k3ym0

@k3ym0@infosec.exchange

[~]$ whoami

principal killswitch engineer. neo-feudalist cybernaut. blueteamer. privacy advocate. disciple of doctorow. reader of white papers. eff member. round-earther. cyber dark arts certified. fellow at the institute of memetic research and development.

i larp as a normie.

(he/him)

opinions expressed =! employers

This profile is from a federated server and may be incomplete. Browse more on the original instance.

k3ym0, to privacy

Data is bought and sold by advertisers, employment agencies, and government institutions to create a profile of you. When you use the internet, you create a trail of data. Every printout, picture, chat, social media like, tag, post, search, purchase and even email, makes up your digital footprint. To minimize your digital footprint always pause and think before clicking because anything can be tracked on the web.

#ThinkBeforeYouClick #Privacy

k3ym0, to Cybersecurity

Don't use Exchange On-Prem - It's riddled with vulnerabilities, they said.

Use Office 365 - It's way more secure, they said.

Meanwhile, MSFT leaving test OAuth accounts active, with:
✅ admin privileges
✅ weak password
✅ no MFA

(insert jokerclapping.gif)

https://arstechnica.com/security/2024/01/in-major-gaffe-hacked-microsoft-test-account-was-assigned-admin-privileges/

#cti #cybersecurity #threatintel #midnightblizzard #apt29

k3ym0, to Cybersecurity

New @FortiGuardLabs Outbreak Alert: Adobe ColdFusion Access Control Bypass Attack (Critical-level detections in the wild) ⮕ ftnt.net/61103ryCs3

FortiGuard Labs observed critical level of continued attacks on Adobe Coldfusion with IPS detections reaching up to 50,000+ unique detections. Users of Adobe ColdFusion are advised to apply patches as per vendor guidelines as soon as possible to mitigate any risk completely, if not already done.

#cybersecurity #cti #threatintel

k3ym0, to Cybersecurity

lmao. xfinity gets hacked and this is the message you get when you go to log into your account:

"As part of our commitment to you, Comcast routinely reviews and monitors account security. Please update your password to help protect you and your account."

We gee golly, xfinity, thanks for being so committed to your customers. FFS.

#xfinity #xfinityhack #cybersecurity

k3ym0,

On the plus side, looks like they've increased the character limit on pwds to 128 characters!

GOOD LUCK BRUTE FORCING THAT, BADDIES.

k3ym0,

@simonzerafa the only acceptable way of course: .xlsx

k3ym0, to Cybersecurity

Chinese APT Volt Typhoon has been observed leveraging EoL SOHO devices as a proxy network to obfuscate their operations.

Read the excellent write up by @blacklotuslabs here

k3ym0, to Cybersecurity

The FortiGuard Labs team recently analyzed the new group, , and found that it attacks Windows machines through VPN devices and RDP, and is targeting industries such as education and manufacturing. 📚 🦾

🔎 Learn more: https://cybersecuritynews.com/rhysida-ransomware-attacking-windows/ via Cyber Security News

k3ym0, to random

@eff - not the hero we deserve, but the one that we need.

keen456, to SEC

From vx-underground on Twitter, news that #ransomware group ALPHV submitted an SEC complaint against MeridianLink for not disclosing the breach by...ALPHV: https://www.databreaches.net/alphv-files-an-sec-complaint-against-meridianlink-for-not-disclosing-a-breach-to-the-sec/ #sec #legal

k3ym0,

@keen456 hahaha this is gold

derekvanvliet, to cycling
@derekvanvliet@mastodon.social avatar
k3ym0,

@derekvanvliet what specialized is that?

zackwhittaker, to random
@zackwhittaker@mastodon.social avatar

New, by me: Microsoft has patched two zero-days in open-source libraries that affect several Microsoft products, including Skype, Teams, and Edge browser.

The two zero-days also affected Google and Apple, and both confirmed the bugs are being exploited in the wild. Citizen Lab said the bugs were exploited to plant commercial spyware.

But Microsoft is refusing to say if those zero-days were exploited to target its products, or if the company even knows either way.

More: https://techcrunch.com/2023/10/04/microsoft-wont-say-if-its-products-were-exploited-by-spyware-zero-days/

k3ym0,

@zackwhittaker Skype is still a thing?

k3ym0,

@chucker @zackwhittaker an yes, I think I remember hearing that.

0x58, to random

Face ID on iOS 17 is absolutely worthless.

k3ym0,

@0x58 works fine for me? I’m on 17.0.2 and have had no issues.

hacks4pancakes, to random

I had a mentoring session last night with a poc I’ve been working with who went to his first local cybersecurity con, recently. He had such a bad experience with people being cliquey there and ignoring him that he’s ready to stop trying to get into the industry. 😥😰 I knew there are some cultural issues at that con and area but had no idea they were so bad, and encouraged him to maybe look at other cities in the US and their cons. Pitch your city’s infosec community and scene and I’ll share with him?

k3ym0,

@hacks4pancakes the amount of "pull yourself up by your bootstraps" comments on this thread make make want to puke. That is not equitable - not everyone is starting from the same starting line as you, especially for people who identify as BIPOC or LGBTQIA+.

