Bobinas P4G
  • Login
  • Public

    • Public
    • Groups
    • Popular
    • People

Notices tagged with infosec

  1. Michał "rysiek" Woźniak · 🇺🇦 (rysiek@mstdn.social)'s status on Tuesday, 21-Jan-2025 23:30:07 UTC Michał "rysiek" Woźniak · 🇺🇦 Michał "rysiek" Woźniak · 🇺🇦

    There's a "Signal deanonymized" thing going around:
    https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117

    Stay calm. Deep breaths.

    👉 while this is a real consideration, the only thing the attacker gets from this is a very rough (kilometers or tens of kilometers radius) location

    👉 other communication platforms that use any kind of caching CDN to deliver attachments are just as affected

    👉 you almost certainly should continue to use Signal, unless you specifically know that this is a big problem for you.

    #Signal #InfoSec

    In conversation about 5 months ago from mstdn.social permalink

    Attachments


  2. Wade Baker (wade@infosec.exchange)'s status on Wednesday, 20-Nov-2024 16:44:22 UTC Wade Baker Wade Baker

    I'm fascinated by the concept of measuring attacker-defender advantage in software, devices, and even entire IT environments. What do I mean by "attacker-defender advantage?" Lemme sum up and then share a chart.

    Let's say you could measure the speed at which defenders remediate various types of security vulnerabilities across all relevant assets. Then say you could detect and measure the speed at which attackers find/exploit those vulnerable assets across the target population of organizations using them. Finally, plot those curves (across time and assets) to see the delta between them and derive a measure of relative advantage for attackers and defenders. That relative value is what I mean by attacker-defender advantage.

    Since a picture is worth a thousand words, here's a visual example of the concept. The blue line represents defenders, measuring the speed of remediation. Red measures how attacker exploitation activity spreads across the target population. When the blue line is on top, defenders have a relative advantage (remediating faster than attackers are attempting to exploit new targets). When red's on top, the opposite is true. The delta between the lines corresponds to the relative degree of advantage (also expressed by the number in the upper left).

    This chart comes from prior Cyentia Institute research in which we were able to combine datasets from two different partners (with their permission). Unfortunately, those datasets/partners are no longer available to further explore this concept - but maybe this post will inspire new partnerships and opportunities!

    Any surprises in the attacker-defender advantage results depicted in the chart? Has anyone measured this or something similar?

    #cybersecurity #vulnerabilities #cyberattacks #infosec #exploitation

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/516/092/496/764/298/original/b192b5542662d394.png
  3. Morishima (morishima@ieji.de)'s status on Thursday, 10-Oct-2024 17:50:53 UTC Morishima Morishima
    • The Tor Project

    Do you use Tor Browser by @torproject?
    Please check for critical security updates.

    Details: https://blog.torproject.org/new-release-tor-browser-1357/

    #security #cybersecurity #infosec #privacy #government #censorship #surveillance #freedom #democracy #tor #torbrowser #opensource

    In conversation about 9 months ago from ieji.de permalink

    Attachments

    1. New Release: Tor Browser 13.5.7 | Tor Project
      Tor Browser 13.5.7 is now available from the Tor Browser download page and also from our distribution directory.
  4. tech (tech@unfufadoo.net)'s status on Monday, 29-Jul-2024 14:38:41 UTC tech tech

    #tech #sysadmin #images #heldesk #photos #infosec #cloud #funny #memes #video

    In conversation about a year ago from unfufadoo.net permalink

    Attachments


  5. tech (tech@unfufadoo.net)'s status on Saturday, 20-Jul-2024 01:46:08 UTC tech tech

    #tech #cloud #sysadmin #memes #photos #infosec #images #heldesk #funny

    In conversation about a year ago from unfufadoo.net permalink

    Attachments


    1. https://unfufadoo.net/system/media_attachments/files/112/814/941/314/632/989/original/5c4c07c0dbcd2e29.jpeg
  6. cr0n0s:~🐧📡⌨️ 🛠️ # (cr0n0s@social.tchncs.de)'s status on Wednesday, 26-Jun-2024 11:42:38 UTC cr0n0s:~🐧📡⌨️ 🛠️ # cr0n0s:~🐧📡⌨️ 🛠️ #

