home.social

#securiy — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securiy, aggregated by home.social.

fetched live
  1. heise.de/news/Phishing-Banken-

    Na, wer von euch traut sich gewinnspiel-sparkasse.de ohne Bauchschmerzen aufzurufen? Fazit: die #Sparkasse geht bei sicheren Domains mit eher schlechtem Beispiel voran.

    #phishing #securiy #banking

    #gefundenVonLukas

  2. heise.de/news/Phishing-Banken-

    Na, wer von euch traut sich gewinnspiel-sparkasse.de ohne Bauchschmerzen aufzurufen? Fazit: die #Sparkasse geht bei sicheren Domains mit eher schlechtem Beispiel voran.

    #phishing #securiy #banking

    #gefundenVonLukas

  3. Spent yesterday at #UofM to discuss Next Gen Workforce in Cyber Security with a focus on healthcare. Got to see a ton of interesting work that is going on at the college and meet a bunch of cool people.

    Got to speak about #memsec and @biohacking_village.

    #CyberSec #securiy #nextgen #healthCare

  4. Spent yesterday at to discuss Next Gen Workforce in Cyber Security with a focus on healthcare. Got to see a ton of interesting work that is going on at the college and meet a bunch of cool people.

    Got to speak about and @biohacking_village.

  5. Strange question and I “think” the answer is NO, but I’m looking for #fediverse wisdom. Is there a way to generate a valid #SSL certificate (not self signed, and no private CA) for a device running on the .local domain. It would need to recognised by any browser trying to connect to it without having to “accept the risk”. It’s also probably not a job for let’s encrypt because it would be great if this worked out of the box with zero config by a user after setting up. #linux #opensource #securiy

  6. Strange question and I “think” the answer is NO, but I’m looking for #fediverse wisdom. Is there a way to generate a valid #SSL certificate (not self signed, and no private CA) for a device running on the .local domain. It would need to recognised by any browser trying to connect to it without having to “accept the risk”. It’s also probably not a job for let’s encrypt because it would be great if this worked out of the box with zero config by a user after setting up. #linux #opensource #securiy

  7. Maybe i need to post this agaian that everyone does understand me

    I AM NOT AGAINST "SIGNAL" MESSENGER

    I am just calling their demand of an phone number for registration to be the antithesis of an anonyous secure messenger

    In the second when Signal allows anonymous registrations without a phone nuber, im right to join there

    #SignalMessenger #Securiy #Anonymousity #BoostsWelcome

  8. Maybe i need to post this agaian that everyone does understand me

    I AM NOT AGAINST "SIGNAL" MESSENGER

    I am just calling their demand of an phone number for registration to be the antithesis of an anonyous secure messenger

    In the second when Signal allows anonymous registrations without a phone nuber, im right to join there

    #SignalMessenger #Securiy #Anonymousity #BoostsWelcome

  9. Another day, another attack to software dependencies:

    arstechnica.com/security/2024/

    This is different from the xz story, but the core idea is the same: take ownership of a popular project, and sneakily replace it with malicious code.

    #securiy #supplychain #polyfill

  10. Derzeit ist wieder ein #USB Wurm im Umlauf diesmal mit dem Namen #LitterDrifter. Ich finde es spannend das dies immer noch ein Ausbreitungsvector ist und Sinn macht der eigentlich nur noch für #OT Systeme wie Kraftwerke da diese hoffentlich meist gut von anderen Netzen getrennt sind. Vielleicht unterschätze ich aber auch die Nutzung von USB im privaten Bereich 🤷 - via Bruce Schneier - schneier.com/blog/archives/202 #securiy #trojaner #malware

  11. ‘Scam-in-a-box’: #MyGov suspends thousands of accounts linked to dark web fraud kits | Australia news | The Guardian

    theguardian.com/australia-news

    > Exclusive: #Scams utilise phishing attacks on #Centrelink, #ATO and #Medicare accounts using obtained login details

    #securiy #Australia #cyber

  12. ‘Scam-in-a-box’: #MyGov suspends thousands of accounts linked to dark web fraud kits | Australia news | The Guardian

    theguardian.com/australia-news

    > Exclusive: #Scams utilise phishing attacks on #Centrelink, #ATO and #Medicare accounts using obtained login details

    #securiy #Australia #cyber

  13. So I’m replacing my Nest Secure with Abode iota. This is how sensitive the motion detection is. This is video recorded from a false alarm triggered by motion.

    I’m going to miss my Nest Secure :(

    #abode #securiy #nest

  14. "“At a high level, if nobody can point to a real-world example of it actually happening in public spaces, then it’s not something that is worth stressing about for the general public,” "

    Those scary warnings of juice jacking in airports and hotels? They’re mostly nonsense arstechnica.com/information-te
    >Juice jacking attacks on mobile phones are nonexistent. So why are we so afraid?

    #securiy #tech #cyber

  15. "“At a high level, if nobody can point to a real-world example of it actually happening in public spaces, then it’s not something that is worth stressing about for the general public,” "

    Those scary warnings of juice jacking in airports and hotels? They’re mostly nonsense arstechnica.com/information-te
    >Juice jacking attacks on mobile phones are nonexistent. So why are we so afraid?

