home.social

#operationalsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #operationalsecurity, aggregated by home.social.

fetched live
  1. Exclusive-US military may require some troops in Mideast to surrender cell phones, sources say

    By Phil Stewart July 29 (Reuters) – The top U.S. commander for the Middle East has warned troops…
    #NewsBeep #News #BreakingNews #Americanservicemembers #BradCooper #breakingnews #Cellphones #deployedtroops #Iran #operationalsecurity
    newsbeep.com/669034/

  2. Incident Response Readiness Exposes Operational Gaps

    Being incident response ready means more than just having a plan - it requires immediate visibility into identity and authentication access, including investigator-level read access to crucial systems. Without this visibility, teams are left making blind containment decisions and piecing together timelines with guesswork.

    osintsights.com/incident-respo

    #IncidentResponse #IdentityAndAccessManagement #Mfa #OperationalSecurity #EmergingThreats

  3. Threat Actors Formalize Operational Security Playbook

    Cybercrime players are now treating operational security as a sophisticated game-changer, and it's time for you to level up your security strategy beyond just using VPNs. A battle-tested three-tier infrastructure model has emerged, separating exposure, execution, and monetization to safeguard high-stakes operations.

    osintsights.com/threat-actors-

    #OperationalSecurity #CardingOperations #ThreatActors #Vpns #Cybercrime

  4. Managed Detection and Response Targets Gaps in Cyber Defenses

    State, local, tribal, and territorial organizations, along with their schools, are facing a perfect storm of rising cyber threats, limited staff, and tight budgets - making it tough to stay ahead of attacks. Managed Detection and Response can help bridge the gaps in their cyber defenses, providing the support…

    osintsights.com/managed-detect

    #ManagedDetectionResponse #EmergingThreats #OperationalSecurity #CyberDefenses #EducationSector

  5. Dutch Navy Exposed by Cheap Bluetooth Tracker Mishap

    A €5 Bluetooth tracker and some basic online sleuthing allowed journalists to track a Dutch navy frigate, exposing a shocking lapse in operational security that has left many wondering how such a breach could occur. It seems that publicly available information, combined with a tiny device that's cheaper than a cup of coffee, was…

    osintsights.com/dutch-navy-exp

    #OperationalSecurity #BluetoothTracker #MilitarySecurity #EmergingThreats #Netherlands

  6. AI Adoption Exposes Hidden Security Gaps in Enterprise Operations

    As AI rapidly moves from experimentation to executive mandate, organizations face a daunting challenge: how to harness its power while securing and governing its adoption. With boards, investors, and executives pushing for integration, the pressure is on to balance AI adoption with robust security and oversight.

    osintsights.com/ai-adoption-ex

    #AiAdoption #EnterpriseSecurity #EmergingThreats #OperationalSecurity #ArtificialIntelligence

  7. New on The Sovereign Auditor.
    The FBI recovered deleted Signal messages from an iPhone -- not by breaking encryption, but from Apple's push notification database. Signal had been deleted. The notifications hadn't.
    The fix is one setting. But the lesson is bigger than that.
    open.substack.com/pub/sovereig
    #Signal #Privacy #OperationalSecurity #InfoSec #OPSEC

  8. LAPD Data Breach Exposes Sensitive Officer Records

    A data breach has exposed sensitive records of the Los Angeles Police Department, raising urgent concerns about operational security, individual privacy, and institutional trust. The incident's implications extend far beyond a single breach, sparking questions about the vulnerability of law enforcement data.

    osintsights.com/lapd-data-brea

    #DataBreach #Lapd #LawEnforcement #OperationalSecurity #Privacy

  9. APT37’s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    • LNK-based initial execution
    • Embedded PowerShell payload extraction
    • Ruby interpreter abuse (v3.3.0)
    • Scheduled task persistence (5-minute interval)
    • USB-based covert bidirectional C2
    • Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    – Command staging offline
    – Data exfiltration without internet access
    – Lateral spread across isolated systems
    – Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection — including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  10. APT37’s Ruby Jumper campaign demonstrates a mature approach to air-gap traversal.

    Observed tradecraft includes:
    • LNK-based initial execution
    • Embedded PowerShell payload extraction
    • Ruby interpreter abuse (v3.3.0)
    • Scheduled task persistence (5-minute interval)
    • USB-based covert bidirectional C2
    • Multi-stage backdoor deployment
    Toolset: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, FOOTWINE, BLUELIGHT.

    The removable media relay model enables:
    – Command staging offline
    – Data exfiltration without internet access
    – Lateral spread across isolated systems
    – Surveillance via Windows spyware
    This reinforces a critical point:
    Air-gap controls must extend beyond physical disconnection — including USB governance, device auditing, behavioral monitoring, and strict runtime execution policies.

    Are critical infrastructure operators prepared for USB-mediated C2 relays?

    Source: bleepingcomputer.com/news/secu

    Engage below.

    Follow TechNadu for high-signal threat intelligence insights.
    Repost to elevate awareness.

    #Infosec #APT37 #AirGapSecurity #ThreatModeling #MalwareAnalysis #NationStateThreats #USBExfiltration #SOC #DetectionEngineering #CyberDefense #OperationalSecurity #ThreatHunting #ZeroTrustArchitecture

  11. 🔐 Secure Connectivity as Crisis Infrastructure
    Internews’ 2025 findings demonstrate a clear pattern: when VPN access declines, exposure to phishing, surveillance, and account compromise increases rapidly.

    With pro-bono Surfshark support:
    • 100 high-risk partners protected
    • 9 countries impacted
    • Field-based digital security training delivered
    • One-year VPN access deployed to journalists and activists

    In hostile environments, encrypted traffic and secure authentication workflows directly affect operational safety.

    Is the cybersecurity sector allocating sufficient resources toward safeguarding independent media?

    Source: internews.org/wp-content/uploa

    Share your insights below.
    Follow TechNadu for continued coverage on digital risk, cyber resilience, and global privacy developments.

    #InfoSec #CyberResilience #DigitalRights #VPNInfrastructure #OperationalSecurity #ThreatIntelligence #PressFreedom

  12. Pax8 disclosed an accidental email distribution that exposed internal business and Microsoft licensing data linked to approximately 1,800 MSP partners.

    Although no PII was involved, the dataset reportedly included customer names, SKUs, license counts, and renewal timelines — information that could carry competitive and threat-intelligence value if misused.
    The incident reinforces the importance of:
    - Least-privilege access to partner data
    - Strong outbound data controls
    - Incident response transparency in partner ecosystems

    What preventive controls do you see as most effective in reducing accidental disclosures?

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for sober, security-focused reporting.
    Add your insights below.

    #InfoSec #DataSecurity #CloudEcosystem #MSP #OperationalSecurity #TechNadu

  13. The reported BreachForums database exposure illustrates a recurring pattern in underground ecosystems: infrastructure weaknesses outweigh perceived anonymity.

    Key considerations:
    • Metadata remains a critical risk vector
    • Forum resilience often masks fragile backends
    • Legal and reputational fallout can be long-lasting

    This incident reinforces why data minimization and secure configuration matter - regardless of intent or audience.

    Source: cybersecuritynews.com/breachfo

    Join the discussion and follow @technadu for fact-based cybersecurity reporting.

    #InfoSec #ThreatIntel #DarkWeb #DataExposure #CyberRisk #OperationalSecurity

  14. POV: You want to find love but also take care of your #OPSEC.

    ✅ Here are 5️⃣ good habits to strengthen your #OPSEC (you probably don’t know the last one):

    1️⃣ Limit what you share on social media (workplace, family/friends, location) and set your personal accounts to private.

    2️⃣ Avoid using the same usernames across different platforms.

    3️⃣ Keep your operating system and apps up to date.

    4️⃣ Use long, unique passwords and a password manager.

    5️⃣ Turn on lockdown mode on your phone when attending events, conferences, or corporate gatherings.

    🔎 As a reminder, OPSEC stands for #OperationalSecurity. It refers to a set of methods and best practices designed to prevent an adversary from obtaining sensitive information about you by observing, collecting, or inferring details that may seem harmless.

    👉 Follow Epieos for more tips and tricks related to #OSINT.

  15. #PeteHegseth #DOD #OperationalSecurity
    "National Security used to require clearance, but not anymore."
    *now with unlimited sharing

    Pete Hegseth's National Security 'Friends & Family Plan'
    youtu.be/-CKXq9KNGZg?si=Cng0rS

  16. Cell Phone OPSEC for Border Crossings

    I have heard stories of more aggressive interrogation of electronic devices at US border crossings. I know a lot about securing computers, but very little about securing phones.
    Are there easy ways to delete data—files, photos, etc.&#... schneier.com/blog/archives/202

    #operationalsecurity #Uncategorized #cellphones #borders

  17. Cell Phone OPSEC for Border Crossings

    I have heard stories of more aggressive interrogation of electronic devices at US border crossings. I know a lot about securing computers, but very little about securing phones.
    Are there easy ways to delete data—files, photos, etc.&#... schneier.com/blog/archives/202

    #operationalsecurity #Uncategorized #cellphones #borders

  18. The news that snr ofcls in the #Trump admin discussed plans on #Signal, a commercial messaging app, for an impending attack angered & bewildered those who have taken to the air on behalf of the #US.

