jakub, to security
@jakub@jirutka.cz avatar

I noticed that #Zed automatically downloads a NodeJS binary from nodejs.org without asking or even informing the user about it. Right after starting it and opening a file, without doing anything else. Then it installs some packages from npmjs via npm. And there’s no option to disable it.

THIS IS ABSOLUTELY UNACCEPTABLE! I can’t stress enough how bad this is from #security point of view. And not just that, consider users on metered connections

#ZedEditor #cybersec #Rust
https://github.com/zed-industries/zed/issues/12589

SceNtriC, to random Polish
@SceNtriC@101010.pl avatar

Na koncie PAP pojawiła się fałszywa depesza o powołaniu 200 tysięcy polskich żołnierzy do walk na Ukrainie. Już ją zdementowano, uspokojono, że to nieprawda i podano, że to prawdopodobnie efekt rosyjskiego cyberataku.

Cruthachail, to privacy

Liberate your digital freedom today.

Twitter.
https://nitter.net
https://fediverse.observer

YouTube.
https://tube.raccoon.quest
https://piped.video
https://joinpeertube.org

Google Map.
https://openstreetmap.org

Reddit.
https://libreddit.kavin.rocks
https://teddit.pussthecat.org
https://join-lemmy.org

TikTok.
https://tok.artemislena.eu

Google Search.
https://startpage.com

Google Translate.
https://translate.metalune.xyz

Imgur, Image storage site.
https://pixelfed.org

Wikipedia.
https://wikiless.org

Discord, Guilded, etc.
https://chat.techsaviours.org
https://xmpp.org/about
https://www.jabber.org/faq.html#jabber
https://www.mumble.info/about

Microsoft Teams, Slack, Zoom, etc.
https://jitsi.riot.im
https://opentalk.eu/en

Microsoft Word, Pages, etc.
https://www.onlyoffice.com/en/download-docs.aspx?from=default#docs-community
https://www.libreoffice.org/download/download-libreoffice

Internet Browsers.
https://floorp.app/download (Firefox-based)
https://github.com/ungoogled-software/ungoogled-chromium (Chromium-based)
https://brave.com (Chromium-based)

Emails.
https://mailfence.com/registration
https://app.tuta.com/login?noAutoLogin=true&keepSession=true

Operating Systems.
https://www.opensuse.org
https://linuxmint.com/about.php
https://grapheneos.org
https://calyxos.org
https://lineageos.org

Password Managers.
https://vault.bitwarden.com/#/register?layout=default
https://keepass.info/download.html

Privacy Guides.
https://www.privacyguides.org/en/about
https://thenewoil.org/en/about

Useful services.

https://joinmobilizon.org/en/#what-is-mobilizon
https://joinbookwyrm.com
https://cryptpad.org/about
https://microbin.eu
https://vikunja.io

, , , , , , , , , .

  • Removed because of its recent compromise in privacy.
phil, to infosec

Looking for an entry-level or job.

Just spent a week grinding through THM, got some certs out of it... are these any good? I don't know, but I have learned a bunch of interesting things.

Haven't had a job since December, and I'm nearing on 7 months here. I'll take anything that's remote.

I learn fast, I'm diligent, and I don't take shortcuts.
I grok computers good.

Anyone, anything?

(Sorry for spamming the tags, I know it's bad form.)

beardedtechguy, to Cybersecurity
  • This includes all Chromium based browsers.

New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation

https://thehackernews.com/2024/05/new-chrome-zero-day-vulnerability-cve.html

Stellar, to random
@Stellar@mk.absturztau.be avatar

i just saw a onion website selling ransomware and they were calling it RaaS and i lost it ​:hakaselaughingrev:​

shalien,
@shalien@projetretro.io avatar

@Stellar RaaS is actually a true term in :D

SceNtriC, to webdev Polish
@SceNtriC@101010.pl avatar

Po zobaczeniu cudownej bramki w meczu Wisła Puławy - drugi zespół Lecha Poznań chciałem sprawdzić coś na stronie internetowej Wisły Puławy. Niestety, nie działa, co się zdarza (a w weekend nie oczekuję, że ktoś to naprawi), ale... Jezu, nie róbcie tak. Zabezpieczajcie ekrany o błędach na serwerze produkcyjnym.

#programowanie #CyberSec #Cyberbezpieczeństwo #WebDev

karma, to random Polish
@karma@101010.pl avatar

🧵 1/6

Szybka historyjka, co działo się w ciągu ostatnich kilkunastu godzin (czy raczej kilkunastu miesięcy?) w świecie open-source.

