home.social

#secuity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #secuity, aggregated by home.social.

fetched live
  1. Interesting Git repos of the week:

    Detection:

    * github.com/EvilBytecode/NoMore - blocks information stealing malware
    * github.com/FoxIO-LLC/ja4 - fingerprint the TLS
    * github.com/facebookexperimenta - intercept all the syscalls from userland
    * github.com/cilium/tetragon - Tetragon uses eBPF so you don't have to

    Bugs:

    * github.com/xairy/kernel-exploi - bunch of Linux kernel PoCs

    Exploitation:

    * github.com/magisterquis/srsocw - cloak of invisibility for .so files
    * github.com/braindead-sec/ssh-g - steal creds, move laterally
    * github.com/bohops/COM-to-the-D - attacking COM
    * github.com/magisterquis/wtrtdt - Linux CTF
    * github.com/mempodippy/vlany - mmm, root kit
    * github.com/invariantlabs-ai/mc - experiments in making non-deterministic models behave

    Data:

    * github.com/sarwarbeing-ai/Agen - design patterns for agentic systems

    Nerd:

    * github.com/LaurieWired/Quine - how about a nice quine?

    #secuity, #code, #research

  2. Interesting Git repos of the week:

    Detection:

    * github.com/EvilBytecode/NoMore - blocks information stealing malware
    * github.com/FoxIO-LLC/ja4 - fingerprint the TLS
    * github.com/facebookexperimenta - intercept all the syscalls from userland
    * github.com/cilium/tetragon - Tetragon uses eBPF so you don't have to

    Bugs:

    * github.com/xairy/kernel-exploi - bunch of Linux kernel PoCs

    Exploitation:

    * github.com/magisterquis/srsocw - cloak of invisibility for .so files
    * github.com/braindead-sec/ssh-g - steal creds, move laterally
    * github.com/bohops/COM-to-the-D - attacking COM
    * github.com/magisterquis/wtrtdt - Linux CTF
    * github.com/mempodippy/vlany - mmm, root kit
    * github.com/invariantlabs-ai/mc - experiments in making non-deterministic models behave

    Data:

    * github.com/sarwarbeing-ai/Agen - design patterns for agentic systems

    Nerd:

    * github.com/LaurieWired/Quine - how about a nice quine?

    #secuity, #code, #research

  3. Interesting Git repos of the week:

    Detection:

    * github.com/EvilBytecode/NoMore - blocks information stealing malware
    * github.com/FoxIO-LLC/ja4 - fingerprint the TLS
    * github.com/facebookexperimenta - intercept all the syscalls from userland
    * github.com/cilium/tetragon - Tetragon uses eBPF so you don't have to

    Bugs:

    * github.com/xairy/kernel-exploi - bunch of Linux kernel PoCs

    Exploitation:

    * github.com/magisterquis/srsocw - cloak of invisibility for .so files
    * github.com/braindead-sec/ssh-g - steal creds, move laterally
    * github.com/bohops/COM-to-the-D - attacking COM
    * github.com/magisterquis/wtrtdt - Linux CTF
    * github.com/mempodippy/vlany - mmm, root kit
    * github.com/invariantlabs-ai/mc - experiments in making non-deterministic models behave

    Data:

    * github.com/sarwarbeing-ai/Agen - design patterns for agentic systems

    Nerd:

    * github.com/LaurieWired/Quine - how about a nice quine?

    #secuity, #code, #research

  4. Interesting Git repos of the week:

    Detection:

    * github.com/EvilBytecode/NoMore - blocks information stealing malware
    * github.com/FoxIO-LLC/ja4 - fingerprint the TLS
    * github.com/facebookexperimenta - intercept all the syscalls from userland
    * github.com/cilium/tetragon - Tetragon uses eBPF so you don't have to

    Bugs:

    * github.com/xairy/kernel-exploi - bunch of Linux kernel PoCs

    Exploitation:

    * github.com/magisterquis/srsocw - cloak of invisibility for .so files
    * github.com/braindead-sec/ssh-g - steal creds, move laterally
    * github.com/bohops/COM-to-the-D - attacking COM
    * github.com/magisterquis/wtrtdt - Linux CTF
    * github.com/mempodippy/vlany - mmm, root kit
    * github.com/invariantlabs-ai/mc - experiments in making non-deterministic models behave

    Data:

    * github.com/sarwarbeing-ai/Agen - design patterns for agentic systems

    Nerd:

    * github.com/LaurieWired/Quine - how about a nice quine?

