Rachel Tobac just released a free security eBook!
Protect your company from cyber criminals
In this eBook, white hat hacker Rachel Tobac exposes the most prevalent cybersecurity threats of the day and shares actionable steps that your business (and employees) can take to protect against them.
Threat modeling
I just got another "your password will expire in 8 days" notice from my district IT dept.
It's so frustrating that they continue to use such outdated security practices. NIST would like a word.
Well this is sub-optimal. #cososec
Backdoored firmware lets China state hackers control routers with “magic packets”
The modified firmware used by BlackTech is hard to detect.
Hackers backed by the Chinese government are planting malware into routers that provides long-lasting and undetectable backdoor access to the networks of multinational companies in the US and Japan, governments in both countries said Wednesday.
Inside ShadowDragon, The Tool That Lets ICE Monitor Pregnancy Tracking Sites and Fortnite Players
https://www.404media.co/inside-shadowdragon-ice-babycenter-pregnancy-fortnite-black-planet/
I seriously question whether LinkedIn is more effective for corporate networking or for providing attack vectors for social engineering.
I really feel for infosec pros and IT managers who get incredulous responses to simple requests for improving safety.
Below is a thread from a recording forum I belong to. I really tried to convince them that running a 12-year-old version of a known vulnerable torrent client was a bad idea. The pushback was disheartening. Chalk up an #InfosecFail on this one. #cososec
/nosanitize
https://taperssection.com/index.php?PHPSESSID=5561d6fa6439cd91b134cb7c34618cd8&topic=203259.0;all
Removing your information from these databases should be a priority. #cososec
https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List
People are losing more money to scammers than ever before.
Here's how to keep yourself safe.
Looking for a great encrypted messenger that protects your privacy far better than Signal?
SimpleX Chat is what you're looking for. Several of us here have been using it for months. Highly recommended.
$5 billion Google lawsuit over ‘Incognito mode’ tracking moves a step closer to trial / Judge Yvonne Gonzalez Rogers denied Google’s push for a summary judgment in a lawsuit over the way it tracked internet activity even after users switched to ‘Incognito mode.’
@rootsecdev
Welcome! It's good to see you here.
#cososec has a lot of content that may interest you.
I posted earlier today (mistakenly) about Amazon being down. It turns out one of my network filter lists had updated and was causing my problem. Checked my #pi-hole logs, and it was blocking:
www.amazon.com
and
unagi-na.amazon.com
The first was obvious, but the second must be part of their regional CDN or something. Not sure why those domains were put on an ad filter list.
Anyway, lesson learned.
Always check your filters first, kids.
Hackers manage to unlock Tesla software-locked features worth up to $15,000
A group of hackers have exposed an exploit that can unlock Tesla’s software-locked features worth up to $15,000.
Free heated seats and Full Self-Driving package, anyone?
https://electrek.co/2023/08/03/hackers-manage-unlock-tesla-software-locked-features/
MOVEit body count closes in on 400 orgs, 20M+ individuals
'One of the most significant hacks of recent years,' we're told
Serious question: Are there any legit reasons to be on darknets? Because I can't think of any reasons outside of doing illegal things and trying to catch the people doing those illegal things.
Just to be clear, I am not recommending all of you go test this theory for me. There's a lot of awful there, and you have to take certain steps to insulate yourself.
Musician | Teacher | Nerd
𝘐 𝘢𝘮 𝘩𝘪𝘵𝘵𝘪𝘯𝘨 𝘮𝘺 𝘩𝘦𝘢𝘥 𝘢𝘨𝘢𝘪𝘯𝘴𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴, 𝘣𝘶𝘵 𝘵𝘩𝘦 𝘸𝘢𝘭𝘭𝘴 𝘢𝘳𝘦 𝘨𝘪𝘷𝘪𝘯𝘨 𝘸𝘢𝘺.
- 𝘎𝘶𝘴𝘵𝘢𝘷 𝘔𝘢𝘩𝘭𝘦𝘳