home.social

#secuity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #secuity, aggregated by home.social.

  1. Interesting Git repos of the week:

    Detection:

    * github.com/EvilBytecode/NoMore - blocks information stealing malware
    * github.com/FoxIO-LLC/ja4 - fingerprint the TLS
    * github.com/facebookexperimenta - intercept all the syscalls from userland
    * github.com/cilium/tetragon - Tetragon uses eBPF so you don't have to

    Bugs:

    * github.com/xairy/kernel-exploi - bunch of Linux kernel PoCs

    Exploitation:

    * github.com/magisterquis/srsocw - cloak of invisibility for .so files
    * github.com/braindead-sec/ssh-g - steal creds, move laterally
    * github.com/bohops/COM-to-the-D - attacking COM
    * github.com/magisterquis/wtrtdt - Linux CTF
    * github.com/mempodippy/vlany - mmm, root kit
    * github.com/invariantlabs-ai/mc - experiments in making non-deterministic models behave

    Data:

    * github.com/sarwarbeing-ai/Agen - design patterns for agentic systems

    Nerd:

    * github.com/LaurieWired/Quine - how about a nice quine?

    #secuity, #code, #research

  2. Interesting Git repos of the week:

    Detection:

    * github.com/EvilBytecode/NoMore - blocks information stealing malware
    * github.com/FoxIO-LLC/ja4 - fingerprint the TLS
    * github.com/facebookexperimenta - intercept all the syscalls from userland
    * github.com/cilium/tetragon - Tetragon uses eBPF so you don't have to

    Bugs:

    * github.com/xairy/kernel-exploi - bunch of Linux kernel PoCs

    Exploitation:

    * github.com/magisterquis/srsocw - cloak of invisibility for .so files
    * github.com/braindead-sec/ssh-g - steal creds, move laterally
    * github.com/bohops/COM-to-the-D - attacking COM
    * github.com/magisterquis/wtrtdt - Linux CTF
    * github.com/mempodippy/vlany - mmm, root kit
    * github.com/invariantlabs-ai/mc - experiments in making non-deterministic models behave

    Data:

    * github.com/sarwarbeing-ai/Agen - design patterns for agentic systems

    Nerd:

    * github.com/LaurieWired/Quine - how about a nice quine?

    #secuity, #code, #research

  3. Interesting Git repos of the week:

    Detection:

    * github.com/EvilBytecode/NoMore - blocks information stealing malware
    * github.com/FoxIO-LLC/ja4 - fingerprint the TLS
    * github.com/facebookexperimenta - intercept all the syscalls from userland
    * github.com/cilium/tetragon - Tetragon uses eBPF so you don't have to

    Bugs:

    * github.com/xairy/kernel-exploi - bunch of Linux kernel PoCs

    Exploitation:

    * github.com/magisterquis/srsocw - cloak of invisibility for .so files
    * github.com/braindead-sec/ssh-g - steal creds, move laterally
    * github.com/bohops/COM-to-the-D - attacking COM
    * github.com/magisterquis/wtrtdt - Linux CTF
    * github.com/mempodippy/vlany - mmm, root kit
    * github.com/invariantlabs-ai/mc - experiments in making non-deterministic models behave

    Data:

    * github.com/sarwarbeing-ai/Agen - design patterns for agentic systems

    Nerd:

    * github.com/LaurieWired/Quine - how about a nice quine?

    #secuity, #code, #research

  4. Interesting Git repos of the week:

    Detection:

    * github.com/EvilBytecode/NoMore - blocks information stealing malware
    * github.com/FoxIO-LLC/ja4 - fingerprint the TLS
    * github.com/facebookexperimenta - intercept all the syscalls from userland
    * github.com/cilium/tetragon - Tetragon uses eBPF so you don't have to

    Bugs:

    * github.com/xairy/kernel-exploi - bunch of Linux kernel PoCs

    Exploitation:

    * github.com/magisterquis/srsocw - cloak of invisibility for .so files
    * github.com/braindead-sec/ssh-g - steal creds, move laterally
    * github.com/bohops/COM-to-the-D - attacking COM
    * github.com/magisterquis/wtrtdt - Linux CTF
    * github.com/mempodippy/vlany - mmm, root kit
    * github.com/invariantlabs-ai/mc - experiments in making non-deterministic models behave

    Data:

    * github.com/sarwarbeing-ai/Agen - design patterns for agentic systems

    Nerd:

    * github.com/LaurieWired/Quine - how about a nice quine?