    #secuity, #code, #research

  5. Interesting Git repos of the week:

    Detection:

    * github.com/EvilBytecode/NoMore - blocks information stealing malware
    * github.com/FoxIO-LLC/ja4 - fingerprint the TLS
    * github.com/facebookexperimenta - intercept all the syscalls from userland
    * github.com/cilium/tetragon - Tetragon uses eBPF so you don't have to

    Bugs:

    * github.com/xairy/kernel-exploi - bunch of Linux kernel PoCs

    Exploitation:

    * github.com/magisterquis/srsocw - cloak of invisibility for .so files
    * github.com/braindead-sec/ssh-g - steal creds, move laterally
    * github.com/bohops/COM-to-the-D - attacking COM
    * github.com/magisterquis/wtrtdt - Linux CTF
    * github.com/mempodippy/vlany - mmm, root kit
    * github.com/invariantlabs-ai/mc - experiments in making non-deterministic models behave

    Data:

    * github.com/sarwarbeing-ai/Agen - design patterns for agentic systems

    Nerd:

    * github.com/LaurieWired/Quine - how about a nice quine?

    #secuity, #code, #research

  6. Top spy chief says ‘realistic possibility’ three foreign governments could attempt assassinations on Australian soil, warns ‘threat is real’ byteseu.com/1510642/ #$50bDefenceBoost #ASIO #auspol #Australia #AustralianPolitics #defence #FederalPolitics #FOREIGNAFFAIRS #NationalSecurity #secuity #SpyAgency #SpyBoss

  7. While I dont like the Idea of big corporate social media and tech. If you have it make it as secure as you can.

    An easy but often overlooked privacy check: review the third-party apps connected to your accounts.

    Old or unused apps can still access your data. It's a good habit to audit and remove anything you no longer use or trust.

    Start here:

    Google: myaccount.google.com/permissio
    Facebook: facebook.com/settings?tab=appl
    Microsoft: account.live.com/consent/Manag
    Apple: appleid.apple.com/

    Stay sharp. Small steps make a big difference.

    #Privacy #secuity

  8. While I dont like the Idea of big corporate social media and tech. If you have it make it as secure as you can.

    An easy but often overlooked privacy check: review the third-party apps connected to your accounts.

    Old or unused apps can still access your data. It's a good habit to audit and remove anything you no longer use or trust.

    Start here:

    Google: myaccount.google.com/permissio
    Facebook: facebook.com/settings?tab=appl
    Microsoft: account.live.com/consent/Manag
    Apple: appleid.apple.com/

    Stay sharp. Small steps make a big difference.

    #Privacy #secuity

  9. While I dont like the Idea of big corporate social media and tech. If you have it make it as secure as you can.

    An easy but often overlooked privacy check: review the third-party apps connected to your accounts.

    Old or unused apps can still access your data. It's a good habit to audit and remove anything you no longer use or trust.

    Start here:

    Google: myaccount.google.com/permissio
    Facebook: facebook.com/settings?tab=appl
    Microsoft: account.live.com/consent/Manag
    Apple: appleid.apple.com/

    Stay sharp. Small steps make a big difference.

    #Privacy #secuity

  10. While I dont like the Idea of big corporate social media and tech. If you have it make it as secure as you can.

    An easy but often overlooked privacy check: review the third-party apps connected to your accounts.

    Old or unused apps can still access your data. It's a good habit to audit and remove anything you no longer use or trust.

    Start here:

    Google: myaccount.google.com/permissio
    Facebook: facebook.com/settings?tab=appl
    Microsoft: account.live.com/consent/Manag
    Apple: appleid.apple.com/

    Stay sharp. Small steps make a big difference.

    #Privacy #secuity

  11. While I dont like the Idea of big corporate social media and tech. If you have it make it as secure as you can.

    An easy but often overlooked privacy check: review the third-party apps connected to your accounts.

    Old or unused apps can still access your data. It's a good habit to audit and remove anything you no longer use or trust.

    Start here:

    Google: myaccount.google.com/permissio
    Facebook: facebook.com/settings?tab=appl
    Microsoft: account.live.com/consent/Manage
    Apple: appleid.apple.com/

    Stay sharp. Small steps make a big difference.

  12. Lazy saturday means: more responsible disclosures. The process is now streamlined on my side: a table with bucketnames, status (usually open...), date of first report, date fixed, content and examples is emailed to #aws #secuity

    Status at the moment: 26 Buckets reported, out of them are 25 are open. Those buckets contain jucy data as names, birthdays, passports, passwords, resumes, medical data, github token.

