jakub, to security
@jakub@jirutka.cz avatar

I noticed that #Zed automatically downloads a NodeJS binary from nodejs.org without asking or even informing the user about it. Right after starting it and opening a file, without doing anything else. Then it installs some packages from npmjs via npm. And there’s no option to disable it.

THIS IS ABSOLUTELY UNACCEPTABLE! I can’t stress enough how bad this is from #security point of view. And not just that, consider users on metered connections

#ZedEditor #cybersec #Rust
https://github.com/zed-industries/zed/issues/12589

SceNtriC, to random Polish
@SceNtriC@101010.pl avatar

Na koncie PAP pojawiła się fałszywa depesza o powołaniu 200 tysięcy polskich żołnierzy do walk na Ukrainie. Już ją zdementowano, uspokojono, że to nieprawda i podano, że to prawdopodobnie efekt rosyjskiego cyberataku.

Cruthachail, to privacy

Liberate your digital freedom today.

Twitter.
https://nitter.net
https://fediverse.observer

YouTube.
https://tube.raccoon.quest
https://piped.video
https://joinpeertube.org

Google Map.
https://openstreetmap.org

Reddit.
https://libreddit.kavin.rocks
https://teddit.pussthecat.org
https://join-lemmy.org

TikTok.
https://tok.artemislena.eu

Google Search.
https://startpage.com

Google Translate.
https://translate.metalune.xyz

Imgur, Image storage site.
https://pixelfed.org

Wikipedia.
https://wikiless.org

Discord, Guilded, etc.
https://chat.techsaviours.org
https://xmpp.org/about
https://www.jabber.org/faq.html#jabber
https://www.mumble.info/about

Microsoft Teams, Slack, Zoom, etc.
https://jitsi.riot.im
https://opentalk.eu/en

Microsoft Word, Pages, etc.
https://www.onlyoffice.com/en/download-docs.aspx?from=default#docs-community
https://www.libreoffice.org/download/download-libreoffice

Internet Browsers.
https://floorp.app/download (Firefox-based)
https://github.com/ungoogled-software/ungoogled-chromium (Chromium-based)
https://brave.com (Chromium-based)

Emails.
https://mailfence.com/registration
https://app.tuta.com/login?noAutoLogin=true&keepSession=true

Operating Systems.
https://www.opensuse.org
https://linuxmint.com/about.php
https://grapheneos.org
https://calyxos.org
https://lineageos.org

Password Managers.
https://vault.bitwarden.com/#/register?layout=default
https://keepass.info/download.html

Privacy Guides.
https://www.privacyguides.org/en/about
https://thenewoil.org/en/about

Useful services.

https://joinmobilizon.org/en/#what-is-mobilizon
https://joinbookwyrm.com
https://cryptpad.org/about
https://microbin.eu
https://vikunja.io

, , , , , , , , , .

  • Removed because of its recent compromise in privacy.
phil, to infosec

Looking for an entry-level or job.

Just spent a week grinding through THM, got some certs out of it... are these any good? I don't know, but I have learned a bunch of interesting things.

Haven't had a job since December, and I'm nearing on 7 months here. I'll take anything that's remote.

I learn fast, I'm diligent, and I don't take shortcuts.
I grok computers good.

Anyone, anything?

(Sorry for spamming the tags, I know it's bad form.)

beardedtechguy, to Cybersecurity
  • This includes all Chromium based browsers.

New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation

https://thehackernews.com/2024/05/new-chrome-zero-day-vulnerability-cve.html

SceNtriC, to webdev Polish
@SceNtriC@101010.pl avatar

Po zobaczeniu cudownej bramki w meczu Wisła Puławy - drugi zespół Lecha Poznań chciałem sprawdzić coś na stronie internetowej Wisły Puławy. Niestety, nie działa, co się zdarza (a w weekend nie oczekuję, że ktoś to naprawi), ale... Jezu, nie róbcie tak. Zabezpieczajcie ekrany o błędach na serwerze produkcyjnym.

