#netsec — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #netsec, aggregated by home.social.
-
-
-
If anyone on Fedi happens to work at, or knows someone working at Wix, please message @xeiaso.net ASAP
Post: https://bsky.app/profile/xeiaso.net/post/3mqwtp36x2c2v
Website: https://xeiaso.net/contact/
Email contact: me @ xeiaso.net
-
If anyone on Fedi happens to work at, or knows someone working at Wix, please message @xeiaso.net ASAP
Post: https://bsky.app/profile/xeiaso.net/post/3mqwtp36x2c2v
Website: https://xeiaso.net/contact/
Email contact: me @ xeiaso.net
-
European Password Manager Shares Origins and Updates with State-Certified Russian Firm https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm
Passwork, a Spain-based password manager used by European government agencies and universities, shares technological ties with a Russian counterpart — an arrangement that experts say poses a state-level security risk.
-
European Password Manager Shares Origins and Updates with State-Certified Russian Firm https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm
Passwork, a Spain-based password manager used by European government agencies and universities, shares technological ties with a Russian counterpart — an arrangement that experts say poses a state-level security risk.
-
👉️ IPv4 address brokers are a critical chokepoint for bulletproof hosters
👉️ Carrier and broker responses to SBL listings reveal a lot about their intentions
👉️ Clustering internet badness at specific facilitators makes them attractive to law enforcement
👉️ Evasion tactics from miscreants signal that the pressure is actually workingIn case you missed it, read the full post here:
https://www.spamhaus.org/resource-hub/bulletproof-hosting/bulletproof-hosting-cutting-off-the-facilitators/#BulletproofHosting #ThreatIntel #InfoSec #Cybercrime #IPv4 #DNSAbuse #NetSec
-
👉️ IPv4 address brokers are a critical chokepoint for bulletproof hosters
👉️ Carrier and broker responses to SBL listings reveal a lot about their intentions
👉️ Clustering internet badness at specific facilitators makes them attractive to law enforcement
👉️ Evasion tactics from miscreants signal that the pressure is actually workingIn case you missed it, read the full post here:
https://www.spamhaus.org/resource-hub/bulletproof-hosting/bulletproof-hosting-cutting-off-the-facilitators/#BulletproofHosting #ThreatIntel #InfoSec #Cybercrime #IPv4 #DNSAbuse #NetSec
-
Security Tip: Move beyond the "castle and moat" security model. 🛡️ In a Zero Trust architecture, micro-segmentation is vital. By dividing your network into granular segments with unique security controls, you prevent attackers from moving laterally. It turns a potential total catastrophe into a contained incident. Stay ahead of emerging threats and track vulnerabilities at https://cvedatabase.com #ZeroTrust #CyberSecurity #InfoSec #NetSec
-
UTT HiPER 1250GW (v3.2.7-210907-180535) hit by HIGH severity stack buffer overflow (CVE-2026-14721). Remote code execution possible via 'ssid' in /goform/ConfigWirelessBase_5g. No patch — restrict access. https://radar.offseq.com/threat/cve-2026-14721-stack-based-buffer-overflow-in-utt--61b09d8093b25eb2 #OffSeq #CVE #Infosec #NetSec
-
Security Tip: The 'flat' network is a gift to attackers. 🛡️ In a Zero Trust architecture, micro-segmentation is key. By creating granular security zones around individual workloads, you ensure that a compromised service cannot be used as a stepping stone to reach your sensitive data. Reduce your risk and prevent lateral movement today. Monitor the latest vulnerabilities at https://cvedatabase.com #ZeroTrust #InfoSec #CyberSecurity #NetSec #SysAdmin
-
What is covert channel amplification? I wrote a short blog post about it: https://wendzel.de/misc/2026/02/28/history-cc.html
#covertchannels #steganography #networksecurity #netsec #cybersec #cybersecurity #informationhiding #infosec #covertchannels #security
-
Blackbird is easily one of the best SOCMINT tools around. We host the email search for free on our website and we have the username search integrated into our multitool username search kit. Check them out! And download the original repo and give it a run in CLI!
Cabal Blackbird Email Search: https://osintcabal.org/livecenter/bla
ckbird.html
Cabal Username Kit: https://osintcabal.org/usernamesearch
.html
#OSINT #OSINTTool #OSINT4Good #SOCMINT #data #python #cli #research #opsec #netsec #free #freetools #freeosint
-
Blackbird is easily one of the best SOCMINT tools around. We host the email search for free on our website and we have the username search integrated into our multitool username search kit. Check them out! And download the original repo and give it a run in CLI!
Cabal Blackbird Email Search: https://osintcabal.org/livecenter/bla
ckbird.html
Cabal Username Kit: https://osintcabal.org/usernamesearch
.html
#OSINT #OSINTTool #OSINT4Good #SOCMINT #data #python #cli #research #opsec #netsec #free #freetools #freeosint
-
[DEMO] Sn1per Professional 2026 Released: A New Era for Attack Surface Management
#offsec #offensivesecurity #netsec #infosec #bugbounty #pentesting #ai
-
[DEMO] Sn1per Professional 2026 Released: A New Era for Attack Surface Management
#offsec #offensivesecurity #netsec #infosec #bugbounty #pentesting #ai
-
Security Tip: Don't rely on "inside vs. outside" network logic. 🛡️ Zero Trust Architecture assumes the network is already compromised. By implementing micro-segmentation and continuous verification, you ensure that a single stolen credential doesn't lead to a total system takeover. "Never trust, always verify" is the new standard. Stay ahead of emerging threats: https://cvedatabase.com #ZeroTrust #Infosec #CyberSecurity #NetSec #TechTips
-
I live in the contentious world of a manager who is so ineffective, that he literally contradicts everything the lead developer on the project says, and then counters My senior cloudops engineers that they are "wrong" without understanding what wrong is........
oh, and he called IaC stupid and useless.
wtf world am I in exactly?
#terraform #iac #aws #devops #cloudops #infosec #netsec #humanstupidity
-
I live in the contentious world of a manager who is so ineffective, that he literally contradicts everything the lead developer on the project says, and then counters My senior cloudops engineers that they are "wrong" without understanding what wrong is........
oh, and he called IaC stupid and useless.
wtf world am I in exactly?
#terraform #iac #aws #devops #cloudops #infosec #netsec #humanstupidity
-
Anyone have recommendations for FOSS, small network monitoring/analysis/IDS tools?
Suricata is interesting but I haven' t found a decent front-end. Wasn't impressed by Suri-Oculus and EveBox isn't baked.
Also looked at Zeek/Rita but, again, wasn't impressed.
Anything more lightweight than above but more advanced than, e.g. wireshark?
-
Anyone have recommendations for FOSS, small network monitoring/analysis/IDS tools?
Suricata is interesting but I haven' t found a decent front-end. Wasn't impressed by Suri-Oculus and EveBox isn't baked.
Also looked at Zeek/Rita but, again, wasn't impressed.
Anything more lightweight than above but more advanced than, e.g. wireshark?
-
the fact that a 15 year old German is a kingpin of a network that sells pre comprised iot devices as ddos client is insane, I was contemplating if I should choose science or commerce when I was 15 😭#ddos #netsec
-
🦀 rustnet is now available in homebrew-core! 🎉
No more tap needed, just run:
brew install rustnet
rustnet is a cross-platform terminal UI for monitoring your network connections in real time, with deep packet inspection and protocol detection (HTTP, DNS, TLS, SSH, QUIC, and more).
Available on macOS and Linux.
-
🦀 rustnet is now available in homebrew-core! 🎉
No more tap needed, just run:
brew install rustnet
rustnet is a cross-platform terminal UI for monitoring your network connections in real time, with deep packet inspection and protocol detection (HTTP, DNS, TLS, SSH, QUIC, and more).
Available on macOS and Linux.
-
"Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised"
https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/
#security #infosec #netsec #npm #node #javascript #supplychain
-
"Mini Shai-Hulud Strikes Again: 317 npm Packages Compromised"
https://safedep.io/mini-shai-hulud-strikes-again-314-npm-packages-compromised/
#security #infosec #netsec #npm #node #javascript #supplychain
-
Need to brute subdomains on the fly?
Subcat is a powerful and well maintained open-source tool that accomplishes this task in seconds. Luckily for you we host it on our server for you to use for free.Check it out and give it go!
https://osintcabal.org/livecenter/subcat.htmlGit link: https://github.com/duty1g/subcat
#OSINT #osint4good #osinttool #tools #netsec #cybersec #domaindata #domainbrute #domainosint #domainintelligence #opsec
-
Fine-Tuning on My Own Commit History: The Model Now Writes Bugs in My Style
Because when you fine-tune on your own history, you are not training a model to be better than you. -
Fine-Tuning on My Own Commit History: The Model Now Writes Bugs in My Style
Because when you fine-tune on your own history, you are not training a model to be better than you. -
Сетевой протокол **Yggdrasil** (версия 0.5.x) сейчас находится в активной фазе «работы над ошибками» перед переходом к крупному обновлению v0.6.
Вот основные технические апдейты и состояние проекта на май 2026 года:
### Технические новости и релизы
* **Оптимизация маршрутизации (v0.5.12+):** В последних патчах (февраль–апрель 2026) разработчики внедрили улучшенный алгоритм выбора пути. Теперь система минимизирует не только «стоимость» линка, но и дистанцию до цели в дереве топологии. Это исправляет старую проблему, когда пакеты могли идти длинным путем через «корень», игнорируя более быстрые прямые маршруты.
* **Быстрое восстановление:** Параметр maxbackoff (время ожидания перед повторной попыткой подключения к пиру) теперь можно снижать до **5 секунд** (раньше было минимум 30). Это критично для мобильных узлов и нестабильных mesh-соединений.
* **Ресурсоемкость:** Оптимизировано потребление памяти при расчете путей, что позволяет протоколу стабильнее работать на слабых роутерах и одноплатниках (типа Orange Pi/Raspberry Pi).
### Главный вызов: «Гонка вооружений» за корень
Одной из самых обсуждаемых проблем сообщества в 2026 году стала нестабильность сети из-за появления мощных узлов с очень «сильными» ключами (high addressed root).
* **Проблема:** Когда кто-то генерирует ключ, претендующий на роль корня всей сети, но имеет при этом плохую связность или нестабильный канал, это «раскачивает» всю глобальную топологию.
* **Решение в v0.6:** Разработчики подтвердили, что в следующей версии (v0.6) дизайн **spanning tree** будет радикально изменен, чтобы лишить смысла попытки захватить роль корня и сделать сеть более устойчивой к таким колебаниям.
### Текущее состояние (Status Quo)
1. **Overlay-сеть:** Yggdrasil по-прежнему работает преимущественно как криптографическая сеть поверх интернета (IPv4/IPv6), обеспечивая сквозное шифрование.
2. **Стабильность:** Проект официально в статусе **Alpha**, но фактически признан сообществом достаточно стабильным для повседневного использования (SSH, локальные сервисы, мессенджеры).
3. **Платформы:** Поддерживаются практически все ОС (Linux, Windows, macOS, Android, iOS), а также прошивки OpenWrt и Ubiquiti.
**Короткий итог:** Если вы используете его для работы, стоит обновиться до актуальной ветки 0.5.12, чтобы получить более быстрый хендшейк и исправления маршрутов. Если же ждете глобальных перемен в архитектуре — следите за анонсами версии **0.6**.#Yggdrasil #YggdrasilNetwork #MeshNetwork #P2P #OverlayNetwork #IPv6 #Routing #SpanningTree #Networking #NetSec #Privacy #Encryption #OpenSource #SelfHosted #Decentralization #Infosec #SysAdmin #DevOps #Linux #OpenWrt #RaspberryPi #OrangePi #Mesh #PeerToPeer #NetworkEngineering #AlphaSoftware #TechUpdate #DistributedSystems
-
Need to check whether or not an IP address belongs to a known VPN service, the tor network, or proxy and scraping services?
Our Cabal Stealth Detector tool takes an IP and returns detection flags, provider/hosting info, and some basic temporal data via the ProxyCheck.io API. Bookmark it and give it a spin the next time you need some quick IP data!
#OSINT #osinttools #osinttool #ipaddress #ipOSINT #osint4good #cli #api #linux #python #netsec #tools #freetools #osintcabal
-
🔒 CVE-2026-7031: HIGH-severity buffer overflow in Tenda F456 (v1.0.0.5). Remote, no user interaction needed. Exploit public, no patch yet. Limit device exposure & monitor for updates. More: https://radar.offseq.com/threat/cve-2026-7031-buffer-overflow-in-tenda-f456-f28ef6c0 #OffSeq #Vulnerability #IoTSecurity #NetSec
-
🔒 CVE-2026-7031: HIGH-severity buffer overflow in Tenda F456 (v1.0.0.5). Remote, no user interaction needed. Exploit public, no patch yet. Limit device exposure & monitor for updates. More: https://radar.offseq.com/threat/cve-2026-7031-buffer-overflow-in-tenda-f456-f28ef6c0 #OffSeq #Vulnerability #IoTSecurity #NetSec
-
#DN42 searches for someone with hardware, expertise, time and passion to host, run and further develop their registry. It's a project of enthusiasts to play around with BGP in a lab and playground environment. There are plenty of hobbyists who run their own #ASN within this #darknet.
Announcement is here. More info on the project on one of their mirrors
-
#DN42 searches for someone with hardware, expertise, time and passion to host, run and further develop their registry. It's a project of enthusiasts to play around with BGP in a lab and playground environment. There are plenty of hobbyists who run their own #ASN within this #darknet.
Announcement is here. More info on the project on one of their mirrors
-
Investigating an email? Our OSINTCabal Email Kit runs four well known Git repos: Zehef, Holehe, MailSleuth, Hashtray, and queries the HIBP API. It then aggregates the data for you. All in just about 30 seconds.
Head to the live center on our site and check it out! Link in bio!
#OSINT4good #osint #emailosint #netsec #socmint #osinttools #tools #cli #linux #emaildata #python #curl #free #freetools #privacy #OPSEC #webdev #communityOSINT #API
-
Investigating domains can take time. We can help make it easier for you.
The OSINTCabal Domain Kit runs multiple CLI tools and APIs to collect host data, extracted credentials and keys, and files discovered through enumerated subdomains, organizing the results by subdomain. Check out our site and give it a go! Link in bio.
#osint #opensource #opensourceintelligence #netsec #tools #domaindata #domainosint #webtools #osint4good #linux #cli #tools #freetools #osinttools #python #github #free
-
Trying to find public records? Our Public Record Search Link Database is your one-stop-shop for quickly locating links to search sites for records of all kinds including criminal, civil, business, UCC, and education records.
Check it out on our site! OSINTCabal.org
#osint #opensource #opensourceintelligence #netsec #tools #osint4good #linux #cli #tools #freetools #osinttools #python #github #free #publicrecords #criminalrecord #civilrecord #ucc #uccfilings #publicdata
-
This Is What a Personal Surveillance System Actually Looks Like
You stop thinking of it as surveillance. It becomes “the system.” Just part of how things run. -
Critics call FCC router rule a ‘big swing’ that could create more supply chain uncertainty | CyberScoop
https://cyberscoop.com/fcc-bans-foreign-routers-critics-warn-about-supply-chain/#Cybersecurity #InfoSec #FCC #SupplyChain #HardwareSecurity #NetSec #TechNews #NationalSecurity #MastodonAdmin
-
OSINT Isn’t About Skill Anymore. It’s About Systems
There’s a moment, if you spend enough time in this space, where your attention changes. You stop looking at individual data points as things to extract. You start seeing them as inputs to a larger structure.https://cha1nc0der.wordpress.com/2026/03/21/osint-isnt-about-skill-anymore-its-about-systems/
-
What is Covert Channel Amplification? What are History Covert Channels? I tried to summarize this in few words:
https://www.wendzel.de/misc/2026/02/28/history-cc.html
The post will be updated soon with our upcoming IFIP SEC 2026 paper.
#netsec #infosec #cybersecurity #cybersec #steganography #covertchannels #informationhiding #research