SomeGadgetGuy, to tech
@SomeGadgetGuy@techhub.social avatar

Sure. Google location tracking "bad" and Apple data harvesting "good", but it's pretty hack to see articles popping up about how poor Android trackers are compared to AirTags.
https://somegadgetguy.com/b/46Q

Ignoring the security nightmare AirTags were at launch, the assumed permissions Apple just takes for the Find My network, and the annoying (and scary looking) process Apple forces users through to OPT OUT of location tracking, it's shocking how well Google is doing only a couple weeks into this new finder network going live.

#tech #technology #editorial #news #technews #bbtg #privacy #security #google #apple #geek #business

publicvoit, to apple German
@publicvoit@graz.social avatar

Bei einem #heise-Artikel zu #Apple und #Security einen Kommentar schreiben, ist immer wieder eine sehr "interessante" Erfahrung.

Meistens wird man da attackiert, die unabhängigen Quellen, die man brav einbindet ignoriert oder heruntergespielt und auf persönlicher Ebene angegriffen. 🤷

#Fanboys

SomeGadgetGuy, to windows
@SomeGadgetGuy@techhub.social avatar

It just clicked in my brain. What I haven't been able to articulate about why I'm so anxious about Recall. I'm sure others have already gotten to where I am.

It's worse than "a system that tracks everything you do" and stores that info in a basic database that could be easily compromised.
It's worse than a nanny surveillance tool for companies to spy on their employees.

It's inescapable.

It doesn't matter if I make a dozen "how to disable recall" tutorials. The second YOUR data shows up on someone ELSE'S screen, it's in THEIR recall database.

It won't matter if you're a master expert specialist. You can't account for EVERY other computer you've ever interacted with. If a family member looks up an old email with your personal data in it, your data is now at risk.

If THEIR system is compromised YOUR data is at risk.

I just went from "vague feeling of unease" to "actively writing templates to canvas elected officials, regulators, and attorneys general."

SomeGadgetGuy,
@SomeGadgetGuy@techhub.social avatar

I think I have a good feeling on what the response might be here on Mastodon, but with Microsoft pledging to improve security, and making Recall opt-in, will this change your perception of Windows 11?
https://www.windowscentral.com/software-apps/windows-11/microsoft-addresses-windows-recall-backlash-promises-to-fix-security-issues-and-make-it-opt-in

lemmyreader, to linux in Flatpak Firefox (and forks) very slow to start

While toolbox and distrobox seem very similar, distrobox comes with a slight warning :

linuxiac, to security
@linuxiac@mastodon.social avatar

OpenSSH tightens security with a new feature that aims to stop attackers in their tracks with smart penalties.
https://linuxiac.com/openssh-enhances-security-with-new-feature/

#ssh #openssh #security #openbsd

br00t4c, to security
@br00t4c@mastodon.social avatar
br00t4c, to security
@br00t4c@mastodon.social avatar
campuscodi, to infosec
@campuscodi@mastodon.social avatar

David Ross, one of the early pioneers of browser security research, has passed away, his family announced on Twitter.

In 1999, together with Georgi Guninski, he authored the first paper on XSS attacks named "Script Injection".

He also worked on implementing X-Frame-Options in Internet Explorer.

https://x.com/randomdross/status/1799284146231185584

br00t4c, to security
@br00t4c@mastodon.social avatar
Nonilex, to Russia
@Nonilex@masto.ai avatar

#Russia #influence grps are fomenting fears of physical #threats at the #Paris #Olympics, promoting possible #terrorist attacks & #violence stemming from the #Israel - #Gaza conflict.

The #disinformation campaign —which also seeks to denigrate #France, President #Macron & the #IOC —blends traditional influence techniques w/ #ArtificialIntelligence, complete w/a fake #Netflix documentary featuring an #AI #TomCruise voiceover.