    It will be very interesting to see the average time to close a bucket for #aws. With n=1 it is 893 days. I hope the n will increase and the number will decrease.

  13. Lazy saturday means: more responsible disclosures. The process is now streamlined on my side: a table with bucketnames, status (usually open...), date of first report, date fixed, content and examples is emailed to #aws #secuity

    Status at the moment: 26 Buckets reported, out of them are 25 are open. Those buckets contain jucy data as names, birthdays, passports, passwords, resumes, medical data, github token.

    It will be very interesting to see the average time to close a bucket for #aws. With n=1 it is 893 days. I hope the n will increase and the number will decrease.

  14. Lazy saturday means: more responsible disclosures. The process is now streamlined on my side: a table with bucketnames, status (usually open...), date of first report, date fixed, content and examples is emailed to #aws #secuity

    Status at the moment: 26 Buckets reported, out of them are 25 are open. Those buckets contain jucy data as names, birthdays, passports, passwords, resumes, medical data, github token.

    It will be very interesting to see the average time to close a bucket for #aws. With n=1 it is 893 days. I hope the n will increase and the number will decrease.

  15. Lazy saturday means: more responsible disclosures. The process is now streamlined on my side: a table with bucketnames, status (usually open...), date of first report, date fixed, content and examples is emailed to #aws #secuity

    Status at the moment: 26 Buckets reported, out of them are 25 are open. Those buckets contain jucy data as names, birthdays, passports, passwords, resumes, medical data, github token.

    It will be very interesting to see the average time to close a bucket for #aws. With n=1 it is 893 days. I hope the n will increase and the number will decrease.

  16. Lazy saturday means: more responsible disclosures. The process is now streamlined on my side: a table with bucketnames, status (usually open...), date of first report, date fixed, content and examples is emailed to #aws #secuity

    Status at the moment: 26 Buckets reported, out of them are 25 are open. Those buckets contain jucy data as names, birthdays, passports, passwords, resumes, medical data, github token.

    It will be very interesting to see the average time to close a bucket for #aws. With n=1 it is 893 days. I hope the n will increase and the number will decrease.

  17. Syft v1.13.0 released 🎉

    Some "enriching" features and fixes in this one! 🥳

    github.com/anchore/syft/releas
    #sbom #secuity

  18. Syft v1.13.0 released 🎉

    Some "enriching" features and fixes in this one! 🥳

    github.com/anchore/syft/releas

  19. Syft v1.13.0 released 🎉

    Some "enriching" features and fixes in this one! 🥳

    github.com/anchore/syft/releas
    #sbom #secuity

  20. Syft v1.13.0 released 🎉

    Some "enriching" features and fixes in this one! 🥳

    github.com/anchore/syft/releas
    #sbom #secuity

  21. @_L1vY_ @falcennial Thanks for the #secuity heads-up about AI becoming turned on by default in #Zoom.

    There’s a lot of switches to turn Off to disable AI Companion. If Zoom keeps reminding me that it thinks it’s more than a video-calling tool I’ll not renew my subscription and use something free instead.

  22. @_L1vY_ @falcennial Thanks for the #secuity heads-up about AI becoming turned on by default in #Zoom.

    There’s a lot of switches to turn Off to disable AI Companion. If Zoom keeps reminding me that it thinks it’s more than a video-calling tool I’ll not renew my subscription and use something free instead.

  23. @_L1vY_ @falcennial Thanks for the #secuity heads-up about AI becoming turned on by default in #Zoom.

    There’s a lot of switches to turn Off to disable AI Companion. If Zoom keeps reminding me that it thinks it’s more than a video-calling tool I’ll not renew my subscription and use something free instead.

  24. @_L1vY_ @falcennial Thanks for the #secuity heads-up about AI becoming turned on by default in #Zoom.

    There’s a lot of switches to turn Off to disable AI Companion. If Zoom keeps reminding me that it thinks it’s more than a video-calling tool I’ll not renew my subscription and use something free instead.

  25. @_L1vY_ @falcennial Thanks for the #secuity heads-up about AI becoming turned on by default in #Zoom.

    There’s a lot of switches to turn Off to disable AI Companion. If Zoom keeps reminding me that it thinks it’s more than a video-calling tool I’ll not renew my subscription and use something free instead.

