infosecsidekick, to infosec

It was super fun to interview @jerry for this week's episode of the Infosec Sidekick Podcast!

I had wanted to do this a while back; when the heat of the twitter migration was taking place, but I almost feel like now was a better time.

With the dust somewhat settled, @jerry and I talk about Information Sharing, Community Building, and how Mastadon plays a role in that.

I genuinely appreciate this conversation and hope it can provide you some value and entertainment throughout your week.

You will be sure to find gems in this episode, such as the unlikely comparison to twitter vs mastadon as Monsters Inc. Power Generation (don't ask, just listen lol)

To Listen -> https://www.infosecsidekick.com/p/building-a-cyber-security-community#details

9to5linux, to debian
@9to5linux@floss.social avatar

Bookworm and Bullseye Are Now Patched Against the “Downfall” and “INCEPTION” CPU Flaws, Update Now https://9to5linux.com/debian-systems-now-patched-against-downfall-and-inception-cpu-flaws

@debian

realn2s, (edited ) to Cybersecurity

Dear #infosecurity crowd,

I would like to hear if you know the #OpenSpace conference format.

Please #boost for reach

#cybersecurity

Edit: Thank you all for boosting and answering.
I would love to make the Open Space format better known in the cybersecurity context. I think it is a valuable addition to existing formats such as traditional conferences or #BSides

If you would like to learn more about Open Space see my follow up posts

If you participated in Open Space events (in any domain) please share your experience.

PogoWasRight, to privacy

Today's reminder of your insider threat:

Deputy U.S. Marshal Pleads Guilty to Obtaining Cell Phone Location Information Unlawfully:
https://www.databreaches.net/deputy-u-s-marshal-pleads-guilty-to-obtaining-cell-phone-location-information-unlawfully/

Polynomial_C, to infosec
@Polynomial_C@mastodon.social avatar
alex_02, to OSINT

Apparently spiderfoot got bought out and I don't know how much longer the github project will be in a working state. Found two alternatives I want to try, but been thinking about writing potentially my own.

One of the issues I've found with sf is the sheer number of modules that frankly aren't really efficient and/or cost money for the api. Started looking at a bunch of apis for some specific things I like to use osint for and going to try to figure out which ones are both effective and efficient. Will be a fun project I think to also hone in my research skills, but I anticipate it will take a while to design and build since I want to do this one right and properly.

In the mean time the alternatives I am looking at are https://github.com/jerlendds/osintbuddy and https://github.com/AccentuSoft/LinkScope_Client which I need to test in my lab first.

Marcociappelli, to technology

“The saddest aspect of life right now is that science gathers knowledge faster than society gathers wisdom.”
— Isaac Asimov

https://www.marcociappelli.com

alex_02, to OSINT
@alex_02@infosec.town avatar

Oh, isn't this lovely. So apparently these goons:

  • Mike Lindell (My Pillow Guy)

  • Jack Posobiec (White supremacist that believes in conspiracies such as the white genocide conspiracy)

  • Jim Jordan (One of the main players to planning Jan 6th)

  • Matt Gaetz (A pedophile and operated a sex ring, but never was charged (fuck you justice department))

  • Steve Bannon (The fraudster that scammed trump supporters for a fake company to build Trump's wall)

-Vivek Ramaswamy (New face, but is young and likable. Dropped out of presidential nominee bid, but probably got a promise of a cushy job position in Trump's administration, from looks of things)

  • JD Vance (Didn't originally like Trump, but changed his opinion in 2018 and started spewing out many points from The Heritage, The Family Leader, etc)

  • Tommy Tuberville (One of the senators that helped to overturn the presidential election in 2020 and closely allied with Trump)

  • Kristi Noem (Governor of South Dakota, that is a terrible governor and well... I don't want to go into too much right now)

All seem to possibly be conspiring to overthrow the government. Articles are here:

Other potential people here: www.digital.cpac.org/speakers-dc2024

And a video: crooksandliars.com/cltv/2024/02/quelle-surprise-jack-posobiec-big-fan

This is all going off of this screenshot, which is a direct threat and should be taken seriously. I quickly put together this and uploaded what I could grab.

