#itsec — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #itsec, aggregated by home.social.
-
«Dateibenachrichtigungen verraten Nutzeraktivitäten:
Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux, Android, Windows und macOS lassen sich Tippverhalten und besuchte Websites ausspähen.»Das Fazit daraus ist, Linux ist wider mal sicherer als die kommerziellen OS's. Microsoft hat nicht unrecht aber sicherer geht andars und das überrascht nun niemensch.
🔓 https://www.it-daily.net/it-sicherheit/cloud-security/dateibenachrichtigung
#linux #android #windows #macos #itsec #passwort #itsicherheit #hacking #tugraz #microsoft
-
«Dateibenachrichtigungen verraten Nutzeraktivitäten:
Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux, Android, Windows und macOS lassen sich Tippverhalten und besuchte Websites ausspähen.»Das Fazit daraus ist, Linux ist wider mal sicherer als die kommerziellen OS's. Microsoft hat nicht unrecht aber sicherer geht andars und das überrascht nun niemensch.
🔓 https://www.it-daily.net/it-sicherheit/cloud-security/dateibenachrichtigung
#linux #android #windows #macos #itsec #passwort #itsicherheit #hacking #tugraz #microsoft
-
«Dateibenachrichtigungen verraten Nutzeraktivitäten:
Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux, Android, Windows und macOS lassen sich Tippverhalten und besuchte Websites ausspähen.»Das Fazit daraus ist, Linux ist wider mal sicherer als die kommerziellen OS's. Microsoft hat nicht unrecht aber sicherer geht andars und das überrascht nun niemensch.
🔓 https://www.it-daily.net/it-sicherheit/cloud-security/dateibenachrichtigung
#linux #android #windows #macos #itsec #passwort #itsicherheit #hacking #tugraz #microsoft
-
«Dateibenachrichtigungen verraten Nutzeraktivitäten:
Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux, Android, Windows und macOS lassen sich Tippverhalten und besuchte Websites ausspähen.»Das Fazit daraus ist, Linux ist wider mal sicherer als die kommerziellen OS's. Microsoft hat nicht unrecht aber sicherer geht andars und das überrascht nun niemensch.
🔓 https://www.it-daily.net/it-sicherheit/cloud-security/dateibenachrichtigung
#linux #android #windows #macos #itsec #passwort #itsicherheit #hacking #tugraz #microsoft
-
«Dateibenachrichtigungen verraten Nutzeraktivitäten:
Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux, Android, Windows und macOS lassen sich Tippverhalten und besuchte Websites ausspähen.»Das Fazit daraus ist, Linux ist wider mal sicherer als die kommerziellen OS's. Microsoft hat nicht unrecht aber sicherer geht andars und das überrascht nun niemensch.
🔓 https://www.it-daily.net/it-sicherheit/cloud-security/dateibenachrichtigung
#linux #android #windows #macos #itsec #passwort #itsicherheit #hacking #tugraz #microsoft
-
1024-bit RSA signatures
can be forged almost in real time: https://github.com/ucsd-hacc/NSNFSSSFSFN
#RSA #SNFS #Cryptography #ITSec -
1024-bit RSA signatures
can be forged almost in real time: https://github.com/ucsd-hacc/NSNFSSSFSFN
#RSA #SNFS #Cryptography #ITSec -
1024-bit RSA signatures
can be forged almost in real time: https://github.com/ucsd-hacc/NSNFSSSFSFN
#RSA #SNFS #Cryptography #ITSec -
1024-bit RSA signatures
can be forged almost in real time: https://github.com/ucsd-hacc/NSNFSSSFSFN
#RSA #SNFS #Cryptography #ITSec -
1024-bit RSA signatures
can be forged almost in real time: https://github.com/ucsd-hacc/NSNFSSSFSFN
#RSA #SNFS #Cryptography #ITSec -
It's kinda interesting that Windows lets non-administrators flash the firmware of IDE and SATA optical drives.
