Tootfinder

Opt-in global Mastodon full text search. Join the index!

@deepthoughts10@infosec.exchange
2024-03-23 01:59:37

I see so few legitimate domains in the .top TLD. I think it’s worth blocking the entire TLD and creating exceptions for the rare non-malicious site your org needs to access. Definitely something to use in #threathunting too. #cybersecurity
From: @…
infosec.exchange/@InfobloxThre

@ErikJonker@mastodon.social
2024-04-21 09:38:22

Beetje onzinnige oproep, het is er al, gaat niet meer weg, ook is het niet perse een belemmering voor opsporing zo is gebleken.
#cybercrime #cybersecurity #e2e

@risottobias@tech.lgbt
2024-04-18 22:40:54

how do you do vulnerability disclosure or bug bounty programs on products that require subscriptions? do you provide limited accounts? or freebee coupons? or access to demo/beta?
#cybersecurity #bugbounty #vulnerabilitymanagement

@alwynispat@mastodon.sg
2024-04-18 09:41:55

So our CISO has been pestering us to collect certificates like catching Pokemon.
Just finished SC-200 training. Gotta plan when to take the exams now.
#Cybersecurity #Azure

@cybeardjm@masto.ai
2024-05-07 15:15:57

Bank Of Ghana set to introduce 1% #cybersecurity levy on all banking transactions.
"This move comes in the face of increased cybersecurity risks in the country and across the world."
So many questions...
* What will the levy do?
* Who's responsible for cybersecurity?
#Banks

Photo: Director of Bank of Ghana
@catsalad@infosec.exchange
2024-06-11 19:07:59

QR code SQL injection from popular biometric terminal
💥⁠#InfoSec #CyberSecurity

@johnleonard@mastodon.social
2024-05-03 11:55:51

Vanta: Cybersecurity spend should be 30% of the IT budget
Currently it's 9% in the UK
computing.co.uk/news/4204614/v

@risottobias@tech.lgbt
2024-04-18 15:07:03

nice, @… is live on discord now about 2FA
#cybersecurity

@ErikJonker@mastodon.social
2024-04-17 09:45:48

Really nice analysis, everybody interested in #cybersecurity and #microsoft should read it,

@geant@mstdn.social
2024-04-11 07:56:46

The Lightning Talks plenary session closes the first day of the GÉANT #SecurityDays. The lively, informative and animated five minute presentations offered great content, perspectives, insights and ideas on various aspects of #cybersecurity.
From external communication during a cyber cris…

GÉANT Security Days 2024 in Prague - Lightning Talks
GÉANT Security Days 2024 in Prague - Lightning Talks
GÉANT Security Days 2024 in Prague - Lightning Talks
GÉANT Security Days 2024 in Prague - Lightning Talks
@Jackobli@mastodon.social
2024-06-12 08:47:32

Hat sich wer schon die Entwürfe der «Cybersicherheitsverordnung» der Schweiz angeschaut?
Dieser StA NCS wird auch ein unmöglicher Moloch, nicht?
#cybersecurity
newsd.admi…

@deepthoughts10@infosec.exchange
2024-04-17 01:42:54

This is bad. Patch your Global Protect Palo Alto firewalls now please. #cybersecurity #paloaltonetworks
From: @simontsui
infosec.exchange/@simontsui/11

@risottobias@tech.lgbt
2024-04-18 12:37:47

oh, neat!
#CISA has opened up signups to their malware analysis service to any #cybersecurity folks that want to view results (any member of the public could anonymously submit samples before)
cisa.gov/news-events/news/cisa

@ErikJonker@mastodon.social
2024-04-17 10:10:27

Unearthing APT44: Russia’s Notorious Cyber Sabotage Unit Sandworm.
#cybersecurity #Russia #APT44

@marcel@waldvogel.family
2024-06-05 07:54:15

Andreas Grünert vom #BACS (paraphrased):
«IT-Security-Checklisten helfen bei der operativen Umsetzung, nicht aber bei der strategischen Planung.»
#SwissIGF #Cybersecurity

Der Vortragende neben der Programmfolie dür die Cybersicherheits-Session
@catsalad@infosec.exchange
2024-04-09 10:45:49

Happy Tuesday everyone! Hope you're all doing well... 😁
Aww, Patch Tuesday wants to say hi!

