home.social

#securityfail — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityfail, aggregated by home.social.

fetched live
  1. 🚨 Oh no, Keyv and Co. were totally bamboozled in the npm supply chain attack! Apparently, their 'Advanced AppSec suite' didn't see this worm coming 🤔. Maybe AI-powered everything isn't as smart as they thought? 😂 #Oops #SecurityFail
    aikido.dev/blog/keyv-and-frien #npmSupplyChainAttack #AdvancedAppSec #AIpoweredSecurity #SecurityBreach #TechHumor #HackerNews #ngated

  2. 🚨 Oh no, Keyv and Co. were totally bamboozled in the npm supply chain attack! Apparently, their 'Advanced AppSec suite' didn't see this worm coming 🤔. Maybe AI-powered everything isn't as smart as they thought? 😂 #Oops #SecurityFail
    aikido.dev/blog/keyv-and-frien #npmSupplyChainAttack #AdvancedAppSec #AIpoweredSecurity #SecurityBreach #TechHumor #HackerNews #ngated

  3. Voici les contraintes de "sécurité" pour un code à 4 chiffres (déjà de base plutôt basique à bruteforcer même à la main.)

    Le nombre de cas que cela retire des combinaisons possibles est absurdement élevé. #SecurityFail

  4. Voici les contraintes de "sécurité" pour un code à 4 chiffres (déjà de base plutôt basique à bruteforcer même à la main.)

    Le nombre de cas que cela retire des combinaisons possibles est absurdement élevé. #SecurityFail

  5. 🚨 Breaking News, folks: Mullvad, the revolutionary VPN that's only 20,000 servers short of being average, has discovered that using the same IP over and over might actually identify you. 🔎 Because nothing screams privacy like a "deterministically picked" IP. 😂 #PrivacyOops
    tmctmt.com/posts/mullvad-exit- #MullvadVPN #PrivacyNews #IPAddress #SecurityFail #HackerNews #ngated

  6. 🚨 Breaking News, folks: Mullvad, the revolutionary VPN that's only 20,000 servers short of being average, has discovered that using the same IP over and over might actually identify you. 🔎 Because nothing screams privacy like a "deterministically picked" IP. 😂 #PrivacyOops
    tmctmt.com/posts/mullvad-exit- #MullvadVPN #PrivacyNews #IPAddress #SecurityFail #HackerNews #ngated

  7. Oh, bravo Microsoft! 🤦‍♂️ Who needs #cybersecurity when you can just store all your #passwords in plain sight? 😂 Clearly, #Edge is redefining "security" as a feature for the past, while the rest of us are just living in 2023. 🔍🔓
    twitter.com/L1v1ng0ffTh3L4N/st #Microsoft #Laughs #SecurityFail #HackerNews #ngated

  8. Oh, bravo Microsoft! 🤦‍♂️ Who needs #cybersecurity when you can just store all your #passwords in plain sight? 😂 Clearly, #Edge is redefining "security" as a feature for the past, while the rest of us are just living in 2023. 🔍🔓
    twitter.com/L1v1ng0ffTh3L4N/st #Microsoft #Laughs #SecurityFail #HackerNews #ngated

  9. Tried logging into my Amazon account only for it to request the security code on a GIFT CARD FROM YEARS AGO
    #amazon #securityfail

  10. Whoa. Serious security breach alert 🚨. Claims are surfacing that Iranian hackers targeted the FBI Director’s Gmail – and potentially accessed classified info. Details are wild, linked to a naval destroyer. Check it out! #KashPatel #SecurityFail #Cybersecurity

    youtube.com/watch?v=DqBVvxS9-Tc

  11. 🔍 Oh, the thrilling saga of an article that wasn't! 😱 #ModSecurity flexes its muscles, proudly serving you... absolutely NOTHING. Bravo, internet! 👏🌐
    jsomers.net/blog/it-turns-out #InternetSaga #SecurityFail #TechNews #CyberSecurity #HackerNews #ngated

  12. 🔍 Oh, the thrilling saga of an article that wasn't! 😱 #ModSecurity flexes its muscles, proudly serving you... absolutely NOTHING. Bravo, internet! 👏🌐
    jsomers.net/blog/it-turns-out #InternetSaga #SecurityFail #TechNews #CyberSecurity #HackerNews #ngated

  13. Just received an email from my mail server administrator. They sent me a link to change my password because it's 'insecure'.

    My mail admin is so efficient...

    ...hey, wait a minute... I AM my mail administrator! 🤦‍♂️

    #Phishing #SelfHosting #SysAdminLife #SecurityFail #InfoSec

  14. Just received an email from my mail server administrator. They sent me a link to change my password because it's 'insecure'.

    My mail admin is so efficient...

