home.social

#cybesecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cybesecurity, aggregated by home.social.

fetched live
  1. C-level executives in #fintech strike a balance between the benefits #AI can offer their businesses and the need to guard against its #cybesecurity risks.

    This feature story includes two in-depth interviews with IT leaders. Each detailed how they used new tools and new approaches to how people work within their companies to avoid becoming the "party of no" regarding employees' use of AI -- while still maintaining security controls.

    Check it out: techtarget.com/it-infrastructu

  2. C-level executives in #fintech strike a balance between the benefits #AI can offer their businesses and the need to guard against its #cybesecurity risks.

    This feature story includes two in-depth interviews with IT leaders. Each detailed how they used new tools and new approaches to how people work within their companies to avoid becoming the "party of no" regarding employees' use of AI -- while still maintaining security controls.

    Check it out: techtarget.com/it-infrastructu

  3. Cybersecurity nel mondo Education: perche’ i servizi MDR diventano strategici: Scuole e universita’ si trovano oggi ad affrontare uno scenario cyber sempre piu’ complesso, in cui ransomware, furti di dati e attacchi mirati mettono a rischio non...
    #SamueleZaniboni #ESETItalia #cybesecurity #IT #MDR dlvr.it/TSbBqL

  4. Weekendowa Lektura: odcinek 657 [2026-01-02]. Bierzcie i czytajcie

    🇵🇱 zaufanatrzeciastrona.pl/post/w

    🇬🇧 badcyber.com/it-security-weeke

    Przestępcy – jak można się było spodziewać – ani myślą o noworoczno-świątecznej przerwie, stąd całkiem sporo artykułów, które mieliśmy okazję przejrzeć i dla Was wybrać.

    #infosec #cyberbezpieczenstwo #cybesecurity #weekendowalektura

  5. Weekendowa Lektura: odcinek 657 [2026-01-02]. Bierzcie i czytajcie

    🇵🇱 zaufanatrzeciastrona.pl/post/w

    🇬🇧 badcyber.com/it-security-weeke

    Przestępcy – jak można się było spodziewać – ani myślą o noworoczno-świątecznej przerwie, stąd całkiem sporo artykułów, które mieliśmy okazję przejrzeć i dla Was wybrać.

    #infosec #cyberbezpieczenstwo #cybesecurity #weekendowalektura

  6. Hello! I’m building a mentoring platform for aspiring #hackers and security learners who want deeper, non-corporate guidance. It’s for self-taught people and students (OSCP, cybersecurity degrees) who want 1-on-1 help. learn2hack.today is almost ready and accounts will open soon. If you're interested, fill this: tally.so/r/J9KZkz
    #hacking #mentoring #students #hackerculture #hackers #students #cybesecurity #security #redteam #pentesting #hackingisnotacrime #oscp #ctf #bughunting

  7. Hello! I’m building a mentoring platform for aspiring #hackers and security learners who want deeper, non-corporate guidance. It’s for self-taught people and students (OSCP, cybersecurity degrees) who want 1-on-1 help. learn2hack.today is almost ready and accounts will open soon. If you're interested, fill this: tally.so/r/J9KZkz
    #hacking #mentoring #students #hackerculture #hackers #students #cybesecurity #security #redteam #pentesting #hackingisnotacrime #oscp #ctf #bughunting

  8. Wazuh: Детальный разбор localfile — настройка сбора логов в SIEM-системе

    Привет, хабровчане! Если вы занимаетесь DevOps, системным администрированием или кибербезопасностью, то Wazuh — это ваш must-have для мониторинга и SIEM. В этой статье (и соответствующем видео на моём канале) мы разберём секцию в конфигурации агента Wazuh. Это ключевой компонент Logcollector'а, который отвечает за сбор логов из файлов, системных событий, команд и даже journald. Без правильной настройки вы рискуете пропустить важные события или утонуть в шуме. Статья основана на официальной документации ( documentation.wazuh.com/curren ), с практическими примерами из реальных конфигов. Если необходимо видео, то можно посмотреть тут ( youtu.be/69mVhQsjXZU ).

    habr.com/ru/articles/964290/

    #siem #сием #wazuh #вазух #security #cybesecurity

  9. I'm not sure if you all read the news about the rogue communication devices found in Chinese solar power inverters?

    If not here is a short recap of the Reuters article from 2025-05-14:

    Two anonymous U.S experts stated that they found "rogue" communication devices that were not listed in product documents in some Chinese solar inverters.
    They also claimed that similar undocumented communication devices, including cellular radios, have also been found previously in some batteries from Chinese suppliers.

