home.social

#infosecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #infosecurity, aggregated by home.social.

fetched live
  1. Advisory for Oracle Fusion middleware:

    - 345 vulnerabilities fixed
    - 9 vulnerabilities with CVE score of 10.0
    - 145 vulnerabilities with CVE score of 9.0 to 9.9

    😒 #infosec #infosecurity #cve #Oracle

  2. Advisory for Oracle Fusion middleware:

    - 345 vulnerabilities fixed
    - 9 vulnerabilities with CVE score of 10.0
    - 145 vulnerabilities with CVE score of 9.0 to 9.9

    😒 #infosec #infosecurity #cve #Oracle

  3. The Gentlemen have usurped Qilin as the most prolific ransomware gang of recent times, according to analysis of incidents which can be attributed to known ransomware threat groups

    (Write up by me. Picture, alas not in article...)

    infosecurity-magazine.com/news

    #infosecurity #ransomware

  4. The Gentlemen have usurped Qilin as the most prolific ransomware gang of recent times, according to analysis of incidents which can be attributed to known ransomware threat groups

    (Write up by me. Picture, alas not in article...)

    infosecurity-magazine.com/news

    #infosecurity #ransomware

  5. @[email protected]

    Guess you’ve upgraded to a non-proprietary operating system like free, open-source Linux, and said goodbye to M$ and G$.
    ​:tuxtyping:​ ​:tux:​

    #microsoft #linux #infosecurity #infosec #tux

  6. Security Tip: The Principle of Least Privilege (PoLP) is a core pillar of Zero Trust. 🛡️ By ensuring that every user, process, and system has only the minimum access levels necessary to function, you significantly reduce the risk of lateral movement during a security breach. Audit your IAM roles regularly to remove permission creep. Stay ahead of emerging threats and track vulnerabilities at cvedatabase.com

  7. A ransomware group and a cyber-criminal gang which specializes in stealing credentials through supply chain attacks have teamed up in a move which what has been described by cybersecurity researchers as an “unprecedented model of industrialized ransomware.”

    As detailed by Sophos, the collaboration is between the Vect ransomware group and TeamPCP, a group associated with The Com, a collective of English-speaking cyber criminals behind a series of high-profile supply chain attacks.

    Sophos warned that the combination of a convergence of TeamPCP’s large-scale supply chain credential theft, which particularly targets developers, alongside Vect’s ransomware-as-a-service service operation represents a “meaningful shift in the ransomware threat landscape”.

    The result is that any organization which has had login credentials stolen by TeamPCP could be at additional risk of also falling victim to a ransomware attack by Vect.

    (Me for Infosecurity Mag)

    #Infosecurity #ransomware

    infosecurity-magazine.com/news

  8. A ransomware group and a cyber-criminal gang which specializes in stealing credentials through supply chain attacks have teamed up in a move which what has been described by cybersecurity researchers as an “unprecedented model of industrialized ransomware.”

    As detailed by Sophos, the collaboration is between the Vect ransomware group and TeamPCP, a group associated with The Com, a collective of English-speaking cyber criminals behind a series of high-profile supply chain attacks.

    Sophos warned that the combination of a convergence of TeamPCP’s large-scale supply chain credential theft, which particularly targets developers, alongside Vect’s ransomware-as-a-service service operation represents a “meaningful shift in the ransomware threat landscape”.

    The result is that any organization which has had login credentials stolen by TeamPCP could be at additional risk of also falling victim to a ransomware attack by Vect.

    (Me for Infosecurity Mag)

    #Infosecurity #ransomware

    infosecurity-magazine.com/news

  9. Защита конфиденциальных данных в облачных LLM

    Защита персональных данных и коммерческой тайны при работе с облачными LLM требует многоуровневого подхода, сочетающего архитектурные, технические и организационные меры. Наиболее надежным решением является полный контроль над средой обработки данных.

    habr.com/ru/articles/1050076/

    #llm #ai #guardrails #infosecurity #infosec

  10. A major cybercriminal network involving thousands of infected websites used to distribute malware has been disrupted by an international law enforcement takedown.

    The action against the SocGholish malware group formed the latest part of Operation Endgame, an ongoing global police investigation to combat ransomware and cybercrime worldwide.

    Announced by the Dutch police on June 18, action was taken to remediate infections of 15,000 websites controlled by SocGholish group and to dismantle the botnet associated with the group.

    Notably, the SocGholish botnet was regularly used by Evil Corp, the notorious, Russia-based ransomware and cyber crime group behind a swath of destructive malware attackers worldwide, including against governments, healthcare institutions and enterprises...