Istnieje sobie otwartoźródłowy projekt o nazwie “xz” autorstwa Lasse Collin[1].
Od około dwóch lat jednym ze współtwórców tego projektu jest użytkownik o pseudonimie “JiaT75”[2].

karma,
@karma@101010.pl avatar
karma, to linux Polish
@karma@101010.pl avatar

Cześć! Jestem najzwyklejszym użytkownikiem Mastodona. Na wszystkich swoich komputerach używam #Linux i pluję na #Windows. Umiem trochę Javy, którą ostatnio zaniedbuję na rzecz Rusta. Gram w #Minecraft, #Fortnite i #Warframe i #Cyberpunk 2077. Nie jestem neurotypowy, więc często zachowuję się dziwnie i nie łapię sarkazmów czy przenośni. Używam głównie oprogramowania #FOSS i selfhostuję swoje usługi, bo jestem paranoikiem prywatności. Siedzę trochę w #cybersec. To chyba tyle o mnie :blobcathearthug:

#introduction #introductions #omnie #aboutme

batichi, to advice
@batichi@masto.batichi.net avatar

Hey nerds, would anyone have some time to offer about getting into the field? I've been seriously thinking about that direction but I have 0 clue how that side specifically runs.
Bonus points if your experience is from .

alex_02, to OSINT
@alex_02@infosec.town avatar

Oh, isn't this lovely. So apparently these goons:

  • Mike Lindell (My Pillow Guy)

  • Jack Posobiec (White supremacist that believes in conspiracies such as the white genocide conspiracy)

  • Jim Jordan (One of the main players to planning Jan 6th)

  • Matt Gaetz (A pedophile and operated a sex ring, but never was charged (fuck you justice department))

  • Steve Bannon (The fraudster that scammed trump supporters for a fake company to build Trump's wall)

-Vivek Ramaswamy (New face, but is young and likable. Dropped out of presidential nominee bid, but probably got a promise of a cushy job position in Trump's administration, from looks of things)

  • JD Vance (Didn't originally like Trump, but changed his opinion in 2018 and started spewing out many points from The Heritage, The Family Leader, etc)

  • Tommy Tuberville (One of the senators that helped to overturn the presidential election in 2020 and closely allied with Trump)

  • Kristi Noem (Governor of South Dakota, that is a terrible governor and well... I don't want to go into too much right now)

All seem to possibly be conspiring to overthrow the government. Articles are here:

Other potential people here: www.digital.cpac.org/speakers-dc2024

And a video: crooksandliars.com/cltv/2024/02/quelle-surprise-jack-posobiec-big-fan

This is all going off of this screenshot, which is a direct threat and should be taken seriously. I quickly put together this and uploaded what I could grab.

Uploaded to Mega: mega.nz/file/ioQGmRBD#FmcuZjDqCpVhvaFMclGsBgyHjPu8czZTokSz3S4H3fo

Please for FFS. Take this seriously.

beardedtechguy, to Cybersecurity

This is very intriguing! I could possibly be on the right track with this AT&T outage.

The FBI, Homeland Security, and CISA is helping with the investigation now?!

#ATT #ATTOutage #CyberSec #CyberSecurity

image/png

beardedtechguy, to Cybersecurity

I’m just going to throw this out there.

I have a feeling that this AT&T outage has something to Cyber Security. There’s something bigger going on.

https://www.cnn.com/2024/02/22/tech/att-cell-service-outage/index.html

#ATTOutage #CyberSecurity #CyberSec

cappy, to Cybersecurity
@cappy@fedi.fyralabs.com avatar
cappy, to Cybersecurity
@cappy@fedi.fyralabs.com avatar

anyway, an early excerpt from the expose you all should read

beardedtechguy, to Cybersecurity

Reddit selling user content to train an AI?

From: @beyondmachines1
https://infosec.exchange/@beyondmachines1/111952862733740047

cappy, to infosec
@cappy@fedi.fyralabs.com avatar

btw here's the script they use for DDoSing Misskey instances

https://github.com/EdamAme-x/misskey-nuke

cappy, to infosec
@cappy@fedi.fyralabs.com avatar

im getting really tired... -w-

summary of today:

someone on a Japanese hacker forum decided it was a good idea to spam the entire Fediverse because they wanted to cancel a minor that DDoSed a Discord bot which apparently made them lost millions (what?)

