YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

🚨 Urgent: Critical Jenkins RCE #vulnerability (CVE-2024-23897) discovered.

Hackers can remotely control your CI/CD pipelines. Patch immediately to prevent malicious code in builds.

https://thehackernews.com/2024/01/critical-jenkins-vulnerability-exposes.html

#cybersecurity #informationsecurity

YourAnonRiots, to Kubernetes Japanese
@YourAnonRiots@mstdn.social avatar

Critical Misconfiguration Found in Google Engine (GKE) - Posing a threat to over 250,000 clusters. Any account could exploit it to take control of your clusters.

https://thehackernews.com/2024/01/google-kubernetes-misconfig-lets-any.html

InfoSecSherpa, to random

InfoSecSherpa's #DataPrivacy and #InformationSecurity News Roundup for Saturday, January 20, 2024 🇻🇮​

Features the Virgin Islands source article by Sian Cobb, "Virgin Islands Lottery Operations Suspended Over #DataBreach"

https://infosecsherpa.medium.com/infosecsherpas-news-roundup-for-saturday-january-20-2024-7a13cb65cbfc

InfoSecSherpa, to random

InfoSecSherpa's #DataPrivacy and #InformationSecurity News Roundup for Friday, January 19, 2024

Features the Cybernews article by Damien Black, "ELO accounting #databreach sparks tax fraud."

https://infosecsherpa.medium.com/infosecsherpas-news-roundup-for-friday-january-19-2024-a34640eb497a

InfoSecSherpa, to random

InfoSecSherpa's and News Roundup for Thursday, January 18, 2024

Features the Cybersecurity and Infrastructure Security Agency post, "CISA, FBI and EPA Release Incident Response Guide for Water and Wastewater Systems Sector."

https://infosecsherpa.medium.com/infosecsherpas-news-roundup-for-thursday-january-18-2024-c03b78bb76e1

tinker, to infosec

If your first instinct is to try and find blame when a security vulnerability is pointed out...

...you have already created an environment where everyone will hide issues from you.

You currently live in a fake reality where you think everything is fine and you have no idea the rot that is underneath you.

If you fire or punish a person every time a vulnerability is found, you will have no one left. Hell, fire yourself first to save us all the trouble.

Vulnerabilities exist. The world changes. Software changes. Attacks change. Business needs change.

Life is fucking impermanence.

So create an environment where folks come to you quickly and tell you what needs to be fixed as they find it.

How do you do that?! Reward vulnerability discovery. Reward mitigations. Reward patch management. Reward security improvement. Reward safety improvement.

#informationsecurity #infosec #operationalsecurity #opsec #ics #ot

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

🔥 Chrome Zero-Day Alert!

Update your browser NOW to patch a new critical flaw exploited by hackers. This memory leak bug lets attackers steal your secrets.

CVE-2024-0519: https://thehackernews.com/2024/01/zero-day-alert-update-chrome-now-to-fix.html

#cybersecurity #informationsecurity

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

🚨 Cisco patches a serious flaw in Unity Connection (CVE-2024-20272, CVSS 7.3).

Don't let attackers compromise your system. Check if your version is affected and update now.

https://thehackernews.com/2024/01/cisco-fixes-high-risk-vulnerability.html

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

🍏 Attention Mac users! Atomic Stealer #malware gets updated to evade detection with payload encryption, stealing your passwords and sensitive info.

https://thehackernews.com/2024/01/atomic-stealer-gets-upgrade-targeting.html

#cybersecurity #hacking #informationsecurity

LukaszOlejnik, to Cybersecurity
@LukaszOlejnik@mastodon.social avatar

"ithere is a legitimate question about whether it’s politically wise for Apple to make a big technical improvement to their AirDrop privacy, right at the moment that the lack of privacy is being viewed as an asset by authorities in China" #cybersecurity #informationsecurity #security #iphone #crypto https://blog.cryptographyengineering.com/2024/01/11/attack-of-the-week-airdrop-tracing/

InfoSec4All, to Cybersecurity

🔍 Case Study Alert! Learn from the Ohio Lottery's encounter with DragonForce hackers. Transform from digital prey to a cyber-savvy guardian! Discover key strategies to shield your online presence. Stay ahead of cyber threats with our insights. #

https://wp.me/peSvjo-fE

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

Collaboration is key in #SaaS applications! But did you know 58% of recent security incidents involve data leakage?

https://thehackernews.com/2024/01/why-public-links-expose-your-saas.html

#cybersecurity #informationsecurity

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

⚠️ Attention Kyocera & #QNAP users:

Kyocera addresses dangerous CVE-2023-50916 flaw, preventing unauthorized access. QNAP tackles CVE-2023-39296, safeguarding against crashes.

https://thehackernews.com/2024/01/alert-new-vulnerabilities-discovered-in.html

#cybersecurity #informationsecurity

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

⚠️ Warning: Turkish hackers targeting poorly secured MS #SQL servers across the U.S., European Union, and Latin America.

Brace yourself for #ransomware deployment!

https://thehackernews.com/2024/01/turkish-hackers-exploiting-poorly.html

#cybersecurity #informationsecurity

InfoSecSherpa, to random

InfoSecSherpa's #InformationSecurity and #DataPrivacy News Roundup for Tuesday, January 9, 2024

Features the Cyber Security Hub article, "A guide to anti-drone systems: Protecting against evil aerial intruders."

https://infosecsherpa.medium.com/infosecsherpas-news-roundup-for-tuesday-january-9-2024-a96e04877438

tinker, to infosec

Aw crap. I found a bunch of things last week and had the audacity to do my job and let people know about it.