#InfoSec #CyberSecurity #️⃣CatSalad

@deepthoughts10@infosec.exchange
2024-04-16 02:29:24

This is good advice: block all of the ipfs services if your organization doesn’t use them #cybersecurity
From: @…
cyberplace.social/@fellows/112

@geant@mstdn.social
2024-04-11 07:56:46

The Lightning Talks plenary session closes the first day of the GÉANT #SecurityDays. The lively, informative and animated five minute presentations offered great content, perspectives, insights and ideas on various aspects of #cybersecurity.
From external communication during a cyber cris…

GÉANT Security Days 2024 in Prague - Lightning Talks
GÉANT Security Days 2024 in Prague - Lightning Talks
GÉANT Security Days 2024 in Prague - Lightning Talks
GÉANT Security Days 2024 in Prague - Lightning Talks
@Szwendacz@social.linux.pizza
2024-05-14 19:15:46

I am looking for a #dataset containing network traffic recording of some TCP based external attacks (ddos, port scan, etc...) and of cource normal traffic. The dataset should be somewhat big, plain csv would be at least few GiB in size.
I already know about www.unb.ca, this is good example, but I need some different source.

@catsalad@infosec.exchange
2024-04-03 14:02:09

How will the Merck settlement affect the insurance industry?

March 28, 2024 — By @… #Cybersecurity #InfoSec #Insurance

@ErikJonker@mastodon.social
2024-04-13 05:13:20

Iddink Learning Materials aangevallen door cybercriminelen.
#cybersecurity #onderwijs #iddink

@risottobias@tech.lgbt
2024-05-09 02:14:53

how can you help people do security when they have no time?
I don't just mean when you have a limited cybersecurity team.
what about when they have a very limited IT team?
when they have no IT team?
#CyberSecurity #Linux #BlueTeam

@geant@mstdn.social
2024-04-11 12:16:21

The closing plenary of the GÉANT #SecurityDays welcomes on stage Daniel Stach, broadcaster & journalist CzechTV, with his presentation: "Lies are (not) everywhere!".
Alf Moens, GÉANT: "What a brilliant way to close GÉANT's first #Cybersecurity conference. Collaborat…

Daniel Stach at the GÉANT Security Days 2024 in Prague
@ErikJonker@mastodon.social
2024-04-13 05:13:20

Iddink Learning Materials aangevallen door cybercriminelen.
#cybersecurity #onderwijs #iddink

@catsalad@infosec.exchange
2024-04-03 14:02:09

How will the Merck settlement affect the insurance industry?

March 28, 2024 — By @… #Cybersecurity #InfoSec #Insurance

@deepthoughts10@infosec.exchange
2024-04-13 18:06:31

Just received my #ATT data breach notification. Could this message look more like a phish? Friendly sender name all run together? Sketchy-looking reply-to address? Do better AT&T.
#cybersecurity

@risottobias@tech.lgbt
2024-04-12 22:01:14

The "we're {blank}, of course we" #meme
But for #cybersecurity or #sysadmin
(Side note now the advertisers are doing it :/)

@geant@mstdn.social
2024-04-11 12:16:21

The closing plenary of the GÉANT #SecurityDays welcomes on stage Daniel Stach, broadcaster & journalist CzechTV, with his presentation: "Lies are (not) everywhere!".
Alf Moens, GÉANT: "What a brilliant way to close GÉANT's first #Cybersecurity conference. Collaborat…

Daniel Stach at the GÉANT Security Days 2024 in Prague
@catsalad@infosec.exchange
2024-04-08 12:51:30

Mystery solved!

