Infosec

MatsurikaGaming, German
@MatsurikaGaming@troet.cafe avatar

Und jetzt nochmal für alle zum Mitklatschen:

MAN 👏
ZEIGT 👏
MENSCHEN 👏
NICHT 👏
FÜR 👏
DAS 👏
MELDEN 👏
VON 👏
SICHERHEITSLÜCKEN 👏
AN! 👏

Man bedankt sich und fixt seinen Scheiß zeitnah.

Koelnmesse vs IT-Student: Sicherheitsbehörde will ’schlichten‘
https://www.gameswirtschaft.de/gamescom/koelnmesse-gamescom-bsi-sicherheitsluecke-030524/

gbraad,
@gbraad@mastodon.social avatar

"XZ Utils cyberattack likely not an isolated incident"

I can attest, as I have been approached before, to rid of my project for continued development, as that was 'in the interest of the user base'.

Also, others have tried to persuade me to sell my chrome extension.

gbraad,
@gbraad@mastodon.social avatar

I admit I was not in the best spot, but I also realized it would not have helped others if I had given in. A large 'crypto' exchange was even linking to my repos for 'support', and they caused a shit ton of extra work.

smithhenry, (edited )

order oxycodone Online no prescription Best Deals & Fast Shipping

Order Here :- https://cheapbuyoxycodoneonline.mystrikingly.com/

ordering oxycodone without a prescription and finding the best deals with fast shipping, it's important to remember the risks involved. Oxycodone is a potent opioid pain medication that should only be used under the supervision of a healthcare professional due to its potential for addiction and abuse. It's always best to prioritize your health and safety by consulting with your doctor before taking any medications, especially those as powerful as oxycodone. Remember, your well-being is the top priority, so don't hesitate to reach out for professional guidance and support.

<p>https://i.postimg.cc/rpfd88pR/new.png</p>

Visit More Products Here

https://community.avid.com/members/get_2D00_vicodin_2D00_online/default.aspx
https://community.avid.com/members/Buy-Oxycodone-40mg-Online/default.aspx
https://community.avid.com/members/Purchase-Xanax-Online/default.aspx
https://community.avid.com/members/Buy-Dilaudid/default.aspx
https://community.avid.com/members/Buy-Percocet/default.aspx
https://community.avid.com/members/Diazepam-Tablet/default.aspx
https://community.avid.com/members/Vyvanse-Online/default.aspx
https://community.avid.com/members/Buy-Codeine/default.aspx
https://community.avid.com/members/Ambien-pills/default.aspx
https://community.avid.com/members/Diazepam-10mg/default.aspx
https://community.avid.com/members/Percocet-pill/default.aspx
https://community.avid.com/members/Buy-Hydrocodone-Pills/default.aspx
https://community.avid.com/members/Percocet-10mg/default.aspx
https://community.avid.com/members/Diazepam-PILL/default.aspx
https://community.avid.com/members/Oxycontin-medicine/default.aspx
https://community.avid.com/members/SomaOnline/default.aspx
https://community.avid.com/members/Online-Alprazolam/default.aspx
https://community.avid.com/members/Buy-Adderall/default.aspx
https://community.avid.com/members/Xanax-2mg-Online/default.aspx
https://community.avid.com/members/Tramadol-buy/default.aspx