    Here's my write up for #Infosecurity Magazine!

    infosecurity-magazine.com/news

  11. A major cybercriminal network involving thousands of infected websites used to distribute malware has been disrupted by an international law enforcement takedown.

    The action against the SocGholish malware group formed the latest part of Operation Endgame, an ongoing global police investigation to combat ransomware and cybercrime worldwide.

    Announced by the Dutch police on June 18, action was taken to remediate infections of 15,000 websites controlled by SocGholish group and to dismantle the botnet associated with the group.

    Notably, the SocGholish botnet was regularly used by Evil Corp, the notorious, Russia-based ransomware and cyber crime group behind a swath of destructive malware attackers worldwide, including against governments, healthcare institutions and enterprises...

    Here's my write up for #Infosecurity Magazine!

    infosecurity-magazine.com/news

  12. Cybercriminals are experiencing the same worries as many employees working in legitimate jobs: many are worried that the rise of #AI tools could result in them losing their jobs, according to analysis of chatter on underground discussion boards by researchers at Sophos.

    Some users explicitly expressed concerns that those selling AI tools could actively take work away from those cybercriminal developers who manually write code. While others are less than impressed by quality of AI-developed malware...

    (I'm loathed to say 'Hey, cyber criminals are just like the rest of us!' And yet...)

    Anyway, here's my write-up for #Infosecurity Magazine!

    infosecurity-magazine.com/news

  13. Cybercriminals are experiencing the same worries as many employees working in legitimate jobs: many are worried that the rise of #AI tools could result in them losing their jobs, according to analysis of chatter on underground discussion boards by researchers at Sophos.

    Some users explicitly expressed concerns that those selling AI tools could actively take work away from those cybercriminal developers who manually write code. While others are less than impressed by quality of AI-developed malware...

    (I'm loathed to say 'Hey, cyber criminals are just like the rest of us!' And yet...)

    Anyway, here's my write-up for #Infosecurity Magazine!

    infosecurity-magazine.com/news

  14. @chum1ng0 I wonder if #HHSOCR pays attention to any of these leak reports where the entity has not responded to responsible disclosure nor acknowledged any problem.

    The patients are lucky you persisted, Chu.

    #dataleak #HealthSec #infosecurity #HIPAA

  15. @chum1ng0 I wonder if #HHSOCR pays attention to any of these leak reports where the entity has not responded to responsible disclosure nor acknowledged any problem.

    The patients are lucky you persisted, Chu.

    #dataleak #HealthSec #infosecurity #HIPAA

  16. 𝗖𝗼𝗺𝗽𝗹𝗶𝗮𝗻𝗰𝗲 𝗶𝘀 𝗯𝗿𝗼𝗸𝗲𝗻... 𝗮𝗻𝗱 𝘄𝗲’𝗿𝗲 𝘀𝗮𝘆𝗶𝗻𝗴 𝗶𝘁 𝗼𝘂𝘁 𝗹𝗼𝘂𝗱.

    If frameworks overlap, contradict, and confuse - what are you really supposed to follow?

    Join our webinar: zurl.co/Zf9aF

    #Compliance #InfoSecurity #DORA #ISO27001 #InfoSec

  17. Happy Weekend you all!
    I am wondering — who's telling stories with us in London this year?

    Corelight and Object First are confirmed, and many more will officially be in this week. So don't miss your chance to record with us and share your story.

    Sean Martin and I have been showing up at Infosecurity Europe since 2018 — every venue, every news cycle, every London weather mood, and a few Guinness pints along the way. June 2–4 at ExCeL we'll be back, doing what we love most: walking the show floor, capturing the conversations that matter, and turning hallway moments into stories that travel. And of course taking a few hours to visit our favorites spots in London!

    If your brand has a story worth telling at the show, there are three ways we can tell it together — all produced on location at ExCeL:

    🎤 Coverage Sponsorship — comprehensive partnership across the event: 15-minute on-site video conversation, 5-minute Brand Highlight, 1–2 sponsored editorial articles, custom companion article, logo placement on the coverage page, multi-platform distribution, full rights to everything we produce together — and you get all the assets, of course!

    🎙️ On Location Brand Briefing — a 15-minute on-site video conversation hosted by Sean and me, paired with a 400–600 word custom companion article, full media assets (MP4 + MP3 + PNG), and logo placement on the coverage page

    🎧 Brand Highlight — a short, 5-minute story recorded on location at the show. Same as a Briefing, just shorter — if you've got less to say! 😉

    See what nine years of doing this looks like — RSAC 2026 coverage just wrapped, Black Hat is getting busy, and Infosec is already taking shape:

    itspmagazine.com/technology-an

    You can book directly from the page, or DM me with questions and we'll take it from there.

