kuketzblog, to microsoft German
@kuketzblog@social.tchncs.de avatar

Nach meiner Einschätzung sind nicht nur große Teile der Microsoft-O365-Service kompromittiert, sondern auch alle Windows-Rechner, die damit verbunden waren. Ein Super-Gau epischen Ausmaßes - scheint vielen aktuell nicht klar zu sein. 🤷‍♂️ 👇

https://www.heise.de/news/Neue-Erkenntnisse-Microsofts-Cloud-Luecken-viel-groesser-als-angenommen-9224640.html

eugenialoli, to GNOME
@eugenialoli@mastodon.social avatar

WTF? Is on the store ? Apparently it was running in the bg AS IF it was an invincible extension so SystemMonitor/htop would NOT see it as a process. But (also from flatpak store) saw it as it is: an app running on startup! Killing it killed Gnome session! It was also spiking wifi, and was leaking the Gnome gjs service from 4MB RAM to 120MB. Uninstalling fixed the prob

Third party flatpak/snaps should be vetted.

avoidthehack, to infosec

More malicious extensions in #Chrome Web Store

At least 18 different malicious extensions (as of 30 MAY and this post) identified by @WPalant

Remember extensions have privileged access to the browser (and data in the browser). Choose your extensions wisely... they could be #spyware or #malware in disguise.

#cybersecurity #infosec #security #opsec #privacy

https://palant.info/2023/05/31/more-malicious-extensions-in-chrome-web-store/

bsi, to random German
@bsi@social.bund.de avatar
davemark, to security
@davemark@mastodon.social avatar

😮

Incredible new malware trick, worth being aware of.

In a nutshell, the character "ķ" (note the little tail under the k) is substituted for the letter "k".

The link looks legit, because who would think to look for that little tail?

Read more here...

https://arstechnica.com/security/2023/10/google-hosted-malvertising-leads-to-fake-keepass-site-that-looks-genuine/
#Security #Malware #Google

Toxic_Flange, to infosec

So I’m testing my assumptions, but does anyone pirate games or software in general anymore? I mean I know they are out there the fitgirl repacks etc etc , but do people still trust the pirates stuff to not come with new and novel malware?

#Malware #infosec

MisuseCase, to microsoft
@MisuseCase@twit.social avatar

Predictably, started injecting ads into powered conversations…and just as predictably, there is now a huge problem in Bing Chat.

It’s actually worse than poisoned advertisements showing up in search engine results for a couple of reasons.

https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot

/1

SophosXOps, to random

Sophos X-Ops is raising the alarm to the industry, warning that threat actors appear to be using requests or complaints as a lure to convince front-desk workers to infect their own computers with password stealing . 1/

https://news.sophos.com/en-us/2023/12/19/inhospitality-malspam-campaign-targets-hotel-industry/

tweedge, to random
@tweedge@cybersecurity.theater avatar

Alright. Fuckit. What's the real benefit of serving samples in an encrypted zip with a password of "infected" ?

Protecting morons from themselves: they'd unzip and run, and disable AV/un-quarantine files/etc. if blocked anyway

Protecting against misclicks: people are going to unzip/unpack, then same issue

Malware downloads a second stage from a sample website: decrypts it seamlessly

Evading firewalls/etc: people will have to disable their protections anyway ...

What am I missing?

SophosXOps, to Citrix

Sophos X-Ops is currently tracking a campaign by threat actors targeting unpatched systems exposed to the internet. Our data indicates strong similarity between using CVE-2023-3519 delivering and and previous attacks using a number of the same .

kuketzblog, to android German
@kuketzblog@social.tchncs.de avatar

Bezüglich des Artikels zu Antiviren-Apps unter Android hat mich die Stiftung Warentest kontaktiert: "[...]
vielen Dank für Ihre Mail und Ihre Auseinandersetzung mit unserem Test. Wir nehmen Ihre Hinweise ernst und werden uns mit dem von uns beauftragten Prüfinstitut in Verbindung setzen und die von Ihnen erwähnten Punkte besprechen. Anschließend werden wir uns zeitnah bei Ihnen melden." 👇

https://www.kuketz-blog.de/stiftung-warentest-07-2023-test-von-antiviren-apps-mit-fragwuerdigen-ergebnissen/

epixoip, to random

Happy !

