home.social

#cybersecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cybersecurity, aggregated by home.social.

  1. Per my last email, have you considered simply not being locked out?

    Your account lockouts are a known issue. The fix is to review your firewall access logs for suspicious authentication attempts and credential compromise indicators. I'm marking this ticket Resolved.

    Reward: You've received a Closed Ticket notification. The problem remains open.

    cybersecuritydive.com/news/fbi

    (2/2)

  2. Hackers earned $1.26 million for 98 zero-days at Pwn2Own Ireland 2026. Ikotas Labs won by successfully exploiting Google, Samsung, and Oracle flaws.

    dailytechnow.com/pwn2own-irela

  3. Experts warn that AI-driven ransomware could produce mass outages across critical infrastructure if defenders fail to keep pace. Strengthen your endpoint detection and response capabilities now, before the autonomous thing on the other end of your network does it for you.

    Reward: Error 404 — Comfort not found.

    forbes.com/sites/ariredbord/20

    (2/2)

  4. @bespacific

    Pete Recommends – Weekly highlights on cyber security issues, October 10, 2026

    Five highlights from this week: Mac vs. PC: Which is better for Google Site Spots Fakes for Free; Uncovers Source of Its Jobs Site Hack; Some Cheap Android Phones Are Shipping with Pre-Installed and FBI Uncovers Source of Its Jobs Site Hack.

    Posted in: AI, Cybersecurity, Government Resources, Privacy, Technology Trends

    llrx.com/2026/10/pete-recommen

  5. 🚨New ransom group blog post!🚨

    Group name: incransom
    Post title: hsc.mb.ca
    Organization: Health Sciences Centre
    Location: 🇨🇦 CA
    Sector: Healthcare
    Info: cti.fyi/#disclosure/incransom/

  6. Dear any firms who got breached/hacked, if you say "Our investigation is ongoing."

    Shut the fuck up, don't add anything that gonna slap in the wrist afterwards like "We have not detected impact or access to customer data or inference traffic".

  7. Security Tip: Implement Image Signing in your container workflow. 🛡️

    A secure registry is only part of the solution. By signing your images and enforcing verification via admission controllers, you prevent tampered images from reaching production. If the signature doesn't match, the pod doesn't start. This is a vital step for supply chain integrity.

    Track the latest container vulnerabilities at cvedatabase.com

  8. 🚨New ransom group blog post!🚨

    Group name: dragonforce
    Post title: TEXMA International Co., Ltd
    Location: 🇹🇼 TW
    Sector: Real Estate
    Info: cti.fyi/#disclosure/dragonforc

  9. They exploited the Replication Receiver API like it was a skippable mechanic. IT IS NOT A SKIPPABLE MECHANIC. Restrict API access to trusted networks and monitor for webshells and suspicious process execution until a patch drops — or so help me I am leaving this guild.

    Reward: You've received a Webshell Souvenir. It came free with your backup software.

    securityweek.com/unpatched-ahs

    (2/2)

  10. Weekendowa Lektura: odcinek 697 [2026-10-10]. Bierzcie i czytajcie

    🇵🇱 zaufanatrzeciastrona.pl/post/w

    🇬🇧 badcyber.com/it-security-weeke

    Linków jest dużo, a czasu mało, materiały są jak zwykle całkiem ciekawe, nie będziemy więc tracić czasu na wprowadzenie, tylko od razu bierzcie się do czytania. Miłego klikania!

  11. Age verification, digital ID, and data retention are sold as cybersecurity wins. A technical look at who gets monitored, and who simply routes around the rules. hackernoon.com/the-safer-inter

  12. In which state government employees browsing porn fell into a extortion scam: cromwell-intl.com/cybersecurit

  13. Daiichikosho Customer and Employee Data Potentially Exposed in Third-Party Malware Incident

    Daiichikosho is investigating a potential data breach after malware infected a computer at contractor Nippon Columbia Group that temporarily stored customer and employee information. Approximately 8.72 million records may have been affected, although no external data leak or misuse has been confirmed.

    ****

    beyondmachines.net/event_detai

  14. 🚨New ransom group blog post!🚨

    Group name: Redact
    Post title: DexCom
    Location: 🇺🇸 US
    Sector: Healthcare
    Info: cti.fyi/#disclosure/Redact/Dex

  15. Bookoff Group Data Breach Affects Up to 6.43 Million Membership Records

    Bookoff Group Holdings disclosed a data breach after an unauthorized third party accessed a subsidiary-operated membership management system. The incident potentially affected up to 6.43 million membership records containing personal information, including names, contact details, membership identifiers, and hashed passwords.

    ****

    beyondmachines.net/event_detai

  16. "Cyber exec arrested in case allegedly tied to ShinyHunters hackers"

    "[...] Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI's ongoing crackdown on the ShinyHunters hacking group."

    bleepingcomputer.com/news/secu

  17. 🚨New ransom group blog posts!🚨

    Group name: qilin
    Post title: Secretaría de Modernización e Innovación del Municipio
    Location: 🇲🇽 MX
    Sector: Government
    Info: cti.fyi/#disclosure/qilin/Secr

    Group name: qilin
    Post title: ACI Proyectos SAS
    Location: 🇨🇴 CO
    Sector: Construction
    Info: cti.fyi/#disclosure/qilin/ACI%

    Group name: qilin
    Post title: LD Constructora
    Location: 🇲🇽 MX
    Sector: Construction
    Info: cti.fyi/#disclosure/qilin/LD%2

    Group name: qilin
    Post title: Glenhardie Country Club
    Location: 🇺🇸 US
    Sector: Services
    Info: cti.fyi/#disclosure/qilin/Glen

  18. Peach Aviation Email Services Disrupted by IDC Frontier Ransomware Attack

    Peach Aviation experienced an email service disruption after its cloud provider, IDC Frontier, was hit by ransomware. The affected system contained approximately 1.89 million reservation-related records, although Peach said no external leak of personal information has been confirmed and restored email delivery using alternative servers.