    The mistaken inclusion of the editor of #TheAtlantic in the chat & #Hegseth’s insistence that he did nothing wrong by disclosing the secret plans upend decades of #military doctrine about #OperationalSecurity, a dozen #AirForce & #Navy fighter pilots said.

    #law #NationalSecurity #SignalGate

  19. The news that snr ofcls in the #Trump admin discussed plans on #Signal, a commercial messaging app, for an impending attack angered & bewildered those who have taken to the air on behalf of the #US.

    The mistaken inclusion of the editor of #TheAtlantic in the chat & #Hegseth’s insistence that he did nothing wrong by disclosing the secret plans upend decades of #military doctrine about #OperationalSecurity, a dozen #AirForce & #Navy fighter pilots said.

    #law #NationalSecurity #SignalGate

  20. #MikeWaltz Left His #Venmo Friends List Public

    A WIRED review shows national #security adviser Mike Waltz, #WhiteHouse chief of staff #SusieWiles , and other top officials left sensitive information exposed via Venmo—until WIRED asked about it.

    > looks like these folks don’t understand the concept of basic operational #security

    #opsec #operationalsecurity #privacy

    wired.com/story/michael-waltz-

  21. #MikeWaltz Left His #Venmo Friends List Public

    A WIRED review shows national #security adviser Mike Waltz, #WhiteHouse chief of staff #SusieWiles , and other top officials left sensitive information exposed via Venmo—until WIRED asked about it.

    > looks like these folks don’t understand the concept of basic operational #security

    #opsec #operationalsecurity #privacy

    wired.com/story/michael-waltz-

  22. Watch it here ➫ youtu.be/u349u65BJLg
    Two darknet markets, two outcomes: Atlas Market succeeded with competence and trust, while Vortex Market collapsed under admin mistakes. This is a clear lesson in why OPSEC and professionalism matter.
    #DarknetMarkets #AtlasMarket #VortexMarket #HiddenWeb #CyberSecurity #OperationalSecurity

  23. Did you miss last week's podcast with @dragosinc's @hacks4pancakes? In this episode of the Breaking Badness Cybersecurity Podcast, Lesley joins @NotTheLinux and @danonsecurity to share insights on OT challenges, incident response, and bridging the gap between cyber and operations. Don’t miss out on this enlightening discussion! 🎙️

    🎧 Listen here: domaintools.com/resources/podc

    #cybersecurity #CyberPodcast #IncidentResponse #OperationalTechnology #OperationalSecurity

  24. Did you miss last week's podcast with @dragosinc's @hacks4pancakes? In this episode of the Breaking Badness Cybersecurity Podcast, Lesley joins @NotTheLinux and @danonsecurity to share insights on OT challenges, incident response, and bridging the gap between cyber and operations. Don’t miss out on this enlightening discussion! 🎙️

    🎧 Listen here: domaintools.com/resources/podc

    #cybersecurity #CyberPodcast #IncidentResponse #OperationalTechnology #OperationalSecurity

  25. "LockBit's Bold Return: A Threat Renewed 🚨 #CyberAlert"

    Despite recent crackdowns, the notorious LockBit ransomware gang has defiantly announced a comeback, threatening new cyber onslaughts on government sectors in the UK and USA. Leveraging a previously exploited PHP vulnerability, they've bounced back, boasting updated security measures and a new dark web haunt for victim listings. This follows a brief hiatus post-Operation Cronos, highlighting the resilient and adaptive nature of cyber threats today. LockBit's strategy now includes manual decryptor releases and rewards for vulnerability reports, underlining an intensified focus on operational security to thwart future law enforcement infiltrations. Stay vigilant, stay informed. #LockBit #CyberSecurity #RansomwareResurgence #ThreatIntelligence #DigitalDefense

    Source: HackRead

    Tags: #APT #CyberCrime #InfoSec #SecurityAwareness #CyberThreats #GovernmentSecurity #OperationalSecurity #PHPVulnerability 🌐🔒💡

