Skip to main content

Search

Items tagged with: Cybersecurity


NEW: female army officers that reported sexual harassment... were hacked with #Pegasus.

Official confirmations from #Poland's AG keep shedding light on more apparent spyware abuses by past gov.

Link [in PL]: https://wiadomosci.onet.pl/kraj/zglosily-molestowanie-w-zandarmerii-wojskowej-byly-inwigilowane-pegasusem/dylyrsv

#Poland #spyware #cybersecurity #infosec #hacking #malware #polska #polish #surveillance #intelligence


🚨 I2P Is Under DDoS Attack By Zombie Routers

#I2P #networking #infosec #cybersecurity #HumanRights #Journalism #activism #surveillance #Privacy #Sybil #ddos #dos #video #proxy #encryption #crypto #e2ee

Watch In I2P

http://invidious.qwik.i2p/watch?v=XfVdxbtTZ5A

#Peertube

https://tube.tchncs.de/w/fMpkjUnNcaKqPchXUPkgV9


#Windows #vulnerability reported by the #NSA exploited to install Russian #malware


Source: https://arstechnica.com/security/2024/04/kremlin-backed-hackers-exploit-critical-windows-vulnerability-reported-by-the-nsa/

When Microsoft patched the vulnerability in October 2022—at least two years after it came under #attack by the Russian hackers—the company made no mention that it was under active exploitation.


#patch #update #exploit #Russia #security #CyberSecurity #news #os #software #hack #hacker


"Citizen, leave a copy of your home keys at the police station."

Hmm, people won't like that.

How about, "home-builders have a social responsibility ...[and must give police copies of all house keys]"

Much better.

#Europol taking another stab at the encryption fight.

#Encryption #privacy #infosec #cybersecurity #europe #surveillance


Advanced #Phishing Kit Adds #LastPass Branding for Use in Phishing Campaigns

Threat actors using phishing kits are pretending to be LastPass in phone calls and emails to steal user credentials.

Actual phishing site: “help-lastpass[.]com”

Shortened URL Embedded in Email: shorturl[.]at/glvT0

Phishing Email Subject Line: We’re here for you

Spoofed Sender: Shows as LastPass Support <support@lastpass>

#security #cybersecurity #passwords

https://blog.lastpass.com/posts/2024/04/advanced-phishing-kit-adds-lastpass-branding-for-use-in-phishing-campaigns


#followfriday is back (after I missed it last week). Once again, here's some cool #infosec / #cybersecurity accounts I've discovered and followed recently...

- @Omkhar
- @zh4ck
- @pietrushnic
- @freddy
- @zerotypic
- @jeFF0Falltrades
- @13reak
- @WPalant

Plus a few cool accounts I've discovered from fun instances around the #fediverse...

- @Shrigglepuss
- @tonicfunk
- @stephan

I've also updated my site's #blogroll with Fediverse handles for each site entry's author - https://shellsharks.com/blogroll


#LLM Agents can Autonomously #Exploit One-day Vulnerabilities


Source: https://arxiv.org/abs/2404.08144

To show this, we collected a dataset of 15 one-day vulnerabilities that include ones categorized as critical severity in the #CVE description. When given the CVE description, GPT-4 is capable of exploiting 87% of these vulnerabilities compared to 0% for every other model we test (GPT-3.5, open-source LLMs) and open-source vulnerability scanners (ZAP and #Metasploit).


#ai #technology #Software #chatgpt #bug #hack #news #cybersecurity


Cisco Duo security reports third-party data breach exposing SMS MFA logs
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/cisco-duo-security-reports-third-party-data-breach-exposing-sms-mfa-logs-g-6-x-f-x/gD2P6Ple2L


📡 HACKRF PORTAPACK H2: What's New Latest Mayhem Firmware v2.0.1

#radio #sdr #Signals #firmware #mayhem #portapack #HackRF #infosec #cybersecurity #privacy #hardware

https://tube.tchncs.de/w/xvj2ZwbFepkHVginNs4H7n


Let's use @protonprivacy and @Tutanota products.


When will the two largest providers of secure encrypted email make it the default for messages sent between them to be securely encrypted? If even they can't manage it what hope is there for the rest of the email world?


Apple has notified iPhone users in 92 countries about a mercenary spyware attack attempting to compromise their devices.

Apple says the attack is likely targeting the victims because of who they are or what they do.

Apple suggests having the latest software updates, enabling lockdown mode and seeking help from specialized experts.

#cybersecurity #threatintel #Apple #iPhone

https://www.bleepingcomputer.com/news/security/apple-mercenary-spyware-attacks-target-iphone-users-in-92-countries/


Let's use @protonprivacy and @Tutanota products.
Encryption is the single best hope against surveillance.

https://www.wired.com/story/house-section-702-vote/

#security #cybersecurity #infosec #nationalsecurity #nsa #fbi #section702 #privacy #government #surveillance #e2ee #tech #proton #protonmail #tuta #tutanota #bigtech #degoogle


The White House is apparently considering a full ban of Kaspersky software throughout the United States, citing national security concerns.

https://edition.cnn.com/2024/04/09/politics/biden-administration-americans-russian-software/index.html

#cybersecurity #kaspersky #russia


Judge: Clark County schools may have immunity in lawsuit over 2023 cybersecurity breach:

https://thenevadaindependent.com/article/judge-clark-county-schools-may-have-immunity-in-lawsuit-over-2023-cybersecurity-breach

Does Nevada state law provide them with a "Get Out of Jail Free" pass? It sounds like it may.

@douglevin @funnymonkey @brett @mkeierleber

#databreach #EduSec #cybersecurity #edtech #accountability #infosec


###
#Microsoft employees exposed internal passwords in #security lapse

source: https://techcrunch.com/2024/04/09/microsoft-employees-exposed-internal-passwords-security-lapse/

Security researchers Can Yoleri, Murat Özfidan and Egemen Koçhisarlı with #SOCRadar, a #cybersecurity company that helps organizations find security weaknesses, discovered an open and public storage server hosted on Microsoft’s #Azure #cloud service that was storing internal information relating to Microsoft’s #Bing search engine.


#fail #password #leak #problem #news


#Twitter’s Clumsy Pivot to X.com Is a Gift to Phishers


source: https://krebsonsecurity.com/2024/04/twitters-clumsy-pivot-to-x-com-is-a-gift-to-phishers/

Those include carfatwitter.com, which Twitter/X truncated to carfax.com when the domain appeared in user messages or tweets. Visiting this domain currently displays a message that begins, “Are you serious, X Corp?”


#internet #fail #security #phishing #cybersecurity #twitter #news


When #security matters: working with #Qubes OS at the #Guardian


Source: https://www.theguardian.com/info/2024/apr/04/when-security-matters-working-with-qubes-os-at-the-guardian

Configuring a Qubes workstation was a new challenge for the team as we abandoned years of experience writing Infrastructure as Code for the cloud and started learning how to write #Salt #configuration. Salt (also know as SaltStack) is a management engine available by default in Qubes.


#cybersecurity #news #journalism #linux #technology #software #securedrop


Panera Bread hit by ransomware attack, systems down for a week
#cybersecurity #infosec #incident #ransomware
https://beyondmachines.net/event_details/panera-bread-hit-by-ransomware-attack-systems-down-for-a-week-k-b-u-u-j/gD2P6Ple2L


Exclusive: #YossiSariel unmasked as head of #Unit8200 and architect of #AI #strategy after book written under pen name reveals his #Google account


Source: https://www.theguardian.com/world/2024/apr/05/top-israeli-spy-chief-exposes-his-true-identity-in-online-security-lapse

The embarrassing #security lapse is linked to a book he published on #Amazon, which left a digital trail to a private Google account created in his name, along with his unique ID and links to the #account’s maps and calendar profiles.


#Israel #internet #Anonymity #privacy #spy #military #CyberSecurity #news #online #leak #identity


📰 XZ Utils Backdoor Attribution Analysis

#News #Linux #XZutils #backdoor #ssh #infosec #cybersecurity #privacy #video #peertube #APT

https://tube.tchncs.de/w/ca2iuxmdqfBE98PwZYY6wh


What #encryption do you use for your everyday #communication?


I'm not talking about your nerd friends, who can be counted on one hand and who know a thing or two about the subject. I'm talking about your normal friends, business partners and colleagues with whom you communicate both professionally and privately.

I was recently called by my support via Microsoft Teams because I had to enter some passwords. The support team proudly said that they were contacting me via Teams because it was more secure than the normal phone. He was then very surprised when I told him that Teams is unencrypted and can be intercepted much more easily.

encryption

#messenger #email #question #security #cybersecurity #internet #spy #surveillance #privacy #nsa #snowden #5eyes


Hey @bitwarden! It's a tad worrisome when a security software company can't handle something as simple as ensuring that its #DMARC record points to valid email addresses.
#infosec #cybersecurity #email


The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind

https://www.wired.com/story/jia-tan-xz-backdoor/

#infosec #cybersecurity