    A Novel DoS Vulnerability affecting WebRTC Media Servers
    https://www.rtcsec.com/article/novel-dos-vulnerability-affecting-webrtc-media-servers

    #webrtc #infosec

    In conversation about a year ago from social.tchncs.de permalink

    Attachments


  7. cr0n0s:~🐧📡⌨️ 🛠️ # (cr0n0s@social.tchncs.de)'s status on Tuesday, 25-Jun-2024 14:13:18 UTC cr0n0s:~🐧📡⌨️ 🛠️ # cr0n0s:~🐧📡⌨️ 🛠️ #

    Next.js and cache poisoning: a quest for the black hole
    https://zhero-web-sec.github.io/research-and-things/nextjs-and-cache-poisoning-a-quest-for-the-black-hole

    #js #infosec

    In conversation about a year ago from social.tchncs.de permalink

    Attachments

    1. Next.js and cache poisoning: a quest for the black hole
  8. cr0n0s:~🐧📡⌨️ 🛠️ # (cr0n0s@social.tchncs.de)'s status on Tuesday, 21-May-2024 13:30:03 UTC cr0n0s:~🐧📡⌨️ 🛠️ # cr0n0s:~🐧📡⌨️ 🛠️ #

    Nueva vulnerabilidad Wi-Fi permite la escucha ilegal de la red mediante ataques de degradación/downgrade
    https://blog.segu-info.com.ar/2024/05/nueva-vulnerabilidad-wi-fi-permite-la.html

    #wifi #infosec

    In conversation about a year ago from social.tchncs.de permalink

    Attachments

    1. Nueva vulnerabilidad Wi-Fi permite la escucha ilegal de la red mediante ataques de degradación/downgrade
  9. cr0n0s:~🐧📡⌨️ 🛠️ # (cr0n0s@social.tchncs.de)'s status on Monday, 06-May-2024 22:59:06 UTC cr0n0s:~🐧📡⌨️ 🛠️ # cr0n0s:~🐧📡⌨️ 🛠️ #

    Tres millones de repositorios de Docker Hub utilizados para difundir malware
    https://blog.segu-info.com.ar/2024/05/tres-millones-de-repositorios-de-docker.html

    #docker #infosec #ciberseguridad #malware

    In conversation about a year ago from social.tchncs.de permalink

    Attachments

    1. Tres millones de repositorios de Docker Hub utilizados para difundir malware
  10. nixCraft (nixcraft@mastodon.social)'s status on Thursday, 02-May-2024 08:46:55 UTC nixCraft nixCraft

    Dropbox Sign has been hacked https://sign.dropbox.com/blog/a-recent-security-incident-involving-dropbox-sign Customer's emails, usernames, phone numbers and hashed passwords, in addition to general account settings and certain authentication information such as API keys, OAuth tokens, and multi-factor authentication data leaked. #infosec #security

    In conversation about a year ago from mastodon.social permalink

    Attachments

    1. A recent security incident involving Dropbox Sign - Dropbox Sign
      Information on a security incident involving Dropbox Sign.
  11. cr0n0s:~🐧📡⌨️ 🛠️ # (cr0n0s@social.tchncs.de)'s status on Thursday, 25-Apr-2024 12:43:19 UTC cr0n0s:~🐧📡⌨️ 🛠️ # cr0n0s:~🐧📡⌨️ 🛠️ #

    #humor #infosec #phishing #IT

    In conversation about a year ago from social.tchncs.de permalink

    Attachments


    1. https://f2.tchncs.de/media_attachments/files/112/331/912/478/241/400/original/5b24264c394f7778.jpg
  12. cr0n0s:~🐧📡⌨️ 🛠️ # (cr0n0s@social.tchncs.de)'s status on Wednesday, 24-Apr-2024 12:18:12 UTC cr0n0s:~🐧📡⌨️ 🛠️ # cr0n0s:~🐧📡⌨️ 🛠️ #