#P4x #CyberSecurity #InfoSec @…

@deepthoughts10@infosec.exchange
2024-04-10 22:29:49

This looks really good. I’m going to give it a try! #cybersecurity #microsoft
From: @…
infosec.exchange/@merill/11224

@risottobias@tech.lgbt
2024-04-12 20:08:08

okay, what are your thoughts about DoD's/Platform One's Big Bang #kubernetes setup?
#cybersecurity #cloudarchitecture

@cybeardjm@masto.ai
2024-06-14 07:07:31

A #MustHave book
#CyberSecurity #Books #Humour

(fake) book cover

Title: Hoping Nobody Hacks You
Security by optimism and prayer

Level: expert
@Szwendacz@social.linux.pizza
2024-05-24 19:36:13

I chose #cybersecurity instead of #datascience on my masters degree course, and guess what.
I am training models on datasets to detect cyberattacks.
The difference is that I understand the data, not the model algorithms.

@catsalad@infosec.exchange
2024-04-01 08:45:08

Too many are focusing on getting a #Cybersecurity warrior badge. We need a balanced team!
🛡️⁠Cybersecurity Tank
🗡️⁠Cybersecurity Rogue
🔮⁠Cybersecurity Mage
🔫⁠Cybersecurity Healer
📢⁠Cybersecurity Bard

@tarah@infosec.exchange
2024-06-04 19:44:23

#infosecjobs #hiring Alert: I'm hiring a career transition, entry-level, or intern-level web developer in Rust/Python at @….
We help managed service providers get and keep their small biz clients safe and secure!
This would be a great role for someone mid-career looking to move into a more technical role or into infosec, or who just finished a bootcamp or similar education.
Remote, US-only. Read the JD carefully or you'll miss the subject line requirement when you email me.
#cybersecurity #compliance #infosec

@risottobias@tech.lgbt
2024-05-09 16:58:19

Phishing protections..
Hmmm...
Hardware 2FA
Strong Dmarc filtering? Filter out newly registered domains, flag newly changed ones?
Contextual auth / posture check of endpoint
UEBA / impossible travel, warnings on multiple locations
Cookie specific to browser string (not to IP due to roaming clients)
What else?
#cybersecurity #phishing

@deepthoughts10@infosec.exchange
2024-06-07 18:46:00

Anyone else having issues with Entra ID PIM today? Seems to be broken for some roles — specifically roles directly related Entra ID itself including Conditional Access Administrator and Privileged Role Administrator
#cybersecurity #Microsoft
cc: @…

@stefanmuelller@climatejustice.social
2024-05-04 05:23:44

#Datensicherheit #CyberSecurity #CyberAttack #Hackerangriff
Schritt 1: Keine #Microsoft Software mehr verwenden. #opensource
tagesschau.de/multimedia/video

@deepthoughts10@infosec.exchange
2024-06-08 19:22:49

I have never seen a legitimate .xyz domain. I’m sure there’s at least one, but you should block this TLD if you can.
I recommend blocking it both at the DNS layer and at your email gateway to prevent email spam and phishing campaigns. As an example, here’s how to block TLDs in #Exchange Online
#cybersecurity #threatintel
From: @…
infosec.exchange/@threatcat_ch

@risottobias@tech.lgbt
2024-04-08 22:55:00

"but PeaceNotWar is the same as #xzbackdoor "
no, no they're not.
one is a secretive RCE.
one is a protest.
"why did that dev get off Scott free?"
they edited their protest to make just a text file instead of wiping files.
#cybersecurity

@cybeardjm@masto.ai
2024-04-29 17:14:11

"When someone tells you they have an automated system to prevent the risk of human error...
Step away, slowly, with no sudden movements."
See also: masto.ai/@cybeardjm/1110964667

@deepthoughts10@infosec.exchange
2024-06-07 01:28:44

Someone’s been busy. A whole lotta new botnet and C2 domains from Sarlack Lab. Block all but the major service providers like Microsoft.com, cloudfront.net, azureedge.net and azurefd.net
#threatintel #cybersecurity
From: @…
ioc.exchange/@SarlackLab/11257