I've cracked billions of from tens of thousands of in the past 12+ years, and because of this, I likely know at least one for 90% of people on the Internet. And I'm not alone! While I primarily crack breached passwords for research purposes and the thrill of the sport, others are selling your breached passwords to criminals who leverage them in and attacks.

How can you keep your accounts safe?

  • Use a ! I recommend @bitwarden and @1password

  • Use a style - four or more words selected at random - for passwords you have to commit to memory, like your master password!

  • Enable MFA for important online accounts, including cloud-based password managers!

  • Harden your master password by tweaking your password manager's KDF settings! For , use Argon2id with 64MB memory, 3 iterations, 4 parallelism. For and other PBKDF2 based password managers, set the iteration count to at least 600,000.

  • Use unique, randomly generated passwords for all your accounts! Use your password manager to generate random 14-16 character passwords for everything. Modern password cracking is heavily optimized for human-generated passwords, because humans are highly predictable. Randomness defeats this and forces attackers to resort to incremental brute force! There's no trick you can do to make a secure, uncrackable password on your own - your meat glob will only betray you.

  • Use an ad blocker like Origin to keep you safe from password-stealing and other browser based threats!

  • Don't fall for attacks and other social engineering attacks! Browser-based password managers help defend against phishing attacks because they'll never autofill your passwords on fake login pages. Think before you click, and never give your passwords to anyone, not even if they offer you chocolate or weed.

  • : require ad blockers, invest in an enterprise password management solution, audit password manager logs to ensure employes aren't sharing passwords outside the org, implement a Fine Grained Password Policy that requires a minimum of 20 characters to encourage the use of long passphrases, implement a password filter to block commonly used password patterns and compromised passwords, disable authentication and disable RC4 for , disable legacy broadcast protocols like LLMNR and NBT-NS, require mandatory signing, use Group Managed Service Accounts instead of shared passwords, monitor public data breaches for employee credentials, and crack your own passwords to audit the effectiveness of your password policy and user training!

Pwnallthethings, to random
@Pwnallthethings@mastodon.social avatar

Justice Department Announces Court-Authorized Disruption of the Snake #Malware Network Controlled by #Russia's Federal Security Service

https://www.justice.gov/usao-edny/pr/justice-department-announces-court-authorized-disruption-snake-malware-network

kuketzblog, to security German
@kuketzblog@social.tchncs.de avatar

Tipp Nr.22: Virenschutzprogramme. Hier scheiden sich die Geister. Wer Windows nutzt, kann den »Microsoft Defender« verwenden. Unter Linux, macOS und auch auf den mobilen Systemen Android und iOS ist ein Virenschutz nicht notwendig. Vorausgesetzt, das System/die Anwendungen sind aktuell, ist die Awareness wichtiger. Antivirenprogramme vermitteln ein trügerisches Gefühl von Sicherheit und verleiten Anwender zu unüberlegten Handlungen.

krelnik, to Software

Just downloading some updates and checking hashes, like you do. Insofar as people actually bother, I wonder how many people just look at the first few digits and the last few digits and call it a day. Which raises a question: has anyone ever explored the idea of hash "partial" collisions in a crypto context? I.e. if the first and last 8 hex digits are the same, but the middle could differ. Might be a useful thing for some attackers trying to deposit nasty things in public repositories.

publicvoit, to android German
@publicvoit@graz.social avatar

-: Falsche Dateimanager mit über 1,5 Millionen Installationen
https://www.heise.de/news/Android-Malware-Falsche-Dateimanager-mit-ueber-1-5-Millionen-Installationen-9211287.html?wt_mc=rss.red.ho.ho.atom.beitrag.beitrag

Warum sehen sich die Menschen nach wie vor kaum an, welche Berechtigungen eine verlangt?

