gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

$10 million reward offer for apprehension of unmasked LockBit ransomware leader.

Read more in my article on the Exponential-e blog: https://www.exponential-e.com/blog/10-million-reward-offer-for-apprehension-of-unmasked-lockbit-ransomware-leader

Mensh123, to Minecraft
@Mensh123@cyberplace.social avatar

Low severity [ incident] A mod called "Windows Borderless" on was taken down yesterday. It contained wich stole credentials from Chrome and Chromium-Based browsers. Only Windows users were affected. The mod was not found in any modpacks and was not uploaded to other platforms. A detection tool can be found in the official blog post. According to @modrinth, ~372 IPs downloaded the mod.
https://blog.modrinth.com/p/windows-borderless-malware-disclosure

parigotmanchot, to wordpress French
@parigotmanchot@mastodon.social avatar

: WPCode keeps reappearing as a malware after deleting | WordPress.org - Options à insérer dans le fichier wp-config (racine d'une installation de WordPress) pour empêcher la modification des fichiers via l'éditeur interne et désactiver l'ajout d'extensions.

Contexte : un hackeur a réussit à faire en sorte que l'extension WP Code s'installe automatiquement même si on efface ladite extens… : https://wordpress.org/support/topic/wpcode-keeps-reappearing-as-a-malware-after-deleting/#post-17115537

jsrailton, (edited ) to infosec
@jsrailton@mastodon.social avatar

Big #VPN companies are churning out bullshit "security advice" on an industrial scale.

It's a marketing funnel that targets those seeking help.

And then misinforms them.

I wish it stopped there

The nonsense makes its way to victims of spyware, where misinformation can have life, death and liberty impacting consequences.

#infosec #cybersecurity #malware #IT #pegasus #predator #spyware #malware

mima, to security

Permission-based systems are bad. See #XUL getting replaced by #WebExtensions for example. It didn't stop #malware from getting into the #browser or the extension store. On the contrary, the malware problem only got worse after the complete replacement of XUL extensions, which is often disparaged as "insecure" because it allowed users to pretty much change how their browser fundamentally works.

Who knew that distrusting your users and not giving them control leads to more malicious software and user #security being broken more often. ​:seija_coffee:​

RE: https://mamot.fr/users/gnomelibre/statuses/112371181710549606

jsrailton, (edited ) to hacking
@jsrailton@mastodon.social avatar

BREAKING: #Israeli private investigator arrested for cyberespionage on behalf of American PR firm.

Caught by UK under #RedNotice from 🇺🇸US while boarding a flight.

BIG TWIST in a wild case that began w/our @citizenlab investigation into indian hack-for-hire group #belltrox

Sound familiar?

Because Amit Forlit is the second PI from #Israel arrested in similar way for this case.

First = convicted.

https://www.reuters.com/world/israeli-private-eye-arrested-uk-over-alleged-hacking-us-pr-firm-2024-05-02/

#hacking #cybersecurity #infosec #malware #espionage #intelligence

jsrailton, (edited )
@jsrailton@mastodon.social avatar

There's a disgraceful ecosystem of public relations & lobbying firms using hackers for hire.

Sometimes they are used to silence critics & advocacy groups.

Like US nonprofits doing climate advocacy.

Our investigation into a group we christened #DarkBasin uncovered a sprawling #India-based hack-for-hire operation.

They enabled US corporations to outsource lawbreaking.

https://citizenlab.ca/2020/06/dark-basin-uncovering-a-massive-hack-for-hire-operation/
#infosec #cybersecurity #malware #hacking #climatechange #climatecrisis #exxon #phishing

jsrailton, (edited )
@jsrailton@mastodon.social avatar

I'd bet my bottom dollar that this "unnamed...PR and lobbying firm" knows exactly who they are...

...and are no doubt experiencing an afternoon of the purest panic.

Using the offshore hack-for-hire ecosystem has been largely consequence-free for the middlemen & the ultimate beneficiaries of stolen information.

The tide may be turning & this latest arrest suggests that more consequences may be inbound.

#hacking #infosec #spyware #malware #cybersecurity #phishing #India

SomeGadgetGuy, to tech
@SomeGadgetGuy@techhub.social avatar

Premiering now! Had a great conversation with Shannon Morse about my issues reviewing some mini PCs that came pre-loaded with malware. https://www.youtube.com/watch?v=oH2R3o-EbTA
She offers some GREAT tips and tricks for folks interested in keeping their home networks secure and their data safe!

sslaia,

@SomeGadgetGuy Sometimes I wonder whether there are companies who pre-loaded their hardware with switches or similar solution instead of software/malware. I guess, in the future the trust in OEM, supply chain and retailer will play important role.

techhelpkb, to random
@techhelpkb@mastodon.social avatar

A new malware named 'Cuttlefish' has been spotted infecting enterprise-grade and small office/home office (SOHO) routers to monitor data that passes through them and steal authentication information.