@risottobias@tech.lgbt
2024-05-06 19:39:04

I just want a search and replace for every article about Russian or Chinese hackers to be replaced with rival football teams or your own state.
"The broncos leveraged a Cisco ASA vulnerability"
"California implanted a backdoor into ssh"
Instead of this nonsense xenophobic distraction about being at war with eastasia and needing permission to surveil all citizens.
#cybersecurity

@risottobias@tech.lgbt
2024-05-05 18:11:51

anybody work in #instagram 's trust and safety department?
got a local LGBT organization I'm helping out with IT stuff that keeps getting flagged and taken down.
(I'm not a facebook user)
#cybersecurity

@deepthoughts10@infosec.exchange
2024-06-06 00:30:01

This article from @… has a ton of great #threatintel I highly recommend searching for web browsing activity to:
*.run.app
*.my.id
*.biz.id
And if you don’t have any activity, consider blocking the domains, or at least alerting on them.
#cybersecurity
From: @…
infosec.exchange/@r1cksec/1125

@ErikJonker@mastodon.social
2024-06-04 15:55:53

Critical incident declared as ransomware attack disrupts multiple London hospitals.
therecord.media/london-hospita

@deepthoughts10@infosec.exchange
2024-06-03 12:55:09

I wonder how many organizations will get burned by this through fourth party use? (You don’t use Snowflake but your SaaS provider does) #cybersecurity
From: @…
cyberplace.social/@GossiTheDog

@metacurity@infosec.exchange
2024-05-25 11:57:59

Metacurity is pleased to offer our free and premium subscribers a weekly digest of the best long-form (and longish) infosec-related pieces we couldn’t properly fit into our daily news crush.
This week's selection covers
--Hackers rescued a bricked Polish train,
--The double life of Incognito Market's founder,
--Tricking Wi-Fi networks into less secure connections,
--Cybercriminals are selling Indian police biometric data,
--AI fakes are used to recruit Indian voters,
--Indian fake news verification tools are a bust
#deepfakes #biometricdata #misinformation #hackers #databreach #infosec #cybersecurity
metacurity.com/p/best-infosecr

@risottobias@tech.lgbt
2024-05-02 15:35:05

"Sloths see the world different [...] And offensive security [is a different way to see things]" - @… live on @… discord
Good discussion on bloodhound, lolbins, red teamers, etc
#bsides is a great resource, offsec professionals at btc,
#cybersecurity #blueteam

@deepthoughts10@infosec.exchange
2024-05-01 22:36:49

I didn’t know SentinelOne was so good in the MacOS space. It’s good to see. And if you manage Macs, you’ll want to read this article and see if you’ve been affected by this malware.
#cybersecurity
From: @…
infosec.exchange/@screaminggoa

@risottobias@tech.lgbt
2024-05-02 15:35:05

"Sloths see the world different [...] And offensive security [is a different way to see things]" - @… live on @… discord
Good discussion on bloodhound, lolbins, red teamers, etc
#bsides is a great resource, offsec professionals at btc,
#cybersecurity #blueteam

@risottobias@tech.lgbt
2024-05-30 15:18:44

These @… talks on discord are AMAZING. It's so nice to catch the talks I missed in person last year.
You coming to Chicago this year?
#cybersecurity #blueteam #blueteamcon

@deepthoughts10@infosec.exchange
2024-04-30 01:05:20

Do you work for a business? Is that business in the video gaming industry? If not, block access to steamcommunity.com. You’ve just neutered this malware. Have a cup of tea and pat yourself on the back. 🙂
#cybersecurity #threatintel #ioc
From: @…
infosec.exchange/@sekoia_io/11

@risottobias@tech.lgbt
2024-04-26 18:40:55

SQL injection
Es q el injection
See quel injection
Squirrel injection
Release the squirrels!
#cybersecurity
es ql
see quel

