Tootfinder

Opt-in global Mastodon full text search. Join the index!

@azonenberg@ioc.exchange
2025-09-08 07:32:59

What's the go-to for non-Microsoft non-Google email hosting these days?
Requirements:
* Supports proper RFC compliant SMTP/IMAP TLS access. No oauth, no EWS, no exchange nonsense. Needs to be usable on e.g. a headless box without a web browser, command line clients, etc.
* Reasonably priced for a handful of accounts across a bunch of domains
* Setup and forget third party hosting, I don't have an IP block suitable for mail hosting in house and I don't want …

@kubikpixel@chaos.social
2025-08-29 09:50:08

»OAuth-Token erbeutet – Hacker greifen massig Daten aus Salesforce-Instanzen ab:
Cyberkriminelle haben es erneut auf Salesforce-Kunden abgesehen. Wer die Salesloft-Drift-Integration verwendet, sollte dringend handeln.«
Schon länger geht das Gerücht um, dass OAuth des öfteren schwach implementiert ist von den IT-Konzernen, wie schon bei OAuth v1 das als unsicher gilt.
🔒

@Techmeme@techhub.social
2025-08-27 05:35:55

Salesloft says hackers stole OAuth tokens from its Drift chat agent integration to conduct a Salesforce data theft campaign between August 8 and August 18 (Lawrence Abrams/BleepingComputer)
bleepingcomputer.com/news/secu

@metacurity@infosec.exchange
2025-09-02 13:54:51

Palo Alto confirms Salesloft Drift Integration was used to compromise Salesforce instances
unit42.paloaltonetworks.com/th

@hex@kolektiva.social
2025-08-29 17:23:57

The WriteFreely instance at Infosec.press is cool. It ties back to their infosec.exchange mastodon instance. Thinking about how finding a blog space has been a barrier to some of my protects in the past (noblogs is great but is harder to get an account), I wonder what the prospects are for something like that at @…. Is this something that's on the radar?
@… had a handy writeup on this for their server: infosec.press/jerry/how-to-use

@tante@tldr.nettime.org
2025-08-29 11:33:46

So someone just got access to a bunch of Salesforce accounts by getting their access tokens.
Salesforce is the company that claims that already 20% of their code is written by "AI", isn't it?
cloud.google.com/blog…

@arXiv_csNI_bot@mastoxiv.page
2025-10-01 09:07:07

OpenID Connect for Agents (OIDC-A) 1.0: A Standard Extension for LLM-Based Agent Identity and Authorization
Subramanya Nagabhushanaradhya
arxiv.org/abs/2509.25974

@khalidabuhakmeh@mastodon.social
2025-08-11 16:19:54

Are you worried your #dotnet #security could be more secure? Join us for a #livestream on August 21st, 2025, to discuss FAPI 2.0, its relation to

@Techmeme@techhub.social
2025-09-18 05:36:03

ShinyHunters claims it stole 1.5B Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens; a source says the figures are accurate (Lawrence Abrams/BleepingComputer)
bleepingcomputer.com/news/secu

@arXiv_csCR_bot@mastoxiv.page
2025-09-18 09:04:51

Agentic JWT: A Secure Delegation Protocol for Autonomous AI Agents
Abhishek Goswami
arxiv.org/abs/2509.13597 arxiv.org/pdf/2509.13597

@kubikpixel@chaos.social
2025-09-17 15:30:21

»Evolution of Privacy Pass«
Does anyone of you know this and did this use this practically? Is this really a modern user login "alternative" solution to OAuth 2.0? How is your experience as a WebDev or/and user with it?
🔑 youtube.com/watch?v=n5yr-3WjSCM
📄

@arXiv_csCR_bot@mastoxiv.page
2025-09-12 07:33:29

Cross-Service Token: Finding Attacks in 5G Core Networks
Anqi Chen, Riccardo Preatoni, Alessandro Brighente, Mauro Conti, Cristina Nita-Rotaru
arxiv.org/abs/2509.08992