#infosecfail — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #infosecfail, aggregated by home.social.
-
1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
2) attackers phish schoolkids' accounts
3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
5) ...
6) Profit?Original source post: https://bsky.app/profile/did:plc:bya76aoajvy6ihmaviywjcil/post/3lyiunxfesc2c
-
1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
2) attackers phish schoolkids' accounts
3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
5) ...
6) Profit?Original source post: https://bsky.app/profile/did:plc:bya76aoajvy6ihmaviywjcil/post/3lyiunxfesc2c
-
1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
2) attackers phish schoolkids' accounts
3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
5) ...
6) Profit?Original source post: https://bsky.app/profile/did:plc:bya76aoajvy6ihmaviywjcil/post/3lyiunxfesc2c
-
1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
2) attackers phish schoolkids' accounts
3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
5) ...
6) Profit?Original source post: https://bsky.app/profile/did:plc:bya76aoajvy6ihmaviywjcil/post/3lyiunxfesc2c
-
1) Ban smartphones in schools, preventing the use of convenient MFA TOTP apps
2) attackers phish schoolkids' accounts
3) attackers set up MFA on the stolen accounts to make it harder for admins to recover
4) admins disable the ability to set up MFA on all accounts to prevent attackers from doing it first
5) ...
6) Profit?Original source post: https://bsky.app/profile/did:plc:bya76aoajvy6ihmaviywjcil/post/3lyiunxfesc2c
-
JFC. The stupid... it burns.
Rly Portland School district?#infosecfail #portland
From: @null
https://puddle.town/@null/115171765470756871 -
JFC. The stupid... it burns.
Rly Portland School district?#infosecfail #portland
From: @null
https://puddle.town/@null/115171765470756871 -
JFC. The stupid... it burns.
Rly Portland School district?#infosecfail #portland
From: @null
https://puddle.town/@null/115171765470756871 -
JFC. The stupid... it burns.
Rly Portland School district?#infosecfail #portland
From: @null
https://puddle.town/@null/115171765470756871 -
JFC. The stupid... it burns.
Rly Portland School district?#infosecfail #portland
From: @null
https://puddle.town/@null/115171765470756871 -
Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail https://www.propublica.org/article/microsoft-sharepoint-hack-china-cybersecurity
-
Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail https://www.propublica.org/article/microsoft-sharepoint-hack-china-cybersecurity
-
Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail https://www.propublica.org/article/microsoft-sharepoint-hack-china-cybersecurity
-
Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail https://www.propublica.org/article/microsoft-sharepoint-hack-china-cybersecurity
-
Oops‼️ Microsoft Used China-Based Engineers to Support Product Recently Hacked by China - And just how did this happen? Cause the whole thing sounds counterintuitive; or, I suppose, utterly incompetent. #Microsoft #hacking #hacked #infosec #InfosecFail #fail https://www.propublica.org/article/microsoft-sharepoint-hack-china-cybersecurity
-
They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
😠 -
They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
😠 -
They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
😠 -
They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
😠 -
They changed their password requirements. So the password that I had *already set up* and *used* was no longer valid. I had to reset it.
😠 -
CW: Cybersecurity satire / national facepalm
"Did your data get breached?
Did your backup disappear?
Did your government email get leaked?"Don’t worry! BSSN™ — Big Silent Shadow Network™ has your back.
🛡️ No press
🛡️ No plans
🛡️ No passwords
🛡️ No presence“Your insecurity is our priority.”
-
Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
a) ausreichend lange und nicht vorhersagbare sowie
b) separate Passwörter für jeden Login
erzeugen und ablegen kann.Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.
Also:
- starkes Master-Passwort (oder #2FA),
- nur die PW zugreifbar, die man wirklich braucht,
- am besten keine Online-Tresore. -
Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
a) ausreichend lange und nicht vorhersagbare sowie
b) separate Passwörter für jeden Login
erzeugen und ablegen kann.Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.
Also:
- starkes Master-Passwort (oder #2FA),
- nur die PW zugreifbar, die man wirklich braucht,
- am besten keine Online-Tresore. -
Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
a) ausreichend lange und nicht vorhersagbare sowie
b) separate Passwörter für jeden Login
erzeugen und ablegen kann.Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.