What could possibly go wrong?
-
It's kinda interesting that Windows lets non-administrators flash the firmware of IDE and SATA optical drives.
What could possibly go wrong?
-
It's kinda interesting that Windows lets non-administrators flash the firmware of IDE and SATA optical drives.
What could possibly go wrong?
-
It's kinda interesting that Windows lets non-administrators flash the firmware of IDE and SATA optical drives.
What could possibly go wrong?
-
It's kinda interesting that Windows lets non-administrators flash the firmware of IDE and SATA optical drives.
What could possibly go wrong?
-
@ReginaMuehlich Aber Datenschützer stören gewisse Leute beim Geld verdienen. Deswegen ist er hart umkämpft. Ob die Vernünftigen gewinnen können?
Zu oft wird vergessen, daß Datenschutz & IT-Sicherheit Hand in Hand gehen. Besonders Firmen und Behörden sollten das beachten.
Bürger*innen wissen m.M. überhaupt nicht, was sie alles verlieren können, wenn Datenschutz weiter aufgeweicht wird. Denn schützenswerte Daten sind auch für Kriminelle interessant.
-
@ReginaMuehlich Aber Datenschützer stören gewisse Leute beim Geld verdienen. Deswegen ist er hart umkämpft. Ob die Vernünftigen gewinnen können?
Zu oft wird vergessen, daß Datenschutz & IT-Sicherheit Hand in Hand gehen. Besonders Firmen und Behörden sollten das beachten.
Bürger*innen wissen m.M. überhaupt nicht, was sie alles verlieren können, wenn Datenschutz weiter aufgeweicht wird. Denn schützenswerte Daten sind auch für Kriminelle interessant.
-
@ReginaMuehlich Aber Datenschützer stören gewisse Leute beim Geld verdienen. Deswegen ist er hart umkämpft. Ob die Vernünftigen gewinnen können?
Zu oft wird vergessen, daß Datenschutz & IT-Sicherheit Hand in Hand gehen. Besonders Firmen und Behörden sollten das beachten.
Bürger*innen wissen m.M. überhaupt nicht, was sie alles verlieren können, wenn Datenschutz weiter aufgeweicht wird. Denn schützenswerte Daten sind auch für Kriminelle interessant.
-
@ReginaMuehlich Aber Datenschützer stören gewisse Leute beim Geld verdienen. Deswegen ist er hart umkämpft. Ob die Vernünftigen gewinnen können?
Zu oft wird vergessen, daß Datenschutz & IT-Sicherheit Hand in Hand gehen. Besonders Firmen und Behörden sollten das beachten.
Bürger*innen wissen m.M. überhaupt nicht, was sie alles verlieren können, wenn Datenschutz weiter aufgeweicht wird. Denn schützenswerte Daten sind auch für Kriminelle interessant.
-
@ReginaMuehlich Aber Datenschützer stören gewisse Leute beim Geld verdienen. Deswegen ist er hart umkämpft. Ob die Vernünftigen gewinnen können?
Zu oft wird vergessen, daß Datenschutz & IT-Sicherheit Hand in Hand gehen. Besonders Firmen und Behörden sollten das beachten.
Bürger*innen wissen m.M. überhaupt nicht, was sie alles verlieren können, wenn Datenschutz weiter aufgeweicht wird. Denn schützenswerte Daten sind auch für Kriminelle interessant.
-
vergleichbar sollte der Angriff auf die Berliner Behörde funktioniert haben
-
vergleichbar sollte der Angriff auf die Berliner Behörde funktioniert haben
-
vergleichbar sollte der Angriff auf die Berliner Behörde funktioniert haben
-
vergleichbar sollte der Angriff auf die Berliner Behörde funktioniert haben
-
vergleichbar sollte der Angriff auf die Berliner Behörde funktioniert haben
-
Mit #ssh auf Port 2222 ausweichen reicht nich.