  26. "LockBit's Bold Return: A Threat Renewed 🚨 #CyberAlert"

    Despite recent crackdowns, the notorious LockBit ransomware gang has defiantly announced a comeback, threatening new cyber onslaughts on government sectors in the UK and USA. Leveraging a previously exploited PHP vulnerability, they've bounced back, boasting updated security measures and a new dark web haunt for victim listings. This follows a brief hiatus post-Operation Cronos, highlighting the resilient and adaptive nature of cyber threats today. LockBit's strategy now includes manual decryptor releases and rewards for vulnerability reports, underlining an intensified focus on operational security to thwart future law enforcement infiltrations. Stay vigilant, stay informed. #LockBit #CyberSecurity #RansomwareResurgence #ThreatIntelligence #DigitalDefense

    Source: HackRead

    Tags: #APT #CyberCrime #InfoSec #SecurityAwareness #CyberThreats #GovernmentSecurity #OperationalSecurity #PHPVulnerability 🌐🔒💡

  27. If your first instinct is to try and find blame when a security vulnerability is pointed out...

    ...you have already created an environment where everyone will hide issues from you.

    You currently live in a fake reality where you think everything is fine and you have no idea the rot that is underneath you.

    If you fire or punish a person every time a vulnerability is found, you will have no one left. Hell, fire yourself first to save us all the trouble.

    Vulnerabilities exist. The world changes. Software changes. Attacks change. Business needs change.

    Life is fucking impermanence.

    So create an environment where folks come to you quickly and tell you what needs to be fixed as they find it.

    How do you do that?! Reward vulnerability discovery. Reward mitigations. Reward patch management. Reward security improvement. Reward safety improvement.

    #informationsecurity #infosec #operationalsecurity #opsec #ics #ot

  28. If your first instinct is to try and find blame when a security vulnerability is pointed out...

    ...you have already created an environment where everyone will hide issues from you.

    You currently live in a fake reality where you think everything is fine and you have no idea the rot that is underneath you.

    If you fire or punish a person every time a vulnerability is found, you will have no one left. Hell, fire yourself first to save us all the trouble.

    Vulnerabilities exist. The world changes. Software changes. Attacks change. Business needs change.

    Life is fucking impermanence.

    So create an environment where folks come to you quickly and tell you what needs to be fixed as they find it.

    How do you do that?! Reward vulnerability discovery. Reward mitigations. Reward patch management. Reward security improvement. Reward safety improvement.

    #informationsecurity #infosec #operationalsecurity #opsec #ics #ot

  29. Greetings, dear followers. Today, we'd like to discuss an often-overlooked aspect of espionage—the humble ballpoint pen—and shed light on the potential risks associated with its usage. While ballpoint pens may seem innocuous, their role in intelligence operations demands caution and consideration. Let's delve into this lesser-known aspect and examine the implications. 🖊️🔒🕵️‍♂️

    In the realm of espionage, the pen is indeed mightier than the sword. However, it's crucial to remember that words committed to paper can become evidence that may be used against you in a court of law. As we navigate the complex world of intelligence, it's essential to understand the long-term implications of documenting sensitive information.

    While our esteemed agency remains committed to upholding national security and safeguarding our country's interests, it's also important to recognize that the political landscape can be unpredictable. The dynamic nature of intelligence work means that the future may hold unexpected twists and turns.

    While ballpoint pens may have been an integral tool in espionage operations throughout history, the CIA remains committed to employing advanced techniques and technology to ensure operational security and mitigate risks.

    So, whether you find yourself embarking on a thrilling journey in the world of intelligence or simply jotting down your thoughts, remember the adage "the pen is mightier than the sword." Exercise caution, remain aware of potential consequences, and always prioritize the integrity of our great nation.

    Together, let us continue to navigate the complex landscape of intelligence while upholding the values that define us.

    #CIA #Espionage #OperationalSecurity #IntelligenceCommunity #Transparency #Accountability #NationalInterests #Ethics #LegalFrameworks #Adaptability #Integrity #USA
  30. I'm working on somenkind of #boardGame to teach the core principles of the #internet, how attacks can be executed and what defenses there are. Target group: non-technical people, who must learn the basics of #operationalSecurity (e.g #activists, #queer persons or just the couple who think it's fine to send nudes via, say, email). Does someone have hints or referrals? Or want to test run?