And now!!!! They want me to help fix the problem!!!! Can you believe that?!?!?!

A) No one ever wants to fix the problem.

and B) I don't like fixing problems. I just wanna hack and have fun and get paid and not accomplish anything!!!!

#infosec #informationSecurity #PenetrationTestingIsJustManualSecurityQualityAssurance

InfoSecSherpa, to random

InfoSecSherpa's #InformationSecurity and #DataPrivacy News Roundup for Monday, January 8, 2024 🇨🇭​

Features the Swiss Info article, "Cyberattack exposes Swiss Air Force documents on the darknet."

https://infosecsherpa.medium.com/infosecsherpas-news-roundup-for-monday-january-8-2024-c40e52f17c61

YourAnonRiots, to security Japanese
@YourAnonRiots@mstdn.social avatar

🚨 Alert: Ivanti releases updates for a critical #security vulnerability (CVE-2023-39336 / CVSS 9.6) in Endpoint Manager, which poses a risk of remote code execution on vulnerable servers.

https://thehackernews.com/2024/01/alert-ivanti-releases-patch-for.html

#cybersecurity #informationsecurity

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

🚨 Discovered a hidden secret in your company's source code?

It's time for swift action to protect against data breaches and reputational damage.

Learn how with this latest article on effective secrets management: https://thehackernews.com/2024/01/exposed-secrets-are-everywhere-heres.html

#cybersecurity #informationsecurity

InfoSecSherpa, to random

InfoSecSherpa's and News Roundup for Friday, January 5, 2024 🖼

Features the ARTnews article by Daniel Cassady, "Hundreds of Online Museum Collections Suffer in Cyber Attack."

https://infosecsherpa.medium.com/infosecsherpas-news-roundup-for-friday-january-5-2024-939db906ef63

InfoSecSherpa, to random

InfoSecSherpa's #DataPrivacy and #InformationSecurity News Roundup for Thursday, January 4, 2024 🇬🇷​

Features the Balkan Insight article, "Greece to Establish New Authority to Counter Cyber-Attacks."

https://infosecsherpa.medium.com/infosecsherpas-news-roundup-for-thursday-january-4-2024-d1568b4af820

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

👩‍💻 80% of today's data breaches involve compromised identities, including cloud and SaaS credentials. Find out how Nudge Security can help you monitor your SaaS attack surface and protect your valuable assets.

https://thehackernews.com/2024/01/5-ways-to-reduce-saas-security-risks.html

#cybersecurity #informationsecurity

InfoSecSherpa, to infosec

InfoSecSherpa's #DataPrivacy and #InformationSecurity News Roundup for Wednesday, January 3, 2024 🚑​ #InfoSec

Features the Teiss article, "Fallon Ambulance Service reports #databreach; consumer information exposed."

https://infosecsherpa.medium.com/infosecsherpas-news-roundup-for-wednesday-january-3-2024-8e2df5b56dfa

redhotcyber, to OpenAI Italian
@redhotcyber@mastodon.bida.im avatar

Le Profezie di Sam Altman! Tra cambiamenti epocali di internet, reddito universale ed energia pulita. Facciamo il punto

Sam #Altman è il CEO di #OpenAI, la #startup che ha sviluppato #ChatGPT che conosciamo tutti. Nel novembre 2023 è stato improvvisamente licenziato dal consiglio di amministrazione e trasferito per un breve periodo a #Microsoft. È tornato dopo che tutti in OpenAI hanno minacciato di dimettersi.

#redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity

https://www.redhotcyber.com/post/le-profezie-di-sam-altman-tra-cambiamenti-epocali-di-internet-reddito-universale-ed-energia-pulita-facciamo-il-punto/

fifonetworks, to GPS

New Year’s Eve: Musings on Y2K
At 3pm PST on 31 December, 1999, I sat down at the computer in my home office in Yakima, Washington. I logged remotely into the network at HQ and started monitoring our systems. The most critical moment would come at 4pm local time. We were in Pacific Standard Time (PST), -0800 UTC. In other words, at 4pm in Yakima, it would be midnight in Greenwich, England, where the time zone aligns with Coordinated Universal Time. (Coordinated Universal Time is abbreviated as UTC, not CUT, because there are actually other languages in the world besides English, and… never mind. Look it up if that story interests you).

Anyway.

The GPS satellites run on UTC, and our entire multi-state operation depended on GPS timing. My first hint of system failure because of a Y2K bug would occur at midnight, UTC.

Beginning at 3:55pm I began testing the major system once a minute. At 4:05pm I sent out the notice to corporate management that all was well.

I tested hourly, then, but the next critical moment wasn’t until 9pm PST, which was when midnight occurred on the US East Coast. Our equipment was all in MST and PST, but some of our many telecom providers might have systems with local time coordination in some other US time zone. (They’d all be using GPS now, but – this was 1999, and US telecommunications had plenty of legacy systems with other clocking methods).

In the end, nothing failed. Our entire system worked.

This wasn’t because Y2K was overblown.

It was because we replaced our billing system, which wasn’t able to generate an invoice after the date flip.

It was because we did software updates on several proprietary systems that would have failed.

It was because we did firmware updates, too.

Equipment inventories.
Application inventories.
Operating system inventories.
Software version inventories.
Firmware version inventories.

The reason January 1, 2000 seemed like such an ordinary day is because of the MASSIVE amount of work and money spent to make it ordinary. There are unsung heroes around the world who put in the work to update or replace systems that would’ve failed otherwise.

If you’re one of those people, I would love to hear your story.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines