home.social

#itsec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #itsec, aggregated by home.social.

fetched live
  1. «Dateibenachrichtigungen verraten Nutzeraktivitäten:
    Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux, Android, Windows und macOS lassen sich Tippverhalten und besuchte Websites ausspähen.»

    Das Fazit daraus ist, Linux ist wider mal sicherer als die kommerziellen OS's. Microsoft hat nicht unrecht aber sicherer geht andars und das überrascht nun niemensch.

    🔓 it-daily.net/it-sicherheit/clo

    #linux #android #windows #macos #itsec #passwort #itsicherheit #hacking #tugraz #microsoft

  2. «Dateibenachrichtigungen verraten Nutzeraktivitäten:
    Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux, Android, Windows und macOS lassen sich Tippverhalten und besuchte Websites ausspähen.»

    Das Fazit daraus ist, Linux ist wider mal sicherer als die kommerziellen OS's. Microsoft hat nicht unrecht aber sicherer geht andars und das überrascht nun niemensch.

    🔓 it-daily.net/it-sicherheit/clo

    #linux #android #windows #macos #itsec #passwort #itsicherheit #hacking #tugraz #microsoft

  3. «Dateibenachrichtigungen verraten Nutzeraktivitäten:
    Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux, Android, Windows und macOS lassen sich Tippverhalten und besuchte Websites ausspähen.»

    Das Fazit daraus ist, Linux ist wider mal sicherer als die kommerziellen OS's. Microsoft hat nicht unrecht aber sicherer geht andars und das überrascht nun niemensch.

    🔓 it-daily.net/it-sicherheit/clo

    #linux #android #windows #macos #itsec #passwort #itsicherheit #hacking #tugraz #microsoft

  4. «Dateibenachrichtigungen verraten Nutzeraktivitäten:
    Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux, Android, Windows und macOS lassen sich Tippverhalten und besuchte Websites ausspähen.»

    Das Fazit daraus ist, Linux ist wider mal sicherer als die kommerziellen OS's. Microsoft hat nicht unrecht aber sicherer geht andars und das überrascht nun niemensch.

    🔓 it-daily.net/it-sicherheit/clo

    #linux #android #windows #macos #itsec #passwort #itsicherheit #hacking #tugraz #microsoft

  5. «Dateibenachrichtigungen verraten Nutzeraktivitäten:
    Forscher der TU Graz zeigen: Über Dateibenachrichtigungen in Linux, Android, Windows und macOS lassen sich Tippverhalten und besuchte Websites ausspähen.»

    Das Fazit daraus ist, Linux ist wider mal sicherer als die kommerziellen OS's. Microsoft hat nicht unrecht aber sicherer geht andars und das überrascht nun niemensch.

    🔓 it-daily.net/it-sicherheit/clo

    #linux #android #windows #macos #itsec #passwort #itsicherheit #hacking #tugraz #microsoft

  6. It's kinda interesting that Windows lets non-administrators flash the firmware of IDE and SATA optical drives.

    What could possibly go wrong?

    #infosec #itsec

  7. It's kinda interesting that Windows lets non-administrators flash the firmware of IDE and SATA optical drives.

    What could possibly go wrong?

    #infosec #itsec

  8. It's kinda interesting that Windows lets non-administrators flash the firmware of IDE and SATA optical drives.

    What could possibly go wrong?

    #infosec #itsec

  9. It's kinda interesting that Windows lets non-administrators flash the firmware of IDE and SATA optical drives.

    What could possibly go wrong?

    #infosec #itsec

  10. It's kinda interesting that Windows lets non-administrators flash the firmware of IDE and SATA optical drives.

    What could possibly go wrong?

    #infosec #itsec

  11. @ReginaMuehlich Aber Datenschützer stören gewisse Leute beim Geld verdienen. Deswegen ist er hart umkämpft. Ob die Vernünftigen gewinnen können?

    Zu oft wird vergessen, daß Datenschutz & IT-Sicherheit Hand in Hand gehen. Besonders Firmen und Behörden sollten das beachten.

