aeveltstra, to random
@aeveltstra@mastodon.social avatar

Oh dear. https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/

will attempt to hack your network by... using tools built into and intended to make back-ups. But Microsoft blames management tools sold by third-party vendors...

symfonystation, to Symfony
@symfonystation@phpc.social avatar

Explore the @symfonystation news communiqués archive for evergreen content. https://www.symfonystation.com/Communiques/ And please sign up for our newsletter to get the latest news communiqués and original content delivered to your inbox. :symfony: :drupal: :php: :fediverse:

aeveltstra, to ai
@aeveltstra@mastodon.social avatar

Wired reports on prompt injection vulnerabilities and risks: https://www.wired.com/story/chatgpt-prompt-injection-attack-security/

mystique, to random

New report reveals a 121% surge in cybercriminals using legitimate websites to obfuscate malicious payloads

Quote: "71% of malicious payloads sent from compromised accounts were HTML smuggling attacks
51% increase in attacks sent from compromised accounts
Advanced phishing attacks commoditized by crime-as-a-service gangs"

https://www.globenewswire.com/en/news-release/2023/05/25/2675963/0/en/New-report-reveals-a-121-surge-in-cybercriminals-using-legitimate-websites-to-obfuscate-malicious-payloads.html

ianRobinson, to random
@ianRobinson@mastodon.social avatar

Reshaping IT security budgets 2020 v 2025 - Renaissance IT Distributor

https://www.renaissance.ie/reshaping-it-security-budgets-2020-vs-2025/

mttaggart, to infosec

Goofy names notwithstanding, let's not overlook the gravity of this straight-up attack by China on US strategic infrastructure. https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/

tomatospy, to random

This week's Seriously Risky Business is out:

  • G-Men Gone Wild
  • And the industrialisation of BEC

https://srslyriskybiz.substack.com/p/g-men-gone-wild?sd=pf

and there is also a podcast edition too:

https://podcasts.apple.com/au/podcast/srsly-risky-biz-g-men-gone-wild/id1621305970?i=1000614406740

itnewsbot, to random

Chinese state hackers infect critical infrastructure throughout the US and Guam - Enlarge (credit: peterschreiber.media | Getty Images)

A Chines... - https://arstechnica.com/?p=1942057

kpwn, to javascript

I've been posting a ton about lately.

To help you keep track, here is an overview of all the topics covered:

  1. Static Analysis 🔍
    https://infosec.exchange/@kpwn/110242352466343321

  2. Dynamic Analysis 📑
    https://infosec.exchange/@kpwn/110287650959218515

  3. Obfuscation & Deobfuscation 🥸
    https://infosec.exchange/@kpwn/110321624840524023

  4. Hands-On: Analyze Obfuscated Code ✍
    https://infosec.exchange/@kpwn/110361260966659611

  5. Local Overrides 📝
    https://infosec.exchange/@kpwn/110400897211108426

  6. Bypass Code Protection 🥷
    Coming this Saturday ;)

Do you find my content valuable?

🔔 Follow me for more web security content!

🔁 Also, boost this toot to help others!

gcluley, to random
@gcluley@mastodon.green avatar

83C0000B: The error code that means a software update bricked your HP printer.

Read more in my article on the Bitdefender blog: https://www.bitdefender.com/blog/hotforsecurity/83c0000b-the-error-code-that-means-a-software-update-bricked-your-hp-printer/

agent0x0, to random

Does the Hacker Manifesto still apply to cybersecurity today? Read my latest blog to find out!

https://spylogic.net/2023/05/the-legacy-of-the-hacker-manifesto/

(This is also my first blog post since 2018! 🤯)

0xor0ne, to infosec

Nice free course by Cornell university for learning a couple of things about compilers and programming languages implementations

https://cs.cornell.edu/courses/cs6120/2020fa/self-guided/

Github repo: https://github.com/sampsyo/cs6120

image/jpeg
image/jpeg

rodtrent, to random

Learn to defend against threats with Microsoft Defender and Microsoft Sentinel https://rodtrent.com/ys9

PogoWasRight, to infosec

Nokowaya also has some listings I have not seen elsewhere, including a data dump with sensitive info allegedly from Wyoming County Community Health System in New York. They claim to have exfiltrated 150 GB of files.

