Skip to main content

Search

Items tagged with: Infosec


Hackers Abuse Windows Search Functionality To Deploy Malware
#DarkWeb #Infosec #CTI #OSINT
#CEH #CPT #GPEN #Hacking #OSCP #snoopgodlinux #Ubuntu https://cybersecuritynews.com/hackers-abuse-windows-search/


🚨DATA LEAK🚨A threat actor has allegedly leaked Israel's Government Services and Information API Database. 268,938 lines of data.

#DarkWeb #Cybersecurity #Security #Cyberattack #Cybercrime #Privacy #Infosec #Israel

Compromised Data includes: Names, Phone Numbers, Plates, DOB, Address.

https://x.com/DarkWebInformer/status/1800975641904398385


Indiana cop who used Clearview AI facial recognition tech for personal reasons resigns #cybersecurity #infosec #privacy #news https://therecord.media/indiana-cop-clearview-use-resigns


QR code SQL injection from popular biometric terminal
💥⁠https://securelist.com/biometric-terminal-vulnerabilities/112800/

Nice blackbox analysis... *sigh* and yet another SQL injection in 2024.

#InfoSec #CyberSecurity


Excited that the team will be teaching 2 classes at @defcon in Vegas this summer: 1) Hunt Methodologies and 2) Advanced Tunneling, Pivoting, and Redirection. (Aug 12-13).

If those awesome topics alone aren't exciting enough, at the end of day 1 of trainings, the founder of #defcon, Jeff Moss will be hosting an evening social/mixer for trainers and students. More opportunities to grow your #infosec network - in person!

Hope to see you there!

Register for Hunt Meth here:
https://training.defcon.org/products/bobby-thomas-hunt-methodologies-dctlv2024
#threathunting

Register for Adv. Tunneling, Pivoting, and Redirection here:
https://training.defcon.org/products/travis-livermore-advanced-tunneling-pivoting-and-redirection-course-dctlv2024
#redteam #cybersecurity


If you're using DuckDuckGo, they have AI Assist on by default. Go to duckduckgo[dot]com main page, click on those three little lines in upper right corner-->Settings --> AI Features --> Toggle all features to OFF.

#duckduckgo #search #AI #safety #privacy #tech #infosec


I'll stick to #Bitwarden for the time being. @protonprivacy Pass has a long way to go. It lacks many basic features.

#privacy #infosec #password


This dumb password rule is from Three.

Password must be at least 7 characters long.
The maximum length is inconsistent, however: when changing password, the maximum length is 30, but when resetting password via email link, the maximum length is 12.

https://dumbpasswordrules.com/sites/three/

#password #passwords #infosec #cybersecurity #dumbpasswordrules


Last year, CrowdStrike published a report on a new crypto-mining operation that was targeting exposed Kubernetes systems with a miner for the Dero cryptocurrency token.

https://www.crowdstrike.com/blog/crowdstrike-discovers-first-ever-dero-cryptojacking-campaign-targeting-kubernetes/

This threat actor—no official name yet—is still active today, according to a new report from cloud security firm Wiz.

https://www.wiz.io/blog/dero-cryptojacking-campaign-adapts-to-evade-detection

#infosec #cybersecurity #security


I've done it! After literal months of work, I've finally finished my (rather long) blog post about how AES-GCM works and how it's security guarantees can be completely broken when a nonce is reused:

https://frereit.de/aes_gcm/

It includes more than 10 interactive widgets for you to try out AES-GCM, GHASH and the nonce reuse attack right in your browser! (Powered by #RustLang and #WASM )

If you're interested in #cryptography , #math (or #maths ) or #infosec you might find it interesting.

If you do read it, I'm all ears for feedback and criticism!


Lukewarm take:

When I see general* "security advice" that mentions "do not use public WiFi" or "use a VPN", I am immediately suspicious about all other advice offered.

Yes, a decade ago that was a consideration, because most sites were not using HTTPS. Credentials were flying cleartext on the wire.

Today, almost all sites use HTTPS. Doesn't mean the risk is zero, but it's way lower.

*) "general" meaning "without a very specific threat model in mind", meant for general public, etc.

#InfoSec


Also, shout-out to @letsencrypt for dramatically changing the security landscape of the Web for the better over the years.

Rarely is there an example of a project so effective and so directly improving everyone's lives, while at the same time keeping the original engineering mindset and just Doing Stuff Right™ humbly in the background.

Next November it will have been exactly a decade since LE started. We all owe them a huge 10th birthday party.

#InfoSec


Microsoft Recall: No admin necessary to access data…

#microsoft #recall #infosec #privacy

https://infosec.exchange/@tiraniddo/112566044174482506



Seen on the MailOp list. A putative joke from Tobias Fiebig.
I’m not sure that I’d put BGP before mail in this hierarchy, but that's mostly because others around me handle it as well as can be expected in a world with the likes of Cogent and Tata swinging their dicks at each other.

#InfoSec #email #dns #bgp


STORY: Microsoft’s Recall AI system takes a screenshot of your laptop every five seconds. Even before it has launched, a security researcher has built a tool that can extract all the unencrypted data from Recall

https://www.wired.com/story/total-recall-windows-recall-ai/ #cybersecurity #infosec #technology #microsoft


#Windows #Recall demands an extraordinary level of #trust that #Microsoft hasn’t earned


source: https://arstechnica.com/ai/2024/06/windows-recall-demands-an-extraordinary-level-of-trust-that-microsoft-hasnt-earned/

This, as many users in #infosec communities on social media immediately pointed out, sounds like a potential #security #nightmare. That’s doubly true because Microsoft says that by default, Recall’s screenshots take no pains to redact sensitive information, from usernames and passwords to health care information to NSFW site visits. By default, on a #PC with 256GB of storage, Recall can store a couple dozen gigabytes of data across three months of PC usage, a huge amount of personal data.


#bigdata #privacy #bigbrother #cybersecurity #software #os #surveillance #danger #warning #AI #fail #news


#infosecjobs #hiring Alert: I'm hiring a career transition, entry-level, or intern-level web developer in Rust/Python at @redqueen.

We help managed service providers get and keep their small biz clients safe and secure!

This would be a great role for someone mid-career looking to move into a more technical role or into infosec, or who just finished a bootcamp or similar education.

Remote, US-only. Read the JD carefully or you'll miss the subject line requirement when you email me.

https://www.redqueendynamics.com/careers #cybersecurity #compliance #infosec


Stealing everything you’ve ever typed or viewed on your own Windows PC is now possible with two lines of code — inside the Copilot+ Recall disaster. https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e #privacy #security #infosec #windows


#followfriday! Here's some #infosec / #cybersecurity accounts I've discovered from the past week to check out!

- @an00brektn
- @dieg0

Plus! Here's some folks from across the Fediverse who's instance names are awesome.

- @pointlessone
- @prettygood
- @markiplier
- @split
- @kopper
- @nev
- @z
- @president
- @EmilyK

All previous follow friday posts: https://shellsharks.com/notes/2023/10/20/infosec-mastodon-starter-pack#for-infosec-folks

Giant list of cool instance names (and those from said instances) here: https://shellsharks.com/notes/2024/03/29/the-whimsical-corners-of-the-fediverse


📡 HackRF Portapack H2 Audio RX App: Listening / Browsing / Shortwave / Radio

#HackRF #FOSS #tutorial #hardware #SDR #Portapack #MayhemFirmware #firmware #shortwave #radio #gadgets #tech #infosec #cyber #RX

https://tube.tchncs.de/w/4RNT554SNRULBimPFxSPfK


Ticketmaster hacked. Breach affects more than ***half a billion*** users.

Emails, phone numbers, addresses, and even financial details have allegedly been exposed by a notorious hacker group. And they are offering the data for half a million bucks.

https://mashable.com/article/ticketmaster-data-breach-shinyhunters-hack

@404mediaco exposed Ticketmaster yesterday for its monopoly power in the concert industry, so its 500 million customers are now being revictimized by the hackers.

https://www.404media.co/the-monopoly-case-against-ticketmaster-explained/

#infosec


So is CircleCityCon still going or no? #infosec


STORY: Police have a new cybercrime fighting tactic: getting into the heads of Russian hackers.

Recent law enforcement takedowns of cybercrime groups have increasingly used psychological tactics as part of their disruption.

https://www.wired.com/story/cop-cybercriminal-hacker-psyops/

#cybersecurity #cybercrime #hacking #infosec


"I'm going to #DEFCON32 this year. Maybe I should enter one of the contests, that should test my expensive #cybersecurity skills and winning will advance my #infosec career!"

The Contests At @defcon:


Kyivstar Cyberattack: Ukraine Allocates $90 Million for Recovery Efforts https://thecyberexpress.com/kyivstar-cyberattack-update/?utm_source=dlvr.it&utm_medium=mastodon #cybersecurity #infosec


#nahamsec is still going strong!

Watch on the #DCG201 LIVE STREAM or on these direct links:

#Twitch: https://twitch.tv/namhamsec
#YouTube: https://www.youtube.com/live/76mNNVVBht0

#hacking #infosec #cybersecurity @defcon


NEW: second judge in #Poland reportedly confirmed as #Pegasus spyware victim.

Appeals court judge told reporter her responsibilities included classified cases where wiretapping was used.

Poland's spyware reckoning continues.

[PL, machine trans.]
Story: https://oko.press/wiemy-o-drugim-polskim-sedzi-inwigilowanym-pegasusem-to-sedzia-apelacyjna-z-krakowa-news-oko-press

#spyware #infosec #cybersecurity #polska #malware #security #intelligence #surveillance


The @owasp amass project will have a workshop on ‘Learning the New Amass Collection Engine’ in @redteamvillage_ at @defcon 32! We hope to see you there! #security #infosec #redteam #osint #recon #easm