mysk, to privacy
@mysk@mastodon.social avatar

iOS 17.5 fixes the marketplace URI bug that we showed it could result in tracking users across websites:

CVE-2024-27852

#privacy #iOS #Apple #DMA #EU #infosecurity #InfoSec

https://support.apple.com/en-us/HT214101

redhotcyber, to IT Italian
@redhotcyber@mastodon.bida.im avatar
redhotcyber, to IT Italian
@redhotcyber@mastodon.bida.im avatar
redhotcyber, to Symfony Italian
@redhotcyber@mastodon.bida.im avatar

Adobe Magneto: una pericolosa minaccia RCE per i siti di e-commerce

Gli specialisti di Sicurezza Informatica hanno avvertito che gli stanno già sfruttando una nuova in (CVE-2024-20720) e l'utilizzatore per implementare una persistente sui siti di e-commerce.

https://www.redhotcyber.com/post/adobe-magneto-una-pericolosa-rce-minaccia-i-siti-di-e-commerce/

jwf, to opensource
@jwf@floss.social avatar
YourAnonRiots, to random Japanese
@YourAnonRiots@mstdn.social avatar

Tools of the Trade: Anti- scanning, WAFs, and sandboxing alone aren't sufficient for protecting against malicious uploads.

https://thehackernews.com/2024/03/demystifying-common-cybersecurity-myth.html

9to5linux, to hacking
@9to5linux@floss.social avatar

Kali Linux 2024.1 Ethical Distro Is Now Available for Download with Kernel 6.6 LTS and New Look https://9to5linux.com/kali-linux-2024-1-penetration-testing-distro-is-here-with-linux-6-6-lts-new-look

alex_02, to OSINT
@alex_02@infosec.town avatar

Oh, isn't this lovely. So apparently these goons:

  • Mike Lindell (My Pillow Guy)

  • Jack Posobiec (White supremacist that believes in conspiracies such as the white genocide conspiracy)

  • Jim Jordan (One of the main players to planning Jan 6th)

  • Matt Gaetz (A pedophile and operated a sex ring, but never was charged (fuck you justice department))

  • Steve Bannon (The fraudster that scammed trump supporters for a fake company to build Trump's wall)

-Vivek Ramaswamy (New face, but is young and likable. Dropped out of presidential nominee bid, but probably got a promise of a cushy job position in Trump's administration, from looks of things)

  • JD Vance (Didn't originally like Trump, but changed his opinion in 2018 and started spewing out many points from The Heritage, The Family Leader, etc)

  • Tommy Tuberville (One of the senators that helped to overturn the presidential election in 2020 and closely allied with Trump)

  • Kristi Noem (Governor of South Dakota, that is a terrible governor and well... I don't want to go into too much right now)

All seem to possibly be conspiring to overthrow the government. Articles are here:

Other potential people here: www.digital.cpac.org/speakers-dc2024

And a video: crooksandliars.com/cltv/2024/02/quelle-surprise-jack-posobiec-big-fan

This is all going off of this screenshot, which is a direct threat and should be taken seriously. I quickly put together this and uploaded what I could grab.

Uploaded to Mega: mega.nz/file/ioQGmRBD#FmcuZjDqCpVhvaFMclGsBgyHjPu8czZTokSz3S4H3fo

Please for FFS. Take this seriously.

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

Ever wondered why cyber attacks seem unstoppable? It's the identity blind spots! Check out how Silverfort's platform fills this crucial gap, ensuring rapid detection and containment of compromised accounts.

https://thehackernews.com/2024/02/why-are-compromised-identities.html

happygeek, to random

New by me at Forbes: Come April, using Gmail will become safer as new mass email rules start to bite.

https://www.forbes.com/sites/daveywinder/2024/02/11/google-warns-of-mass-gmail-message-blocks-new-email-security-rules/

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

Navigating the complexities of cyber threats requires more than just out-of-the-box settings. Learn how intent-based configurations can lead to more resilient cybersecurity frameworks.⤵️

https://hubs.la/Q02j-6y50

#Configuration #Infosecurity #Cybersecurity

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

Enterprise seamlessly integrates with IBM i without the need for extensive code changes.

Ron Adams details the simple setup process using PASE and how it maximizes efficiency and security:⤵️

https://hubs.la/Q02hYX7g0

btanderson, to infosec

In every instance that I’ve discovered shadow IT in an environment, I’ve eventually found someone in IT who knew about it and/or implicitly/explicitly enabled it. I hate to think it, and I understand there are always reasons but…

The call is coming from inside the house.

That means Shadow IT isn’t really in the shadows, and the solution has to start inside IT itself.