arzookanak,

https://www.addonface.com/arzookanak
https://www.pinterest.ie/arzookanak/
https://www.businesssoftwarehelp.com/solutioneer/arzoo-kanak
https://startuppoint.copiny.com/question/details/id/834421
https://production.openhumans.org/member/arzookanak/
https://propeller.hu/tagok/arzookanak/adatlap
https://forum.tinycontrol.pl/member.php?action=profile&uid=11514
https://www.blafusel.de/phpbb/memberlist.php?mode=viewprofile&u=10141
https://www.lorraineaucoeur.com/userinfo.php?uid=67347
https://usdinstitute.com/forums/users/arzookanak/
https://miro.com/app/board/uXjVN-6LaJQ=/
https://forumreklamowe.com/User-arzookanak
https://www.blogger.com/profile/07398303351710938780
https://fr.blurb.ca/user/arzookanak
https://calendly.com/arzookanak555/meandyou
https://sanjose.granicusideas.com/ideas/chandigarh-top-class-call-girl-service
https://www.forteforums.com/members/arzookanak.117782/#about
https://pornyteen.com/user/arzookanak-19405/
https://hellomahi.com/top-class-chandigarh-call-girl-service/72720
https://dto.to/u/1952936
https://git.hatthieves.es/arzookanak
https://www.kanyetothe.com/members/arzookanak.1753218/#about
https://vandogtraveller.com/forum/index.php?action=profile;area=summary;u=76584
https://www.kincony.com/forum/member.php?action=profile&uid=4422
https://www.trysmallbiz.com/food-dining/arzoo-kanak
https://www.bunity.com/arzoo-kanak-agency
https://7tdmjpf5yuwu.jobboard.io/employers/2943522-arzoo-kanak-agency
https://lkc.hp.com/member/arzookanak
https://www.theconservativelibertariansociety.com/profile/arzookanak555/profile
https://www.nissanclub.com/members/arzookanak.432045/#about
https://co.pinterest.com/arzookanak/
https://penposh.com/arzookanak
https://limia.jp/user/5ufeemq/
https://perfect2perfection.in/author/arzookanak/
https://pornyteen.com/user/arzookanak-19405/
https://arzookanak.flazio.com/
https://olomouc.hnutiduha.cz/nase-aktivity/ekoporadna/forum/odpady/chandigarh-top-class-call-girl-service/
https://www.oursmallkingdom.com/profile/arzookanak555/profile
https://www.maanation.com/arzookanak
https://www.jointcorners.com/arzookanak
https://tecunosc.ro/arzookanak
https://www.vtforeignpolicy.com/author/arzookanak/
https://www.christifriesen.com/profile/arzookanak555/profile
https://wto.to/marker/arzookanak
https://soundcloud.com/arzoo-kanak
https://www.statscrop.com/www/arzookanak.in
https://qnapandit.com/profile/arzookanak/
https://www.theecofactory.com/profile/arzookanak555/profile
https://forum.squarespace.com/profile/423050-arzookanak/?tab=field_core_pfield_1
https://praktik.copiny.com/question/details/id/834414
https://heylink.me/arzookanak/
https://www.forwhomthecowbelltolls.com/users/arzookanak
https://www.youtube.com/@ArzooKanak
https://www.blurb.co.uk/user/arzookanak
https://www.participatepbchicago.org/profiles/arzoo_kanak/activity
https://www.aberdeen-music.com/profile/81157-arzoo-kanak/?tab=field_core_pfield_11
https://loginza.copiny.com/question/details/id/834415
https://rentry.co/arzookanak01
https://runkit.com/arzookanak/hotprofiles
https://members.boardhost.com/ReGather/msg/1715152781.html
https://hu.pinterest.com/arzookanak/
https://imgur.com/user/arzookanak/about
https://newyorkknicksclub.com/arzookanak
https://olympiquelyonnaisfansclub.com/arzookanak
https://www.euusedgoodstrading.com/arzookanak
https://chandigarhcallgirls4mens.mystrikingly.com/
https://cristianoronaldoclub.com/arzookanak
https://ukluxuryfootballshoe.com/arzookanak
https://www.adrex.com/en/forum/climbing/chandigarh-call-girl-service-38884/
https://www.linkedin.com/in/arzookanak/overlay/contact-info/
https://webcilo.com/user/arzookanak/about
https://praca.uxlabs.pl/author/arzookanak/
https://callgirlsinchandigarh0.godaddysites.com/
https://www.twitch.tv/arzookanak/about
https://www.jigsawplanet.com/arzookanak
https://www.sutori.com/en/user/azroo-kanak
https://adultnode.com/arzookanak
https://grpz.copiny.com/question/details/id/834416
https://xbato.net/user/1952936/arzookanak
https://www.blague-courte.com/elegant-call-girls-in-chandigarh-who-will-completely-satisfie-your-needs
https://apk.tw/space-uid-6272691.html
https://www.freelancelift.com/members/arzookanak/
https://pimpandhost.com/arzookanak/about
https://www.facer.io/user/3ZlKNOQEFT
https://benficafansclub.com/arzookanak
https://intermilanfansclub.com/arzookanak
https://arzookanak.escortbook.com/
https://butik.copiny.com/question/details/id/834418
https://www.pexels.com/@arzoo-kanak-770154148/
https://www.lucseuropeanmeats.ca/profile/arzookanak555/profile
https://www.slideshare.net/slideshow/call-girls-in-chandigarh-free-delivery-cheap-rate/267779247
https://skywarriorthemes.com/arcane/members/arzookanak/
https://www.tripadvisor.com.sg/Profile/arzookanak
https://www.adrex.com/en/forum/climbing/chandigarh-call-girl-service-38884/
https://cloudim.copiny.com/question/details/id/834420
http://ptits.net/boards/t/137297/real-fun-with-vip-chandigarh-call-girls.aspx

mana_z,
@mana_z@mastodon.social avatar

I'm kind of annoyed by VPN ads everywhere. VPNs have some valid use cases, but many of the advertised claims are false.