    Bürger*innen wissen m.M. überhaupt nicht, was sie alles verlieren können, wenn Datenschutz weiter aufgeweicht wird. Denn schützenswerte Daten sind auch für Kriminelle interessant.

    #itsecurity #itsec #privacy #privatsphäre

  12. @ReginaMuehlich Aber Datenschützer stören gewisse Leute beim Geld verdienen. Deswegen ist er hart umkämpft. Ob die Vernünftigen gewinnen können?

    Zu oft wird vergessen, daß Datenschutz & IT-Sicherheit Hand in Hand gehen. Besonders Firmen und Behörden sollten das beachten.

    Bürger*innen wissen m.M. überhaupt nicht, was sie alles verlieren können, wenn Datenschutz weiter aufgeweicht wird. Denn schützenswerte Daten sind auch für Kriminelle interessant.

    #itsecurity #itsec #privacy #privatsphäre

  13. @ReginaMuehlich Aber Datenschützer stören gewisse Leute beim Geld verdienen. Deswegen ist er hart umkämpft. Ob die Vernünftigen gewinnen können?

    Zu oft wird vergessen, daß Datenschutz & IT-Sicherheit Hand in Hand gehen. Besonders Firmen und Behörden sollten das beachten.

    Bürger*innen wissen m.M. überhaupt nicht, was sie alles verlieren können, wenn Datenschutz weiter aufgeweicht wird. Denn schützenswerte Daten sind auch für Kriminelle interessant.

    #itsecurity #itsec #privacy #privatsphäre

  14. @ReginaMuehlich Aber Datenschützer stören gewisse Leute beim Geld verdienen. Deswegen ist er hart umkämpft. Ob die Vernünftigen gewinnen können?

    Zu oft wird vergessen, daß Datenschutz & IT-Sicherheit Hand in Hand gehen. Besonders Firmen und Behörden sollten das beachten.

    Bürger*innen wissen m.M. überhaupt nicht, was sie alles verlieren können, wenn Datenschutz weiter aufgeweicht wird. Denn schützenswerte Daten sind auch für Kriminelle interessant.

    #itsecurity #itsec #privacy #privatsphäre

  15. @ReginaMuehlich Aber Datenschützer stören gewisse Leute beim Geld verdienen. Deswegen ist er hart umkämpft. Ob die Vernünftigen gewinnen können?

    Zu oft wird vergessen, daß Datenschutz & IT-Sicherheit Hand in Hand gehen. Besonders Firmen und Behörden sollten das beachten.

    Bürger*innen wissen m.M. überhaupt nicht, was sie alles verlieren können, wenn Datenschutz weiter aufgeweicht wird. Denn schützenswerte Daten sind auch für Kriminelle interessant.

    #itsecurity #itsec #privacy #privatsphäre

  16. Mit #ssh auf Port 2222 ausweichen reicht nich.

    Wenn Mitte des Monats die Alert quota von 500(!!) bei #crowdsec free tier aufgebraucht ist, sollte man weiterziehen. Auf ner anderen Box ist bspw. Ruhe auf 22022.

    Ist #portknocking immernoch ein Ding?

    #cti #itsec #homelab

  17. Mit #ssh auf Port 2222 ausweichen reicht nich.

    Wenn Mitte des Monats die Alert quota von 500(!!) bei #crowdsec free tier aufgebraucht ist, sollte man weiterziehen. Auf ner anderen Box ist bspw. Ruhe auf 22022.

    Ist #portknocking immernoch ein Ding?

    #cti #itsec #homelab

  18. Mit #ssh auf Port 2222 ausweichen reicht nich.

    Wenn Mitte des Monats die Alert quota von 500(!!) bei #crowdsec free tier aufgebraucht ist, sollte man weiterziehen. Auf ner anderen Box ist bspw. Ruhe auf 22022.

    Ist #portknocking immernoch ein Ding?