    ...hey, wait a minute... I AM my mail administrator! 🤦‍♂️

    #Phishing #SelfHosting #SysAdminLife #SecurityFail #InfoSec

  15. Me: Tries to access my personal stuff on the work machine (which is allowed!).

    The laptop security: "I'm afraid I can't let you do that."

    Looks like the SSL inspector is feeling a bit overprotective today.

    #techfail #corporateit #tlsfail #funny #infosec #worklaptop #privacy #securityfail #humor #proton #fediverse

  16. Me: Tries to access my personal stuff on the work machine (which is allowed!).

    The laptop security: "I'm afraid I can't let you do that."

    Looks like the SSL inspector is feeling a bit overprotective today.

    #techfail #corporateit #tlsfail #funny #infosec #worklaptop #privacy #securityfail #humor #proton #fediverse

  17. 🚨 ALERT! 🚨 #NextJS finally achieved what we all thought impossible: a CVSS 10.0 vulnerability! 🎯 Bravo, they've hit the bullseye of FAIL! 🙈 It's always heartwarming when devs leave the #backdoor open for #hackers to make themselves at home. 🏠🔓
    nextjs.org/blog/CVE-2025-66478 #Vulnerability #CVSS10 #SecurityFail #HackerNews #ngated

  18. 🚨 ALERT! 🚨 #NextJS finally achieved what we all thought impossible: a CVSS 10.0 vulnerability! 🎯 Bravo, they've hit the bullseye of FAIL! 🙈 It's always heartwarming when devs leave the #backdoor open for #hackers to make themselves at home. 🏠🔓
    nextjs.org/blog/CVE-2025-66478 #Vulnerability #CVSS10 #SecurityFail #HackerNews #ngated

  19. This is a "fun" read.

    I've never really understood why sites like the ones covered in this article exist, since they cater to people who should be pretty comfortable with command-line linting/pretty-printing tools. But now I know that they survive (thrive on ad revenue, even!) because so many of their users are a few bits short of a byte.

    labs.watchtowr.com/stop-puttin

  20. This is a "fun" read.

    I've never really understood why sites like the ones covered in this article exist, since they cater to people who should be pretty comfortable with command-line linting/pretty-printing tools. But now I know that they survive (thrive on ad revenue, even!) because so many of their users are a few bits short of a byte.

    labs.watchtowr.com/stop-puttin

    #facepalmSec #cybersecurity #infosec #SecurityFail #WTFsec #facepalm

  21. I have never felt better about a bicycle being my primary form of transport.

    "What the fuck, Flock?"

    It's so much worse than you may've heard. The clown show is _spectacular_. It's a five-season arc in progress of only the most upper level, purest clownery.

    Here's a very high view on The WAN Show (jump to 3:12:09 if the time stamp start doesn't work):

    youtube.com/live/Vzgimftolys?t

    Here's the original source with much more details:

    youtube.com/watch?v=uB0gr7Fh6lY

    #Flock #FuckFlock #HolyShit #surveillance #fascism #SurveillanceSociety #incompetence #RubberDucky #SecurityFail #security #HilariousIncompetence #shenanigans #clowns #ClownShow #TempestAttack #EveryAttack #AuthenticationInPlainText #EverythingThatCanBeWrongIsWrong

  22. I have never felt better about a bicycle being my primary form of transport.

    "What the fuck, Flock?"

    It's so much worse than you may've heard. The clown show is _spectacular_. It's a five-season arc in progress of only the most upper level, purest clownery.

    Here's a very high view on The WAN Show (jump to 3:12:09 if the time stamp start doesn't work):

    youtube.com/live/Vzgimftolys?t

    Here's the original source with much more details:

    youtube.com/watch?v=uB0gr7Fh6lY

    #Flock #FuckFlock #HolyShit #surveillance #fascism #SurveillanceSociety #incompetence #RubberDucky #SecurityFail #security #HilariousIncompetence #shenanigans #clowns #ClownShow #TempestAttack #EveryAttack #AuthenticationInPlainText #EverythingThatCanBeWrongIsWrong

  23. Oh wow, the Louvre’s surveillance password was literally Louvre. Nothing says world class security like using the museum’s own name 😜
    Thieves: $102M in jewels, 7-minute heist, cherry picker exit
    Louvre: We couldn’t have foreseen this

    *My professional #cybersecurity tip: try password123 next upgrade

    #louvre #heist #securityfail #france #arttheft #itsecurity #itsec

    abcnews.go.com/International/p

  24. Oh wow, the Louvre’s surveillance password was literally Louvre. Nothing says world class security like using the museum’s own name 😜
    Thieves: $102M in jewels, 7-minute heist, cherry picker exit
    Louvre: We couldn’t have foreseen this

