Show more

🇬🇧

Looks like Vodaphone and Virgin may be loading on a root CA (a potential MitM attack vector) onto phones.

twitter.com/GossiTheDog/status

If you're in charge of any cloud infrastructure.

protect.
your.
information!

51Gb of mortgage data found just sitting without so much as a password to protect it.

darkreading.com/attacks-breach

Can somebody with a FB account verify this?

The implications of this are staggering.

Facebook automatically weakens your passwords?

Wow, so much fail, so much f-up, so much word salad cover up.

ktva.com/story/39834995/state-

The Trojan named in this article had been around since 2009, and they claim that "researchers" had yet to come up with a way to detect it for their virus scanner definitions. It as claims that there was almost no way that data was exfiltrated, but that's what this does.

Anyway, sorry, Alaskans, you're getting a "you've been breached" letter.

poll

Are you a builder, breaker or defender, or some combination of?

(builder here)

people,

My wife's W2 just showed up partially opened. Salary and SSN are visible with minimal effort.

Outside of a credit block, what can be done?

sigh - another nick in 2FA's armor.

an attacker can craft an email which will send you to a phishing server. This server will make you think you're entering your credentials and 2FA code, but in reality you're just entering it to the attacker.

listen, 2FA is still a good idea, but you need to make sure that you're actually going to the site you think you are. Check the link in emails, type it in manually.

This attack *doesn't* work on fob-based 2FA.

itpro.co.uk/two-factor-authent

in

I just found out about this.

a free Day of SHEcurity event in Boston on February 22nd.

dayofshecurity.com/boston-2019

Remember that Town Of Salem breach earlier?

Yeah, well, if you were affected, then as if right now there is a 27% chance that your password is unhashed. (Now readable)

Devs.. don't use MD5 for hashing, but if you must, salt your passwords.

Everybody else... You don't know what kind of password security any given site is using so make sure that the password is unique and not guessable on another site.

bleepingcomputer.com/news/secu

Brilliant! Use Google's speech to text engine to defeat Google's recaptcha

and just like that Captcha's are broken again.

github.com/ecthros/uncaptcha2

hey, everybody, I've told you before, and I'm sure I'm not the only one, but go to your router setup and disable uPnP.

There's at least 2 people scanning the internet and forcing chromecasts and smart TVs to play pewdipie videos.

twitter.com/GossiTheDog/status

Show more

<invalid character>

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.