Remember kids lock your phone screen. Never know who might find it and get up to shenanigans.

got a phishing message from "Paypal" -- actually an individual gmail account -- that Proton Mail didn't catch. Reported it to them, bit surprised b/c: obvious.

Novel attack against virtually all VPN apps neuters their entire purpose
TunnelVision vulnerability has existed since 2002 and may already be known to attackers.
Uses DHCP server option to evade VPN.

arstechnica.com/security/2024/

FOUR YEARS c'mon seriously? Tell me that was so we could backdoor them.

"Kremlin-backed hackers have been exploiting a critical Microsoft vulnerability for four years in attacks that targeted a vast array of organizations with a previously undocumented tool, the software maker disclosed Monday."

arstechnica.com/security/2024/

Not one to preach, but this being 2024 it's high time everyone used a password manager. Doesn't need to cost anything.

Little learning curve in exchange for greatly increased security and never again needing to memorize a password.

allthingssecured.com/identity-

“In the default configuration, Ray does not enforce authentication,”

I read that sentence in 2024.

Thousands of servers hacked in ongoing attack targeting Ray AI framework
arstechnica.com/security/2024/

Ars Technica used in malware campaign with never-before-seen obfuscation

"That technique spread the second stage using a text file that browsers and normal text editors showed to be blank.

Opening the same file in a hex editor—a tool for analyzing and forensically investigating binary files—showed that a combination of tabs, spaces, and new lines were arranged in a way that encoded executable code"

I hate it.

arstechnica.com/security/2024/

Not in a car, not near or far
I do not want infotainment anywhere

Ford SYNC 3 infotainment vulnerable to drive-by Wi-Fi hijacking


theregister.com/2023/08/14/for

I'm just finding out that 1)Target (stores) has a tech blog and 2) they've created and open sourced a credit card skimmer-detector.


tech.target.com/blog/cybersecu

Good thing Google got out of the domain business. The .zip idea was...bad.

A simple uBlock Origin* rule can block all zip domains:
My Filters:

||zip^

*A browser extension that filters out ads, cruft, and surveillance-y web content.

duckduckgo.com/?q=.zip+domain+

nosanitize

Pretty slick phish from what appears to be GoDaddy, confirming $400 charge for domains.

But.

I don't do business with that company under any circumstances.

PSA: keep the shields up and the laser sharks at full power.

Aggravation Show more

backsaw - я українець

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.