These bank phishing emails are getting convincing. I just got one that looked like it came from my bank, saying my online access was suspended temporarily because of too many incorrect password entries. It asked me to log in and confirm my info.
I could definitely see a lot of people falling for this, but there were some clear red flags:
1. It was sent from some random email account.
2. It was sent to an email that has not been associated with my bank account for a very long time.
Need to send files securely? Check out this excellent fork of Send, originally a Mozilla project:
https://github.com/timvisee/send
Here are the instances, each of which have different capabilities. Two of them allow transfers of up to 20 GB!!
Well this could keep you busy for a long time.
Don't do anything stupid, friends.
#cososec
The August LastPass breach is worse than we thought. I've seen enough. If you use this service, time to dump them.
#cososec
https://twitter.com/SwiftOnSecurity/status/1606071798667173888
SiriusXM, MyHyundai Car Apps Showcase Next-Gen Car Hacking
A trio of security bugs allow remote attackers to unlock or start the car, operate climate controls, pop the trunk, and more — all via poorly coded mobile apps.
Here is a great way to remove all kinds of bloatware and other packages from your #Android phone or tablet. It requires a little bit of technical knowledge, but very simple if you read the directions.
Basically it reads all the installed packages on your phone. You click one to get a description, and can remove individually or in bulk. You could use adb commands in the console, but would not get the helpful descriptions so this way may be safer.
https://forum.xda-developers.com/t/2022-07-03-v0-5-1-universal-android-debloater.4069209/
Apple iOS analytics are shown to *personally identify* users, despite Apple's statements to the contrary. #cososec #osint
"Apple’s analytics data include an ID called “dsId”. We were able to verify that “dsId” is the “Directory Services Identifier”, an ID that uniquely identifies an iCloud account. Meaning, Apple’s analytics can personally identify you."
DraftKings accounts have been compromised, even with 2FA enabled and no evidence of SIM swaps
#cososec
Google Pixel vulnerability allows lock screen bypass using a pin-locked SIM.
Patched in November 5 2022 security update. Pixel owners: Make sure you are on the latest update!
https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/
Someone nearby has a network-connected fridge.
Seongji is a Korean electronic components manufacturer, so I assume the refrigerator is a Samsung.
The string after [fridge] isn't a model number. Maybe the serial?
I'm going to go out on a limb and assume this person doesn't have the fridge on an isolated VLAN.
Google has agreed to a $391.5 million settlement with 40 states in connection with an investigation into how the company tracked users' locations, state attorneys general announced Monday, calling it the largest multistate privacy settlement in U.S history.
https://apnews.com/article/google-privacy-settlement-location-data-57da4f0d3ae5d69b14f4b284dd084cca
🚨
TransUnion LLC Confirms Recent Data Breach with State Attorney General’s Office | Console and Associates, P.C. - JDSupra
https://www.jdsupra.com/legalnews/transunion-llc-confirms-recent-data-6828319/
👋Welcome, new CoSoNauts!
Time to crack those eggs. Upload a profile pic, and say hello. Check out the user guide:
https://counter.social/userguide.pdf
Some tags to follow:
Infosec discussion: #cososec.
Music lovers and musicians: check out #cosomusic, #cosoclassical, #cosojazz, and #musictheory.
If you love good drinks, follow #caffeineclub #winetime #beerme #spirited and #mixmeup.
Animal lovers: #petsofcoso, #dogsofcoso, #catsofcoso.
We're glad you made it here. Enjoy the realness!
Guess what? Twitter's Blue vs. Verified checkmarks are done in a lame way that can be manipulated on the user side using JS. So if you have Blue, you can easily make yourself Verified!
Surely NO ONE is going to take advantage of this.
Thread:
https://twitter.com/shadowbIood/status/1590454913834045440
Script
https://gist.github.com/busybox11/53c76f57a577a47a19fab649a76f18e3
#cososec
nosanitize
#cososec PSA for anyone who still has a Twitter account:
If you do not have 2FA enabled for your account, you should enable it ASAP. (You should use 2FA on all your accounts anyway.)
Settings > Security and Account Access > Security > Two Factor Authentication
Also, de-authorize any third-party apps you have previously granted access.
Settings > Security and Account Access > Apps and Sessions > Connected Apps
For those participating in #Twexit - Do this to remove all of your content there instead of deactivating your account.
https://counter.social/@voltronic/109257543870020693
Be aware that you cannot ever truly delete your data there, but you can remove it from public view.
📢 Welcome, new CoSoNauts! 👋
Time to crack those eggs. Upload a profile pic, and say hello. Check out the user guide:
https://counter.social/userguide.pdf
Some tags to follow:
Infosec discussion: #cososec.
Music lovers and musicians: check out #cosomusic, #cosoclassical, #cosojazz, and #musictheory.
If you love good drinks, follow #caffeineclub #winetime #beerme #spirited and #mixmeup.
Animal lovers: #petsofcoso, #dogsofcoso, #catsofcoso.
We're glad you made it here. Enjoy the realness!
Since we've had a bunch of new infosec people join recently, I would like to revive our fun #infosecfail posts.
Share cringe-worthy infosec incidents from your personal experience using the above tag. No need to reply to this thread; just tag them. Bonus points if you were responsible for said fail.
Hit the tag for past examples.
Hundreds of U.S. news sites hit in SocGholish supply-chain attack
Threat actors are using the compromised infrastructure of an undisclosed media company to deploy the SocGholish JavaScript malware framework (also known as FakeUpdates) on the websites of hundreds of newspapers across the U.S.
👋Welcome, new CoSoNauts!
Time to crack those eggs. Upload a profile pic, and say hello. Check out the user guide:
https://counter.social/userguide.pdf
Some tags to follow:
Infosec discussion: #cososec.
Music lovers and musicians: check out #cosomusic, #cosoclassical, #cosojazz, and #musictheory.
If you love good drinks, follow #caffeineclub #winetime #beerme #spirited and #mixmeup.
Animal lovers: #petsofcoso, #dogsofcoso, #catsofcoso.
We're glad you made it here. Enjoy the realness!
Musician | Teacher | Nerd
𝘐 𝘢𝘮 𝘩𝘪𝘵𝘵𝘪𝘯𝘨 𝘮𝘺 𝘩𝘦𝘢𝘥 𝘢𝘨𝘢𝘪𝘯𝘴𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴, 𝘣𝘶𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴 𝘢𝘳𝘦 𝘨𝘪𝘷𝘪𝘯𝘨 𝘸𝘢𝘺.
- 𝘎𝘶𝘴𝘵𝘢𝘷 𝘔𝘢𝘩𝘭𝘦𝘳