You don't need a VPN to protect yourself against eavesdroppers on public WiFis. You already have HTTPS for that. This point did make sense ~10 years ago, when HTTPS was not that omnipresent and pushing users to fall back to plain HTTP was much easier, but nowadays...

That lock next to your address bar is much better than any VPN!

pseudonym,
@pseudonym@mastodon.online avatar

From a friend's discord

Viss,
@Viss@mastodon.social avatar

@pseudonym so boeing, basically

vwbusguy,
@vwbusguy@mastodon.online avatar

@pseudonym Hey @garethgreenaway , you might appreciate this.

box464, (edited )
@box464@mastodon.social avatar

I don’t know what is more disappointing. Batgirl’s “hacking” skills or Batman’s password choices.

mkb,
@mkb@mastodon.social avatar

@box464 Disappointing, but hardly surprising. :(

helma, (edited )
@helma@mastodon.social avatar

If I were to do a talk at the information security conference this October in NL, what topic would you want to hear more about? Other suggestions welcome in reply.

@wicca

h3artbl33d,
@h3artbl33d@exquisite.social avatar

@helma

I took the liberty if voting for the surveillance state through the CSAM excuse. If I were to visit a talk, that would have my preference.

I feel like I should mention, within this context, that I am a cisgender male.

@wicca

helma,
@helma@mastodon.social avatar

@h3artbl33d @wicca Thanks!

rysiek,
@rysiek@mstdn.social avatar

Dear Hivemind!

We've seen supply chain attacks where old unmaintained npm packages were taken over and malwared, targeting devs.

We've seen attacks that typosquatted names of popular npm packages to get devs to include these accidentally.

We've seen malicious JS libraries hosted on large CDNs, used in attacks.

Have we seen a case where a JS library / npm package got taken over, malwered, and then published to CDNs in order to target websites that include it?

:boost_ok:

tanepiper,
@tanepiper@tane.codes avatar

@rysiek this is one that terrifies me for almost a decade now. So far haven't seen it, but this is why we are moving to compiled node apps in containers with SBOMs and absolutely no external CDNs

rysiek,
@rysiek@mstdn.social avatar

@tanepiper honestly I am surprised that I was so far not able to find a specific example of this happening.

I do vaguely remember some cryptocurrency websites being targeted that way, but I think the vector was not CDNs but malicious npm dependencies on build time. 🤔

mttaggart,

Your periodic reminder that a Content-Security-Policy that includes cdn.jsdelivr.net is not safe. Any GitHub repo can be loaded via that CDN, so if you find it on a test, prove the point.

Here, have a payload.

mttaggart,

@hrbrmstr I guess? There's plenty of the internet that isn't, and CSPs are still the best defense against XSS.

hrbrmstr,
@hrbrmstr@mastodon.social avatar

@mttaggart except nobody that needs to uses them.

mamabashiirah,

+27603483377 .NO 1 AFRICA INSTANT DEATH SPELL CASTER, DEATH SPELLS CASTING SPECIALIST IN MACEDONIA, AUSTRALIA, TORONTO, ALASKA, MALTA.
+27603483377 Mama bashiirah, I Want my ex to die, I want to kill my enemies, spells to kill enemies, spells to kill my ex-husband, wife, boyfriend, girlfriend, Death spell on someone, death spells that work overnight, death spells for someone to die in an accident. Spells for revenge to cause your enemy to have sleepless nights & frightening dreams. Banish bad dreams & nightmares if someone has cast bad dreams revenge spells. voodoo death spells, voodoo doll spells death spell chant, death spells that work fast, real black magic spells casters , black magic spells see result in days, real black magic spells that work, guaranteed black magic love spells, guaranteed voodoo spells, spell to make someone sick and die, revenge spells that work instantly, real witches for hire, revenge spells on an ex – lover, how to put a spell on someone who hurts you, spell to make someone sick, voodoo spells to hurt someone, spells to curse someone, powerful revenge spells, most powerful death spell, spell to die in your sleep, successful death spell , most powerful voodoo spell caster, in South Africa Monaco Dubai Kuwait Europe Arizona, Arkansas, Colorado, Connecticut, Revenge spells Florida
+27603483377 Mama Bashiirah