    Vulnerabilidad grave en GNU C Library (glibc) de 24 años de antigüedad afecta PHP
    https://blog.segu-info.com.ar/2024/04/vulnerabilidad-grave-en-gnu-c-library.html #php #infosec #gnu #c

    In conversation about a year ago from social.tchncs.de permalink

    Attachments

    1. Vulnerabilidad grave en GNU C Library (glibc) de 24 años de antigüedad afecta PHP
  13. John Scott-Railton ☕ (jsrailton@mastodon.social)'s status on Tuesday, 16-Apr-2024 11:30:35 UTC John Scott-Railton ☕ John Scott-Railton ☕

    IMPORTANT: has #Apple recently sent you a #MercenarySpyware threat notification?

    This is serious. Seek expert help.

    If you're a journalist, activist, dissident, academic, etc. etc:

    ✅contact the Access Now Digital Security Helpline.

    https://www.accessnow.org/help/

    #Apple #Spyware #malware #infosec #cybersecurity #humanrights #security #privacy

    In conversation about a year ago from mastodon.social permalink
  14. :hispagatos: :anarchohacker: (nothing@hispagatos.space)'s status on Friday, 12-Jan-2024 14:15:34 UTC :hispagatos: :anarchohacker: :hispagatos: :anarchohacker:
    • (RTP):tor:Privacy & Tech Tips

    📫GREAT Reason To Both Use / Support @thunderbird #Thunderbird

    New Microsoft #Outlook Collects / Shares Your Data w/Over 772 Parties

    #email #communication #FOSS #Microsoft #Thunderbird #Mozilla #encryption #crypto #e2ee #infosec #Proton #surveillance #cybersecurity #privacy #News

    https://proton.me/blog/outlook-is-microsofts-new-data-collection-service https://fosstodon.org/@RTP/111741233556740248

    @RTP

    In conversation Friday, 12-Jan-2024 14:15:34 UTC from hispagatos.space permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      📡(RTP) Privacy & Tech Tips (@RTP@fosstodon.org)
      from 📡(RTP) Privacy & Tech Tips
      📫GREAT Reason To Both Use / Support @thunderbird@mastodon.online #Thunderbird New Microsoft #Outlook Collects / Shares Your Data w/Over 772 Parties #email #communication #FOSS #Microsoft #Thunderbird #Mozilla #encryption #crypto #e2ee #infosec #Proton #surveillance #cybersecurity #privacy #News https://proton.me/blog/outlook-is-microsofts-new-data-collection-service
  15. Linux TLDR (linuxtldr@noc.social)'s status on Thursday, 24-Aug-2023 03:49:41 UTC Linux TLDR Linux TLDR

    You guys have updates!

    #linux #linuxfan #linuxuser #ubuntu #debian #dev #devops #webdevelopment #programmingmemes #linuxmemes #memes #coding #developer #tech #ethicalhacking #computerscience #coder #security #infosec #cyber

    In conversation Thursday, 24-Aug-2023 03:49:41 UTC from noc.social permalink

    Attachments


    1. https://noc.social/system/media_attachments/files/110/942/474/131/255/155/original/59a8e1c5bacdfc21.png
  16. cr0n0s:~🐧📡⌨️ 🛠️ # (cr0n0s@social.tchncs.de)'s status on Monday, 31-Jul-2023 16:37:28 UTC cr0n0s:~🐧📡⌨️ 🛠️ # cr0n0s:~🐧📡⌨️ 🛠️ #

    Principales técnicas de evasión de firewalls

    https://www.hackplayers.com/2023/07/tecnicas-evasion-firewall.html de la mano de @hackplayers