    These communication devices could be used to bypass firewalls and switch off inverters remotely, or change their settings, could destabilize power grids, damage energy infrastructure, and trigger widespread blackouts. In the end the devices could be used to physically destroy the grid.

    The whole article is here:
    reuters.com/sustainability/cli

    While Reuters stayed vague enough to not be wrong, other news outlets were quick to postulate that a Chinese “kill switches” had been found hidden in American solar farms.

    While I don't doubt the theoretical possibility of the envisioned attack, the story still feels off to me!

    The story just contains too few details. Reading it carefully it just states that undocumented components or undocumented communication devices were found. The "rogue" part is an interpretation. The theoretical consequences are valid nevertheless.

    It remind me a lot of the story of spy chips on server boards (2018), which The Register described as a "mishmash of disparate and inaccurate allegations" .
    theregister.com/2021/02/12/sup

    What do you think?

    #Cybesecurity #CriticalInfrastructure

  10. I'm not sure if you all read the news about the rogue communication devices found in Chinese solar power inverters?

    If not here is a short recap of the Reuters article from 2025-05-14:

    Two anonymous U.S experts stated that they found "rogue" communication devices that were not listed in product documents in some Chinese solar inverters.
    They also claimed that similar undocumented communication devices, including cellular radios, have also been found previously in some batteries from Chinese suppliers.

    These communication devices could be used to bypass firewalls and switch off inverters remotely, or change their settings, could destabilize power grids, damage energy infrastructure, and trigger widespread blackouts. In the end the devices could be used to physically destroy the grid.

    The whole article is here:
    reuters.com/sustainability/cli

    While Reuters stayed vague enough to not be wrong, other news outlets were quick to postulate that a Chinese “kill switches” had been found hidden in American solar farms.

    While I don't doubt the theoretical possibility of the envisioned attack, the story still feels off to me!

    The story just contains too few details. Reading it carefully it just states that undocumented components or undocumented communication devices were found. The "rogue" part is an interpretation. The theoretical consequences are valid nevertheless.

    It remind me a lot of the story of spy chips on server boards (2018), which The Register described as a "mishmash of disparate and inaccurate allegations" .
    theregister.com/2021/02/12/sup

    What do you think?

    #Cybesecurity #CriticalInfrastructure

  11. Explore the power of Urlex! 🌐✨ This amazing URL expander safely reveals the full links behind shortened URLs, making it the fastest and easiest way to unmask them. 🚀🔗 With batch expansion and custom timeouts, it's perfect for anyone needing efficiency! Check it out 👉 urlex.org #URLExpander #SafetyFirst #TechTools #WebUtility #privacy #cybesecurity

  12. Explore the power of Urlex! 🌐✨ This amazing URL expander safely reveals the full links behind shortened URLs, making it the fastest and easiest way to unmask them. 🚀🔗 With batch expansion and custom timeouts, it's perfect for anyone needing efficiency! Check it out 👉 urlex.org #URLExpander #SafetyFirst #TechTools #WebUtility #privacy #cybesecurity

  13. Videosorveglianza e Privacy: la tutela dell’operatore in ambito Forze dell’Ordine, sanita’, trasporti. Relatori al convegno di Battipaglia: Il Comune di Battipaglia ospitera’ l’evento formativo l’8 ottobre prossimo, segniamo la data! Al centro dell’iniziativa e della serie di interventi, un tema emergente nel mondo dell’utenza pubblica e privata, in ambito sanitario, dei trasporti e della sicurezza urbana: la tutela...
    #Videosorveglianza #privacy #cybesecuritydlvr.it/TCPsWV