    #secuity, #code, #research

  5. Interesting Git repos of the week:

    Detection:

    * github.com/EvilBytecode/NoMore - blocks information stealing malware
    * github.com/FoxIO-LLC/ja4 - fingerprint the TLS
    * github.com/facebookexperimenta - intercept all the syscalls from userland
    * github.com/cilium/tetragon - Tetragon uses eBPF so you don't have to

    Bugs:

    * github.com/xairy/kernel-exploi - bunch of Linux kernel PoCs

    Exploitation:

    * github.com/magisterquis/srsocw - cloak of invisibility for .so files
    * github.com/braindead-sec/ssh-g - steal creds, move laterally
    * github.com/bohops/COM-to-the-D - attacking COM
    * github.com/magisterquis/wtrtdt - Linux CTF
    * github.com/mempodippy/vlany - mmm, root kit
    * github.com/invariantlabs-ai/mc - experiments in making non-deterministic models behave

    Data:

    * github.com/sarwarbeing-ai/Agen - design patterns for agentic systems

    Nerd:

    * github.com/LaurieWired/Quine - how about a nice quine?

    #secuity, #code, #research

  6. While I dont like the Idea of big corporate social media and tech. If you have it make it as secure as you can.

    An easy but often overlooked privacy check: review the third-party apps connected to your accounts.

    Old or unused apps can still access your data. It's a good habit to audit and remove anything you no longer use or trust.

    Start here:

    Google: myaccount.google.com/permissio
    Facebook: facebook.com/settings?tab=appl
    Microsoft: account.live.com/consent/Manag
    Apple: appleid.apple.com/

    Stay sharp. Small steps make a big difference.

    #Privacy #secuity

  7. Lazy saturday means: more responsible disclosures. The process is now streamlined on my side: a table with bucketnames, status (usually open...), date of first report, date fixed, content and examples is emailed to #aws #secuity

    Status at the moment: 26 Buckets reported, out of them are 25 are open. Those buckets contain jucy data as names, birthdays, passports, passwords, resumes, medical data, github token.

    It will be very interesting to see the average time to close a bucket for #aws. With n=1 it is 893 days. I hope the n will increase and the number will decrease.

  8. Syft v1.13.0 released 🎉

    Some "enriching" features and fixes in this one! 🥳

    github.com/anchore/syft/releas

  9. @_L1vY_ @falcennial Thanks for the #secuity heads-up about AI becoming turned on by default in #Zoom.

    There’s a lot of switches to turn Off to disable AI Companion. If Zoom keeps reminding me that it thinks it’s more than a video-calling tool I’ll not renew my subscription and use something free instead.

  10. Wow... #RockYou2024 is definitely gonna rock some houses in a pretty bad way. Still digging into it, but folks - please keep your head on a swivel and start to change passwords, NOW. Don't wait for results. Frequently changing passwords is good practice anyhow, so change everything as you're able as a practice and you'll be safer from the starting line. Make it a habit. #cybersec #technology #secuity

  11. Ross J. Anderson, britischer Professor für IT-Sicherheit, ist verstorben.
    RIP

    #secuity #sicherheit #Privacy

  12. Today i found that having #NordVPN installed on an OSX laptop caused perfectly valid SSL certs for HTTPS to not be trusted, when the app was not open. Open the app and it worked.
    Immediate uninstall, but WTF was going on there #secuity

  13. Your #VPN provider won't go to jail for you for 5 dollars

    @ivpn explains how competent service providers can avoid sharing sensitive information about users...

    Hint: It involves not collecting/storing that information in the first place. Unfortunately, most VPN providers are not worthy of trust.

