jsrailton, to poland
@jsrailton@mastodon.social avatar

NEW: second judge in reportedly confirmed as spyware victim.

Appeals court judge told reporter her responsibilities included classified cases where wiretapping was used.

Poland's spyware reckoning continues.

[PL, machine trans.]
Story: https://oko.press/wiemy-o-drugim-polskim-sedzi-inwigilowanym-pegasusem-to-sedzia-apelacyjna-z-krakowa-news-oko-press

gtbarry, to Canada
@gtbarry@mastodon.social avatar

LockBit says they stole data in London Drugs ransomware attack

the LockBit ransomware gang claimed they were behind the April cyberattack on Canadian pharmacy chain London Drugs and is now threatening to publish stolen data online after allegedly failed negotiations

https://www.bleepingcomputer.com/news/security/lockbit-says-they-stole-data-in-london-drugs-ransomware-attack/

publicvoit, to security
@publicvoit@graz.social avatar

Google Online #Security Blog: On Fire Drills and #Phishing Tests
https://security.googleblog.com/2024/05/on-fire-drills-and-phishing-tests.html

"The more effective approach to both risks is a focused pursuit of secure-by-default systems in the long term, and a focus on investment in engineering defenses such as unphishable credentials (like passkeys) and implementing multi-party approval for sensitive security contexts throughout production systems."

I'd say that basically means: no #Microsoft products.

#phishingtests #FIDO2 #ransomware #malware

helma, to random
@helma@mastodon.social avatar

Heaven for domestic abuse: a new spywaretool just up for grabs. It's like having Pegasus at home. What could possibly go wrong? Microsoft knows most families share their accounts or at least can easily log into eachothers accounts. They just choose to ignore it.

.

https://arstechnica.com/gadgets/2024/05/microsofts-new-recall-feature-will-record-everything-you-do-on-your-pc/

br00t4c, to random
@br00t4c@mastodon.social avatar

Watch Out for This Malware Hosted on GitHub and FileZilla

https://lifehacker.com/tech/malware-hosted-on-filezilla-and-github

linuxmagazine, to linux
@linuxmagazine@fosstodon.org avatar
nschont, to linux French
@nschont@mastodon.mim-libre.fr avatar
linuxmagazine, to security
@linuxmagazine@fosstodon.org avatar

From last week's Linux Update: Franciszek Pokryszko explores Linux tools you can use to analyze malware without triggering an attack https://www.linux-magazine.com/Issues/2024/280/Malware-Analysis

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

Black Basta ransomware group's techniques evolve, as FBI issues new warning in wake of hospital attack.

Read more in my article on the Exponential-e blog: https://www.exponential-e.com/blog/black-basta-ransomware-groups-techniques-evolve-as-fbi-issues-new-warning-in-wake-of-hospital-attack

#cybersecurity #databreach #ransomware #socialengineering #malware

gtbarry, to microsoft
@gtbarry@mastodon.social avatar

Windows vulnerability reported by the NSA exploited to install Russian malware

Kremlin-backed hackers have been exploiting a critical Microsoft vulnerability for four years in attacks that targeted a vast array of organizations with a previously undocumented tool, the software maker disclosed

https://arstechnica.com/security/2024/04/kremlin-backed-hackers-exploit-critical-windows-vulnerability-reported-by-the-nsa/

br00t4c, to random
@br00t4c@mastodon.social avatar

'Four horsemen of cyber' look back on 2008 DoD IT breach that led to US Cyber Command

https://go.theregister.com/feed/www.theregister.com/2024/05/10/dod_usb_attack/

gtbarry, to security
@gtbarry@mastodon.social avatar

Boeing confirms attempted $200 million ransomware extortion attempt

The cybercriminals who targeted Boeing using the LockBit ransomware platform in October 2023 demanded a $200 million extortion payment.

Boeing reportedly did not pay any ransom to LockBit after roughly 43 gigabytes of company data was posted to LockBit’s website in early November.

#Boeing #LockBit #ransomware #malware #security #cybersecurity #hackers #hacking #hacked

https://cyberscoop.com/boeing-confirms-attempted-200-million-ransomware-extortion-attempt/

gcluley, to Cybersecurity
@gcluley@mastodon.green avatar

$10 million reward offer for apprehension of unmasked LockBit ransomware leader.

Read more in my article on the Exponential-e blog: https://www.exponential-e.com/blog/10-million-reward-offer-for-apprehension-of-unmasked-lockbit-ransomware-leader

#cybersecurity #ransomware #malware #lockbit

Mensh123, to Minecraft
@Mensh123@cyberplace.social avatar

Low severity [ incident] A mod called "Windows Borderless" on was taken down yesterday. It contained wich stole credentials from Chrome and Chromium-Based browsers. Only Windows users were affected. The mod was not found in any modpacks and was not uploaded to other platforms. A detection tool can be found in the official blog post. According to @modrinth, ~372 IPs downloaded the mod.
https://blog.modrinth.com/p/windows-borderless-malware-disclosure

parigotmanchot, to wordpress French
@parigotmanchot@mastodon.social avatar

: WPCode keeps reappearing as a malware after deleting | WordPress.org - Options à insérer dans le fichier wp-config (racine d'une installation de WordPress) pour empêcher la modification des fichiers via l'éditeur interne et désactiver l'ajout d'extensions.