#cuttlefish #malware #enterprise #office
https://tchlp.com/3woKabl

whydoesnothingwork, to linux
@whydoesnothingwork@mastodon.social avatar
br00t4c, to chrome
@br00t4c@mastodon.social avatar

Clicking This Fake Chrome Update Could Drain Your Bank Account and Leak Your Location

#chrome #malware

https://lifehacker.com/tech/android-malware-poses-as-chrome-update-steals-bank-info-location-call-history

estherschindler, to random
@estherschindler@hachyderm.io avatar

#Malware attacks against millions of #DockerHub repositories have been discovered. Assume all the content you host on a publicly accessible repository might be compromised.
https://cloudnativenow.com/topics/cloudnativedevelopment/docker/jfrog-reveals-docker-hub-compromise-spanning-millions-of-repositories/

kagan, to security
@kagan@wandering.shop avatar

Oh, great. Computer security researchers have developed a proof-of-concept for a type of ransomware that would act when you try to upload a file. It would be able to encrypt any files in the folder you uploaded from, and any subfolders of it.

This is a proof-of-concept; the researchers have not seen any such attacks in the wild. But stay careful out there, okay?

Affects Chrome and Edge, but not Firefox or Safari!

https://theconversation.com/cybersecurity-researchers-spotlight-a-new-ransomware-threat-be-careful-where-you-upload-files-219560

#security #cybersecurity #malware #ransomware

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

"Junk gun" ransomware: the cheap new threat to small businesses.

Read more in my article on the Tripwire blog: https://www.tripwire.com/state-of-security/junk-gun-ransomware-cheap-new-threat-small-businesses

br00t4c, to random
@br00t4c@mastodon.social avatar

Governments issue alerts after 'sophisticated' state-backed actor found exploiting flaws in Cisco security boxes

https://go.theregister.com/feed/www.theregister.com/2024/04/24/spies_cisco_firewall/

deflockcom, to ads
@deflockcom@mastodon.social avatar
jsrailton, to poland
@jsrailton@mastodon.social avatar

NEW: "shocking and depressing"

"...even in this room I am speaking to people who were victims of this system"

's prosecutor general testifies to 🇵🇱 parliament about hacking of 100s with spyware.

Story: https://apnews.com/article/poland-spyware-pegasus-nso-group-israel-413bb3cb27daac011d52b524c6d16160

image/png

toxi, to github
@toxi@mastodon.thi.ng avatar

"Instead of generating the URL after a comment is posted, GitHub automatically generates the download link after you add the file to an unsaved comment, [...]. This allows threat actors to attach their malware to any repository without them knowing."

I always wondered if these attachments would stay around and if so for how long. Seems to be permanent, though (at least until this is going to be fixed)...

https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/

aral, (edited ) to random
@aral@mastodon.ar.al avatar

I remember folks in the web community shunning me when I first started speaking out against Big Tech – because I was criticising their friends who worked at Google, Facebook, etc. – saying I was exaggerating things.

I wonder what the same folks think now given what we know about these very same corporations; given a number of them are actively enabling a genocide.

Am I still an alarmist?

(I understand if some of you are too busy working at one or debating the minutiae of CSS syntax to reply.)

oldguycrusty,
@oldguycrusty@mastodon.world avatar

@aral

You are not wrong. You may be an alarmist, but that may be a good thing in this case.

is

and are that use business models to extract your and then resell it to other parasites in an ever expanding of cloaked in the of .

TalosSecurity, to random
@TalosSecurity@mstdn.social avatar

We have new research on the #CoralRaider APT out this morning. They've added three new information-stealing #Malware families to their arsenal, allowing them to expand the geographies they target https://blog.talosintelligence.com/suspected-coralraider-continues-to-expand-victimology-using-three-information-stealers/

br00t4c, to Russia
@br00t4c@mastodon.social avatar

Old Windows print spooler bug is latest target of Russia's Fancy Bear gang

#malware #russia

https://go.theregister.com/feed/www.theregister.com/2024/04/23/russia_fancy_bear_goose_egg/

jsrailton, to infosec
@jsrailton@mastodon.social avatar

BREAKING: US imposes visa restrictions on 13 mercenary spyware proliferators / immediate family.

First known application of policy rolled out in Feb.

A lot of shady players are surely having a little panic.

...wondering if their name is or will be on a list.

#spyware #pegasus #malware #mercenary #infosec #cybersecurity #hacking

br00t4c, to random
@br00t4c@mastodon.social avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • Leos
  • Durango
  • ngwrru68w68
  • thenastyranch
  • magazineikmin
  • hgfsjryuu7
  • DreamBathrooms
  • Youngstown
  • slotface
  • vwfavf
  • PowerRangers
  • everett
  • kavyap
  • rosin
  • anitta
  • khanakhh
  • tacticalgear
  • InstantRegret
  • cubers
  • mdbf
  • ethstaker
  • osvaldo12
  • GTA5RPClips
  • cisconetworking
  • tester
  • normalnudes
  • modclub
  • provamag3
  • All magazines