    (IVPN is pretty great and highly recommended in the privacy community, though.)

    #privacy #secuity #opsec

    ivpn.net/blog/your-vpn-provide

  14. The Strategic Compass provides direction in the areas of security and defence.
    EU leaders:
    🧭 take stock of what has been achieved so far
    🧭 give guidance for further work
    More info ⬇️
    #EUCO #StrategicCompass #secuity #defence

    🐦🔗: n.respublicae.eu/EUCouncil/sta

  15. Top spy chief says ‘realistic possibility’ three foreign governments could attempt assassinations on Australian soil, warns ‘threat is real’ byteseu.com/1510642/ #$50bDefenceBoost #ASIO #auspol #Australia #AustralianPolitics #defence #FederalPolitics #FOREIGNAFFAIRS #NationalSecurity #secuity #SpyAgency #SpyBoss

  16. While I dont like the Idea of big corporate social media and tech. If you have it make it as secure as you can.

    An easy but often overlooked privacy check: review the third-party apps connected to your accounts.

    Old or unused apps can still access your data. It's a good habit to audit and remove anything you no longer use or trust.

    Start here:

    Google: myaccount.google.com/permissio
    Facebook: facebook.com/settings?tab=appl
    Microsoft: account.live.com/consent/Manag
    Apple: appleid.apple.com/

    Stay sharp. Small steps make a big difference.

    #Privacy #secuity

  17. While I dont like the Idea of big corporate social media and tech. If you have it make it as secure as you can.

    An easy but often overlooked privacy check: review the third-party apps connected to your accounts.

    Old or unused apps can still access your data. It's a good habit to audit and remove anything you no longer use or trust.

    Start here:

    Google: myaccount.google.com/permissio
    Facebook: facebook.com/settings?tab=appl
    Microsoft: account.live.com/consent/Manag
    Apple: appleid.apple.com/

    Stay sharp. Small steps make a big difference.

    #Privacy #secuity

  18. While I dont like the Idea of big corporate social media and tech. If you have it make it as secure as you can.

    An easy but often overlooked privacy check: review the third-party apps connected to your accounts.

    Old or unused apps can still access your data. It's a good habit to audit and remove anything you no longer use or trust.

    Start here:

    Google: myaccount.google.com/permissio
    Facebook: facebook.com/settings?tab=appl
    Microsoft: account.live.com/consent/Manag
    Apple: appleid.apple.com/

    Stay sharp. Small steps make a big difference.

    #Privacy #secuity

  19. While I dont like the Idea of big corporate social media and tech. If you have it make it as secure as you can.

    An easy but often overlooked privacy check: review the third-party apps connected to your accounts.

    Old or unused apps can still access your data. It's a good habit to audit and remove anything you no longer use or trust.

    Start here:

    Google: myaccount.google.com/permissio
    Facebook: facebook.com/settings?tab=appl
    Microsoft: account.live.com/consent/Manage
    Apple: appleid.apple.com/

    Stay sharp. Small steps make a big difference.

  20. Lazy saturday means: more responsible disclosures. The process is now streamlined on my side: a table with bucketnames, status (usually open...), date of first report, date fixed, content and examples is emailed to #aws #secuity

    Status at the moment: 26 Buckets reported, out of them are 25 are open. Those buckets contain jucy data as names, birthdays, passports, passwords, resumes, medical data, github token.

    It will be very interesting to see the average time to close a bucket for #aws. With n=1 it is 893 days. I hope the n will increase and the number will decrease.

  21. Lazy saturday means: more responsible disclosures. The process is now streamlined on my side: a table with bucketnames, status (usually open...), date of first report, date fixed, content and examples is emailed to #aws #secuity

    Status at the moment: 26 Buckets reported, out of them are 25 are open. Those buckets contain jucy data as names, birthdays, passports, passwords, resumes, medical data, github token.

    It will be very interesting to see the average time to close a bucket for #aws. With n=1 it is 893 days. I hope the n will increase and the number will decrease.