YourAnonRiots, to azure Japanese
@YourAnonRiots@mstdn.social avatar

🛡️ Researchers uncover details of 3 vulnerabilities in #Azure HDInsight's Apache Hadoop, Kafka, and Spark services that could have allowed attackers root access and system disruption.

https://thehackernews.com/2024/02/high-severity-flaws-found-in-azure.html

#cybersecurity #infosecurity #cloudsecurity

YourAnonRiots, to windows Japanese
@YourAnonRiots@mstdn.social avatar

The Windows Security Account Manager (SAM) is an essential yet often overlooked component of Windows security.

Dilki Rathnayake breaks down its role and importance for every Windows user:⤵️

https://hubs.la/Q02gTT0H0

PogoWasRight, to Cybersecurity

Hooray for NYS AG Letitia James. She has sued Citibank for poor security and failure to comply with when consumers report or .

Snippets from the press release:

"The OAG found that Citi’s systems do not respond effectively to red flags, such as scammers who are using unrecognized devices, are accessing accounts from new locations, or are changing banking passwords or usernames. Additionally, Citi systems do not flag and stop efforts to transfer funds from multiple accounts into a single account and then send tens of thousands of dollars out the door in minutes. Citi also does not automatically initiate investigations or report fraudulent activity to police or law enforcement authorities when consumers first report it to Citi."

"Under EFTA, banks such as Citi are required to reimburse their customers for money in their accounts that is lost or stolen through unauthorized electronic payments. However, Citi illegally exploited a narrow exception in these laws to deny consumer claims for reimbursement, resulting in millions of dollars in losses for New York consumers. Through this lawsuit, Attorney General James is seeking to stop Citi’s deceptive practices and to collect restitution for victims who were denied reimbursement in the last six years, penalties, and disgorgement. "

Press release: https://ag.ny.gov/press-release/2024/attorney-general-james-sues-citibank-failing-protect-and-reimburse-victims

Direct link to complaint: https://ag.ny.gov/sites/default/files/2024-01/citi-complaint.pdf

realn2s, (edited ) to Cybersecurity

Dear crowd,

I would like to hear if you know the conference format.

Please for reach

Edit: Thank you all for boosting and answering.
I would love to make the Open Space format better known in the cybersecurity context. I think it is a valuable addition to existing formats such as traditional conferences or

If you would like to learn more about Open Space see my follow up posts

If you participated in Open Space events (in any domain) please share your experience.

9to5linux, to debian
@9to5linux@floss.social avatar
PogoWasRight, to ukteachers

Because these posts scroll away, I have posted something on DataBreaches.net about the discrepancies between what Raptor Technologies has told school districts and WIRED and what we know about the incident -- and what we don't know yet:

https://www.databreaches.net/raptor-technologies-unsecured-blob-exposure-was-worse-than-they-acknowledged-heres-what-we-know-and-dont-know-so-far/

Someone might want to ask the U.S. Education Department and the to look into this incident.

@brett @allan @douglevin @michaelfklein @funnymonkey

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

🚨 Ransomware roars back! 55.5% surge in victims in 2023, but isn't the only king anymore.

Meet 3AM, Rhysida, and Akira - rising stars you need to know.

Report: https://thehackernews.com/2024/01/3-ransomware-group-newcomers-to-watch.html

9to5linux, to security
@9to5linux@floss.social avatar

XOrg Server and Xwayland Patched Against Multiple Vulnerabilities, Update Your Systems Now https://9to5linux.com/xorg-server-and-xwayland-patched-against-multiple-security-vulnerabilities

9to5linux, to linux
@9to5linux@floss.social avatar
9to5linux, to debian
@9to5linux@floss.social avatar

Bookworm and Bullseye Users Receive Important Kernel Updates to Patch Up to 20 Vulnerabilities https://9to5linux.com/debian-bookworm-and-bullseye-users-receive-important-linux-security-updates

9to5linux, to linux
@9to5linux@floss.social avatar

IPFire Hardened Firewall Distro Kicks Off 2024 with New Update That Blocks Email Spammers by Default on New Installations https://9to5linux.com/ipfire-linux-firewall-distro-kicks-off-2024-by-blocking-email-spammers-by-default

redhotcyber, to IT Italian
@redhotcyber@mastodon.bida.im avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • rosin
  • ngwrru68w68
  • Durango
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • thenastyranch
  • Youngstown
  • khanakhh
  • slotface
  • everett
  • vwfavf
  • kavyap
  • provamag3
  • osvaldo12
  • GTA5RPClips
  • ethstaker
  • tacticalgear
  • InstantRegret
  • cisconetworking
  • cubers
  • tester
  • anitta
  • modclub
  • Leos
  • normalnudes
  • JUstTest
  • All magazines