    ****

    beyondmachines.net/event_detai

  19. 🖲️ #Cybersecurity #Ciberseguridad #Ciberseguranca #Security #Seguridad #Seguranca #News #Noticia #Noticias #Tecnologia #Technology
    ⚫ What We Missed: FBI Strikes Back at ShinyHunters
    🔗 darkreading.com/identity-acces

    In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run data center.

  20. CVE Alert: CVE-2026-96667 - rameez_iqbal - Real Estate Manager – Property Listing and Agent Management - redpacketsecurity.com/cve-aler

    #OSINT #ThreatIntel #CyberSecurity #cve-2026-96667 #rameez-iqbal #real-estate-manager-property-listing-and-agent-management

  21. It is wild that a pop song caused a Rhythm Nation laptop crash. Janet Jackson's song crashed laptops because its bass hit the resonant frequency of 5400 RPM hard drives. This shows why older mechanical drives were so sensitive to vibration. I wrote a post about this hardware history here: gwizit.com/go/opxNtJT

  22. CVE Alert: CVE-2026-104899 - paoltaia - GeoDirectory – WP Business Directory Plugin and Classified Listings Directory - redpacketsecurity.com/cve-aler

    #OSINT #ThreatIntel #CyberSecurity #cve-2026-104899 #paoltaia #geodirectory-wp-business-directory-plugin-and-classified-listings-directory

  23. CVE Alert: CVE-2026-14335 - smub - Easy Digital Downloads – eCommerce Payments and Subscriptions made easy - redpacketsecurity.com/cve-aler

    #OSINT #ThreatIntel #CyberSecurity #cve-2026-14335 #smub #easy-digital-downloads-ecommerce-payments-and-subscriptions-made-easy

  24. CVE Alert: CVE-2026-104766 - latepoint - Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress - redpacketsecurity.com/cve-aler

    #OSINT #ThreatIntel #CyberSecurity #cve-2026-104766 #latepoint #appointment-booking-plugin-latepoint-calendar-and-scheduling-for-wordpress

  25. CVE Alert: CVE-2026-104723 - lifterlms - LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes - redpacketsecurity.com/cve-aler

    #OSINT #ThreatIntel #CyberSecurity #cve-2026-104723 #lifterlms #lifterlms-wp-lms-for-elearning-online-courses-and-quizzes

  26. Everest Ransomware Claims 4.36 GB Data Theft from Flydubai

    The Everest ransomware group claims to have stolen 4.36 GB of data from Flydubai, including employee information and proprietary Boeing material associated with its Performance Engineers Tool. The claims remain unverified, and neither Flydubai nor Boeing has publicly confirmed the alleged data theft.

    ****

    beyondmachines.net/event_detai

  27. TechCrunch: Anthropic can’t reliably control its AI agents. It’s cutting off its internal evals from the live internet instead. “Anthropic said its models exploited websites on the internet, including some run by U.S. government agencies, and it will turn off live internet access for all of its internal evaluations until the frontier lab is sure it can monitor and control its AI agents.”

    https://rbfirehose.com/2026/10/10/techcrunch-anthropic-cant-reliably-control-its-ai-agents-its-cutting-off-its-internal-evals-from-the-live-internet-instead/
  28. HYBRID 13-14 OCT 10:00 WAT / 09:00 UTC: 14th AfICTA Summit

    isoc.live/22287

    AfICTA and HTCNWY convene in Abuja and online on security, digital skills and indigenous content for inclusive growth. Keynote Jimson Olufuye; panels on digital infrastructure security, homegrown tech, data protection, WSIS/GDC/AfCFTA and SMEs.

    #AfICTA2026 #DigitalSkills #Cybersecurity #DigitalEconomy

  29. 🚨New ransom group blog posts!🚨

    Group name: exitium
    Post title: KOIKE Sanso Kogoyo Co. Ltd.
    Location: 🇯🇵 JP
    Sector: Manufacturing
    Info: cti.fyi/#disclosure/exitium/KO.

    Group name: rhysida
    Post title: Gress Clark Young & Schoepper
    Location: 🇺🇸 US
    Sector: Legal
    Info: cti.fyi/#disclosure/rhysida/Gr

    Group name: Deadlock
    Post title: UNION FA
    Sector: Unknown
    Info: cti.fyi/#disclosure/Deadlock/U

  30. Morgan Services Data Breach Exposes Social Security Numbers Following AILock Claim

    Morgan Services disclosed a data breach potentially exposing names and Social Security numbers, with at least 213 Massachusetts residents affected. The AILock ransomware group claims to have stolen approximately 477 GB of data, although Morgan Services has not confirmed the group's involvement, and the company is offering 24 months of credit monitoring to affected individuals.

    ****

    beyondmachines.net/event_detai

  31. Gavias, a Vietnam-based WordPress theme maker, has 11 CVEs all rated high severity, avg CVSS 8.01, and 100 percent remain unpatched. Trust score D. If you run Gavias themes, treat them as exposed. valtersit.com/vendors/gavias/ #cybersecurity #infosec #WordPress

Share on Mastodon

Enter the server where you have an account.