    #cti #itsec #homelab

  19. Mit #ssh auf Port 2222 ausweichen reicht nich.

    Wenn Mitte des Monats die Alert quota von 500(!!) bei #crowdsec free tier aufgebraucht ist, sollte man weiterziehen. Auf ner anderen Box ist bspw. Ruhe auf 22022.

    Ist #portknocking immernoch ein Ding?

    #cti #itsec #homelab

  20. Mit #ssh auf Port 2222 ausweichen reicht nich.

    Wenn Mitte des Monats die Alert quota von 500(!!) bei #crowdsec free tier aufgebraucht ist, sollte man weiterziehen. Auf ner anderen Box ist bspw. Ruhe auf 22022.

    Ist #portknocking immernoch ein Ding?

    #cti #itsec #homelab

  21. «Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens:
    […] Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. […]»

    It is becoming more and more that passwords / passkeys are not stolen or hacked, are their generated tokens. Many of them, in my opinion, say too much about the users and their use.

    🧑‍💻 gbhackers.com/mass-scanning-ta

    #vite #aws #key #awskeys #web #itsec #itsecurity #azure #token #honeynet

  22. «Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens:
    […] Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. […]»

    It is becoming more and more that passwords / passkeys are not stolen or hacked, are their generated tokens. Many of them, in my opinion, say too much about the users and their use.

    🧑‍💻 gbhackers.com/mass-scanning-ta

    #vite #aws #key #awskeys #web #itsec #itsecurity #azure #token #honeynet

  23. «Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens:
    […] Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. […]»

    It is becoming more and more that passwords / passkeys are not stolen or hacked, are their generated tokens. Many of them, in my opinion, say too much about the users and their use.

    🧑‍💻 gbhackers.com/mass-scanning-ta

    #vite #aws #key #awskeys #web #itsec #itsecurity #azure #token #honeynet

  24. «Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens:
    […] Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. […]»

    It is becoming more and more that passwords / passkeys are not stolen or hacked, are their generated tokens. Many of them, in my opinion, say too much about the users and their use.

    🧑‍💻 gbhackers.com/mass-scanning-ta

    #vite #aws #key #awskeys #web #itsec #itsecurity #azure #token #honeynet

  25. «Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens:
    […] Honeynet telemetry recorded 807 session-grouped attacks and approximately 32,000 raw events during the monthly analysis period. […]»

    It is becoming more and more that passwords / passkeys are not stolen or hacked, are their generated tokens. Many of them, in my opinion, say too much about the users and their use.

    🧑‍💻 gbhackers.com/mass-scanning-ta

    #vite #aws #key #awskeys #web #itsec #itsecurity #azure #token #honeynet

  26. «Erfolgreicher Angriff — Revolut gibt vertrauliche Kundendaten an gefälschte Behörden-E-Mail:
    Wie viele Kunden von dem Vorfall betroffen sind, behält Revolut für sich. Ausweisdokumente von Bankkunden sind an Unbefugte weitergeleitet worden»

    Wenn reale Behörden ihre Kommunikation verschlüsselt oder zumindest signiert wäre mit öffentlichen nachweisbaren Schlüssel, ja dann wäre dies wahrscheinlich nicht geschehen.

    🔓 golem.de/news/erfolgreicher-an

    #email #revolut #england #behorden #bank #fintech #itsec

  27. «Erfolgreicher Angriff — Revolut gibt vertrauliche Kundendaten an gefälschte Behörden-E-Mail:
    Wie viele Kunden von dem Vorfall betroffen sind, behält Revolut für sich. Ausweisdokumente von Bankkunden sind an Unbefugte weitergeleitet worden»

    Wenn reale Behörden ihre Kommunikation verschlüsselt oder zumindest signiert wäre mit öffentlichen nachweisbaren Schlüssel, ja dann wäre dies wahrscheinlich nicht geschehen.