Uploaded to Mega: mega.nz/file/ioQGmRBD#FmcuZjDqCpVhvaFMclGsBgyHjPu8czZTokSz3S4H3fo

Please for FFS. Take this seriously. #osint #osint4good #republican #trump #theheritage #theheritagefoundation #gop #project2025 #traitors #traitortrump #infosec #infosecurity #cybersec #cybersecurity

9to5linux, to linux
@9to5linux@floss.social avatar
PogoWasRight, to ukteachers

Because these posts scroll away, I have posted something on DataBreaches.net about the discrepancies between what Raptor Technologies has told school districts and WIRED and what we know about the incident -- and what we don't know yet:

https://www.databreaches.net/raptor-technologies-unsecured-blob-exposure-was-worse-than-they-acknowledged-heres-what-we-know-and-dont-know-so-far/

Someone might want to ask the U.S. Education Department and the to look into this incident.

@brett @allan @douglevin @michaelfklein @funnymonkey

redhotcyber, to IT Italian
@redhotcyber@mastodon.bida.im avatar
jwf, to opensource
@jwf@floss.social avatar
mysk, to privacy
@mysk@mastodon.social avatar

iOS 17.5 fixes the marketplace URI bug that we showed it could result in tracking users across websites:

CVE-2024-27852

https://support.apple.com/en-us/HT214101

redhotcyber, to Symfony Italian
@redhotcyber@mastodon.bida.im avatar

Adobe Magneto: una pericolosa minaccia RCE per i siti di e-commerce

Gli specialisti di Sicurezza Informatica hanno avvertito che gli #hacker stanno già sfruttando una nuova #vulnerabilità in #Magento (CVE-2024-20720) e l'utilizzatore per implementare una #backdoor persistente sui siti di e-commerce.

#redhotcyber #online #it #web #ai #hacking #privacy #cybersecurity #cybercrime #intelligence #intelligenzaartificiale #informationsecurity #ethicalhacking #dataprotection #cybersecurityawareness #cybersecuritytraining #cybersecuritynews #infosecurity

https://www.redhotcyber.com/post/adobe-magneto-una-pericolosa-rce-minaccia-i-siti-di-e-commerce/

redhotcyber, to Software Italian
@redhotcyber@mastodon.bida.im avatar

Attacco agli ATM riuscito! Un Tasso del 99% di Efficacia Spaventa tutte le Banche Europee

Nello spazio si sta diffondendo attivamente un nuovo tipo di . Il suo tasso di successo, secondo i suoi autori, raggiunge il 99%.

Questo dannoso, chiamato “EU ATM Malware”, è in grado di quasi tutti gli sportelli in e circa il 60% degli sportelli bancomat in tutto il mondo, il che rappresenta una significativa per la sicurezza bancaria globale..

https://www.redhotcyber.com/post/attacco-agli-atm-riuscito-un-tasso-del-99-di-efficacia-spaventa-tutte-le-banche-europee/

redhotcyber, to Wisconsin Italian
@redhotcyber@mastodon.bida.im avatar
redhotcyber, to IT Italian
@redhotcyber@mastodon.bida.im avatar
YourAnonRiots, to windows Japanese
@YourAnonRiots@mstdn.social avatar

The Windows Security Account Manager (SAM) is an essential yet often overlooked component of Windows security.