    #securiy #tech #cyber

  16. @heisec wie wäre es mit einer Einordnung? Oder auch mit der Erwähnung, das bereits endsprechende Tools seit langer Zeit aus dem opensource Bereich gibt?

    Stimmt, das klickt ja nicht... und jemanden fragen der sich damit auskennt, zum Beispiel aus dem QS-bereich ist wahrscheinlich auch zu viel.

    #securiy #TLS #Verschlüsselung #Test

  17. @heisec wie wäre es mit einer Einordnung? Oder auch mit der Erwähnung, das bereits endsprechende Tools seit langer Zeit aus dem opensource Bereich gibt?

    Stimmt, das klickt ja nicht... und jemanden fragen der sich damit auskennt, zum Beispiel aus dem QS-bereich ist wahrscheinlich auch zu viel.

    #securiy #TLS #Verschlüsselung #Test

  18. Morning on the first day of #DevOpsTalks #Sydney, and it's clear it should be renamed #DevSecOps talks :)

    The main focus of everyone seems to be on #securiy, which is a good surprise and a relief. Getting more people interested and pushing good security practices in #development is bound to make everyone's life easier.

  19. Morning on the first day of #DevOpsTalks #Sydney, and it's clear it should be renamed #DevSecOps talks :)

    The main focus of everyone seems to be on #securiy, which is a good surprise and a relief. Getting more people interested and pushing good security practices in #development is bound to make everyone's life easier.

  20. Gestern ist Episode 104 online gegangen.
    Dieses Mal hat sich Sven aufgrund mehrerer Empfehlungen das tool winget angesehen und erzählt mir was das ist.
    Wie immer gibt es auch viel am Rande zu News, Datenverlusten, Hausmeister-Info und am Schluss noch ein wenig spaß.

    0x0d.de/2023/03/0d104-mehr-sic

    #zeroday #podcat #securiy #datenschutz #windows #Winget #paketmanager #datenverlust #news #informationssicherheit #dsgvo

  21. #securiy
    Cosa è successo, tra gli altri, ai siti di Atac, al Ministero dei Trasporti e aeroporto di Bologna go.squidapp.co/n/icxFPns

  22. #ClamAV being used in a lot of architectures, it's time to patch!

    #securiy #CyberSec

    Cisco warns of critical flaw in ClamAV antivirus • The Register
    theregister.com/2023/02/17/cis

  23. #ClamAV being used in a lot of architectures, it's time to patch!

    #securiy #CyberSec

    Cisco warns of critical flaw in ClamAV antivirus • The Register
    theregister.com/2023/02/17/cis

  24. Calling all #pentest, #redteam, and #bugbounty professionals in #bengaluru, #india. I'll soon be #hiring an experienced technical lead for my #attacksurface operations team at @zerofox. The person selected for the role will report to me and manage the day-to-day tasking of that team. Also, this person could eventually be promoted to my #research team. Please contact me if you're interested in discussing the opportunity and you're not a recruiter.

    #osint #recon #reconnaissance #securiy #infosec #golang #attacksurfacemgmt #automation #scalability #cloudinfrastructure #hiringnow #talentacquisition

  25. Calling all #pentest, #redteam, and #bugbounty professionals in #bengaluru, #india. I'll soon be #hiring an experienced technical lead for my #attacksurface operations team at @zerofox. The person selected for the role will report to me and manage the day-to-day tasking of that team. Also, this person could eventually be promoted to my #research team. Please contact me if you're interested in discussing the opportunity and you're not a recruiter.

    #osint #recon #reconnaissance #securiy #infosec #golang #attacksurfacemgmt #automation #scalability #cloudinfrastructure #hiringnow #talentacquisition

  26. #introduction Hi 👋 my name is Tim and I work as a #infosec professional. Done classical consultancy as #pentester and now doing #securiy research and #pentesting internally for #IoT devices.

  27. #introduction Hi 👋 my name is Tim and I work as a #infosec professional. Done classical consultancy as #pentester and now doing #securiy research and #pentesting internally for #IoT devices.

  28. @nielsa hi there. Feel free to loop me in on #cryptography or #securiy or #infosec discussions. I was a C/Unix software dev for 20+ years and had moved over to the security space. #ttrpgs , #scifi or #philosophy all good topics too. Let me know if you find that tribe you are looking for, and I'll likely follow along. Cheers.

  29. ExpressVPN was not my FIRST choice to begin with, but they were top ten for me. Now they have been acquired by a company with an unscrupulous history.

    reviewgeek.com/97650/expressvp

    #VPN #Privacy #Securiy #ExpressVPN

  30. I've spent almost one hour syncing my mobile and my tablet with my multi-factor authentication credentials on all my online services. In case I lose my mobile I will not be locked out on those (important) online services and I'll be able to change the codes in case of it's stolen.

    Not having two mfa devices was a stupid mistake.

    #2fa #mfa #securiy