alex_02, to infosec

Been thinking about this for a while now. I wonder if I could write a "worm" that uses smb to spread? It would require access to the DC with the design I have. Think it would be interesting to code, but would require specific requirements before it can be used.

realn2s, (edited ) to Cybersecurity

Dear #infosecurity crowd,

I would like to hear if you know the #OpenSpace conference format.

Please #boost for reach

#cybersecurity

Edit: Thank you all for boosting and answering.
I would love to make the Open Space format better known in the cybersecurity context. I think it is a valuable addition to existing formats such as traditional conferences or #BSides

If you would like to learn more about Open Space see my follow up posts

If you participated in Open Space events (in any domain) please share your experience.

jwf, to opensource
@jwf@floss.social avatar
PogoWasRight, to ukteachers

Because these posts scroll away, I have posted something on DataBreaches.net about the discrepancies between what Raptor Technologies has told school districts and WIRED and what we know about the incident -- and what we don't know yet:

https://www.databreaches.net/raptor-technologies-unsecured-blob-exposure-was-worse-than-they-acknowledged-heres-what-we-know-and-dont-know-so-far/

Someone might want to ask the U.S. Education Department and the to look into this incident.

@brett @allan @douglevin @michaelfklein @funnymonkey

alex_02, to infosec

Anyone know where I can get something like this or similar that can fit under a desk?

btanderson, to infosec

In every instance that I’ve discovered shadow IT in an environment, I’ve eventually found someone in IT who knew about it and/or implicitly/explicitly enabled it. I hate to think it, and I understand there are always reasons but…

The call is coming from inside the house.

That means Shadow IT isn’t really in the shadows, and the solution has to start inside IT itself.

#InformationSecurity
#InfoSec
#InfoSecurity

PogoWasRight, to random

National Grid customer data exposed in ‘cyber incident,’ utility says:

https://www.bostonglobe.com/2023/08/23/metro/national-grid-customer-data-exposed-cyber-incident-utility-says/

Sounds like incident, but they don't name it.

9to5linux, (edited ) to linux
@9to5linux@floss.social avatar
alex_02, to infosec

So apparently I'm supposed to toot infosec related stuff? If I did that way more often I would be looking at how much a farm cost.

alex_02, to Blog

Thinking about setting up a blog that is markdown. Anyone know if a self hosted blog like this exists that has a crappy, ugly theme I could use with it?

PogoWasRight, to Cybersecurity

Hooray for NYS AG Letitia James. She has sued Citibank for poor security and failure to comply with #EFTA when consumers report #fraud or #theft.

Snippets from the press release:

"The OAG found that Citi’s systems do not respond effectively to red flags, such as scammers who are using unrecognized devices, are accessing accounts from new locations, or are changing banking passwords or usernames. Additionally, Citi systems do not flag and stop efforts to transfer funds from multiple accounts into a single account and then send tens of thousands of dollars out the door in minutes. Citi also does not automatically initiate investigations or report fraudulent activity to police or law enforcement authorities when consumers first report it to Citi."

"Under EFTA, banks such as Citi are required to reimburse their customers for money in their accounts that is lost or stolen through unauthorized electronic payments. However, Citi illegally exploited a narrow exception in these laws to deny consumer claims for reimbursement, resulting in millions of dollars in losses for New York consumers. Through this lawsuit, Attorney General James is seeking to stop Citi’s deceptive practices and to collect restitution for victims who were denied reimbursement in the last six years, penalties, and disgorgement. "

Press release: https://ag.ny.gov/press-release/2024/attorney-general-james-sues-citibank-failing-protect-and-reimburse-victims

Direct link to complaint: https://ag.ny.gov/sites/default/files/2024-01/citi-complaint.pdf

#FinSec #infosecurity #cybersecurity #UCC #enforcement

YourAnonRiots, to wordpress Japanese
@YourAnonRiots@mstdn.social avatar

Heads up: Over a million sites are affected by a critical bug in the All-In-One Security (AIOS) plugin.

It stored user passwords in plaintext, posing a risk if admins reused them on other services.

https://thehackernews.com/2023/07/aios-wordpress-plugin-faces-backlash.html

mysk, to infosec

Security ProTip: If you have already enabled syncing in Google Authenticator and now changed your mind and want to use the app offline, opting out won't delete your tokens and their metadata from Google servers.

To remove your data from the cloud and use the app offline, you need to follow these steps:

1- Make sure syncing is active

2- Either back up the existing tokens by exporting them, or invalidate them by requesting new ones from each service (don't scan the new QR codes in this app yet)

3- Delete all the accounts from your Google Authenticator, this will let the app sync the deletion action with the cloud, and remove the accounts from the cloud, too

4- Now tap on your profile picture in the upper-right corner and tap on "Use Authenticator without an account" as shown in the screenshot*

5- Import the existing tokens from your backup or add new ones

*Hopefully the redaction is right this time 🙈

alex_02, to infosec

For anyone with a youtube channel specifically for hacking/infosec... did you guys start out with a set path?

I'm going to be working off of some very budget setup, but my idea is to start out small with 15 to 20 minute videos. I want to cover several topics specifically hacking on a budget (I have a lot to share on this), hardware, osint, talk about recent news possibly, talk about recent hacks by gangs, apts, hacking groups, etc.