#Security
https://cyberscoop.com/russia-tom-cruise-ai-paris-olympics/

campuscodi, to infosec
@campuscodi@mastodon.social avatar

Last year, CrowdStrike published a report on a new crypto-mining operation that was targeting exposed Kubernetes systems with a miner for the Dero cryptocurrency token.

https://www.crowdstrike.com/blog/crowdstrike-discovers-first-ever-dero-cryptojacking-campaign-targeting-kubernetes/

This threat actor—no official name yet—is still active today, according to a new report from cloud security firm Wiz.

https://www.wiz.io/blog/dero-cryptojacking-campaign-adapts-to-evade-detection

campuscodi, to infosec
@campuscodi@mastodon.social avatar

The Cyber Partisans say they hacked the Belarusian State University.

The group claims it obtained documents and audio records from the university's internal network showing how its leadership dismissed staff and students who participated in anti-government protests.

The files show that the university declined to admit new students who participated in protests and left comments online against the dictatorship.

https://www.by.cpartisans.org/en/post/bsu-uncut-2020-2024-part-1

campuscodi, to infosec
@campuscodi@mastodon.social avatar

Analyst1 has published a report that looks at the history of a ransomware operation named RansomHouse.

Researchers say the platform has been used by threat actors with links to ransomware gangs such as White Rabbit, Mario ESXi, RagnarLocker, and Dark Angels (Dunghill Leak).

https://analyst1.com/ransomhouse-stolen-data-market-influence-operations-amp-other-tricks-up-the-sleeve/

Not to be confused with RansomHub, which is a different ransomware group.

campuscodi, to infosec
@campuscodi@mastodon.social avatar

The threat actor behind the Kuiper ransomware tried to sell its source code on the XSS hacking forums only to get immediately banned back in April

https://x.com/Libranalysis/status/1778036668236222483

campuscodi, (edited ) to random
@campuscodi@mastodon.social avatar

The EU Agency for Law Enforcement Training (CEPOL) says it was the victim of a cyberattack:

https://www.cepol.europa.eu/newsroom/news/cyber-incident-eu-agency-law-enforcement-training-cepol

campuscodi, (edited ) to random
@campuscodi@mastodon.social avatar

Security firm watchTowr has published its own analysis of CVE-2024-4577, a PHP-CGI vulnerability impacting Windows systems: https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/

The bug was initially discovered by DEVCORE: https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/

watchTowr has also released proof-of-concept code: https://github.com/watchtowrlabs/CVE-2024-4577 #infosec #cybersecurity #security

metin, to infosec
@metin@graphics.social avatar

From the ar(t)chive…

Stylized 3D illustration for an early-2000s article in the Dutch PC-Active magazine, about a mobile phone virus. This was before smartphones were introduced. 🙂

majorlinux, to php
@majorlinux@toot.majorshouse.com avatar

Hope your weekends are still uneventful.

Nasty bug with very simple exploit hits PHP just in time for the weekend

https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/

br00t4c, to security
@br00t4c@mastodon.social avatar

Airport security guards suspended for fighting in front of passengers

#security

https://www.independent.co.uk/tv/news/bangkok-airport-security-fight-departures-b2559139.html

br00t4c, to security
@br00t4c@mastodon.social avatar
majorlinux, to Nvidia
@majorlinux@toot.majorshouse.com avatar

Time to patch some holes!

NVIDIA reveal new security issues in their GPU drivers for June 2024

https://www.gamingonlinux.com/2024/06/nvidia-reveal-new-security-issues-in-their-gpu-drivers-for-june-2024/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • thenastyranch
  • magazineikmin
  • mdbf
  • GTA5RPClips
  • everett
  • rosin
  • Youngstown
  • tacticalgear
  • slotface
  • ngwrru68w68
  • kavyap
  • DreamBathrooms
  • khanakhh
  • megavids
  • tester
  • ethstaker
  • cubers
  • osvaldo12
  • cisconetworking
  • Durango
  • InstantRegret
  • normalnudes
  • Leos
  • modclub
  • anitta
  • provamag3
  • lostlight
  • All magazines