#programowanie #CyberSec #Cyberbezpieczeństwo #WebDev

karma, to linux Polish
@karma@101010.pl avatar

Cześć! Jestem najzwyklejszym użytkownikiem Mastodona. Na wszystkich swoich komputerach używam i pluję na . Umiem trochę Javy, którą ostatnio zaniedbuję na rzecz Rusta. Gram w , i i 2077. Nie jestem neurotypowy, więc często zachowuję się dziwnie i nie łapię sarkazmów czy przenośni. Używam głównie oprogramowania i selfhostuję swoje usługi, bo jestem paranoikiem prywatności. Siedzę trochę w . To chyba tyle o mnie :blobcathearthug:

batichi, to advice
@batichi@masto.batichi.net avatar

Hey #cyberSec nerds, would anyone have some time to offer #advice about getting into the field? I've been seriously thinking about that direction but I have 0 clue how that side specifically runs.
Bonus points if your experience is from #Canada.

cappy, to Cybersecurity
@cappy@fedi.fyralabs.com avatar
alex_02, to OSINT
@alex_02@infosec.town avatar

Oh, isn't this lovely. So apparently these goons:

  • Mike Lindell (My Pillow Guy)

  • Jack Posobiec (White supremacist that believes in conspiracies such as the white genocide conspiracy)

  • Jim Jordan (One of the main players to planning Jan 6th)

  • Matt Gaetz (A pedophile and operated a sex ring, but never was charged (fuck you justice department))

  • Steve Bannon (The fraudster that scammed trump supporters for a fake company to build Trump's wall)

-Vivek Ramaswamy (New face, but is young and likable. Dropped out of presidential nominee bid, but probably got a promise of a cushy job position in Trump's administration, from looks of things)

  • JD Vance (Didn't originally like Trump, but changed his opinion in 2018 and started spewing out many points from The Heritage, The Family Leader, etc)

  • Tommy Tuberville (One of the senators that helped to overturn the presidential election in 2020 and closely allied with Trump)

  • Kristi Noem (Governor of South Dakota, that is a terrible governor and well... I don't want to go into too much right now)

All seem to possibly be conspiring to overthrow the government. Articles are here:

Other potential people here: www.digital.cpac.org/speakers-dc2024

And a video: crooksandliars.com/cltv/2024/02/quelle-surprise-jack-posobiec-big-fan

This is all going off of this screenshot, which is a direct threat and should be taken seriously. I quickly put together this and uploaded what I could grab.

Uploaded to Mega: mega.nz/file/ioQGmRBD#FmcuZjDqCpVhvaFMclGsBgyHjPu8czZTokSz3S4H3fo

Please for FFS. Take this seriously.

beardedtechguy, to Cybersecurity

This is very intriguing! I could possibly be on the right track with this AT&T outage.

The FBI, Homeland Security, and CISA is helping with the investigation now?!

#ATT #ATTOutage #CyberSec #CyberSecurity

image/png

beardedtechguy, to Cybersecurity

I’m just going to throw this out there.

I have a feeling that this AT&T outage has something to Cyber Security. There’s something bigger going on.

https://www.cnn.com/2024/02/22/tech/att-cell-service-outage/index.html

#ATTOutage #CyberSecurity #CyberSec

cappy, to Cybersecurity
@cappy@fedi.fyralabs.com avatar

anyway, an early excerpt from the expose you all should read

beardedtechguy, to Cybersecurity

Reddit selling user content to train an AI?

From: @beyondmachines1
https://infosec.exchange/@beyondmachines1/111952862733740047

cappy, to infosec
@cappy@fedi.fyralabs.com avatar

im getting really tired... -w-

summary of today:

someone on a Japanese hacker forum decided it was a good idea to spam the entire Fediverse because they wanted to cancel a minor that DDoSed a Discord bot which apparently made them lost millions (what?)

A Discord bot. I can't make this shit up man.