There is no notice on the health system's site. I have reached out to them and will update when I find out more.

jmamblat, to infosec
evawolfangel, to random German
@evawolfangel@chaos.social avatar

Klingt wie mein letzter Artikel, ist aber neu: Wieder hat eine Gesundheits-App Daten verloren. 🥺 Langsam werde ich zugegeben ungeduldig. Würde gerne mal wieder was Neues schreiben. Und mir nicht die persönlichen Dramen ausmalen müssen, die schlechte IT-Sicherheit vor allem in so sensiblen Bereichen verursacht.
Lest es bitte trotzdem und sensibilisiert euer Umfeld. Ich wäre derzeit wirklich vorsichtig mit Gesundheitsapps aller Art.
https://www.zeit.de/digital/datenschutz/2023-05/sicherheitsluecke-app-gesundheit-diagnose-hacker/komplettansicht

kpwn, to javascript

web apps requires you to analyze their .

Benefit from my experience of 5 years of pentests!

👈 The last thread covered how to work with local overrides.

👉 This Saturday's thread shows you how to bypass code protection measures.

➡️ Follow me to not miss a bit!

andrazaharia, to random

I was -1 years old when The Hacker Manifesto was published, but its influence has traveled through decades to reach you today. Its spirit continues to galvanize specialists and inspire fiends. But why does this happen?

👉 Join me and the thoughtful @agent0x0 as we dive into the depths of hacker culture and the driving forces behind it.

This episode wraps up season 3 of the Cyber Empathy ! https://cyberempathy.org/episodes/ethical-hackers-legacy-hacker-manifesto

Keep your podcast app open for season 4. It's gonna be a good one!

dantemercurio, to infosec
@dantemercurio@ioc.exchange avatar
fifonetworks, to random

Cybersecurity professionals who promote fear are doing harm to overall cybersecurity awareness training efforts.

As an example, I received this inquiry from a person who was unnecessarily afraid to use a legitimate payment system. Read their question and my reply below:

"Hi Bob, I have a tech question for you. I just had my car serviced at the dealer. They offered a pickup and return service (of the car) which I used, so I did not physically have to go there. When they were done they texted me a copy of the bill and there was a link to make the payment. Since I wasn’t sure how safe that was I called and made the payment, but for future reference I thought I’d ask you if it is a safe/secure way to pay.
Thanks"

My reply:
"Yes! It's safe and secure to use a link in a text message, or QR code, given to you directly by a local business. That business is paying a transaction fee to use an online credit card payment services provider."

Instead of fostering fear, teach people how to distinguish between legitimate payment links and payment links from scammers.

Empower them.
Don't intimidate them.

#callmeifyouneedme #fifonetworks

#cybersecurity #fintech #scams #phishing #smishing #training

avoidthehack, to infosec

Google are getting worse, at your expense

They're also concerns... especially the search engine sponsored results (which are paid ads).

https://proton.me/blog/google-ads

0xor0ne, to infosec

Nice blog post showing how to analyze and produce a PoC for CVE-2022-42475 (heap-based buffer overflow vulnerability in FortiOS SSL-VPN)

https://blog.scrt.ch/2023/03/14/producing-a-poc-for-cve-2022-42475-fortinet-rce/

image/jpeg
image/jpeg

cybercareersblog, to infosec
cybercareersblog, to infosec
tristan, to random

For anyone even vaguely interested in infosec, I highly recommend the Darknet Diaries podcast. Even if you're not deep in the weeds of security, there's lots to learn for people that like to know about the darker side of the internet.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines