jakub, to security
@jakub@jirutka.cz avatar

I noticed that automatically downloads a NodeJS binary from nodejs.org without asking or even informing the user about it. Right after starting it and opening a file, without doing anything else. Then it installs some packages from npmjs via npm. And there’s no option to disable it.

THIS IS ABSOLUTELY UNACCEPTABLE! I can’t stress enough how bad this is from point of view. And not just that, consider users on metered connections


https://github.com/zed-industries/zed/issues/12589

exa,
@exa@mastodon.online avatar

@jakub
so I was wondering what Zed is and

> Code at the speed of thought – Zed is a high-performance, multiplayer code editor from the creators of Atom and Tree-sitter.

they may have a tradition in doing it wrong

kimschulz,
@kimschulz@social.data.coop avatar

@jakub
Zed's dead baby, Zed's dead.
@chx

SceNtriC, to random Polish
@SceNtriC@101010.pl avatar

Na koncie PAP pojawiła się fałszywa depesza o powołaniu 200 tysięcy polskich żołnierzy do walk na Ukrainie. Już ją zdementowano, uspokojono, że to nieprawda i podano, że to prawdopodobnie efekt rosyjskiego cyberataku.

#CyberSec #Cyberbezpieczeństwo

Cruthachail, to privacy

Liberate your digital freedom today.

Twitter.
https://nitter.net
https://fediverse.observer

YouTube.
https://tube.raccoon.quest
https://piped.video
https://joinpeertube.org

Google Map.
https://openstreetmap.org

Reddit.
https://libreddit.kavin.rocks
https://teddit.pussthecat.org
https://join-lemmy.org

TikTok.
https://tok.artemislena.eu

Google Search.
https://startpage.com

Google Translate.
https://translate.metalune.xyz

Imgur, Image storage site.
https://pixelfed.org

Wikipedia.
https://wikiless.org

Discord, Guilded, etc.
https://chat.techsaviours.org
https://xmpp.org/about
https://www.jabber.org/faq.html#jabber
https://www.mumble.info/about

Microsoft Teams, Slack, Zoom, etc.
https://jitsi.riot.im
https://opentalk.eu/en

Microsoft Word, Pages, etc.
https://www.onlyoffice.com/en/download-docs.aspx?from=default#docs-community
https://www.libreoffice.org/download/download-libreoffice

Internet Browsers.
https://floorp.app/download (Firefox-based)
https://github.com/ungoogled-software/ungoogled-chromium (Chromium-based)
https://brave.com (Chromium-based)

Emails.
https://mailfence.com/registration
https://app.tuta.com/login?noAutoLogin=true&keepSession=true

Operating Systems.
https://www.opensuse.org
https://linuxmint.com/about.php
https://grapheneos.org
https://calyxos.org
https://lineageos.org

Password Managers.
https://vault.bitwarden.com/#/register?layout=default
https://keepass.info/download.html

Privacy Guides.
https://www.privacyguides.org/en/about
https://thenewoil.org/en/about

Useful services.

https://joinmobilizon.org/en/#what-is-mobilizon
https://joinbookwyrm.com
https://cryptpad.org/about
https://microbin.eu
https://vikunja.io

#privacy, #privacymatters, #cybersecurity, #cybersec, #infosecurity, #infosec, #opensource, #oss, #freesoftware, #freedom.

  • Removed #proton because of its recent compromise in privacy.
kubikpixel,
@kubikpixel@chaos.social avatar

@Cruthachail ...or use the @libredirect browser plugin for more and easy privat surving in the Internet:

🔗 :mastodon: https://chaos.social/@kubikpixel/111789133230036811

phil, to infosec

Looking for an entry-level #InfoSec or #CyberSec job.

Just spent a week grinding through THM, got some certs out of it... are these any good? I don't know, but I have learned a bunch of interesting things.

Haven't had a job since December, and I'm nearing on 7 months here. I'll take anything that's remote.

I learn fast, I'm diligent, and I don't take shortcuts.
I grok computers good.

Anyone, anything?

#fedihire #forhire #jobs #jobsearch #job #jobseeker #hireme #cybersecurityjobs #cybersecurity #infosecjobs #informationsecurity

(Sorry for spamming the tags, I know it's bad form.)

beardedtechguy, to Cybersecurity
@beardedtechguy@allthingstech.social avatar
  • This includes all Chromium based browsers.