    *My professional #cybersecurity tip: try password123 next upgrade

    #louvre #heist #securityfail #france #arttheft #itsecurity #itsec

    abcnews.go.com/International/p

  25. 🍾🤡 #Bubblewrap, the high-tech innovation to #NetBSD, because who needs robust security when you can just pop your way to safety? 🎈✨ Welcome to the future of sandboxing: as strong as the packaging your last Amazon delivery came in. 🚀🛍️
    blog.netbsd.org/tnf/entry/gsoc #TechInnovation #Sandboxing #SecurityFail #FutureOfTech #HackerNews #ngated

  26. 🍾🤡 #Bubblewrap, the high-tech innovation to #NetBSD, because who needs robust security when you can just pop your way to safety? 🎈✨ Welcome to the future of sandboxing: as strong as the packaging your last Amazon delivery came in. 🚀🛍️
    blog.netbsd.org/tnf/entry/gsoc #TechInnovation #Sandboxing #SecurityFail #FutureOfTech #HackerNews #ngated

  27. Veria Labs has discovered that MCP's authentication is about as secure as a wet paper towel, leading to #RCE in Claude Code and Gemini CLI 🤦‍♂️💻. The article is a rollercoaster of jargon trying to sound important while basically saying, "Oops, we broke everything!" 🤷‍♀️🔧. Meanwhile, the rest of the industry is scrambling like headless chickens to patch this mess 🐔🔥.
    verialabs.com/blog/from-mcp-to #VeriaLabs #MCP #securityFail #patchingCrisis #techNews #HackerNews #ngated

  28. Veria Labs has discovered that MCP's authentication is about as secure as a wet paper towel, leading to #RCE in Claude Code and Gemini CLI 🤦‍♂️💻. The article is a rollercoaster of jargon trying to sound important while basically saying, "Oops, we broke everything!" 🤷‍♀️🔧. Meanwhile, the rest of the industry is scrambling like headless chickens to patch this mess 🐔🔥.
    verialabs.com/blog/from-mcp-to #VeriaLabs #MCP #securityFail #patchingCrisis #techNews #HackerNews #ngated

  29. Time to complain about MS Teams again. Locked me out of my account last week for "suspicious activity" which was a bug on their end which kept asking me to login. But still dutifully sends me email updates from Teams #SecurityFail

  30. Time to complain about MS Teams again. Locked me out of my account last week for "suspicious activity" which was a bug on their end which kept asking me to login. But still dutifully sends me email updates from Teams #SecurityFail

  31. 🧠🔒 So, an "elite" Air National Guard member thinks $250/month for plugging laptops into random networks is a steal? 🙄 Welcome to the world of 'legal botnets', where your top secret clearance means you can be legally clueless. 🔌💸 #SecurityFail
    krebsonsecurity.com/2025/08/ds #SecurityFail #LegalBotnets #AirNationalGuard #Cybersecurity #Cluelessness #TechNews #HackerNews #ngated

  32. 🧠🔒 So, an "elite" Air National Guard member thinks $250/month for plugging laptops into random networks is a steal? 🙄 Welcome to the world of 'legal botnets', where your top secret clearance means you can be legally clueless. 🔌💸 #SecurityFail
    krebsonsecurity.com/2025/08/ds #SecurityFail #LegalBotnets #AirNationalGuard #Cybersecurity #Cluelessness #TechNews #HackerNews #ngated

  33. Ah, the SSO Hall of Shame: where companies treat essential security like a preposterous premium add-on. 🎟️ Why bother with proper authentication when you can nickel and dime clients in the name of "luxury"? 🙄 Because who needs security when you have profits to make, right? 💸
    sso.tax/ #SSOHallOfShame #SecurityFail #AuthenticationIssues #CorporateGreed #UserSafety #HackerNews #ngated

  34. Ah, the SSO Hall of Shame: where companies treat essential security like a preposterous premium add-on. 🎟️ Why bother with proper authentication when you can nickel and dime clients in the name of "luxury"? 🙄 Because who needs security when you have profits to make, right? 💸
    sso.tax/ #SSOHallOfShame #SecurityFail #AuthenticationIssues #CorporateGreed #UserSafety #HackerNews #ngated

  35. #ebay needs to update their #GeoIP database.

    I've just logged on from an old computer in my house, and it's sent me an email saying someone has logged in from Shropshire, which is over 100miles away, when most sites think I am based in North London (which is still wrong, but my ISP is at least based there).

    No other site seems to ever think I'm in Shropshire.

    I wish companies would just list the IP address and browser details in their "a new device had logged in to you account" emails, any other details seem to be totally wrong, and therefore useless 🤬

    #SecurityFail #SecurityTheatre

  36. #ebay needs to update their #GeoIP database.