@deepthoughts10@infosec.exchange
2024-04-29 21:39:12

This is really bad. If you were vulnerable to this issue, the only way out of it is through Palo Alto support. Open a case with them to review your logs.
I could see this requiring some organizations to completely replace their Global Protect-enabled firewalls with new ones.
#cybersecurity
From: @…
infosec.exchange/@screaminggoa

@risottobias@tech.lgbt
2024-04-26 18:40:55

SQL injection
Es q el injection
See quel injection
Squirrel injection
Release the squirrels!
#cybersecurity
es ql
see quel

@deepthoughts10@infosec.exchange
2024-04-30 03:38:35

I wasn’t aware that Autodesk had a file sharing service either! Definitely block drive.autodesk[.]com in your org if you don’t use it.
Also, here’s the original Netcraft post that the Security Week article is based on.
#cybersecurity #threathunting #ioc
From: @…
cyberplace.social/@fellows/112

@metacurity@infosec.exchange
2024-05-25 11:57:59

Metacurity is pleased to offer our free and premium subscribers a weekly digest of the best long-form (and longish) infosec-related pieces we couldn’t properly fit into our daily news crush.
This week's selection covers
--Hackers rescued a bricked Polish train,
--The double life of Incognito Market's founder,
--Tricking Wi-Fi networks into less secure connections,
--Cybercriminals are selling Indian police biometric data,
--AI fakes are used to recruit Indian voters,
--Indian fake news verification tools are a bust
#deepfakes #biometricdata #misinformation #hackers #databreach #infosec #cybersecurity
metacurity.com/p/best-infosecr

@deepthoughts10@infosec.exchange
2024-05-29 02:28:26

Once you get your drivers up to date, ensure that you have the Windows Vulnerable Driver Blocklist enabled. This is available in Windows Security Settings --> Device Security. If it is enabled and greyed out like in this screenshot, you are good to go. If not, enable it. Also, while there I recommend enabling Memory Integrity as it is a good complimentary security control for your computer #cybersecurity #microsoft

@deepthoughts10@infosec.exchange
2024-05-29 02:28:26

Once you get your drivers up to date, ensure that you have the Windows Vulnerable Driver Blocklist enabled. This is available in Windows Security Settings --> Device Security. If it is enabled and greyed out like in this screenshot, you are good to go. If not, enable it. Also, while there I recommend enabling Memory Integrity as it is a good complimentary security control for your computer #cybersecurity #microsoft

@deepthoughts10@infosec.exchange
2024-04-28 23:57:56

Sophos has done quite an extensive investigation into this malware operation and provided over 450 #IOCs to hunt for. I also find they are abusing WebDAV servers (those servers with <at>80 in the URL). WebDAV is an uncommonly used protocol these days. If you can, try to block access to all WebDAV servers except those that are used by your organization.
#threatintel #cybersecurity
From: @…
infosec.exchange/@SophosXOps/1

@deepthoughts10@infosec.exchange
2024-04-25 15:59:23

For my #threatintel folks here’s an easy one: any traffic in your environment to/from 45.142.166[.]112? If so, track it down. You have an infected system.
#cybersecurity
From: @…
mastodon.social/@campuscodi/11

@risottobias@tech.lgbt
2024-04-18 15:20:18

okay, I'm aware of how #U2F and #WebAuthN work at the protocol/implementation level.
I'm not sure someone's given a simple explanation for why #evilginx or similar #phishing #mitm proxies wouldn't work.
there's surely modes you could do FIDO2 that are vulnerable to phishing (kinda like doing JWTs wrong)
#cybersecurity

@catsalad@infosec.exchange
2024-04-10 09:39:46
Content warning
⚠️⁠CVE-2024-27983 – Node.js HTTP/⁠2 server
⚠️⁠CVE-2024-27919 – Envoy's oghttp codec
⚠️⁠CVE-2024-2758 – Tempesta FW
⚠️⁠CVE-2024-2653 – amphp/⁠http
⚠️⁠CVE-2024-28182 – nghttp2 library
⚠️⁠CVE-2024-27316 – Apache Httpd
⚠️⁠CVE-2024-31309 – Apache Traffic Server
⚠️⁠CVE-2024-30255 – Envoy < 1.29.2
⚠️⁠CVE-2023-45288 – Go packages net/⁠http and net/⁠http2


