
Opt-in global Mastodon full text search. Join the index!
2024-05-25 11:57:59

Metacurity is pleased to offer our free and premium subscribers a weekly digest of the best long-form (and longish) infosec-related pieces we couldn’t properly fit into our daily news crush.
This week's selection covers
--Hackers rescued a bricked Polish train,
--The double life of Incognito Market's founder,
--Tricking Wi-Fi networks into less secure connections,
--Cybercriminals are selling Indian police biometric data,
--AI fakes are used to recruit Indian voters,
--Indian fake news verification tools are a bust
#deepfakes #biometricdata #misinformation #hackers #databreach #infosec #cybersecurity
2024-05-24 15:13:05

My poor peers in Infosec. It never gets easier does it?
#OWASP #Infosec #AI #LLM
2024-05-25 11:57:59

Metacurity is pleased to offer our free and premium subscribers a weekly digest of the best long-form (and longish) infosec-related pieces we couldn’t properly fit into our daily news crush.
This week's selection covers
--Hackers rescued a bricked Polish train,
--The double life of Incognito Market's founder,
--Tricking Wi-Fi networks into less secure connections,
--Cybercriminals are selling Indian police biometric data,
--AI fakes are used to recruit Indian voters,
--Indian fake news verification tools are a bust
#deepfakes #biometricdata #misinformation #hackers #databreach #infosec #cybersecurity
2024-06-14 21:03:17

Hey everyone. I'm promoting a new YouTube channel hosted by a friend and her family. I'm loving the content she's putting out there. Consider subscribing!
#infosec #training
2024-06-11 19:07:59

QR code SQL injection from popular biometric terminal
💥⁠#InfoSec #CyberSecurity
2024-04-27 15:20:36

EDIT: on its way to @…. Thanks, all!
Please share to wireless hackers: Who in the community is doing hacking on fitness trackers, BTLE stuff, radio/wireless, etc? I have an Oura Ring that I had replaced by warranty because the battery life halved suddenly, but it works fine (if with 2-3 days of battery life instead of 5).
Who's the person who'd like this for their lab? I will send a charger as well as the ring because I have an extra one. #infosec #btle #wireless
2024-05-22 13:30:21

Days without DATETIME / TIMESTAMP incident:
#infosec #mysql #development

a sign with text "days without datetime / timestamp incident" and digits in red on black showing -32768
2024-05-09 17:44:05

When someone wants us to mitigate vulnerable devices by "putting it behind a firewall". Image stolen from @…
#infosec #firewall #meme
2024-05-09 17:44:05

When someone wants us to mitigate vulnerable devices by "putting it behind a firewall". Image stolen from @…
#infosec #firewall #meme
2024-06-12 16:24:27

#Tile has been breached according to @…. I'm disturbed to find out that they had a police query tool. I'm going to end up being a hermit just to have some god damn privacy from my government.
#breach #infosec
2024-05-17 02:20:00

#Infosec #Warning
Don't click on any link with "Google" or "Facebook" in the domain, it links to a terrible surveillance capitalist who will build a profile on you to try and help the capital manipulate you.
Be Safe: Never click on Google.
2024-04-30 15:27:53

File under #deplorable
Hacker jailed for blackmailing therapy patients
2024-05-14 17:12:45

Found an interesting bug in #LittleSnitch, a connection gatekeeper for #macOS that I know many people in #InfoSec use and/or help others use.
If you have a program which is NOT a web browser (in my case, <…
2024-05-09 19:15:33

It looks like #Dell have suffered a data breach. I bought a Dell laptop a few years ago and have just received this to the email address I used when purchasing it.
#Infosec #DataBreach
2024-06-05 13:52:49

#ai #infosec #InfosecMemes

Screen shot of a bluesky post by Jason Sullivan where he adds this caption

"One of the toughest problems Microsoft has to solve is that Windows has to serve two very different types of users: business users who don't want this at all, and home users who don't want this at all."

to a screen shot of a news site that reads:

TECH / PRODUCT NEWS & REVIEWS New Windows Al feature records everything you’ve done on your PC Recall use Al features "to take imaages of vour active …
2024-06-01 17:35:46

Great story of how good the scammers are getting. I suggest most folks read, even us #infosec folks.
2024-06-04 17:10:37

Great blog post going into how the author discovered they could reach any Cox account/modem remotely and change settings.
#infosec #vulnerability #cablemodem #coxcommunications
2024-06-04 19:44:23

#infosecjobs #hiring Alert: I'm hiring a career transition, entry-level, or intern-level web developer in Rust/Python at @….
We help managed service providers get and keep their small biz clients safe and secure!
This would be a great role for someone mid-career looking to move into a more technical role or into infosec, or who just finished a bootcamp or similar education.
Remote, US-only. Read the JD carefully or you'll miss the subject line requirement when you email me.
#cybersecurity #compliance #infosec
2024-05-30 22:32:16

Big #infosec news day...
2024-06-13 20:05:20

The way you prevent big customers from being cranky about breaking SSO is to never give them *already broken SSO*
#Sysadminnery #InfoSec
2024-06-01 14:47:58

Some hard #infosec truths from the South African border agency
2024-05-07 17:30:00