I'm kind of going off into the unknown with this and not expecting to become big anytime soon, but I want to at least try.

I am also trying to figure out what to do with a Patreon and at the moment I don't even have a phone plan so not even sure if the content I will make will be any good.

Any input would be appreciated.

alex_02, to infosec

Might be a stupid question, but brainstorming and I can't find the answers that I am looking for. Anyone know for sure if you have to "poison" to get the hash with responder?

PogoWasRight, to ukteachers
PogoWasRight, to random
Cruthachail, to privacy

Liberate your digital freedom today.

Twitter.
https://nitter.net
https://fediverse.observer

YouTube.
https://tube.raccoon.quest
https://piped.video
https://joinpeertube.org

Google Map.
https://openstreetmap.org

Reddit.
https://libreddit.kavin.rocks
https://teddit.pussthecat.org
https://join-lemmy.org

TikTok.
https://tok.artemislena.eu

Google Search.
https://startpage.com

Google Translate.
https://translate.metalune.xyz

Imgur, Image storage site.
https://pixelfed.org

Wikipedia.
https://wikiless.org

Discord, Guilded, etc.
https://chat.techsaviours.org
https://xmpp.org/about
https://www.jabber.org/faq.html#jabber
https://www.mumble.info/about

Microsoft Teams, Slack, Zoom, etc.
https://jitsi.riot.im
https://opentalk.eu/en

Microsoft Word, Pages, etc.
https://www.onlyoffice.com/en/download-docs.aspx?from=default#docs-community
https://www.libreoffice.org/download/download-libreoffice

Internet Browsers.
https://floorp.app/download (Firefox-based)
https://github.com/ungoogled-software/ungoogled-chromium (Chromium-based)
https://brave.com (Chromium-based)

Emails.
https://mailfence.com/registration
https://app.tuta.com/login?noAutoLogin=true&keepSession=true

Operating Systems.
https://www.opensuse.org
https://linuxmint.com/about.php
https://grapheneos.org
https://calyxos.org
https://lineageos.org

Password Managers.
https://vault.bitwarden.com/#/register?layout=default
https://keepass.info/download.html

Privacy Guides.
https://www.privacyguides.org/en/about
https://thenewoil.org/en/about

Useful services.

https://joinmobilizon.org/en/#what-is-mobilizon
https://joinbookwyrm.com
https://cryptpad.org/about
https://microbin.eu
https://vikunja.io

#privacy, #privacymatters, #cybersecurity, #cybersec, #infosecurity, #infosec, #opensource, #oss, #freesoftware, #freedom.

  • Removed #proton because of its recent compromise in privacy.
YourAnonRiots, to random Japanese
@YourAnonRiots@mstdn.social avatar

Even experienced compliance professionals can find the GDPR difficult to navigate.

Don’t worry if you're struggling to comprehend the regulation, Josh Breaker-Rolfe has a helpful summary to help you understand it.⤵️

https://hubs.la/Q01Zz4R80

redhotcyber, to Symfony Italian
@redhotcyber@mastodon.bida.im avatar

Adobe Magneto: una pericolosa minaccia RCE per i siti di e-commerce

Gli specialisti di Sicurezza Informatica hanno avvertito che gli #hacker stanno già sfruttando una nuova #vulnerabilità in #Magento (CVE-2024-20720) e l'utilizzatore per implementare una #backdoor persistente sui siti di e-commerce.

#redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #cybersecurityawareness #cybersecuritytraining #cybersecuritynews #infosecurity

https://www.redhotcyber.com/post/adobe-magneto-una-pericolosa-rce-minaccia-i-siti-di-e-commerce/

PogoWasRight, to random

Admiration for my friend @amvinfe for his persistence in following up on the attack of 2020 and trying to get accurate info on the education sector victims. See his "final chapter" blog post at:

https://www.suspectfile.com/blackbaud-data-breach-2020-2023-the-final-chapter/

@douglevin @funnymonkey

PogoWasRight, to random

Does anyone proofread anymore? This is from a breach notification letter from a county agency. The notification letter is dated January 19, 2023 and states, in relevant part:

"What Happened?
DPSS is writing to you because of a privacy incident that occurred on January 19, 2023 at the County of Los Angeles (County) DPSS. A County employee accessed your personal information contained in our electronic systems without a legitimate business reason. County personnel discovered the incident during an internal investigation on December 27, 2022. "

And of course, they don't explain why the lengthy gap between discovery and notification -- unless the notification really was sent on January 19 and they are just first sending it to the state now? What a confusing submission.

🤔 🤦‍♀️

9to5linux, to debian
@9to5linux@floss.social avatar

Bookworm and Bullseye Are Now Patched Against the “Downfall” and “INCEPTION” CPU Flaws, Update Now https://9to5linux.com/debian-systems-now-patched-against-downfall-and-inception-cpu-flaws

@debian

9to5linux, to hacking
@9to5linux@floss.social avatar

Kali Linux 2024.1 Ethical Distro Is Now Available for Download with Kernel 6.6 LTS and New Look https://9to5linux.com/kali-linux-2024-1-penetration-testing-distro-is-here-with-linux-6-6-lts-new-look

alex_02, to infosec

Uh my brain isn't working right now, but does anyone know of sites to buy domains that aren't namecheap or godaddy?

I want to buy two for labs.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines