Skip to main content

Search

Items tagged with: cybersecurity


#followfriday is back (after I missed it last week). Once again, here's some cool #infosec / #cybersecurity accounts I've discovered and followed recently...

- @Omkhar
- @zh4ck
- @pietrushnic
- @freddy
- @zerotypic
- @jeFF0Falltrades
- @13reak
- @WPalant

Plus a few cool accounts I've discovered from fun instances around the #fediverse...

- @Shrigglepuss
- @tonicfunk
- @stephan

I've also updated my site's #blogroll with Fediverse handles for each site entry's author - https://shellsharks.com/blogroll


#LLM Agents can Autonomously #Exploit One-day Vulnerabilities


Source: https://arxiv.org/abs/2404.08144

To show this, we collected a dataset of 15 one-day vulnerabilities that include ones categorized as critical severity in the #CVE description. When given the CVE description, GPT-4 is capable of exploiting 87% of these vulnerabilities compared to 0% for every other model we test (GPT-3.5, open-source LLMs) and open-source vulnerability scanners (ZAP and #Metasploit).


#ai #technology #Software #chatgpt #bug #hack #news #cybersecurity


Cisco Duo security reports third-party data breach exposing SMS MFA logs
#cybersecurity #infosec #incident #databreach
https://beyondmachines.net/event_details/cisco-duo-security-reports-third-party-data-breach-exposing-sms-mfa-logs-g-6-x-f-x/gD2P6Ple2L


Security folks, I need some help. My wife is looking for a job after taking a few years off to take care of the kids and she's having a hard time finding legit security opportunities. And the legit ones she does find don't like the gap in her resume.

If you have or know of any legit remote openings for someone with experience in identity and access management, can you please share?

She has her CISSP and while most of her experience is in IAM she's willing to branch out and learn a new specialty. She also happens to be both the faster learner and the smarter one of the two of us!

Boosts greatly appreciated!

#InformationSecurity #Cybersecurity #IAM #FediHired #GetFediHired #FediJobs #Jobs


πŸ“‘ HACKRF PORTAPACK H2: What's New Latest Mayhem Firmware v2.0.1

#radio #sdr #Signals #firmware #mayhem #portapack #HackRF #infosec #cybersecurity #privacy #hardware

https://tube.tchncs.de/w/xvj2ZwbFepkHVginNs4H7n


Let's use @protonprivacy and @Tutanota products.


When will the two largest providers of secure encrypted email make it the default for messages sent between them to be securely encrypted? If even they can't manage it what hope is there for the rest of the email world?


I read some article about them being concerned about AI cyberattacks, and actually recommended 'fighting fire with fire'.

??

Um.. you can't just rely solely on AI systems when the main reason why cyberattacks keep on succeeding is mostly due to social engineering. People are being tricked into enabling attackers access their systems and data.
AI-based attacks are currently mainly driven by deception via fake messages, deepfakes, etc.

#cybersecurity #infosec #socialengineering #AI


Apple has notified iPhone users in 92 countries about a mercenary spyware attack attempting to compromise their devices.

Apple says the attack is likely targeting the victims because of who they are or what they do.

Apple suggests having the latest software updates, enabling lockdown mode and seeking help from specialized experts.

#cybersecurity #threatintel #Apple #iPhone

https://www.bleepingcomputer.com/news/security/apple-mercenary-spyware-attacks-target-iphone-users-in-92-countries/


Let's use @protonprivacy and @Tutanota products.
Encryption is the single best hope against surveillance.

https://www.wired.com/story/house-section-702-vote/

#security #cybersecurity #infosec #nationalsecurity #nsa #fbi #section702 #privacy #government #surveillance #e2ee #tech #proton #protonmail #tuta #tutanota #bigtech #degoogle


The White House is apparently considering a full ban of Kaspersky software throughout the United States, citing national security concerns.

https://edition.cnn.com/2024/04/09/politics/biden-administration-americans-russian-software/index.html

#cybersecurity #kaspersky #russia


Judge: Clark County schools may have immunity in lawsuit over 2023 cybersecurity breach:

https://thenevadaindependent.com/article/judge-clark-county-schools-may-have-immunity-in-lawsuit-over-2023-cybersecurity-breach

Does Nevada state law provide them with a "Get Out of Jail Free" pass? It sounds like it may.

@douglevin @funnymonkey @brett @mkeierleber

#databreach #EduSec #cybersecurity #edtech #accountability #infosec


###
#Microsoft employees exposed internal passwords in #security lapse

source: https://techcrunch.com/2024/04/09/microsoft-employees-exposed-internal-passwords-security-lapse/

Security researchers Can Yoleri, Murat Γ–zfidan and Egemen KoΓ§hisarlΔ± with #SOCRadar, a #cybersecurity company that helps organizations find security weaknesses, discovered an open and public storage server hosted on Microsoft’s #Azure #cloud service that was storing internal information relating to Microsoft’s #Bing search engine.


#fail #password #leak #problem #news


#Twitter’s Clumsy Pivot to X.com Is a Gift to Phishers


source: https://krebsonsecurity.com/2024/04/twitters-clumsy-pivot-to-x-com-is-a-gift-to-phishers/

Those include carfatwitter.com, which Twitter/X truncated to carfax.com when the domain appeared in user messages or tweets. Visiting this domain currently displays a message that begins, β€œAre you serious, X Corp?”