  22. Lazy saturday means: more responsible disclosures. The process is now streamlined on my side: a table with bucketnames, status (usually open...), date of first report, date fixed, content and examples is emailed to #aws #secuity

    Status at the moment: 26 Buckets reported, out of them are 25 are open. Those buckets contain jucy data as names, birthdays, passports, passwords, resumes, medical data, github token.

    It will be very interesting to see the average time to close a bucket for #aws. With n=1 it is 893 days. I hope the n will increase and the number will decrease.

  23. Lazy saturday means: more responsible disclosures. The process is now streamlined on my side: a table with bucketnames, status (usually open...), date of first report, date fixed, content and examples is emailed to #aws #secuity

    Status at the moment: 26 Buckets reported, out of them are 25 are open. Those buckets contain jucy data as names, birthdays, passports, passwords, resumes, medical data, github token.

    It will be very interesting to see the average time to close a bucket for #aws. With n=1 it is 893 days. I hope the n will increase and the number will decrease.

  24. Syft v1.13.0 released 🎉

    Some "enriching" features and fixes in this one! 🥳

    github.com/anchore/syft/releas
    #sbom #secuity

  25. Syft v1.13.0 released 🎉

    Some "enriching" features and fixes in this one! 🥳

    github.com/anchore/syft/releas
    #sbom #secuity

  26. Syft v1.13.0 released 🎉

    Some "enriching" features and fixes in this one! 🥳

    github.com/anchore/syft/releas
    #sbom #secuity

  27. @_L1vY_ @falcennial Thanks for the #secuity heads-up about AI becoming turned on by default in #Zoom.

    There’s a lot of switches to turn Off to disable AI Companion. If Zoom keeps reminding me that it thinks it’s more than a video-calling tool I’ll not renew my subscription and use something free instead.

  28. @_L1vY_ @falcennial Thanks for the #secuity heads-up about AI becoming turned on by default in #Zoom.

    There’s a lot of switches to turn Off to disable AI Companion. If Zoom keeps reminding me that it thinks it’s more than a video-calling tool I’ll not renew my subscription and use something free instead.

  29. @_L1vY_ @falcennial Thanks for the #secuity heads-up about AI becoming turned on by default in #Zoom.

    There’s a lot of switches to turn Off to disable AI Companion. If Zoom keeps reminding me that it thinks it’s more than a video-calling tool I’ll not renew my subscription and use something free instead.

  30. @_L1vY_ @falcennial Thanks for the #secuity heads-up about AI becoming turned on by default in #Zoom.

    There’s a lot of switches to turn Off to disable AI Companion. If Zoom keeps reminding me that it thinks it’s more than a video-calling tool I’ll not renew my subscription and use something free instead.

  31. Wow... #RockYou2024 is definitely gonna rock some houses in a pretty bad way. Still digging into it, but folks - please keep your head on a swivel and start to change passwords, NOW. Don't wait for results. Frequently changing passwords is good practice anyhow, so change everything as you're able as a practice and you'll be safer from the starting line. Make it a habit. #cybersec #technology #secuity

  32. Wow... #RockYou2024 is definitely gonna rock some houses in a pretty bad way. Still digging into it, but folks - please keep your head on a swivel and start to change passwords, NOW. Don't wait for results. Frequently changing passwords is good practice anyhow, so change everything as you're able as a practice and you'll be safer from the starting line. Make it a habit. #cybersec #technology #secuity

  33. Wow... #RockYou2024 is definitely gonna rock some houses in a pretty bad way. Still digging into it, but folks - please keep your head on a swivel and start to change passwords, NOW. Don't wait for results. Frequently changing passwords is good practice anyhow, so change everything as you're able as a practice and you'll be safer from the starting line. Make it a habit. #cybersec #technology #secuity

  34. Wow... #RockYou2024 is definitely gonna rock some houses in a pretty bad way. Still digging into it, but folks - please keep your head on a swivel and start to change passwords, NOW. Don't wait for results. Frequently changing passwords is good practice anyhow, so change everything as you're able as a practice and you'll be safer from the starting line. Make it a habit. #cybersec #technology #secuity