Wenn Mitte des Monats die Alert quota von 500(!!) bei #crowdsec free tier aufgebraucht ist, sollte man weiterziehen. Auf ner anderen Box ist bspw. Ruhe auf 22022.
Ist #portknocking immernoch ein Ding?
-
Mit #ssh auf Port 2222 ausweichen reicht nich.
Wenn Mitte des Monats die Alert quota von 500(!!) bei #crowdsec free tier aufgebraucht ist, sollte man weiterziehen. Auf ner anderen Box ist bspw. Ruhe auf 22022.
Ist #portknocking immernoch ein Ding?
-
Mit #ssh auf Port 2222 ausweichen reicht nich.
Wenn Mitte des Monats die Alert quota von 500(!!) bei #crowdsec free tier aufgebraucht ist, sollte man weiterziehen. Auf ner anderen Box ist bspw. Ruhe auf 22022.
Ist #portknocking immernoch ein Ding?
-
Mit #ssh auf Port 2222 ausweichen reicht nich.
Wenn Mitte des Monats die Alert quota von 500(!!) bei #crowdsec free tier aufgebraucht ist, sollte man weiterziehen. Auf ner anderen Box ist bspw. Ruhe auf 22022.
Ist #portknocking immernoch ein Ding?
-
Mit #ssh auf Port 2222 ausweichen reicht nich.
Wenn Mitte des Monats die Alert quota von 500(!!) bei #crowdsec free tier aufgebraucht ist, sollte man weiterziehen. Auf ner anderen Box ist bspw. Ruhe auf 22022.
Ist #portknocking immernoch ein Ding?
-
«Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens:
[…] Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. […]»It is becoming more and more that passwords / passkeys are not stolen or hacked, are their generated tokens. Many of them, in my opinion, say too much about the users and their use.
🧑💻 https://gbhackers.com/mass-scanning-targets-exposed-vite-servers-to-steal-aws-keys/
#vite #aws #key #awskeys #web #itsec #itsecurity #azure #token #honeynet
-
«Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens:
[…] Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. […]»It is becoming more and more that passwords / passkeys are not stolen or hacked, are their generated tokens. Many of them, in my opinion, say too much about the users and their use.
🧑💻 https://gbhackers.com/mass-scanning-targets-exposed-vite-servers-to-steal-aws-keys/
#vite #aws #key #awskeys #web #itsec #itsecurity #azure #token #honeynet
-
«Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens:
[…] Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. […]»It is becoming more and more that passwords / passkeys are not stolen or hacked, are their generated tokens. Many of them, in my opinion, say too much about the users and their use.
🧑💻 https://gbhackers.com/mass-scanning-targets-exposed-vite-servers-to-steal-aws-keys/
#vite #aws #key #awskeys #web #itsec #itsecurity #azure #token #honeynet
-
«Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens:
[…] Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. […]»It is becoming more and more that passwords / passkeys are not stolen or hacked, are their generated tokens. Many of them, in my opinion, say too much about the users and their use.
🧑💻 https://gbhackers.com/mass-scanning-targets-exposed-vite-servers-to-steal-aws-keys/
#vite #aws #key #awskeys #web #itsec #itsecurity #azure #token #honeynet
-
«Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens:
[…] Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. […]»It is becoming more and more that passwords / passkeys are not stolen or hacked, are their generated tokens. Many of them, in my opinion, say too much about the users and their use.
🧑💻 https://gbhackers.com/mass-scanning-targets-exposed-vite-servers-to-steal-aws-keys/
#vite #aws #key #awskeys #web #itsec #itsecurity #azure #token #honeynet
-
«Erfolgreicher Angriff — Revolut gibt vertrauliche Kundendaten an gefälschte Behörden-E-Mail:
Wie viele Kunden von dem Vorfall betroffen sind, behält Revolut für sich. Ausweisdokumente von Bankkunden sind an Unbefugte weitergeleitet worden»Wenn reale Behörden ihre Kommunikation verschlüsselt oder zumindest signiert wäre mit öffentlichen nachweisbaren Schlüssel, ja dann wäre dies wahrscheinlich nicht geschehen.