A Discord bot. I can't make this shit up man.

The real culprit seems to be someone who goes by mumei in the ctkpaarr.org forums, whose first post was literally a threat to ap12, that if they don't delete their "Kuroneko Server" Discord bot, they will spam every blog, forum and SNS and cancel him.

This shit is ridiculous.

The ap12 account from mastodon-japan was actually fake, and this dude impersonated a minor to get all of the Fediverse (us) to bully him.

The forum admins didn't even stop this. Why? lulz apparently.

cappy, to infosec
@cappy@fedi.fyralabs.com avatar
cappy, to OSINT
@cappy@fedi.fyralabs.com avatar

I'm doing some funny OSINT stuff and... I have found some funny stuff.

I looked him up on Google, Found a Discord report about him with his real email attached.

Looked up his email, and found a post on the ctkpaarr forums (the one he's advertising the discord) of him being currently flamed for this current ongoing incident.

The best part? He bought the script using a PayPal account. With his real name and identity.

He is a real skid. He just bought an off-the-shelf script and decided to piss off a lot of people, even the dude he bought it from with his antics. Bro snitched on himself and his entire community LMEOW

For the sake of my own job, my rep and legal security I'm not gonna tell where exactly I found this, but you guys can find it yourself. Figure it out.

This guy is making me dying out of laughter 💀 Our team @hq is hysterical right now at this horrible opsec.

Don't be a skid, kids.

RE: https://fedi.fyralabs.com/notes/9pr6thyvz5

cappy, to random
@cappy@fedi.fyralabs.com avatar

There's currently an incident involving some kind of Japanese skids who call themselves the "Kuroneko" organization.

They seem to be attempting to commit DDoS attacks on Misskey servers, constantly creating new accounts on compromised instances and spamming advertisements for their hacking services.

Admins who are federating with these compromised servers, while they might not get compromised themselves, may be affected by the sheer amount of traffic volume from their spam.

Admins are advised to or temporarily stop sending requests to affected servers for now, if they don't want to get secondhand DoS'd

IMO I never expected them to be Japanese out of all things, kinda funny. They also host VOICEROID and VOICEVOX TTS bots on their Discord apparently. Kinda a weird flex I guess.

But yeah, probably just a bunch of skids.

cappy,
@cappy@fedi.fyralabs.com avatar
bytephantom, to Cybersecurity
bytephantom, to Cybersecurity
wilda, to security Polish

Funkcja przypomnienia hasła jest bardzo specyficzna - z jednej strony niepozorna, z drugiej wymagająca dobrych zabezpieczeń, a więc szalenie ważna. Dlatego jest to też fragment systemu, na których uwagę zwracają audytorzy cyberbezpieczeństwa. A warto powiedzieć, że nie trzeba dużo, aby poprawnie ochronić tę część procesu - wystarczy trzymać się reguł, które wymienia choćby Niebezpiecznik.

#Cyberbezpieczeństwo #CyberSec #security

https://niebezpiecznik.pl/post/najczestsze-bledy-programistow-w-formularzu-resetu-hasla/

Norobiik, to Philippines
@Norobiik@noc.social avatar

"Deliberately grounded on a tiny reef in the #SouthChinaSea, part of an island chain claimed by the two Asian countries, the #BRPSierraMadre is now the unlikely base for a detachment of Filipino marines who stand guard over the atoll, scanning the turquoise waters for Chinese ships." #AyunginShoal #SecondThomasShoal #Philippines

Wreck, Rats and Roaches : Standoff in the #SouthChinaSea (2014 article)
https://edition.cnn.com/interactive/2014/07/world/south-china-sea-dispute/

Norobiik,
@Norobiik@noc.social avatar

Earlier, the PCG said that its X account had been “compromised.”

Posts on the PCG’s X page and its reply tabs were empty, although the “like” reactions were kept – however, most of the “likes” came from a particular account promoting cryptocurrency. #Philippines #WestPHSea #PHCoastGuard #CyberSec

PCG regains X page after hack
https://newsinfo.inquirer.net/1904814/fwd-break-pcgs-x-page-now-retrieved

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • Durango
  • ethstaker
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • Leos
  • osvaldo12
  • tacticalgear
  • cubers
  • cisconetworking
  • anitta
  • provamag3
  • modclub
  • mdbf
  • GTA5RPClips
  • tester
  • megavids
  • normalnudes
  • lostlight
  • All magazines