symfonystation, to Symfony
@symfonystation@phpc.social avatar

This week's Symfony Station newsletter exploring Symfony, Drupal, PHP, Cybersecurity, and the Fediverse is out. https://mailchi.mp/de62fe0833cf/explore-this-weeks-symfony-drupal-php-cybersecurity-and-fediverse-news If you like what you see, subscribe via the button in the top left corner and boost this post. Thanks for following us and enjoy our development-focused curation.

SecureOwl, to infosec
AlexJimenez, to random
@AlexJimenez@mas.to avatar
symfonystation, to Symfony
@symfonystation@phpc.social avatar

Symfony Station is your source for Symfony, Drupal, PHP, Cybersecurity, and Fediverse news. https://www.symfonystation.com Contact us to let us know what you want to be covered. And while you are there, please sign up for our "newsletter" to get the latest news communiques and original content delivered to your inbox. Thanks for following us on Mastodon. :symfony: :elephpant_purple: :drupalicon: :mastodon: :fediverse: 🇺🇦

PogoWasRight, to infosec

(SCOOP) Unwelcome guest: Trigona ransomware group claims they've taken up residence in Unique Imaging's network:

https://www.databreaches.net/unwelcome-guest-trigona-ransomware-group-claims-theyve-taken-up-residence-in-unique-imagings-network/

If an entity decides to ignore contacts or demands from attackers, that's somewhat understandable. But if the threat actors added you to their leak site, maybe you should say something?

@brett @allan @aj_vicens @campuscodi @lawrenceabrams

symfonystation, to Symfony
@symfonystation@phpc.social avatar

Explore the February 24, 2023 @symfonystation Communiqué of Symfony, Drupal, PHP, Fediverse, and Cybersecurity news. https://www.symfonystation.com/Symfony-Station-Communique-24-February-2023 :symfony: :elephpant_purple: :drupalicon: :wordpress: :mastodon: :fediverse: :php: :phpunit: :mariadb: :laravel: :apiplatform: :phpstan: 🇺🇦

0x58, to infosec

Dallas was hit with a ransomware attack that brought down its Police Department and City Hall websites on May 3rd.

https://www.securityweek.com/ransomware-attack-affects-dallas-police-court-websites/

gcluley, to random
@gcluley@mastodon.green avatar
0xor0ne, to gaming
arpwatch, to random
@arpwatch@ioc.exchange avatar

Italian water supplier serving 500,000 people hit with ransomware attack

https://therecord.media/italian-water-supplier-ransomware-attack-disruptions-medusa

avoidthehack, to infosec

1Password explains scary Secret Key and change alerts

https://www.bleepingcomputer.com/news/security/1password-explains-scary-secret-key-and-password-change-alerts/

According to 1Pass, due to service maintenance/disruption - not a breach.

shortridge, to infosec
@shortridge@hachyderm.io avatar

cybersecurity loves Sun Tzu quotes so I’m reverse uno carding with this post on why he would actually be disappointed in the industry: https://kellyshortridge.com/blog/posts/sun-tzu-wouldnt-like-the-cybersecurity-industry/

I am NOT saying we should bring Sun Tzu quotes back! I AM suggesting we “where is your god now” as much harmful folk wisdom as we can — fighting fire with fire, if fire was appeal to authority

anyway enjoy the spice xx

InfoSecSherpa, to infosec

Read InfoSecSherpa's and News Roundup for Wednesday, May 3, 2023 🛰️📡

Features the Via Satellite article by Rachel Jewett, "U.S. Senators Reintroduce Legislation on Commercial Satellite ."

https://infosecsherpa.medium.com/infosecsherpas-news-roundup-for-wednesday-may-3-2023-bc16f507ca04

YourAnonRiots, to random Japanese
@YourAnonRiots@mstdn.social avatar

Chinese state-sponsored hacking outfit Earth Longzhi, a subgroup within , has launched a new campaign targeting government, healthcare, tech & manufacturing entities in Taiwan, Thailand, the Philippines, and Fiji.