-
«Erfolgreicher Angriff — Revolut gibt vertrauliche Kundendaten an gefälschte Behörden-E-Mail:
Wie viele Kunden von dem Vorfall betroffen sind, behält Revolut für sich. Ausweisdokumente von Bankkunden sind an Unbefugte weitergeleitet worden»Wenn reale Behörden ihre Kommunikation verschlüsselt oder zumindest signiert wäre mit öffentlichen nachweisbaren Schlüssel, ja dann wäre dies wahrscheinlich nicht geschehen.
-
«Erfolgreicher Angriff — Revolut gibt vertrauliche Kundendaten an gefälschte Behörden-E-Mail:
Wie viele Kunden von dem Vorfall betroffen sind, behält Revolut für sich. Ausweisdokumente von Bankkunden sind an Unbefugte weitergeleitet worden»Wenn reale Behörden ihre Kommunikation verschlüsselt oder zumindest signiert wäre mit öffentlichen nachweisbaren Schlüssel, ja dann wäre dies wahrscheinlich nicht geschehen.
-
«Erfolgreicher Angriff — Revolut gibt vertrauliche Kundendaten an gefälschte Behörden-E-Mail:
Wie viele Kunden von dem Vorfall betroffen sind, behält Revolut für sich. Ausweisdokumente von Bankkunden sind an Unbefugte weitergeleitet worden»Wenn reale Behörden ihre Kommunikation verschlüsselt oder zumindest signiert wäre mit öffentlichen nachweisbaren Schlüssel, ja dann wäre dies wahrscheinlich nicht geschehen.
-
«Erfolgreicher Angriff — Revolut gibt vertrauliche Kundendaten an gefälschte Behörden-E-Mail:
Wie viele Kunden von dem Vorfall betroffen sind, behält Revolut für sich. Ausweisdokumente von Bankkunden sind an Unbefugte weitergeleitet worden»Wenn reale Behörden ihre Kommunikation verschlüsselt oder zumindest signiert wäre mit öffentlichen nachweisbaren Schlüssel, ja dann wäre dies wahrscheinlich nicht geschehen.
-
@bsi Update zum Klärungsversuch bzgl. CVE-2026-50768:
Im Henkel-Repo heißt es zwar freundlich "For any inquiries or further details, feel free to reach out to us." – in der Praxis sind PRs, Issues & Diskussionen dicht und Kontaktinfos fehlen völlig.Wie betreibt man eigentlich #ResponsibleDisclosure, wenn man offiziell zum Dialog einlädt, aber sämtliche Feedback-Türen fest verriegelt? 😉
#HenkelAG #Henkel #CyberSecurity #InfoSec #AppSec #ITSec #GitHub #Sicherheit #BugBounty #CVE
-
Frage an #ITSec Experten:
Die Bank-Security App auf meinem Smartphone, die ausschließlich zur Signatur von Web-Aktivitäten dient:Wie sensibel ist das Passwort? Dient es nur dem Schutz vor unbefugter Verwendung auf dem Smartphone? Oder kann es auch im Web zur Authentifizierung dienen, wenn es gestohlen wird?
-
Frage an #ITSec Experten:
Die Bank-Security App auf meinem Smartphone, die ausschließlich zur Signatur von Web-Aktivitäten dient:Wie sensibel ist das Passwort? Dient es nur dem Schutz vor unbefugter Verwendung auf dem Smartphone? Oder kann es auch im Web zur Authentifizierung dienen, wenn es gestohlen wird?
-
Frage an #ITSec Experten:
Die Bank-Security App auf meinem Smartphone, die ausschließlich zur Signatur von Web-Aktivitäten dient:Wie sensibel ist das Passwort? Dient es nur dem Schutz vor unbefugter Verwendung auf dem Smartphone? Oder kann es auch im Web zur Authentifizierung dienen, wenn es gestohlen wird?
