cybersecurity experts Tommy Mysk and Talal Haj Bakry have shown in a recent YouTube video how to "hack" a Tesla
using Flipper Zero, a Raspberry Pi, or just a laptop to pull the "hack" off.
Okay peeps
fun social engineering / physical security quiz!
Based on this picture of a door lock, what do you think the passcode is for entry? Please include the order the characters are entered.
(This is from a thread on X I'll post the thread URL later I'll give it a few hours) ((no cheating now by trying to find the thread lol))
Nissan Oceania is notifying roughly 100,000 individuals of a data breach resulting from a ransomware attack conducted by a known cybercrime group in late 2023.
“The type of information involved will be different for each person. Current estimates are that up to 10% of individuals have had some form of government identification compromised. The data set includes approximately 4,000 Medicare cards, 7,500 driver’s licenses, 220 passports and 1,300 tax file numbers,”
Say goodbye to Google or Apple Contacts: From now on you can use your Tuta Contacts to start a chat or make a call!
The arms race continues, as burglars are learning how to use jammers to disable Wi-Fi security cameras.
Wi-Fi jamming to knock out cameras suspected in nine Minnesota burglaries -- smart security systems vulnerable as tech becomes cheaper and easier to acquire
Critical security flaws found in ChatGPT plugins expose users to data breaches. Attackers could steal login details and access sensitive data on third-party websites
Salt Security, has discovered critical security vulnerabilities within popular plugins of OpenAI’s AI chatbot ChatGPT
These flaws may allow attackers to steal sensitive user data and gain unauthorized access to accounts on third-party websites or data retrieval from Google Drive
Report
"With TutaCrypt we are revolutionizing the security of emails. For the first time, people can now send and receive emails that are encrypted so strongly that not even quantum computers will be able to break the encryption and decipher the messages," stated Tuta's CEO, Arne Möhle
New Tuta Mail accounts will get TutaCrypt upon creation, and existing users will get the superior protocol through a gradual key rotation that will take place over the next period.
The British Library ransomware attack was likely caused by the compromise of third-party credentials coupled with no multifactor authentication (MFA) in place to stop the attackers, despite previous warnings about these risks.
The lack of MFA on the domain was identified and raised as a risk when MFA was introduced to other parts of the Library in 2020, “but the possible consequences were perhaps under-appraised,” the report stated.
https://blogs.bl.uk/living-knowledge/2024/03/learning-lessons-from-the-cyber-attack.html
Microsoft confirms that Russian state-sponsored hackers, known as Midnight Blizzard, infiltrated their systems and stole source code. Experts warn of potential zero-day vulnerabilities.
The breach, originally discovered on January 12, 2024, and reported on January 19, raised concerns about the potential misuse of proprietary information and the security of millions of users relying on Microsoft’s products and services.
https://www.hackread.com/russia-midnight-blizzard-hackers-microsoft-source-code/
This is from 1yr ago - it might come in handy for some
THREAD: How to verify images online?
A seemingly mundane purchase by the Romanian military on January 16 for Chinese-made surveillance equipment could have far-reaching national-security implications.
Valued at under $1,000, an employee of the Romanian Defense Ministry purchased an eight-port switch and two surveillance cameras from Hikvision, a Chinese company with purported ties to the Chinese military.
A team of researchers from the University of Florida, collaborating with CertiK, a Web3 smart contract auditor, have uncovered potential security threats in wireless charging systems. Their research introduces new attack methods, named VoltSchemer, which exploit vulnerabilities in these systems by manipulating power supply voltages.
https://www.cysecurity.news/2024/03/researchers-develop-voltschemer.html
look what just popped up on my radar
#Chrome users now have a way to guard against the threat of extension subversion, that is, if they don't mind installing yet another browser extension.
Matt Frisbie, a software developer and programming book author, has released a Chrome add-on called Under New Management to alert users when installed extensions have changed owners.
/nosanitize
threat actor is creating fake Skype, Google Meet, and Zoom meetings, mimicking these popular collaboration applications to spread various commodity malware that can steal sensitive data from both Android and Windows users.
The campaign, which began in December, demonstrates an emerging cybersecurity threat for corporate users
Critical DNS Bug Poses Threat to Internet Stability
https://www.cysecurity.news/2024/02/critical-dns-bug-poses-threat-to.html
As the story unfolds, it now rests on the shoulders of DNS service providers to prioritise updating their systems and implementing necessary measures to secure the DNS infrastructure, thereby safeguarding the uninterrupted functioning of the Internet
Outlook has identified a security flaw that affects how it handles certain hyperlinks.
CVE number for this vulnerability is CVE-2024-21413, with a severity rating of 9.8 (Critical).
The Daily Dark Web recently reported that specific hacking forums have been discussing an exploit for CVE-2024-21413.
all google account sign-ins you will see a new page soon
the new Google Account sign-in page is rolling out to phones, tablets, and computers.
instead of the page being centered on desktop, Google places the email/phone text field to the right, while a Google logo and other information appears at the left
A pill-shaped button is used for “Next,” while every other button is just directly placed text
The RCMP has launched a criminal investigation as it manages a cybersecurity attack targeting its networks
In an email sent to staff Friday, RCMP chief security officer Paul L. Brown said the force is managing a "cyber event" and urged employees to stay vigilant.
https://www.ctvnews.ca/canada/rcmp-confirms-alarming-cyber-event-targeting-its-networks-1.6781207
The RCMP says the situation is evolving quickly and acknowledged a breach of this magnitude is alarming
E = Mc2 - Energy Milk Coffee
Fáilte Abhaile 🏴 “a nod’s as guid as a wink tae a blind horse”
ta be aff yer heid helps