  14. In my last livestream you could witness LIVE, how not reading an exploit (or its code for that matter) can cause some unnecessary headaches (in the best case). Sometimes I fall into these kind of "amateur-ish" patterns (especially during livestreams). :ablobcatmelt:

    ⬇️ I downloaded this exploit and tried to run it with a simple "PHP GET-CMD" webshell:

    github.com/kimusan/pkwner/blob

    After failing to do some damage with that one, I finally read the code and saw the "/bin/bash" at the end (thanks to the walkthrough of @0xdf I found the exploit in the first place, and after reading the walkthrough I also saw the bash line there). :flan_hacker:

    And then I got the root flag thanks to the writeup :blobsmile:

    TL;DR: Read the Exploit Code and try to understand it...

    #hacking #cybesecurity #ctf #hackthebox

  15. In my last livestream you could witness LIVE, how not reading an exploit (or its code for that matter) can cause some unnecessary headaches (in the best case). Sometimes I fall into these kind of "amateur-ish" patterns (especially during livestreams). :ablobcatmelt:

    ⬇️ I downloaded this exploit and tried to run it with a simple "PHP GET-CMD" webshell:

    github.com/kimusan/pkwner/blob

    After failing to do some damage with that one, I finally read the code and saw the "/bin/bash" at the end (thanks to the walkthrough of @0xdf I found the exploit in the first place, and after reading the walkthrough I also saw the bash line there). :flan_hacker:

    And then I got the root flag thanks to the writeup :blobsmile:

    TL;DR: Read the Exploit Code and try to understand it...

    #hacking #cybesecurity #ctf #hackthebox

  16. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  17. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  18. The Canadian Centre for Cyber Security has an interesting article on #CybeSecurity #ThreatActors (adversaries) and their motivation.

    cyber.gc.ca/en/guidance/introd

    The article IMHO leaves out at some threat actors (which might not be that relevant for a commercial or critical infrastructure setting)

    • Abusive Partners
    • Stalkers
    • Kids

    while these could be seen as part of insider threats, I believe that their capabilities and opportunities are different from other insiders.
    And they are often overlooked when developing consumer products.
    Think of the problems with #AirTags or the bike theft "problem" with Strava.

    I really like this and are thinking of creating a game around it to raise security awareness (especially within development and designe of systems). #SeriousGames

    Idea is to have a collaborative game where you play through threats against your system. Starting with the Threat Actors, their intend, capabilities and opportunities.
    Going through techniques used (maybe using a subset of #MitreAttack but also common #SocialEngineering techniques).
    And then choosing mitigation and defense options.

    A bit of a mixture between #ElevationOfPrivilege/#EoP, #BackdoorsAndBreaches and #FearlessJourney

  19. The Canadian Centre for Cyber Security has an interesting article on #CybeSecurity #ThreatActors (adversaries) and their motivation.

    cyber.gc.ca/en/guidance/introd

    The article IMHO leaves out at some threat actors (which might not be that relevant for a commercial or critical infrastructure setting)

    • Abusive Partners
    • Stalkers
    • Kids

    while these could be seen as part of insider threats, I believe that their capabilities and opportunities are different from other insiders.
    And they are often overlooked when developing consumer products.
    Think of the problems with #AirTags or the bike theft "problem" with Strava.

    I really like this and are thinking of creating a game around it to raise security awareness (especially within development and designe of systems). #SeriousGames

    Idea is to have a collaborative game where you play through threats against your system. Starting with the Threat Actors, their intend, capabilities and opportunities.
    Going through techniques used (maybe using a subset of #MitreAttack but also common #SocialEngineering techniques).
    And then choosing mitigation and defense options.

    A bit of a mixture between #ElevationOfPrivilege/#EoP, #BackdoorsAndBreaches and #FearlessJourney