-
Frage an #ITSec Experten:
Die Bank-Security App auf meinem Smartphone, die ausschließlich zur Signatur von Web-Aktivitäten dient:Wie sensibel ist das Passwort? Dient es nur dem Schutz vor unbefugter Verwendung auf dem Smartphone? Oder kann es auch im Web zur Authentifizierung dienen, wenn es gestohlen wird?
-
Frage an #ITSec Experten:
Die Bank-Security App auf meinem Smartphone, die ausschließlich zur Signatur von Web-Aktivitäten dient:Wie sensibel ist das Passwort? Dient es nur dem Schutz vor unbefugter Verwendung auf dem Smartphone? Oder kann es auch im Web zur Authentifizierung dienen, wenn es gestohlen wird?
-
Acting director of CISA, Nick Andersen:
"We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”
https://therecord.media/cisa-hiring-nick-andersen-warning
#infosec #itsec #itsecurity #tech #architecture #development
-
Acting director of CISA, Nick Andersen:
"We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”
https://therecord.media/cisa-hiring-nick-andersen-warning
#infosec #itsec #itsecurity #tech #architecture #development
-
Acting director of CISA, Nick Andersen:
"We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”
https://therecord.media/cisa-hiring-nick-andersen-warning
#infosec #itsec #itsecurity #tech #architecture #development
-
Acting director of CISA, Nick Andersen:
"We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”
https://therecord.media/cisa-hiring-nick-andersen-warning
#infosec #itsec #itsecurity #tech #architecture #development
-
Acting director of CISA, Nick Andersen:
"We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”
https://therecord.media/cisa-hiring-nick-andersen-warning
#infosec #itsec #itsecurity #tech #architecture #development
-
Save the date: Saturday October 17th.
#OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters.
This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon.
For the community. By the community.
#OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity
-
Save the date: Saturday October 17th.
#OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters.
This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon.
For the community. By the community.
#OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity
-
Save the date: Saturday October 17th.
#OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters.
This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon.
For the community. By the community.
#OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity
-
Save the date: Saturday October 17th.
#OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters.
This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon.
For the community. By the community.
#OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity
-
Save the date: Saturday October 17th.
#OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters.
This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon.
For the community. By the community.
#OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity
-
AI usage is not safe, just as any other tooling. But the level of damage that can be inflicted is much higher. That's why the level of attention needs to be higher as well.
https://www.manifold.security/blog/ai-coding-agents-git-hijack
It is important to think about topics like Sandboxing or hooks to secure your SDLC.
#tech #ai #architecture #itsec #infosec #secureSoftwareDevelopmentLifecycle #SSDLC #SDLC #agents
-
AI usage is not safe, just as any other tooling. But the level of damage that can be inflicted is much higher. That's why the level of attention needs to be higher as well.
https://www.manifold.security/blog/ai-coding-agents-git-hijack
It is important to think about topics like Sandboxing or hooks to secure your SDLC.
#tech #ai #architecture #itsec #infosec #secureSoftwareDevelopmentLifecycle #SSDLC #SDLC #agents
-
AI usage is not safe, just as any other tooling. But the level of damage that can be inflicted is much higher. That's why the level of attention needs to be higher as well.
https://www.manifold.security/blog/ai-coding-agents-git-hijack
It is important to think about topics like Sandboxing or hooks to secure your SDLC.
#tech #ai #architecture #itsec #infosec #secureSoftwareDevelopmentLifecycle #SSDLC #SDLC #agents
-
AI usage is not safe, just as any other tooling. But the level of damage that can be inflicted is much higher. That's why the level of attention needs to be higher as well.
https://www.manifold.security/blog/ai-coding-agents-git-hijack
It is important to think about topics like Sandboxing or hooks to secure your SDLC.
#tech #ai #architecture #itsec #infosec #secureSoftwareDevelopmentLifecycle #SSDLC #SDLC #agents