Also:
- starkes Master-Passwort (oder #2FA),
- nur die PW zugreifbar, die man wirklich braucht,
- am besten keine Online-Tresore. -
Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
a) ausreichend lange und nicht vorhersagbare sowie
b) separate Passwörter für jeden Login
erzeugen und ablegen kann.Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.
Also:
- starkes Master-Passwort (oder #2FA),
- nur die PW zugreifbar, die man wirklich braucht,
- am besten keine Online-Tresore. -
Der vermehrte Einsatz von #Passwort-Tresor-Anwendungen ist eine gute Sache, weil man damit
a) ausreichend lange und nicht vorhersagbare sowie
b) separate Passwörter für jeden Login
erzeugen und ablegen kann.Aber wenn man nur ein schwaches Master-Passwort (oder sogar nur eine PIN) verwendet, serviert man alle seine Daten Angreifern frei Haus.
Also:
- starkes Master-Passwort (oder #2FA),
- nur die PW zugreifbar, die man wirklich braucht,
- am besten keine Online-Tresore. -
I needed to make a few #dns changes to a client's domain, who uses a third party for their website and DNS stuff.
Contacted the third party to ask them to add the TXT records and they instead sent me their company login details for the registrar in plaintext via email. This account has access to all their clients sites and DNS stuff.
Wtf.
-
As of Feb 24th City of #Oakland #Cyber #InfoSecFail
#Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
https://www.sfchronicle.com/eastbay/article/ransomware-cripples-oakland-s-311-system-winter-17803917.php -
As of Feb 24th City of #Oakland #Cyber #InfoSecFail
#Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
https://www.sfchronicle.com/eastbay/article/ransomware-cripples-oakland-s-311-system-winter-17803917.php -
As of Feb 24th City of #Oakland #Cyber #InfoSecFail
#Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
https://www.sfchronicle.com/eastbay/article/ransomware-cripples-oakland-s-311-system-winter-17803917.php -
As of Feb 24th City of #Oakland #Cyber #InfoSecFail
#Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
https://www.sfchronicle.com/eastbay/article/ransomware-cripples-oakland-s-311-system-winter-17803917.php -
As of Feb 24th City of #Oakland #Cyber #InfoSecFail
#Ransomware attack persists weeks later, and continues to cripple citizen communications with city and between departments during cold spell. New Mayor Sheng Thao has issued no updates on restoration of services or city's 311 hotline as storm looms.
https://www.sfchronicle.com/eastbay/article/ransomware-cripples-oakland-s-311-system-winter-17803917.php -
O.M.G (the men’s room of the restaurant we were at) #InfosecFail
-
O.M.G (the men’s room of the restaurant we were at) #InfosecFail
-
O.M.G (the men’s room of the restaurant we were at) #InfosecFail
-
ok... what numpty designed a system that requires a one time password sent to an email account, before you can log into said email account?
#InfosecFail #OTP #ITFail -
ok... what numpty designed a system that requires a one time password sent to an email account, before you can log into said email account?
#InfosecFail #OTP #ITFail -
ok... what numpty designed a system that requires a one time password sent to an email account, before you can log into said email account?
#InfosecFail #OTP #ITFail -
ok... what numpty designed a system that requires a one time password sent to an email account, before you can log into said email account?
#InfosecFail #OTP #ITFail -
According to @GossiTheDog #CloudOffice and web hosting provider #Rackspace manages around 2m biz email boxes for tens of thousands of customers and has been down for two wks due to #Ransomware attack after failing to apply avail security patches released since August. Customers have not fully had access restored, but were simply migrated to a competitor Microsoft365 and no backups of contacts or contents exist unless customer had used own or third party backup service.
https://www.cybersecuritydive.com/news/rackspace-ransomware-response-investigation/638985/ #InfoSecFail
-
According to @GossiTheDog #CloudOffice and web hosting provider #Rackspace manages around 2m biz email boxes for tens of thousands of customers and has been down for two wks due to #Ransomware attack after failing to apply avail security patches released since August. Customers have not fully had access restored, but were simply migrated to a competitor Microsoft365 and no backups of contacts or contents exist unless customer had used own or third party backup service.
https://www.cybersecuritydive.com/news/rackspace-ransomware-response-investigation/638985/ #InfoSecFail