    🔓 golem.de/news/erfolgreicher-an

    #email #revolut #england #behorden #bank #fintech #itsec

  28. «Erfolgreicher Angriff — Revolut gibt vertrauliche Kundendaten an gefälschte Behörden-E-Mail:
    Wie viele Kunden von dem Vorfall betroffen sind, behält Revolut für sich. Ausweisdokumente von Bankkunden sind an Unbefugte weitergeleitet worden»

    Wenn reale Behörden ihre Kommunikation verschlüsselt oder zumindest signiert wäre mit öffentlichen nachweisbaren Schlüssel, ja dann wäre dies wahrscheinlich nicht geschehen.

    🔓 golem.de/news/erfolgreicher-an

    #email #revolut #england #behorden #bank #fintech #itsec

  29. «Erfolgreicher Angriff — Revolut gibt vertrauliche Kundendaten an gefälschte Behörden-E-Mail:
    Wie viele Kunden von dem Vorfall betroffen sind, behält Revolut für sich. Ausweisdokumente von Bankkunden sind an Unbefugte weitergeleitet worden»

    Wenn reale Behörden ihre Kommunikation verschlüsselt oder zumindest signiert wäre mit öffentlichen nachweisbaren Schlüssel, ja dann wäre dies wahrscheinlich nicht geschehen.

    🔓 golem.de/news/erfolgreicher-an

    #email #revolut #england #behorden #bank #fintech #itsec

  30. «Erfolgreicher Angriff — Revolut gibt vertrauliche Kundendaten an gefälschte Behörden-E-Mail:
    Wie viele Kunden von dem Vorfall betroffen sind, behält Revolut für sich. Ausweisdokumente von Bankkunden sind an Unbefugte weitergeleitet worden»

    Wenn reale Behörden ihre Kommunikation verschlüsselt oder zumindest signiert wäre mit öffentlichen nachweisbaren Schlüssel, ja dann wäre dies wahrscheinlich nicht geschehen.

    🔓 golem.de/news/erfolgreicher-an

    #email #revolut #england #behorden #bank #fintech #itsec

  31. @bsi Update zum Klärungsversuch bzgl. CVE-2026-50768:
    Im Henkel-Repo heißt es zwar freundlich "For any inquiries or further details, feel free to reach out to us." – in der Praxis sind PRs, Issues & Diskussionen dicht und Kontaktinfos fehlen völlig.

    Wie betreibt man eigentlich #ResponsibleDisclosure, wenn man offiziell zum Dialog einlädt, aber sämtliche Feedback-Türen fest verriegelt? 😉

    #HenkelAG #Henkel #CyberSecurity #InfoSec #AppSec #ITSec #GitHub #Sicherheit #BugBounty #CVE

  32. Frage an #ITSec Experten:
    Die Bank-Security App auf meinem Smartphone, die ausschließlich zur Signatur von Web-Aktivitäten dient:

    Wie sensibel ist das Passwort? Dient es nur dem Schutz vor unbefugter Verwendung auf dem Smartphone? Oder kann es auch im Web zur Authentifizierung dienen, wenn es gestohlen wird?

  33. Frage an #ITSec Experten:
    Die Bank-Security App auf meinem Smartphone, die ausschließlich zur Signatur von Web-Aktivitäten dient:

    Wie sensibel ist das Passwort? Dient es nur dem Schutz vor unbefugter Verwendung auf dem Smartphone? Oder kann es auch im Web zur Authentifizierung dienen, wenn es gestohlen wird?

  34. Frage an #ITSec Experten:
    Die Bank-Security App auf meinem Smartphone, die ausschließlich zur Signatur von Web-Aktivitäten dient:

    Wie sensibel ist das Passwort? Dient es nur dem Schutz vor unbefugter Verwendung auf dem Smartphone? Oder kann es auch im Web zur Authentifizierung dienen, wenn es gestohlen wird?

  35. Frage an #ITSec Experten:
    Die Bank-Security App auf meinem Smartphone, die ausschließlich zur Signatur von Web-Aktivitäten dient:

    Wie sensibel ist das Passwort? Dient es nur dem Schutz vor unbefugter Verwendung auf dem Smartphone? Oder kann es auch im Web zur Authentifizierung dienen, wenn es gestohlen wird?