Dilki Rathnayake breaks down its role and importance for every Windows user:⤵️

https://hubs.la/Q02gTT0H0

#Windows #AccountManagement #Infosecurity

YourAnonRiots, to random Japanese
@YourAnonRiots@mstdn.social avatar

Tools of the Trade: Anti- scanning, WAFs, and sandboxing alone aren't sufficient for protecting against malicious uploads.

https://thehackernews.com/2024/03/demystifying-common-cybersecurity-myth.html

YourAnonRiots, to azure Japanese
@YourAnonRiots@mstdn.social avatar

🛡️ Researchers uncover details of 3 vulnerabilities in #Azure HDInsight's Apache Hadoop, Kafka, and Spark services that could have allowed attackers root access and system disruption.

https://thehackernews.com/2024/02/high-severity-flaws-found-in-azure.html

#cybersecurity #infosecurity #cloudsecurity

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

Ever wondered why cyber attacks seem unstoppable? It's the identity blind spots! Check out how Silverfort's platform fills this crucial gap, ensuring rapid detection and containment of compromised accounts.

https://thehackernews.com/2024/02/why-are-compromised-identities.html

#cybersecurity #infosecurity

btanderson, to infosec

In every instance that I’ve discovered shadow IT in an environment, I’ve eventually found someone in IT who knew about it and/or implicitly/explicitly enabled it. I hate to think it, and I understand there are always reasons but…

The call is coming from inside the house.

That means Shadow IT isn’t really in the shadows, and the solution has to start inside IT itself.

#InformationSecurity
#InfoSec
#InfoSecurity

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

Navigating the complexities of cyber threats requires more than just out-of-the-box settings. Learn how intent-based configurations can lead to more resilient cybersecurity frameworks.⤵️

https://hubs.la/Q02j-6y50

YourAnonRiots, to Cybersecurity Japanese
@YourAnonRiots@mstdn.social avatar

#Tripwire Enterprise seamlessly integrates with IBM i without the need for extensive code changes.

Ron Adams details the simple setup process using PASE and how it maximizes efficiency and security:⤵️

https://hubs.la/Q02hYX7g0

#IBMi #Infosecurity #Cybersecurity

Cruthachail, to privacy

Liberate your digital freedom today.

Twitter.
https://nitter.net
https://fediverse.observer

YouTube.
https://tube.raccoon.quest
https://piped.video
https://joinpeertube.org

Google Map.
https://openstreetmap.org

Reddit.
https://libreddit.kavin.rocks
https://teddit.pussthecat.org
https://join-lemmy.org

TikTok.
https://tok.artemislena.eu

Google Search.
https://startpage.com

Google Translate.
https://translate.metalune.xyz

Imgur, Image storage site.
https://pixelfed.org

Wikipedia.
https://wikiless.org

Discord, Guilded, etc.
https://chat.techsaviours.org
https://xmpp.org/about
https://www.jabber.org/faq.html#jabber
https://www.mumble.info/about

Microsoft Teams, Slack, Zoom, etc.
https://jitsi.riot.im
https://opentalk.eu/en

Microsoft Word, Pages, etc.
https://www.onlyoffice.com/en/download-docs.aspx?from=default#docs-community
https://www.libreoffice.org/download/download-libreoffice

Internet Browsers.
https://floorp.app/download (Firefox-based)
https://github.com/ungoogled-software/ungoogled-chromium (Chromium-based)
https://brave.com (Chromium-based)

Emails.
https://mailfence.com/registration
https://app.tuta.com/login?noAutoLogin=true&keepSession=true

Operating Systems.
https://www.opensuse.org
https://linuxmint.com/about.php
https://grapheneos.org
https://calyxos.org
https://lineageos.org

Password Managers.
https://vault.bitwarden.com/#/register?layout=default
https://keepass.info/download.html

Privacy Guides.
https://www.privacyguides.org/en/about
https://thenewoil.org/en/about

Useful services.

https://joinmobilizon.org/en/#what-is-mobilizon
https://joinbookwyrm.com
https://cryptpad.org/about
https://microbin.eu
https://vikunja.io

#privacy, #privacymatters, #cybersecurity, #cybersec, #infosecurity, #infosec, #opensource, #oss, #freesoftware, #freedom.

  • Removed #proton because of its recent compromise in privacy.
  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • ngwrru68w68
  • provamag3
  • magazineikmin
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • anitta
  • Leos
  • tester
  • JUstTest
  • All magazines