Tootfinder

Opt-in global Mastodon full text search. Join the index!

@hacksilon@infosec.exchange
2026-08-19 17:02:26

PSA: Critical unauthenticated account takeover vulnerability in #Keycloak - allows resetting arbitrary users‘ passwords. Update to 26.7.2 immediately or disable password reset. Tracked as CVE-2026-18963. #infosec

@cjust@infosec.exchange
2026-09-20 19:21:21

#Shitpost #Shitposting #Infosec #OtterNonsense

@grumpybozo@toad.social
2026-07-15 23:19:32

RE: ioc.exchange/@percepticon/1169
Note the hygiene recommendations at the end of that article. Quite basic. Quite simple. PLEASE PLEASE PLEASE just follow them. You all know that you should.

@adulau@infosec.exchange
2026-09-04 13:45:20

ptrclassify is a small, dependency-free Python library and CLI that infers likely IP usage and location from reverse-DNS PTR hostnames.
Version 0.3 released including new rules and CSV tool.
#ptrclassify #infosec #cybersecurity
🔗 github.com/adulau/ptrclassify

@floheinstein@chaos.social
2026-07-02 12:20:35

Arthur C. Clarke: "Any sufficiently advanced technology is indistinguishable from magic."
Me: "Therefore, any sufficiently complicated technical problem is indistinguishable from a curse."
#infosec #sysadmin

@jtk@infosec.exchange
2026-07-23 21:32:50

Any #PortlandME fedi people involved with #DNS, #BGP, #infosec, or

@groupnebula563@mastodon.social
2026-06-30 10:44:47

any #cybersecurity people interested in getting into a webserver in order to rescue a dying website?
boosts appreciated :P
#cybersec #infosec

@GroupNebula563@mastodon.social
2026-06-30 10:44:47

any #cybersecurity people interested in getting into a webserver in order to rescue a dying website?
boosts appreciated :P
#cybersec #infosec

@floheinstein@chaos.social
2026-07-01 12:43:24
Content warning: What do you call the art of being able to replicate a data center after sniffing its vent shaft?

Colo-nose-copy.
#infosec #dadjoke #shitpost

@castarco@hachyderm.io
2026-08-20 18:40:54

If you are developing in #Rustlang then you should check this post: #cybersecurity #infosec #supplychain #supplychainattack

@adulau@infosec.exchange
2026-08-31 06:54:26

CVSS and WRONG models are just the same.
#cvss #infosec

@Xavier@infosec.exchange
2026-08-11 20:18:44

This is being actively exploited. CVE-2026-20349. Patch now. Like right now. #infosec #vpn #cisco #cve
bleepingcomputer.com/news/secu

@grumpybozo@toad.social
2026-08-24 15:04:07

Weird #InfoSec behavior..
Saturday I logged into FB for the first time in maybe a year or more. Saw that they now support passkeys. Between their bad UI/UX design, incompatibility with StrongBox, GMail filter idiocy, and my fumble in manual credential management ended up needing to reset all credentials.
This morning I woke up to an email from FaceBook telling me that I am required to e…

@adulau@infosec.exchange
2026-09-15 04:55:36

Pivotick v2.0.0 has been released.
Pull more graph out of wherever your data lives, and you choose what lands. History is the way back out of anything that does.
Actually you can update, pivot graph and review. This release also includes many new other features.
#graph #library #infosec #opensource #graphing #pivotick #cti #threatintelligence

@cjust@infosec.exchange
2026-08-23 01:03:49

#Shitpost #Shitposting #ShamelesslyStolenFromSomeWhereElseOnTheInternetSeriouslyICantKeepTrackOfThisStuffAnymore #InfosecMemes

@adulau@infosec.exchange
2026-09-06 10:17:02

Doing some statistics on the persistence of information published on security and threat intelligence blogs. A surprising number of the domains in the list below are NXDOMAIN nowadays.
Don't assume that security information and threat intelligence will remain accessible over time, especially when it is hosted by large private entities.
Some are simply mistyped, while others reflect DNS changes over time that eventually left the original URLs broken.
Stability and persistence of information is hard on Internet.
#threatintelligence #threatintel #infosec #cybersecurity

  app.response.ncr.com
blog.0x3a.com
blog.anomali.com
blog.cert.societegenerale.com
blog.cylance.com
blog.deniable.org
blog.ioactive.com
blog.jpcert.or.jp
blog.kleissner.org
blog.malwareclipboard.com
blog.malwaretracker.com
blog.passivetotal.org
blog.safebit.mn
blog.team-cymru.org
blog.zimperium.com
blogs.rsa.com
cdn.securelist.com
community.saas.hpe.com
ddos.arbornetworks.com
dnsdb.isc.org
edu.arabsgate.com
info.baesystemsdetica.com
info.isightpartners.com
insider.domaintools.com
ioc.forensicartifacts.com
iranthreats.github.i
joedd.joesecurity.org
lab.anchiva.com
labs.alienvault.com
labs.lastline.com
labs.snort.org
labsblog.f-secure.com
luminosity.link
malware.sekoia.fr
morphick.net
motherboard.vice.com
ocelot.li
permalink.gmane.org
r.virscan.org
remchp.com
research.riskiq.net
resources.infosecinstitute.com
sandbox.deepviz.com
sec.sexy
securityblog.s21sec.com
securityblog.switch.ch
securitydaily.org
sub0day.com
tif.mcafee.com
wepawet.iseclab.org
www.cve.mitre.org
www.cyintanalysis.com
www.cyphort.com
www.icebrg.io
www.infosecdailynews.com
www.isightpartners.com
www.lexsi.com
www.novetta.com
www.packetmail.net
www.root9b.com
www.skycure.com
www.threatexpert.com
www.vxsecurity.sg
@castarco@hachyderm.io
2026-07-24 07:31:51

⚠️ If your web apps are built on top of #NodeJS , be sure to upgrade your NodeJS instances this next Monday 27 #infosec