The onus is on us who are established in the career, especially those of us who are non-marginalized, to go out of our way to be intentionally inclusive and lend a hand up to those who need it. I'll go as far as to say that I believe that the security of the organizations we're defending rely on this.

We are stronger together when we have diversity of thought. Not fostering inclusivity is inherently accepting more risk.

#StrongerTogether

k3ym0,

@hacks4pancakes it's okay to step away. it's exhausting. you need to take care of yourself. this fight is not yours alone.

pierstoval, (edited ) to random French
@pierstoval@mastodon.social avatar

Project manager: "What's technical debt? Explain it to me like I'm 6 years old"

Devs:

(source: "Richard Scarry's Storybook Dictionary" : https://archive.org/details/1scarryRichardStorybookDictionary/page/n56/mode/1up )

k3ym0,

@pierstoval We need more analogies from children's books like this so our C-level executives can understand these challenges.

k3ym0, to programming

NullPointerExemption goes burrrr
Source: @a_smeriglia

hacks4pancakes, to random

TechCrunch Disrupt is definitely the strangest conference I’ve ever been to (full on SF startup investor community culture) but like everyone is here on the security stage so that’s awesome.

k3ym0,

@hacks4pancakes wow. Never thought I’d see signal sharing the same stage as meta.

k3ym0, to random

Doctors don’t want you to know about this one simple trick to cure your depression and anxiety.

k3ym0, to random

WHEN I WANT A WHOPPER I WANT IT NOW GOD DAMNIT

video/mp4

k3ym0, to random

OSINT challenge participants be like

video/mp4

BleepingComputer, to random

Signal has announced that it upgraded its end-to-end communication protocol to use quantum-resistant encryption keys to protect users from future attacks.

https://www.bleepingcomputer.com/news/security/signal-adds-quantum-resistant-encryption-to-its-e2ee-messaging-protocol/

k3ym0,
janeadams, to reddit
@janeadams@vis.social avatar

I realize that I haven't shared much in the past few years about my previous work at the UVM Comp. Story Lab, where we studied phenomena like incels, k-pop, and linguistic turbulence on platforms like #Reddit and #Twitter. Explains why I know so much obscure internet lore 😅 Enjoy:

Incel lexicon: https://arxiv.org/pdf/2105.12006.pdf
K-pop > "god": https://arxiv.org/pdf/1910.00149.pdf
Turbulence: https://arxiv.org/pdf/2008.13078.pdf

#DigitalHumanities #Linguistics #internet #dh #kpop #incels #history #socialmedia #mediastudies

Zipf distribution of terms that end with "-cel" in the incel corpus. The above distribution shows the frequency of each term that ends in "-cel" in the incel corpus vs its rank. Some of the points have been labelled with their respective "-cel" term. The highest ranked and most frequently occurring term is "incel". "Volcel", or "voluntary celibate" is another popular instance of "-cel" terms. The diversity of these terms is indicative of user identification with the incel movement.
Charts comparing the word usage ranks of @bts_twt (the Twitter account of BTS) versus usage of the word 'god' over time, showing BTS consistently outpacing god beginning in 2018
Allotaxonograph using probability-turbulence divergence to compare normalized 1-gram usage rates on two days of Twitter, 2020/03/12 and 2020/05/30—key dates in the US for the COVID-19 pandemic and the Black Lives Matter protests following George Floyd’s murder. Details are the same as for Fig. 1. The days are according to Coordinated Universal Time (UTC) and the 1-grams are those containing latin characters found in English- language tweets [27, 28].

k3ym0,

@janeadams oh. My god. This is amazing.

“Deciphering the emergent cryptolect of a global misogynistic community” is my new favorite white paper.

Em0nM4stodon, to programming

Music Recommendation Request :ablobdj:​:

I have been coding a lot this week
and I think I have listened to the entirety of YouTube's "Programming Music" mixes :ablobcatbongokeyboard:​🎶

Do you have any YouTube or ideally even PeerTube "Programming Music" mixes to recommend to me? 👀​

Preferably something without lyrics, energetic but not like going to a club, and not slow like being in a spa 😅

k3ym0,

@Em0nM4stodon checkout synthwave radio if you haven’t already: https://www.youtube.com/live/4xDzrJKXOOY

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • magazineikmin
  • ethstaker
  • InstantRegret
  • tacticalgear
  • rosin
  • love
  • Youngstown
  • slotface
  • ngwrru68w68
  • kavyap
  • cubers
  • DreamBathrooms
  • provamag3
  • mdbf
  • cisconetworking
  • GTA5RPClips
  • modclub
  • khanakhh
  • everett
  • Leos
  • osvaldo12
  • normalnudes
  • tester
  • Durango
  • anitta
  • JUstTest
  • All magazines