    So — who's joining us in London?

    #Cybersecurity #InfosecEurope #InfosecCommunity #technology #infosecurity #infosec Studio C60 / ITSPmagazine

  18. Happy Weekend you all!
    I am wondering — who's telling stories with us in London this year?

    Corelight and Object First are confirmed, and many more will officially be in this week. So don't miss your chance to record with us and share your story.

    Sean Martin and I have been showing up at Infosecurity Europe since 2018 — every venue, every news cycle, every London weather mood, and a few Guinness pints along the way. June 2–4 at ExCeL we'll be back, doing what we love most: walking the show floor, capturing the conversations that matter, and turning hallway moments into stories that travel. And of course taking a few hours to visit our favorites spots in London!

    If your brand has a story worth telling at the show, there are three ways we can tell it together — all produced on location at ExCeL:

    🎤 Coverage Sponsorship — comprehensive partnership across the event: 15-minute on-site video conversation, 5-minute Brand Highlight, 1–2 sponsored editorial articles, custom companion article, logo placement on the coverage page, multi-platform distribution, full rights to everything we produce together — and you get all the assets, of course!

    🎙️ On Location Brand Briefing — a 15-minute on-site video conversation hosted by Sean and me, paired with a 400–600 word custom companion article, full media assets (MP4 + MP3 + PNG), and logo placement on the coverage page

    🎧 Brand Highlight — a short, 5-minute story recorded on location at the show. Same as a Briefing, just shorter — if you've got less to say! 😉

    See what nine years of doing this looks like — RSAC 2026 coverage just wrapped, Black Hat is getting busy, and Infosec is already taking shape:

    itspmagazine.com/technology-an

    You can book directly from the page, or DM me with questions and we'll take it from there.

    So — who's joining us in London?

    #Cybersecurity #InfosecEurope #InfosecCommunity #technology #infosecurity #infosec Studio C60 / ITSPmagazine

  19. BSidesDayton is still looking for a handful of sponsors for our event May 23rd, 2026! If you know of a company that would be interested, please get them in contact with us!

    Tickets are on sale now!

    eventbrite.com/e/bsidesdayton-

    #bsides #infosec #infosecurity #InfoSecCommunity #informationsecurity #informationsecurity #informationtechnology

  20. 🚀 BSidesDayton 2026 🚀

    It's happening in less than a month! There's not much time left to get your tickets. We look forward to seeing you there!

    🎟️ Tickets - bsidesdayton.com/tickets/

    Tickets are now available to purchase!

    📅 Date: Saturday, May 23, 2026
    ⏰ Time: 9:30 AM – 5:00 PM
    📍 Location: Fairborn City Church, 206 W. Dayton–Yellow Springs Rd., Fairborn, OH
    🎯 Theme: Going Offline – Decentralize, Disconnect, DIY
    🎟️ Tickets: bsidesdayton.com/tickets/
    👥 Audience: Security professionals, researchers, students, hackers, makers, and anyone passionate about cybersecurity and hands-on learning.

    📣 Call for Participation - Now Open!
    Our Call for Papers and Call for Villages/Workshops are officially open.
    Have a talk, hands-on session, or community activity to share?
    Apply now on our website!
    bsidesdayton.com/

    🤝 Sponsorship Opportunities
    We are currently seeking sponsors for this year’s event.
    Please reach out if your organization is interested.

    #bsides #infosec #infosecurity #InfoSecCommunity #informationsecurity #informationsecurity #informationtechnology

  21. 🚀 BSidesDayton 2026 🚀

    It's happening in less than a month! There's not much time left to get your tickets. We look forward to seeing you there!

    🎟️ Tickets - bsidesdayton.com/tickets/

    Tickets are now available to purchase!

    📅 Date: Saturday, May 23, 2026
    ⏰ Time: 9:30 AM – 5:00 PM
    📍 Location: Fairborn City Church, 206 W. Dayton–Yellow Springs Rd., Fairborn, OH
    🎯 Theme: Going Offline – Decentralize, Disconnect, DIY
    🎟️ Tickets: bsidesdayton.com/tickets/
    👥 Audience: Security professionals, researchers, students, hackers, makers, and anyone passionate about cybersecurity and hands-on learning.

    📣 Call for Participation - Now Open!
    Our Call for Papers and Call for Villages/Workshops are officially open.
    Have a talk, hands-on session, or community activity to share?
    Apply now on our website!
    bsidesdayton.com/

    🤝 Sponsorship Opportunities
    We are currently seeking sponsors for this year’s event.
    Please reach out if your organization is interested.

    #bsides #infosec #infosecurity #InfoSecCommunity #informationsecurity #informationsecurity #informationtechnology