New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation

https://thehackernews.com/2024/05/new-chrome-zero-day-vulnerability-cve.html

SceNtriC, to webdev Polish
@SceNtriC@101010.pl avatar

Po zobaczeniu cudownej bramki w meczu Wisła Puławy - drugi zespół Lecha Poznań chciałem sprawdzić coś na stronie internetowej Wisły Puławy. Niestety, nie działa, co się zdarza (a w weekend nie oczekuję, że ktoś to naprawi), ale... Jezu, nie róbcie tak. Zabezpieczajcie ekrany o błędach na serwerze produkcyjnym.

karma, to linux Polish
@karma@101010.pl avatar

Cześć! Jestem najzwyklejszym użytkownikiem Mastodona. Na wszystkich swoich komputerach używam #Linux i pluję na #Windows. Umiem trochę Javy, którą ostatnio zaniedbuję na rzecz Rusta. Gram w #Minecraft, #Fortnite i #Warframe i #Cyberpunk 2077. Nie jestem neurotypowy, więc często zachowuję się dziwnie i nie łapię sarkazmów czy przenośni. Używam głównie oprogramowania #FOSS i selfhostuję swoje usługi, bo jestem paranoikiem prywatności. Siedzę trochę w #cybersec. To chyba tyle o mnie :blobcathearthug:

#introduction #introductions #omnie #aboutme

batichi, to advice
@batichi@masto.batichi.net avatar

Hey nerds, would anyone have some time to offer about getting into the field? I've been seriously thinking about that direction but I have 0 clue how that side specifically runs.
Bonus points if your experience is from .

alex_02, to OSINT
@alex_02@infosec.town avatar

Oh, isn't this lovely. So apparently these goons:

  • Mike Lindell (My Pillow Guy)

  • Jack Posobiec (White supremacist that believes in conspiracies such as the white genocide conspiracy)

  • Jim Jordan (One of the main players to planning Jan 6th)

  • Matt Gaetz (A pedophile and operated a sex ring, but never was charged (fuck you justice department))

  • Steve Bannon (The fraudster that scammed trump supporters for a fake company to build Trump's wall)

-Vivek Ramaswamy (New face, but is young and likable. Dropped out of presidential nominee bid, but probably got a promise of a cushy job position in Trump's administration, from looks of things)

  • JD Vance (Didn't originally like Trump, but changed his opinion in 2018 and started spewing out many points from The Heritage, The Family Leader, etc)

  • Tommy Tuberville (One of the senators that helped to overturn the presidential election in 2020 and closely allied with Trump)

  • Kristi Noem (Governor of South Dakota, that is a terrible governor and well... I don't want to go into too much right now)

All seem to possibly be conspiring to overthrow the government. Articles are here:

Other potential people here: www.digital.cpac.org/speakers-dc2024

And a video: crooksandliars.com/cltv/2024/02/quelle-surprise-jack-posobiec-big-fan

This is all going off of this screenshot, which is a direct threat and should be taken seriously. I quickly put together this and uploaded what I could grab.

Uploaded to Mega: mega.nz/file/ioQGmRBD#FmcuZjDqCpVhvaFMclGsBgyHjPu8czZTokSz3S4H3fo

Please for FFS. Take this seriously. #osint #osint4good #republican #trump #theheritage #theheritagefoundation #gop #project2025 #traitors #traitortrump #infosec #infosecurity #cybersec #cybersecurity

beardedtechguy, to Cybersecurity
@beardedtechguy@allthingstech.social avatar

This is very intriguing! I could possibly be on the right track with this AT&T outage.

The FBI, Homeland Security, and CISA is helping with the investigation now?!

image/png

beardedtechguy, to Cybersecurity
@beardedtechguy@allthingstech.social avatar

I’m just going to throw this out there.

I have a feeling that this AT&T outage has something to Cyber Security. There’s something bigger going on.

https://www.cnn.com/2024/02/22/tech/att-cell-service-outage/index.html

cappy, to Cybersecurity
@cappy@fedi.fyralabs.com avatar
ErikUden,
@ErikUden@mastodon.de avatar

@cappy I am so excited to read this report, thank you very much for your time and effort!

niconiconi,

@cappy

"CCP-themed Japanese troll group"

It's not really CCP-themed. It's Cultural Revolution themed. These trolls seem to find inspiration from this period in which ordinary people are encouraged to organize themselves at the grassroot level to attack anyone they deem to be the enemies of people.

cappy, to Cybersecurity
@cappy@fedi.fyralabs.com avatar

anyway, an early excerpt from the expose you all should read

beardedtechguy, to Cybersecurity
@beardedtechguy@allthingstech.social avatar

Reddit selling user content to train an AI?

From: @beyondmachines1
https://infosec.exchange/@beyondmachines1/111952862733740047

cappy, to infosec
@cappy@fedi.fyralabs.com avatar

btw here's the script they use for DDoSing Misskey instances

https://github.com/EdamAme-x/misskey-nuke

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • cisconetworking
  • khanakhh
  • mdbf
  • magazineikmin
  • modclub
  • InstantRegret
  • rosin
  • Youngstown
  • slotface
  • Durango
  • tacticalgear
  • megavids
  • ngwrru68w68
  • everett
  • tester
  • cubers
  • normalnudes
  • thenastyranch
  • osvaldo12
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • lostlight
  • All magazines