drinstant,

WhatsApp +13239854245
Voodoo Revenge death spell
It is a quick death spell that's use to cause heart attack on an enemies overnight and they will pass away instantly.
Voodoo revenge death spell that work fast to kill any witch craft enemies - Revenge Curses Spells it is use to cause pain on an enemies- 
black magic curse removals,this spell is to remove a curse from your marriage, career or business and your family.
 Death Spells That Work Overnight - Death Spell Chant - Death sleep spells to revenge wicked enemies.
SEX Spell
Romantic spell
I want my boyfriend to make me Cum spell.
Black Magic Love Spells- that quick to bring back an Ex Girlfriend Ex Boyfriend Lost lover and Divorce Wife or Husband Back spells. Marriage Spells.Binding love spell
Gay Love spells-Lesbian Love spells
Voodoo Death Spells Black Magic Revenge Spells Black magic revenge spell- spells can be cast on your behalf to curse hurt those you want to cause suffering Curses spells, voodoo revenge spells, spells, powerful revenge spell­s, voodoo revenge & witchcraft revenge spells. Discipline someone with voodoo revenge spells. Get rid on enemies & regain confidence using voodoo revenge spells Voodoo Revenge Spells- Cast voodoo revenge spell on someone who is abusive or has wrong you. Regain the respect of the community & the people whose opinion matters to you with voodoo revenge spells Financial Disaster Revenge Spells Voodoo financial disaster revenge spells to hurt someone financially causing them to lose money, get fired from their job or experience financial disaster .
Revenge Curses Spells Cause someone to suffer in one way or another using revenge curses spell Let misery & suffering befall your enemies using revenge spells Spells To Break A Curse­ Break a curse using these powerful voodoo spells. Reverse a curse, remove a curse or cancel a jinx using powerful black magic voodoo spells.
My 7demonspirits has being providing solutions to many people all over the world.i have been casting love spell and other spell for over 3 decades.
Spain-London-England-United States-Canada-Iran-Iraq-Poland-Netherland-Germany-Denmark-France-Gergia-Turkish-India-China -Africa-Paris-Rome-Italy.
WhatsApp +13239854245
drinstantspellresult@gmail.com

analog_cafe,
@analog_cafe@mas.to avatar

London Drugs, a large local chain of stores that I frequent to buy Polaroid film and coffee from (they also develop and scan) has been hacked.

They've been closed for nearly a week and they say that the customer data (my data) is breached.

This hits close to home.

Meanwhile, getting disclosure out of LD is like pulling teeth.

https://calgary.ctvnews.ca/breach-of-personal-information-a-concern-following-london-drugs-cybersecurity-incident-tech-security-expert-1.6868076

FlohEinstein,
@FlohEinstein@chaos.social avatar

X: "I need SSH access to your server to do make that configuration change."
Me: "OK, send me your public key."
X: "I don't have a public key of that server. You need to send me username and password."
Me: 🤦‍♀️

Nope, you're definitely not tech savvy enough that I would allow you with SSH on my server.

#infosec

FlohEinstein,
@FlohEinstein@chaos.social avatar

@alda please don't tell me that someone ran that to make good use of the cpu?

alda,
@alda@topspicy.social avatar

@FlohEinstein I still suspect the incompetent CTO (who shared his work laptop with his wife for personal use and insisted on using password authentication) was to blame in one way or another.

mcfly, (edited ) German
@mcfly@milliways.social avatar

https://www.securityweek.com/should-cybersecurity-leadership-finally-be-professionalized/

Interesting read but i am not sure if i agree.
Professionalism in this area usually means more compliance and you can't achieve more security with more compliancy.

What do you think?

Venty,
@Venty@chaos.social avatar

@mcfly Compliance in business is what homoeopathy is to science.

nixCraft,
@nixCraft@mastodon.social avatar

Dropbox Sign has been hacked https://sign.dropbox.com/blog/a-recent-security-incident-involving-dropbox-sign Customer's emails, usernames, phone numbers and hashed passwords, in addition to general account settings and certain authentication information such as API keys, OAuth tokens, and multi-factor authentication data stolen by threat actors.

acesabe,
@acesabe@mastodon.social avatar

@nixCraft Sheesh... people still use Dropbox?!

tek,
@tek@todon.eu avatar

A WEB OF SURVEILLANCE
Unravelling a murky network of
spyware exports to Indonesia
by @donncha @drwhax and the Amnesty Security Lab team
https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • infosec
  • slotface
  • kavyap
  • thenastyranch
  • everett
  • tacticalgear
  • rosin
  • Durango
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • InstantRegret
  • Youngstown
  • khanakhh
  • ethstaker
  • JUstTest
  • ngwrru68w68
  • cisconetworking
  • modclub
  • normalnudes
  • osvaldo12
  • cubers
  • GTA5RPClips
  • Leos
  • tester
  • megavids
  • provamag3
  • anitta
  • lostlight
  • All magazines