Shapps: "I can confirm to the House that we do have indications that this [data breach] was the suspected work of a malign actor."
So the personal and financial details of the UK Armed Forces has been stolen, and the Defence Secretary says it's "suspected" it was a "malign actor".
"Malign actor" is just another way of saying "the bad guys". And it was hardly someone working in the Army's best interests, was it!?
#Infosec #UKNews #DataSecurity
2024-05-02 13:28:30

X: "I need SSH access to your server to do make that configuration change."
Me: "OK, send me your public key."
X: "I don't have a public key of that server. You need to send me username and password."
Me: 🤦‍♀️
Nope, you're definitely not tech savvy enough that I would allow you with SSH on my server.
2024-05-07 06:47:05

„Two is one and one is none.“
Deswegen hab ich mir irgendwann gleich zwei YubiKeys bestellt.
Seitdem liegen sie ungenutzt in einer Schublade herum.
Thanks for coming to my security talk.
#YubiKey #ITSecurity
2024-05-09 18:39:36

Deeply disappointed in the supposed “perimeter defense” tool which solicits CIDR blocks to be scanned but maxes out at 100 IPs, so anything /25 or larger is rejected.
So, I guess I won’t be having them scan our two /21s and various /24s.
#Sysadminnery #InfoSec
2024-05-10 16:19:09

The threat actor said he registered with several different names on a particular Dell portal as a “partner.” A partner, he said, refers to a company that resells #Dell products or services. After Dell approved his partner accounts, Menelik said he brute-forced customer service tags, which are made of seven digits of only numbers and consonants. He also said that “any kind of partner” could access the portal he was granted access to.
“[I] sent more than 5,000 requests per minute to this page that contains sensitive information. Believe me or not, I kept doing this for nearly 3 weeks and Dell did notice anything. Nearly 50 Million requests…After I thought I got enough data, I sent multiple emails to Dell and notified the vulnerability. It took them nearly a week to patch it all up,” Menelik told #TechCrunch.
#infosec #breach
2024-05-07 19:34:57

Indeed, if you are doing things that are likely to lead to legal demands from law enforcement to your email provider that you want them to fight, you had best be your own email provider.
Proton, Tutanota, MS, Yahoo, Google, Apple, GMX, Fastmail, et al will not fight a valid legal demand for your data that they can fulfill.
Intrinsically, email security is extremely difficult. There's a reason Signal does not do email.
2024-05-10 16:19:09

The threat actor said he registered with several different names on a particular Dell portal as a “partner.” A partner, he said, refers to a company that resells #Dell products or services. After Dell approved his partner accounts, Menelik said he brute-forced customer service tags, which are made of seven digits of only numbers and consonants. He also said that “any kind of partner” could access the portal he was granted access to.
“[I] sent more than 5,000 requests per minute to this page that contains sensitive information. Believe me or not, I kept doing this for nearly 3 weeks and Dell did notice anything. Nearly 50 Million requests…After I thought I got enough data, I sent multiple emails to Dell and notified the vulnerability. It took them nearly a week to patch it all up,” Menelik told #TechCrunch.
#infosec #breach
2024-05-07 19:34:57

Indeed, if you are doing things that are likely to lead to legal demands from law enforcement to your email provider that you want them to fight, you had best be your own email provider.
Proton, Tutanota, MS, Yahoo, Google, Apple, GMX, Fastmail, et al will not fight a valid legal demand for your data that they can fulfill.
Intrinsically, email security is extremely difficult. There's a reason Signal does not do email.
2024-06-04 13:50:38

See thread context…
If you are actually facing an #InfoSec threat environment that credibly includes physical violence, you need MUCH more expertise than you can find in any online bullshitting forum. I can argue either side of the wipe vs. Potemkin Village UI issue for a durress password, because I AM A BOZO WHO KNOWS NOTHING OF THAT OF WHICH I SPEAK.
99.9% of people really do not …
2024-06-04 19:51:57

SimpleX Chat is now available with private message routing, IP address protection for messages, files & media, new chat themes and more #simplex #privacy #infosec
2024-05-03 16:19:01

7 million customers had their #DNA #data exposed in a hacker #InfoSec breach at 23andMe and #lawyers are feuding over will get the lion's share of
2024-05-30 22:29:38

I heard that the attackers were just trying to get Taylor Swift tickets.
#breakingnews #infosec #breach #ticketmaster
2024-05-27 16:04:22

Once again I dodge a bullet entirely by accident.
I mean, #FluentBit would almost certainly be something I’d be using if $dayjob's expansion plans had not been blown up by Covid.
My condolences for all of the people who have to deal with this.
2024-06-07 14:43:40

#Recall is the gift that keeps on giving. #infosec #microsoft_recall #microsoft
2024-05-02 12:24:20

Oh look, the assholes calling themselves have put some of their scanners on Azure UK. Easy enough to shun THAT /13…
#Infosec #scanners
2024-05-31 22:03:03

#infosec #copilot #microsoft_recall
On the one hand #Microsoft has Windows Defender that blocks k…

Tweet from @GossiTheDog.

Microsoft told media outlets a hacker cannot exfiltrate Copilot+ Recall activity remotely.

Reality: how do you think hackers will exfiltrate this plain text database of everything the user has ever viewed on their PC? Very easily, I have it automated.

Followed by a screen shot of opening the sqlite activity database with some example activity