Ein Dateimanager braucht kein Netzwerk, ganz einfach. 🤷

kuketzblog, to random German
@kuketzblog@social.tchncs.de avatar

Tipp Nr.8: Sei vorsichtig beim Öffnen von E-Mail-Anhängen oder dem Klicken auf Links, insbesondere von unbekannten Absendern. Diese können Phishing-Versuche oder schädliche Dateien enthalten. Phishing lässt sich bspw. über Rechtschreibfehler und/oder Prüfung der finalen URLs (Mouse-over-Effekt) erkennen. Wissenswert: Eure Bank wird euch nicht per E-Mail oder SMS zur Aktualisierung eurer Daten/Passwörtern/Installation von Apps auffordern.

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

Google blocks staff's internet access to reduce attacks - but will it work?

Read more in my article on the Bitdefender blog: https://www.bitdefender.com/blog/hotforsecurity/google-blocks-staffs-internet-access-to-reduce-attacks-but-will-it-work/

#cybersecurity #malware #hacking #google

publicvoit, (edited ) to firefox
@publicvoit@graz.social avatar

On my desktop #Firefox, 99% of those malicious requests are blocked. On my mobile Firefox 97%.

Does your browser protect you and your data? Test yourself:
https://d3ward.github.io/toolz/adblock.html

#privacy #security #adblocker #malware

linuxmagazine, (edited ) to linux
@linuxmagazine@fosstodon.org avatar

Issue is available now! This month we take a look at the Plasma 6 release. On the DVD: @linuxmint 21.3 MATE and 17 Core. See what else we're talking about this month https://mailchi.mp/linux-magazine.com/linux-magazine-preview-issue-280-march-2024

jsrailton, (edited ) to poland
@jsrailton@mastodon.social avatar

BREAKING: spyware abused in 🇵🇱 under previous PiS-party government, confirms the new PM Donald Tusk

"Very, very long" victim list.

Vindication.

When we @citizenlab first confirmed the hacking in 2021 both we & victims were targeted w/extensive harassment & disinformation.

REPORT: https://apnews.com/article/poland-government-pegasus-spyware-tusk-duda-78420fc7099401926d28b5be98669192

chikorita157, to infosec
@chikorita157@sakurajima.moe avatar

Not so sure if I can trust those Mini PCs from Chinese manufacturers because of this. There is instances of preinstalled malware that steals passwords, credit card information, and more :bunhdthink:

Sure, the manufacturer eventually admits it, but their reputation is already ruined.

Granted, if you do a clean install of Windows or install Linux, it will be okay, but most users will use it as is.

https://www.youtube.com/watch?v=Pi0_wzdz7aY&t=8

avoidthehack, to infosec

RomCom #malware spread via #Google Ads for ChatGPT, GIMP, more

Threat actors abusing the "sponsored results" features to push their phishing/malware sites on unsuspecting users.

Best/easiest advice here is to use an adblocker.

It also helps to use a private search alternative to Google Search, such as @StartpageSearch @Mojeek or @brave search.

#cybersecurity #infosec #privacy #privacymatters

https://www.bleepingcomputer.com/news/security/romcom-malware-spread-via-google-ads-for-chatgpt-gimp-more/

SomeGadgetGuy, to tech
@SomeGadgetGuy@techhub.social avatar

Premiering now! Had a great conversation with Shannon Morse about my issues reviewing some mini PCs that came pre-loaded with malware. https://www.youtube.com/watch?v=oH2R3o-EbTA
She offers some GREAT tips and tricks for folks interested in keeping their home networks secure and their data safe!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • khanakhh
  • mdbf
  • InstantRegret
  • Durango
  • Youngstown
  • rosin
  • slotface
  • thenastyranch
  • osvaldo12
  • ngwrru68w68
  • kavyap
  • cisconetworking
  • DreamBathrooms
  • megavids
  • magazineikmin
  • cubers
  • vwfavf
  • modclub
  • everett
  • ethstaker
  • normalnudes
  • tacticalgear
  • tester
  • provamag3
  • GTA5RPClips
  • Leos
  • JUstTest
  • All magazines