home.social

#information-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #information-security, aggregated by home.social.

fetched live
  1. I’m struggling a little with this:

    We’re many of us rightfully concerned about the scale and volume of surveillance tech in everyday life (Flock, Ring, etc). And I see a lot of righteous anger over it.

    But even in “liberal” local forums I see the same, otherwise normal adults encouraging others to ‘review camera footage’ any time something bad happens nearby.

    We can’t have both.

    #Security
    #InformationSecurity

  2. Alert for professionals: Dynamic QR Code Quishing scams are being deployed in public spaces to clone banking credentials. Our latest blog explains the techniques attackers use, the risks to businesses and employees, and recommended mitigation steps. Read the full post: wix.to/b6FlcBr

    #QRScams
    #CyberSecurity
    #FraudPrevention
    #RiskManagement
    #InformationSecurity

  3. Two new preprints from my #research center!

    "Is Cleaning Costly? Evaluating the -fret-cleanAnti-Return-Oriented Programming Mitigation from the OpenBSD Operating System" — an evaluation and critique of #cybersecurity #engineering: briancallahan.net/preprints/Ca (and #blog post about it: briancallahan.net/blog/2026081)

    "Write Your Way to Better Cybersecurity Awareness Training with Active Word Games" — about identifying creating cybersecurity training as a site of learning worthwhile of studying: briancallahan.net/preprints/Wr

    #academic #academia #professor #freebsd #openbsd #netbsd #dragonflybsd #unix #linux #illumos #solaris #compiler #compilers #cybersec #cyber #informationsecurity #infosec

  4. It is with great pleasure that I announce I am a co-author of the Seventh Edition of Gray Hat Hacking, alongside outstanding cybersecurity minds such as Stephen Sims, Valentina Palmiotti, Natalie Silvanovich, Luna Tong, Pavel Yosifovich, Moses Frost, and Huascar Tejeda!

    We are undoubtedly living through exciting times, and I hope readers appreciate this complete overhaul of modern, completely updated content. Stay tuned!

    #cybersecurity #hacking #exploitation #exploit #programming #informationsecurity #infosec

  5. New article: Digital Signatures and Watermarks — Defending Authenticity in the Era of Generative AI.

    As generative AI makes convincing fakes easier, robust authenticity tools become essential. This piece explains how digital signatures and watermarking work, where they fit in compliance and risk strategies, and what organizations should consider when implementing them. Read the full article: wix.to/XM8P8vJ

    #AI
    #Watermarking
    #ContentIntegrity
    #DigitalSignatures
    #RiskManagement
    #InformationSecurity

  6. Weekly output: DDoS attacks, Ed Zitron at Ai4, Delta WiFi spoofing, security perspectives from Black Hat’s NOC, AT&T’s Turbo Live

    Having zero in-person work events on my calendar this week was a real treat after spending the prior week in Vegas bouncing between two conferences. That downtime also allowed me to finish two stories from those events.

    8/11/2026: Major DDoS Attacks Are Booming, But US No Longer the Most Targeted Country, PCMag

    I wrote up a Cloudflare report on trends in distributed denial-of-service attacks and closed it out with a reminder of how efforts to set security standards for the connected gadgets that are often enlisted into DDoS botnets continue to lag.

    8/11/2026: This Tech Expert Thinks It’s ‘Time to Call Bullshit on the AI Industry’, PCMag

    The easier thing to do with Ed Zitron’s talk at Ai4 would have been to write a scaffold of a post around his most memorable lines, but I wanted to provide some context for the numbers he threw out. The required research started feeling like an exercise in yak shaving, in part because the AI data-center news cycle did not stop.

    8/12/2026: Delta Passenger Spoofs Wi-Fi in the Air (Pro Tip: Don’t Do This), PCMag

    After seeing so many other places jump on this story, I decided I should do my part–and make sure that my own post, unlike so many others, would feature a photo of 757 in Delta colors instead of some other plane in DL’s fleet.

    8/14/2026: At Black Hat, AI is helping security pros find threats—and creating new ones, Fast Company

    This was a Black Hat meeting request that I enthusiastically obliged, because Black Hat network admins don’t hold back when they’re talking about unwise behavior they’ve seen on the conference’s WiFi. James Pope (outside this information-security conference, senior director of security product research at Corelight) had some forceful advice for people using AI to vibe-code their own software: “Stop having janky apps.”

    8/15/2026: At Rush Concert, AT&T’s Turbo Live Rocked, With Dazzling Download Speeds, PCMag

    This story ran almost a month after the concert in question; first I had to field various bits of breaking news, then I had to tell my AT&T PR contact to set aside my questions about this data-only power-up and instead answer a query about a round of retroactive rate hikes, then Ai4 and Black Hat monopolized my journalistic bandwidth. I may or may not have also needed additional time to see how many Rush song-title references I could sneak into this post.

    #AI #AIHype #Ai4 #ATT #BlackHat #Cloudflare #cybersecurity #dataCenters #DDoS #Delta #DeltaWiFi #DeltaWiFi #DL #EdZitron #informationSecurity #infosec #NetworkOperationsCenter #NOC #Rush #TurboLive #UnitedCenter #vibeCoding
  7. Losing your phone is no longer just an annoyance.
    Read the blog: marshsecurity.org/protecting-a

    Losing your phone when it contains access to your email, Microsoft 365, MFA, corporate data, personal accounts, banking, photos and potentially your entire digital identity is a little more serious than "annoyance".

    I’ve published a new post looking at what you can do to reduce the impact of a lost or stolen mobile device, both from a personal perspective and also within a business. This blog covers some of the practical protections available through Microsoft and modern device management, as well as the steps worth taking before a device disappears.

    Because realistically, the best time to think about how you’d respond to a lost phone probably isn’t five minutes after realising it’s no longer in your pocket.

    Read the blog: marshsecurity.org/protecting-a

    Tags:
    #Microsoft #Security #Cyber #Tech #Technology #CyberSecurity #MicrosoftSecurity #MicrosoftIntune #Intune #Microsoft365 #EntraID #IdentitySecurity #MobileSecurity #InformationSecurity #DataProtection

  8. 💰 Webinar Gratuito: "Fundamentos de Finanzas Empresariales" 🏢 Miércoles 19 de Agosto 2026. De 11:00 am a 11:45 am (UTC -05:00) 🎆 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLScesLnXuVWAIjM5liWUZ5A06BUHghVL0G6GZnWjANCvA9ssBg/viewform #cybersecurity #infosec #informationsecurity #cyber #cyberrisk #cyberresilience
  9. A wild #blog post appears!

    I discuss a new #research publication: an empirical evaluation of the #OpenBSD -fret-clean flag. We examine the history of the mitigation, measure its costs, and deliberate whether or not it is worth keeping.

    Worth the read if you like security and/or compilers.

    briancallahan.net/blog/2026081

    #freebsd #netbsd #dragonflybsd #bsd #linux #unix #solaris #illumos #compiler #compilers #llvm #gcc #rop #cybersecurity #cybersec #cyber #security #infosec #informationsecurity