https://thehackernews.com/2023/05/chinese-hacker-group-earth-longzhi.html

jbqueru, to opensource
@jbqueru@fosstodon.org avatar

I wrote a quick something about the draft EU Cyber Resilience Act and its interaction with the practice of publishing source code history: https://www.linkedin.com/posts/jbqueru_cyber-resilience-act-activity-7059571610034339840-dh3w

0x58, to infosec

🔥 Hot off the press! Co-authored blog with esteemed colleague Sambit Misra on SecurityIntelligence.com about SaaS Security Posture Management: *"Is Your Critical SaaS Data Secure?"*¨

https://securityintelligence.com/posts/is-your-critical-saas-data-secure/

avoidthehack, to random

Some of you might have noticed I launched a Ko-Fi page. Some users have expressed wanting to tip/support without using affiliate links (totally understandable) in the past, so I set this up. It also let's me give extras!

Couldn't in my conscious mind use Patreon, despite it's popularity. I still haven't forgiven them for firing their entire team. 😱

https://ko-fi.com/avoidthehack/tiers

cybercareersblog, to infosec
insiderua, to random Ukrainian
@insiderua@social.kyiv.dcomm.net.ua avatar

✅ Запустили Гарячу лінію з цифрової безпеки Nadiyno https://nadiyno.org/ в публічний простір Києва

MichaelBTech, to infosec

I've been hearing some great things about Delete Me as I've been on this journey of removing my digital footprint within data brokers/whitepages.

Have any of you used "Delete Me"?

https://joindeleteme.com/refer?coupon=RFR-224729-J9WF4X

0x58, to infosec

Researchers at Meta have seen a rise in ChatGPT-themed attacks, the company said in an overview of cybersecurity issues on its platforms.

https://cyberscoop.com/chatgpt-scam-facebook-meta-hackers-malware/

sophos, to random

Cyber insurance is a critical part of a strategy, but weak cyber defenses can negatively impact policy terms. Our new U.S. partnership with Measured Analytics and Insurance allows customers to combine strong with secure coverage. Learn more: https://bit.ly/3LplZNH

0x58, to infosec

Great write-up by @0xtdec on the risk management, its threat model and security failure modes 👇

https://int3.substack.com/p/how-does-ai-fail

0x58, to infosec

Meanwhile, in the 's world.. 🔒

1Password says a recent incident that caused customers to receive notifications about changed passwords was the result of service disruption and not a security breach.

The company first revealed in an incident report five days ago that the notifications were erroneous and linked to routine database maintenance scheduled on Thursday, April 27th.

Today, 1Password chief technology officer (CTO) Pedro Canahuati provided more details and said the customers' information was unaffected.

https://www.bleepingcomputer.com/news/security/1password-explains-scary-secret-key-and-password-change-alerts/

shibashecurity, to random

To me, this "GovAssure" is just the UK Government putting a branding wrapper around NCSC's CAF, so they can be "seen to be doing something"

Am I just being overly cynical?

Reading the bit in the middle particularly:

"
GovAssure introduces a number of changes in the way government protects itself from cyber threats. These include:

  • Using NCSC’s Cyber Assessment Framework (CAF) to review the assurance measures all government departments have. The framework includes measures such as setting out indicators of good practice for managing security risk and protecting against a cyber attack and was designed for making critical national services resilient to attack.

  • Departments will also be assessed by third parties to increase standardisation and validate results.

  • Centralised cyber security policy and guidance to help government organisations identify best practice.
    "

Aren't these things already happening? Are departments currently not being assessed by third parties? Hasn't the NCSC already got "centralised cyber security policy and guidance" all covered off?

Apart from pure branding, what's actually new here?

https://www.gov.uk/government/news/government-launches-new-cyber-security-measures-to-tackle-ever-growing-threats--2

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • magazineikmin
  • everett
  • khanakhh
  • slotface
  • InstantRegret
  • Durango
  • Youngstown
  • kavyap
  • mdbf
  • DreamBathrooms
  • osvaldo12
  • thenastyranch
  • rosin
  • JUstTest
  • provamag3
  • ethstaker
  • modclub
  • GTA5RPClips
  • tacticalgear
  • cisconetworking
  • cubers
  • ngwrru68w68
  • megavids
  • Leos
  • normalnudes
  • tester
  • lostlight
  • All magazines