#InfoSec #CyberSecurity #CVE #DoS #HTTP2 #Vulnerability #️⃣CatSalad

@deepthoughts10@infosec.exchange
2024-04-25 00:51:30

Spamhaus always has good #threatintel in their reports. Great source for #threathunting and/or evidence to support blocking commonly abused TLDs like .bond
#cybersecurity
From: @…
infosec.exchange/@spamhaus/112

@deepthoughts10@infosec.exchange
2024-05-29 02:18:17

Do you occasionally check your Windows drivers to keep them up to date? Many drivers are not updated by Windows Update -- you have to get them from the manufacturer of your computer and peripherals. Why is this important? Drivers, like all other software, can have security-related defects. Attackers can leverage these vulnerabilities to escalate privileges and install malware on your computers.
Major PC manufacturers have utilities that can help you keep your drivers up to date, such as these from Dell, Lenovo and HP:
#cybersecurity #microsoft

@deepthoughts10@infosec.exchange
2024-05-29 02:18:17

Do you occasionally check your Windows drivers to keep them up to date? Many drivers are not updated by Windows Update -- you have to get them from the manufacturer of your computer and peripherals. Why is this important? Drivers, like all other software, can have security-related defects. Attackers can leverage these vulnerabilities to escalate privileges and install malware on your computers.
Major PC manufacturers have utilities that can help you keep your drivers up to date, such as these from Dell, Lenovo and HP:
#cybersecurity #microsoft

@risottobias@tech.lgbt
2024-05-15 16:09:51

Stellar posts. What are some of your favorite #SecurityDesign guides?
#CyberSecurity #CloudArchitecture #BlueTeam

@risottobias@tech.lgbt
2024-06-08 16:10:22

I kinda think there should be a #honeytoken alliance between most providers. or maybe just between small shops.
Like an agreement to make API keys that your SIEM will alert on, that you give to trusted partners, where you'll ping them if something uses their canary.
#cybersecurity #blueteam #cloudarchitecture #canarytokens #canarytoken

@risottobias@tech.lgbt
2024-06-02 14:40:23

more #snowflake #snowflakebreach news.
#cybersecurity #blueteam

@risottobias@tech.lgbt
2024-04-26 17:30:49

you're air dropped into an organization. what are your priorities? what do you want fixed first? if you had to do things one at a time.
inventory, backups? patching? hardening? budget, staffing, AV, firewalls, telemetry, IRP,
#CyberSecurity #BlueTeam #GRC #CISO

@risottobias@tech.lgbt
2024-04-26 17:30:49

you're air dropped into an organization. what are your priorities? what do you want fixed first? if you had to do things one at a time.
inventory, backups? patching? hardening? budget, staffing, AV, firewalls, telemetry, IRP,
#CyberSecurity #BlueTeam #GRC #CISO

@deepthoughts10@infosec.exchange
2024-05-26 20:49:42

I talk a lot about blocking certain Internet services such as Dynamic DNS, but I realize that not everyone has a fancy DNS security service or NGFW that gives you an easy way to do this. If you don't have those, but do use Windows DNS, you can create a DNS Policy to create your own #DNS block list by running a simple PowerShell command on your DNS server:
Add-DnsServerQueryResolutionPolicy -Name "BlockListPolicy" -Action IGNORE -FQDN "EQ,*.duckdns.org" -PassThru
#cybersecurity

@risottobias@tech.lgbt
2024-06-01 03:29:27

okay, the #snowflake / #SnowflakeBreach thing...
Okay, which is it. one or the other or both? either their servicenow's messed up, or their customers have bad passwords and no MFA, or both?
#cybersecurity #blueteam #incidentresponse #servicenow #okta