest corrections, perhaps by filing some sort of report...

TehPenguin,
@TehPenguin@hachyderm.io avatar

If you're going to claim something is a security issue, please explain what the attacker has gained by exploiting the bug. That is, what they can now do they couldn't before.

If you can't explain what the attacker has gained, then that's not a security bug, that's just sparkling MS07-052 (https://web.archive.org/web/20100930203109/http://blogs.msdn.com/b/oldnewthing/archive/2007/08/07/4268706.aspx#4282521)

#RulesForBugFiling #RustLang #Rust #cpp #infosec

osma, to infosec
@osma@mas.to avatar

Just as we got a conviction in the #Vastaamo case, now #Helsinki primary education IT has been breached and 120k students', parents' and teachers' info has been stolen.

Details are sparse, but parts of what has been revealed sound like a #Office365 #breach to me. Not confirmed though.

"Possibly the largest data breach affecting [Finland's] municipal sector"

#infosec

https://yle.fi/a/74-20088448

mysk, to privacy
@mysk@mastodon.social avatar

iOS 17.5 fixes the marketplace URI bug that we showed it could result in tracking users across websites:

CVE-2024-27852

https://support.apple.com/en-us/HT214101

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
pootriarch, to infosec
@pootriarch@eldritch.cafe avatar

i have been reworking some security bits and a friend got swept up in my sand traps. he's on iOS, isn't a techie, doesn't think he's using a VPN or using special security/privacy settings — but his traffic is coming from CDN addresses (akamai, cloudflare). something's going on that i didn't know about. can anyone point me to learning links?
#infosec

percepticon, to Cybersecurity
@percepticon@ioc.exchange avatar
neurovagrant, to Cybersecurity
@neurovagrant@masto.deoan.org avatar

Whole lot of IDN Homoglyph Attack registrations via GoDaddy and hosted on Amazon the past few days. Examples from yesterday and today:

xn--fcbook-pta36b[.]com (fácębook[.]com)

xn--xnt-rmal15isb[.]com (xƭínïtƴ[.]com)

xn--xnt-vmag15isb[.]com (xƭînïtƴ[.]com)

xn--goole-b3b[.]com (gooǵle[.]com)

#cybersecurity #infosec #threatintel

nixCraft, to debian
@nixCraft@mastodon.social avatar

DNSCrypt-proxy is an open-source and free software designed to encrypt DNS traffic, thus protecting it from eavesdropping and manipulation. Let us see how to install DNSCrypt-proxy on a 11/12 with Adblocker or Malware blocker https://www.cyberciti.biz/faq/installing-dnscrypt-proxy-on-debian-linux/

johnleonard, to infosec
@johnleonard@mastodon.social avatar

MoD hack: IT contractor concealed major hack for months

SSCL was reportedly awarded a contract worth over £500,000 in April, despite the breach occurring weeks earlier

https://www.computing.co.uk/news/4207119/mod-hack-contractor-concealed-major-hack-months

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • magazineikmin
  • Youngstown
  • osvaldo12
  • khanakhh
  • slotface
  • tacticalgear
  • InstantRegret
  • ngwrru68w68
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • everett
  • rosin
  • provamag3
  • Durango
  • GTA5RPClips
  • ethstaker
  • modclub
  • mdbf
  • cisconetworking
  • anitta
  • Leos
  • cubers
  • normalnudes
  • tester
  • megavids
  • lostlight
  • All magazines