Contexte : un hackeur a réussit à faire en sorte que l'extension WP Code s'installe automatiquement même si on efface ladite extens… : https://wordpress.org/support/topic/wpcode-keeps-reappearing-as-a-malware-after-deleting/#post-17115537

jsrailton, (edited ) to infosec
@jsrailton@mastodon.social avatar

Big companies are churning out bullshit "security advice" on an industrial scale.

It's a marketing funnel that targets those seeking help.

And then misinforms them.

I wish it stopped there

The nonsense makes its way to victims of spyware, where misinformation can have life, death and liberty impacting consequences.

mima, to security

Permission-based systems are bad. See #XUL getting replaced by #WebExtensions for example. It didn't stop #malware from getting into the #browser or the extension store. On the contrary, the malware problem only got worse after the complete replacement of XUL extensions, which is often disparaged as "insecure" because it allowed users to pretty much change how their browser fundamentally works.

Who knew that distrusting your users and not giving them control leads to more malicious software and user #security being broken more often. ​:seija_coffee:​

RE: https://mamot.fr/users/gnomelibre/statuses/112371181710549606

jsrailton, (edited ) to hacking
@jsrailton@mastodon.social avatar

BREAKING: private investigator arrested for cyberespionage on behalf of American PR firm.

Caught by UK under from 🇺🇸US while boarding a flight.

BIG TWIST in a wild case that began w/our @citizenlab investigation into indian hack-for-hire group

Sound familiar?

Because Amit Forlit is the second PI from arrested in similar way for this case.

First = convicted.

https://www.reuters.com/world/israeli-private-eye-arrested-uk-over-alleged-hacking-us-pr-firm-2024-05-02/

jsrailton, (edited )
@jsrailton@mastodon.social avatar

There's a disgraceful ecosystem of public relations & lobbying firms using hackers for hire.

Sometimes they are used to silence critics & advocacy groups.

Like US nonprofits doing climate advocacy.

Our investigation into a group we christened #DarkBasin uncovered a sprawling #India-based hack-for-hire operation.

They enabled US corporations to outsource lawbreaking.

https://citizenlab.ca/2020/06/dark-basin-uncovering-a-massive-hack-for-hire-operation/
#infosec #cybersecurity #malware #hacking #climatechange #climatecrisis #exxon #phishing

jsrailton, (edited )
@jsrailton@mastodon.social avatar

I'd bet my bottom dollar that this "unnamed...PR and lobbying firm" knows exactly who they are...

...and are no doubt experiencing an afternoon of the purest panic.

Using the offshore hack-for-hire ecosystem has been largely consequence-free for the middlemen & the ultimate beneficiaries of stolen information.

The tide may be turning & this latest arrest suggests that more consequences may be inbound.

#hacking #infosec #spyware #malware #cybersecurity #phishing #India

SomeGadgetGuy, to tech
@SomeGadgetGuy@techhub.social avatar

Premiering now! Had a great conversation with Shannon Morse about my issues reviewing some mini PCs that came pre-loaded with malware. https://www.youtube.com/watch?v=oH2R3o-EbTA
She offers some GREAT tips and tricks for folks interested in keeping their home networks secure and their data safe!

#tech #technology #interview #geek #privacy #windows #windows11 #bbtg #microsoft #malware #security #cybersecurity

sslaia,

@SomeGadgetGuy Sometimes I wonder whether there are companies who pre-loaded their hardware with switches or similar solution instead of software/malware. I guess, in the future the trust in OEM, supply chain and retailer will play important role.

techhelpkb, to random
@techhelpkb@mastodon.social avatar

A new malware named 'Cuttlefish' has been spotted infecting enterprise-grade and small office/home office (SOHO) routers to monitor data that passes through them and steal authentication information.


https://tchlp.com/3woKabl

whydoesnothingwork, to linux
@whydoesnothingwork@mastodon.social avatar
br00t4c, to chrome
@br00t4c@mastodon.social avatar

Clicking This Fake Chrome Update Could Drain Your Bank Account and Leak Your Location

https://lifehacker.com/tech/android-malware-poses-as-chrome-update-steals-bank-info-location-call-history

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • ngwrru68w68
  • cisconetworking
  • magazineikmin
  • Youngstown
  • InstantRegret
  • rosin
  • slotface
  • khanakhh
  • mdbf
  • Durango
  • megavids
  • modclub
  • tacticalgear
  • GTA5RPClips
  • normalnudes
  • osvaldo12
  • everett
  • anitta
  • ethstaker
  • tester
  • Leos
  • cubers
  • provamag3
  • lostlight
  • All magazines