#internet #fail #security #phishing #cybersecurity #twitter #news


When #security matters: working with #Qubes OS at the #Guardian


Source: https://www.theguardian.com/info/2024/apr/04/when-security-matters-working-with-qubes-os-at-the-guardian

Configuring a Qubes workstation was a new challenge for the team as we abandoned years of experience writing Infrastructure as Code for the cloud and started learning how to write #Salt #configuration. Salt (also know as SaltStack) is a management engine available by default in Qubes.


#cybersecurity #news #journalism #linux #technology #software #securedrop


Panera Bread hit by ransomware attack, systems down for a week
#cybersecurity #infosec #incident #ransomware
https://beyondmachines.net/event_details/panera-bread-hit-by-ransomware-attack-systems-down-for-a-week-k-b-u-u-j/gD2P6Ple2L


Exclusive: #YossiSariel unmasked as head of #Unit8200 and architect of #AI #strategy after book written under pen name reveals his #Google account


Source: https://www.theguardian.com/world/2024/apr/05/top-israeli-spy-chief-exposes-his-true-identity-in-online-security-lapse

The embarrassing #security lapse is linked to a book he published on #Amazon, which left a digital trail to a private Google account created in his name, along with his unique ID and links to the #account’s maps and calendar profiles.


#Israel #internet #Anonymity #privacy #spy #military #CyberSecurity #news #online #leak #identity


πŸ“° XZ Utils Backdoor Attribution Analysis

#News #Linux #XZutils #backdoor #ssh #infosec #cybersecurity #privacy #video #peertube #APT

https://tube.tchncs.de/w/ca2iuxmdqfBE98PwZYY6wh


🧬Types of DNS Records

πŸ”ΉA
πŸ”ΉAAAA
πŸ”ΉCNAME
πŸ”ΉMX
πŸ”ΉPTR
πŸ”ΉNS
πŸ”ΉSOA
πŸ”ΉTXT

πŸ”–#infosec #cybersecurity #hacking #pentesting #security


What #encryption do you use for your everyday #communication?


I'm not talking about your nerd friends, who can be counted on one hand and who know a thing or two about the subject. I'm talking about your normal friends, business partners and colleagues with whom you communicate both professionally and privately.

I was recently called by my support via Microsoft Teams because I had to enter some passwords. The support team proudly said that they were contacting me via Teams because it was more secure than the normal phone. He was then very surprised when I told him that Teams is unencrypted and can be intercepted much more easily.

encryption

#messenger #email #question #security #cybersecurity #internet #spy #surveillance #privacy #nsa #snowden #5eyes


Hey @bitwarden! It's a tad worrisome when a security software company can't handle something as simple as ensuring that its #DMARC record points to valid email addresses.
#infosec #cybersecurity #email


The Mystery of β€˜Jia Tan,’ the XZ Backdoor Mastermind

https://www.wired.com/story/jia-tan-xz-backdoor/

#infosec #cybersecurity


Several popular messaging apps, including Messenger, Signal, Telegram and WhatsApp, use end-to-end encryption.

Here’s how it protects you:
https://theconversation.com/are-private-conversations-truly-private-a-cybersecurity-expert-explains-how-end-to-end-encryption-protects-you-224477
#Cybersecurity


Great news! Amazon has got back to me about the Β£700 iPhone they failed to deliver (and wouldn't refund or replace) Bad news: what they told me...

Based on this experience, why would anyone buy anything expensive from Amazon ever again? Please share, like and comment if you agree.

Watch my #video.

#amazon #delivery #scam #jeffbezos #cybersecurity


A cybersecurity researcher finds that 20% of software packages recommended by GPT-4 are fake, so he builds one that 15,000 code bases already depend on, to prevent some hacker from writing a malware version.

Disaster averted in this case, but there aren't enough fingers to plug all the AI-generated holes 😬

https://it.slashdot.org/story/24/03/30/1744209/ai-hallucinated-a-dependency-so-a-cybersecurity-researcher-built-it-as-proof-of-concept-malware

#AIethics #Cybersecurity #GPT #OpenAI #LLM #GenAI #GenerativeAI #Python #NodeJS #Ruby #Golang


βš’οΈ35 Top Cybersecurity Tools for 2024

1. Nmap
2. Metasploit
3. Wireshark
4. Invicti
5. John the Ripper
6. Nikto
7. Burp Suite
8. Tor
9. Tcpdump
10. Aircrack-ng
11. Splunk
12. Acunetix
13. Snort
14. Mimecast
15. Malwarebytes
16. OpenVAS
17. SecPod SanerNow
18. UnderDefense
19. Intruder
20. ManageEngine Vulnerability Manager Plus
21. ManageEngine Log360
22. SolarWinds Security Event Manager
23. Norton Security
24.McAfee
25. AVG
26. System Mechanic Ultimate Defense
27. Vipre
28. LifeLock
29. Bitdefender Total Security
30. NordLayer
31. Perimeter 81
32. CIS
33. Webroot
34. GnuPG
35. Sparta Antivirus

πŸ”–#infosec #cybersecurity #hacking #pentesting #security

πŸ‘€beacons.ai/cyberkid1987
πŸ‘€t.me/VasileiadisAnastasis
πŸ‘₯t.me/infosec101


Why everyone should be using an ad blocker. Ads are not just annoying, they are a security issue.
#infosec #Scam #cybersecurity


PancakesCon 5 (@pancakescon) is happening :D With talks including:

  • MITRE ATT&CK mapping and the world’s best muffins
  • Stopping botnets with astrophysics
  • Thrive or survive: What a life in the mosh pit taught me about cyber security

... and many more.

Here's the schedule: https://pancakescon.com/2024-conference-information/

#PancakesCon #security #CyberSecurity

⇧