  36. Frage an #ITSec Experten:
    Die Bank-Security App auf meinem Smartphone, die ausschließlich zur Signatur von Web-Aktivitäten dient:

    Wie sensibel ist das Passwort? Dient es nur dem Schutz vor unbefugter Verwendung auf dem Smartphone? Oder kann es auch im Web zur Authentifizierung dienen, wenn es gestohlen wird?

  37. Acting director of CISA, Nick Andersen:

    "We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”

    therecord.media/cisa-hiring-ni

    #infosec #itsec #itsecurity #tech #architecture #development

  38. Acting director of CISA, Nick Andersen:

    "We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”

    therecord.media/cisa-hiring-ni

    #infosec #itsec #itsecurity #tech #architecture #development

  39. Acting director of CISA, Nick Andersen:

    "We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”

    therecord.media/cisa-hiring-ni

    #infosec #itsec #itsecurity #tech #architecture #development

  40. Acting director of CISA, Nick Andersen:

    "We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”

    therecord.media/cisa-hiring-ni

    #infosec #itsec #itsecurity #tech #architecture #development

  41. Acting director of CISA, Nick Andersen:

    "We know the worst that can happen, and if we don't make some very serious, very significant changes in quick succession … you all are going to have to go home and look to your family, look to your friends, and explain to them how you knew the worst that could happen and why we didn't do enough.”

    therecord.media/cisa-hiring-ni

    #infosec #itsec #itsecurity #tech #architecture #development

  42. Save the date: Saturday October 17th.

    #OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters.

    This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon.

    For the community. By the community.

    #OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity

  43. Save the date: Saturday October 17th.

    #OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters.

    This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon.

    For the community. By the community.

    #OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity

  44. Save the date: Saturday October 17th.

    #OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters.

    This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon.

    For the community. By the community.

    #OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity

  45. Save the date: Saturday October 17th.

    #OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters.

    This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon.

    For the community. By the community.

    #OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity

  46. Save the date: Saturday October 17th.

    #OWASP #Ottawa is pleased to announce a day of learning, community, and mentorship to celebrate the 25th Anniversary of the OWASP Foundation and the OWASP Ottawa Chapter’s selection of one of the top chapters in a constellation of over 130 Chapters.

    This will be a free _and_ ticketed event. Details on tickets, speakers, and other details will be made available soon.

    For the community. By the community.

    #OWASPOttawaDay2026 #Security hashtag#appsec #Itsec #Cyber #Cybersecurity

  47. AI usage is not safe, just as any other tooling. But the level of damage that can be inflicted is much higher. That's why the level of attention needs to be higher as well.

    manifold.security/blog/ai-codi

    It is important to think about topics like Sandboxing or hooks to secure your SDLC.

    #tech #ai #architecture #itsec #infosec #secureSoftwareDevelopmentLifecycle #SSDLC #SDLC #agents

  48. AI usage is not safe, just as any other tooling. But the level of damage that can be inflicted is much higher. That's why the level of attention needs to be higher as well.

    manifold.security/blog/ai-codi

    It is important to think about topics like Sandboxing or hooks to secure your SDLC.

    #tech #ai #architecture #itsec #infosec #secureSoftwareDevelopmentLifecycle #SSDLC #SDLC #agents

  49. AI usage is not safe, just as any other tooling. But the level of damage that can be inflicted is much higher. That's why the level of attention needs to be higher as well.

    manifold.security/blog/ai-codi

    It is important to think about topics like Sandboxing or hooks to secure your SDLC.

    #tech #ai #architecture #itsec #infosec #secureSoftwareDevelopmentLifecycle #SSDLC #SDLC #agents

  50. AI usage is not safe, just as any other tooling. But the level of damage that can be inflicted is much higher. That's why the level of attention needs to be higher as well.

    manifold.security/blog/ai-codi

    It is important to think about topics like Sandboxing or hooks to secure your SDLC.

    #tech #ai #architecture #itsec #infosec #secureSoftwareDevelopmentLifecycle #SSDLC #SDLC #agents