    #firewalls #seguridad #infosec #redes

    In conversation Monday, 31-Jul-2023 16:37:28 UTC from social.tchncs.de permalink
  17. Philipp-Harald Rack (jomo@mstdn.io)'s status on Monday, 24-Jul-2023 19:51:25 UTC Philipp-Harald Rack Philipp-Harald Rack

    "Despite being widely used and relying on secret cryptography, #TETRA had never been subjected to in-depth public security research in its 20+ year history as a result of this secrecy. […] Midnight Blue managed to reverse-engineer and publicly analyze the TAA1 and TEA algorithms for the first time, and as a result discovered the TETRA:BURST vulnerabilities."

    https://tetraburst.com/ #infosec

    In conversation Monday, 24-Jul-2023 19:51:25 UTC from mstdn.io permalink

    Attachments

    1. TETRA:BURST | Midnight Blue
      TETRA:BURST is a collection of five vulnerabilities, two of which are deemed critical, affecting the Terrestrial Trunked Radio (TETRA) standard used globally by law enforcement, military, critical infrastructure, and industrial asset owners in the power, oil & gas, water, and transport sectors and beyond.
  18. Ain Tohvri (tekkie@mstdn.social)'s status on Wednesday, 14-Jun-2023 10:02:00 UTC Ain Tohvri Ain Tohvri

    Even on a very small static website #Cloudflare makes a difference. #Security #InfoSec

    In conversation Wednesday, 14-Jun-2023 10:02:00 UTC from mstdn.social permalink

    Attachments


    1. https://media.mstdn.social/media_attachments/files/110/190/897/604/916/112/original/cc5872793a7d75a6.png
  19. Joxean Koret (@matalaz) (joxean@mastodon.social)'s status on Thursday, 01-Jun-2023 20:37:28 UTC Joxean Koret (@matalaz) Joxean Koret (@matalaz)

    People are talking about #antivirus security again? Let me tell you a random brief history: once, an AV I won't mention forgot for at least some 2 years to remove from their signatures container (distributed to any and all clients) the *source code* for at least one plugin.

    #AV #Antivirus #Security #infosec

    In conversation Thursday, 01-Jun-2023 20:37:28 UTC from mastodon.social permalink
  20. cr0n0s:~🐧📡⌨️ 🛠️ # (cr0n0s@social.tchncs.de)'s status on Friday, 19-May-2023 22:07:05 UTC cr0n0s:~🐧📡⌨️ 🛠️ # cr0n0s:~🐧📡⌨️ 🛠️ #

    OriON es una máquina virtual desarrollada por Clara Babot como proyecto fin de máster dentro del máster de ciberinteligencia del Campus Internacional de Ciberseguridad.

    OriON tiene integradas distintas herramientas para investigaciones de recopilación de información en fuentes abiertas (#OSINT) sobre personas.

    📝 https://github.com/Cl4r4-5/OriON

    ▶️ https://youtu.be/rTYlaGtA2tE

    #Ciberinteligencia #infosec

    In conversation Friday, 19-May-2023 22:07:05 UTC from social.tchncs.de permalink

    Attachments

    1. GitHub - Cl4r4-5/OriON: OriON is a virtual machine in Spanish that incorporates several tools for Open Source Intelligence (OSINT) on people.
      OriON is a virtual machine in Spanish that incorporates several tools for Open Source Intelligence (OSINT) on people. - GitHub - Cl4r4-5/OriON: OriON is a virtual machine in Spanish that incorporat...
    2. La Nebulosa de OriON
      from OriON
      OriON es una màquina virtual basada en Linux Ubuntu 22.10 que tiene integradas distintas herramientas para investigaciones de recopilación de información en ...
  • Before

Feeds

  • Activity Streams
  • RSS 1.0
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • Privacy
  • Source
  • Version
  • Contact

Bobinas P4G is a social network. It runs on GNU social, version 2.0.1-beta0, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Bobinas P4G content and data are available under the Creative Commons Attribution 3.0 license.