    I've just logged on from an old computer in my house, and it's sent me an email saying someone has logged in from Shropshire, which is over 100miles away, when most sites think I am based in North London (which is still wrong, but my ISP is at least based there).

    No other site seems to ever think I'm in Shropshire.

    I wish companies would just list the IP address and browser details in their "a new device had logged in to you account" emails, any other details seem to be totally wrong, and therefore useless 🤬

    #SecurityFail #SecurityTheatre

  37. 🔨🎉 BREAKING: BAE Systems achieves monumental success in #munitions production—unfortunately, they forgot to secure their website! 🚫📉 The only explosive development here is their web server crashing harder than their test dummies. 💥🙃
    baesystems.com/en/article/majo #BAESystems #SecurityFail #WebServerCrash #ExplosiveDevelopment #HackerNews #HackerNews #ngated

  38. 🔨🎉 BREAKING: BAE Systems achieves monumental success in #munitions production—unfortunately, they forgot to secure their website! 🚫📉 The only explosive development here is their web server crashing harder than their test dummies. 💥🙃
    baesystems.com/en/article/majo #BAESystems #SecurityFail #WebServerCrash #ExplosiveDevelopment #HackerNews #HackerNews #ngated

  39. 🚨 While Marco #Rubio oversees the rendition of innocent men to indefinite detention in foreign prisons, one of his top security personnel is arrested in Brussels for allegedly assaulting cops and hotel staff after demanding a drink after hours. 🍹🚫👮‍♂️

    The best people? 🤔 washingtonexaminer.com/news/33
    #MarcoRubio #PoliticalScandal #SecurityArrest #Brussels #PoliceAssault #PoliticalCorruption #Accountability #InnocentMen #ForeignPrisons #PoliticalHypocrisy #SecurityFail #PoliticalNews #BreakingNews #uspol

  40. 🚨 While Marco #Rubio oversees the rendition of innocent men to indefinite detention in foreign prisons, one of his top security personnel is arrested in Brussels for allegedly assaulting cops and hotel staff after demanding a drink after hours. 🍹🚫👮‍♂️

    The best people? 🤔 washingtonexaminer.com/news/33
    #MarcoRubio #PoliticalScandal #SecurityArrest #Brussels #PoliceAssault #PoliticalCorruption #Accountability #InnocentMen #ForeignPrisons #PoliticalHypocrisy #SecurityFail #PoliticalNews #BreakingNews #uspol

  41. This dumpster fire Phantasma Market leaked its clearnet IP on DAY ONE. Zero OpSec. Just handing themselves to feds on a silver platter. youtu.be/t3ebaBn4MVU #SecurityFail #DarknetFail #Honeypot

  42. 📬🚫 Oh, the irony! A tech wizard pens a magnum opus on automating mail alerts, only to have their masterpiece blocked by ModSecurity—because apparently, the server had higher standards than their script. 😆🔒
    taslim.xyz/blog/2025/sharing-m #techhumor #automation #irony #securityfail #serverissues #HackerNews #ngated

  43. 📬🚫 Oh, the irony! A tech wizard pens a magnum opus on automating mail alerts, only to have their masterpiece blocked by ModSecurity—because apparently, the server had higher standards than their script. 😆🔒
    taslim.xyz/blog/2025/sharing-m #techhumor #automation #irony #securityfail #serverissues #HackerNews #ngated

  44. Ah, yes, because nothing screams "security" like a government agency casually asking ex-employees to email their sensitive data. 🦊🔒 Trust us, we promise to keep your info as safe as a toddler with a Sharpie! 🤣📝
    krebsonsecurity.com/2025/03/do #securityfail #dataprivacy #governmenttrust #exemployees #humor #HackerNews #ngated

  45. This isn't Apple's fault, as it still has to follow local laws to sell its products. However, this is a huge #securityfail.

    Even though Apple no longer fights for mindshare in the enterprise computing market as it once did, this will force companies that require secure data to either avoid iCloud-enabled apps altogether—which can be hard to do on a Mac—or stop using Macs altogether for anything that processes #PII, #PHI, or even proprietary #sourcecode.

    In particular, many #softwaredevelopers prefer #MacBooks since they offer a mainstream user experience but run #Unix under the hood. If they can't use MacBooks anymore for security reasons, companies will have to rethink some of their long-standing laptop and desktop #cybersecurity practices.

    bbc.com/news/articles/cgj54eq4

  46. Ach. Bei #VW sind sie zu blöd, eine S3 Instanz anständig zu konfigurieren. 800k Datensätze zu Autos, frei abrufbar. 420k identifizierbar und mit Positionsdaten. Läuft bei uns. 🙄
    Zur Strafe 800k mal Artikel 32 der DSGVO abschreiben.
    #infosec #securityfail #datenschutz