The real culprit seems to be someone who goes by mumei in the ctkpaarr.org forums, whose first post was literally a threat to ap12, that if they don't delete their "Kuroneko Server" Discord bot, they will spam every blog, forum and SNS and cancel him.

This shit is ridiculous.

The ap12 account from mastodon-japan was actually fake, and this dude impersonated a minor to get all of the Fediverse (us) to bully him.

The forum admins didn't even stop this. Why? lulz apparently.

cappy, to infosec
@cappy@fedi.fyralabs.com avatar

btw here's the script they use for DDoSing Misskey instances

https://github.com/EdamAme-x/misskey-nuke

cappy, to infosec
@cappy@fedi.fyralabs.com avatar
cappy, to OSINT
@cappy@fedi.fyralabs.com avatar

I'm doing some funny OSINT stuff and... I have found some funny stuff.

I looked him up on Google, Found a Discord report about him with his real email attached.

Looked up his email, and found a post on the ctkpaarr forums (the one he's advertising the discord) of him being currently flamed for this current ongoing incident.

The best part? He bought the script using a PayPal account. With his real name and identity.

He is a real skid. He just bought an off-the-shelf script and decided to piss off a lot of people, even the dude he bought it from with his antics. Bro snitched on himself and his entire community LMEOW

For the sake of my own job, my rep and legal security I'm not gonna tell where exactly I found this, but you guys can find it yourself. Figure it out.

This guy is making me dying out of laughter 💀 Our team @hq is hysterical right now at this horrible opsec.

Don't be a skid, kids.

RE: https://fedi.fyralabs.com/notes/9pr6thyvz5

bytephantom, to Cybersecurity
bytephantom, to Cybersecurity
wilda, to security Polish

Funkcja przypomnienia hasła jest bardzo specyficzna - z jednej strony niepozorna, z drugiej wymagająca dobrych zabezpieczeń, a więc szalenie ważna. Dlatego jest to też fragment systemu, na których uwagę zwracają audytorzy cyberbezpieczeństwa. A warto powiedzieć, że nie trzeba dużo, aby poprawnie ochronić tę część procesu - wystarczy trzymać się reguł, które wymienia choćby Niebezpiecznik.

#Cyberbezpieczeństwo #CyberSec #security

https://niebezpiecznik.pl/post/najczestsze-bledy-programistow-w-formularzu-resetu-hasla/

diker, to Israel

Provider, Aminia Hit by Pro- , Website Inaccessible....The group claims to have compromised Aminia’s billing and Managed WiFi services portals, hinting at a potential data breach. The attack follows the group’s threat to target Malaysian internet infrastructure.

Cyberattack on Aminia; R00TK1T ISC Cyber Team Responsibility

Source🔗
https://thecyberexpress.com/cyberattack-on-aminia-cybersecurity-incident/amp/

diker, to Cybersecurity

NSA Buying Bulk Data on without a Warrant

It finally admitted to buying bulk data on Americans from data brokers in response to a query by Senator Weyden.

This is almost certainly illegal, although the maintains that it is legal until it’s told otherwise.

Source🔗
https://www.wyden.senate.gov/imo/media/doc/signed_wyden_letter_to_dni_re_nsa_purchase_of_domestic_metadata_and_ftc_order_on_data_brokers_with_attachments.pdf

muxelplexer, to austria
@muxelplexer@larkspur.one avatar

Also, on a Side Note: https://www.wko.at/internetrecht/cybersicherheit-nis-2-richtlinie#heading_Massnahmen

Austria is finally going to enforce NIS2 later this year. Who wanna take bets that nothing will change?

phylum, to opensource

We continue to identify sophisticated threats originating from the use of software packages. This time the attacker uses a signed executable to initiate the attack chain through an package.

https://blog.phylum.io/npm-package-found-delivering-sophisticated-rat/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • JUstTest
  • GTA5RPClips
  • tacticalgear
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • ethstaker
  • anitta
  • Leos
  • cisconetworking
  • provamag3
  • lostlight
  • All magazines