  26. Wow... #RockYou2024 is definitely gonna rock some houses in a pretty bad way. Still digging into it, but folks - please keep your head on a swivel and start to change passwords, NOW. Don't wait for results. Frequently changing passwords is good practice anyhow, so change everything as you're able as a practice and you'll be safer from the starting line. Make it a habit. #cybersec #technology #secuity

  27. Wow... #RockYou2024 is definitely gonna rock some houses in a pretty bad way. Still digging into it, but folks - please keep your head on a swivel and start to change passwords, NOW. Don't wait for results. Frequently changing passwords is good practice anyhow, so change everything as you're able as a practice and you'll be safer from the starting line. Make it a habit. #cybersec #technology #secuity

  28. Wow... #RockYou2024 is definitely gonna rock some houses in a pretty bad way. Still digging into it, but folks - please keep your head on a swivel and start to change passwords, NOW. Don't wait for results. Frequently changing passwords is good practice anyhow, so change everything as you're able as a practice and you'll be safer from the starting line. Make it a habit. #cybersec #technology #secuity

  29. Wow... #RockYou2024 is definitely gonna rock some houses in a pretty bad way. Still digging into it, but folks - please keep your head on a swivel and start to change passwords, NOW. Don't wait for results. Frequently changing passwords is good practice anyhow, so change everything as you're able as a practice and you'll be safer from the starting line. Make it a habit. #cybersec #technology #secuity

  30. Ross J. Anderson, britischer Professor für IT-Sicherheit, ist verstorben.
    RIP

    #secuity #sicherheit #Privacy

  31. Ross J. Anderson, britischer Professor für IT-Sicherheit, ist verstorben.
    RIP

    #secuity #sicherheit #Privacy

  32. Ross J. Anderson, britischer Professor für IT-Sicherheit, ist verstorben.
    RIP

    #secuity #sicherheit #Privacy

  33. Ross J. Anderson, britischer Professor für IT-Sicherheit, ist verstorben.
    RIP

    #secuity #sicherheit #Privacy

  34. Ross J. Anderson, britischer Professor für IT-Sicherheit, ist verstorben.
    RIP

    #secuity #sicherheit #Privacy

  35. Today i found that having #NordVPN installed on an OSX laptop caused perfectly valid SSL certs for HTTPS to not be trusted, when the app was not open. Open the app and it worked.
    Immediate uninstall, but WTF was going on there #secuity

  36. Today i found that having #NordVPN installed on an OSX laptop caused perfectly valid SSL certs for HTTPS to not be trusted, when the app was not open. Open the app and it worked.
    Immediate uninstall, but WTF was going on there #secuity

  37. Today i found that having installed on an OSX laptop caused perfectly valid SSL certs for HTTPS to not be trusted, when the app was not open. Open the app and it worked.
    Immediate uninstall, but WTF was going on there

  38. Today i found that having #NordVPN installed on an OSX laptop caused perfectly valid SSL certs for HTTPS to not be trusted, when the app was not open. Open the app and it worked.
    Immediate uninstall, but WTF was going on there #secuity

  39. Your #VPN provider won't go to jail for you for 5 dollars

    @ivpn explains how competent service providers can avoid sharing sensitive information about users...

    Hint: It involves not collecting/storing that information in the first place. Unfortunately, most VPN providers are not worthy of trust.

    (IVPN is pretty great and highly recommended in the privacy community, though.)

    #privacy #secuity #opsec

    ivpn.net/blog/your-vpn-provide

  40. Your #VPN provider won't go to jail for you for 5 dollars

    @ivpn explains how competent service providers can avoid sharing sensitive information about users...

    Hint: It involves not collecting/storing that information in the first place. Unfortunately, most VPN providers are not worthy of trust.

    (IVPN is pretty great and highly recommended in the privacy community, though.)

    #privacy #secuity #opsec

    ivpn.net/blog/your-vpn-provide

  41. Your #VPN provider won't go to jail for you for 5 dollars

    @ivpn explains how competent service providers can avoid sharing sensitive information about users...

    Hint: It involves not collecting/storing that information in the first place. Unfortunately, most VPN providers are not worthy of trust.

    (IVPN is pretty great and highly recommended in the privacy community, though.)

    #privacy #secuity #opsec

    ivpn.net/blog/your-vpn-provide

  42. Your #VPN provider won't go to jail for you for 5 dollars

    @ivpn explains how competent service providers can avoid sharing sensitive information about users...

    Hint: It involves not collecting/storing that information in the first place. Unfortunately, most VPN providers are not worthy of trust.

    (IVPN is pretty great and highly recommended in the privacy community, though.)

    #privacy #secuity #opsec

    ivpn.net/blog/your-vpn-provide