Salta al contenuto principale

Lorenzo ha ricondiviso questo.


Happy one-week anniversary, CrowdStrike customers!

reshared this


Friendica Support ha ricondiviso questo.


!Friendica Support I take this opportunity to point out this guide to Friendica in Italian (but with an automatic translator you can understand everything). It doesn't seem to me that so far there have been produced guides to Friendica that are so easy and so conversational

https://www.informapirata.it/2024/07/25/w-la-friendica-che-dio-la-benedendica-la-guida-al-facebook-del-fediverso/


La guida di Informapirata a Friendica, dedicata a tutti coloro che dal Fediverso vogliono ottenere tutto il possibile.

Un Mastodon con gli steroidi e attualmente l’unica alternativa a Facebook di tutto il Fediverso. Con mille pregi e, soprattutto, mille difetti. E mai nessuno che ci spieghi come utilizzarlo.
Almeno finora…

https://www.informapirata.it/2024/07/25/w-la-friendica-che-dio-la-benedendica-la-guida-al-facebook-del-fediverso/



Lorenzo ha ricondiviso questo.


La guida di Informapirata a Friendica, dedicata a tutti coloro che dal Fediverso vogliono ottenere tutto il possibile.

Un Mastodon con gli steroidi e attualmente l’unica alternativa a Facebook di tutto il Fediverso. Con mille pregi e, soprattutto, mille difetti. E mai nessuno che ci spieghi come utilizzarlo.
Almeno finora…

https://www.informapirata.it/2024/07/25/w-la-friendica-che-dio-la-benedendica-la-guida-al-facebook-del-fediverso/

in reply to ❄️ freezr ❄️

io mi trovo abbastanza bene sia con Tusky sia con Fedilab, Ma l'esperienza migliore continua ad avercela come browser dello smartphone, che preferisco addirittura al browser desktop A meno che non si tratti di scrivere post complessi.

Il fatto è che utilizzando Friendica da un'app mastodon, ti perdi tutte le caratteristiche che rendono Friendica diverso da mastodon. A quel punto conviene utilizzare direttamente Mastodon...

@informapirata@poliverso.org @macfranc @notizie



Lorenzo ha ricondiviso questo.


Newsletter: https://news.risky.biz/risky-biz-news-new-dns-attack-impacts-a-quarter-of-all-open-dns-resolvers/
Podcast: https://risky.biz/RBNEWS313/

-New DNS attack impacts a quarter of all open DNS resolvers
-EU MP targeted with Candiru spyware;
-Meta suspends Nigerian scammer accounts;
-US charges Andariel member for ransomware attacks
-Israel govt covers NSO in lawsuit
-Tech giants go against NSO in another lawsuit
-CrowdStrike losses to reach $15 billion
-China+Russia use CrowdStrike outgage for propaganda
-Russia admits slowing down YouTube
-ServiceNow exploitation

reshared this

in reply to Catalin Cimpanu

Plus:

-Leidos, big US govt IT contractor, gets hacked
-Z-Library copycat leaks user data
-India's BSNL has a breach
-Spytech spyware vendor gets hacked, data leaked
-MonoSwap crypto platform gets hacked
-CrowdStrike blames outage on content validator bug
-A buggy Windows Update is sending systems to BitLocker recovery boots
-Proton launches crypto-wallet
-Chrome 127 is out with cookie protection
-Chrome also adds warning for password-protected archives
-Switzerland govt goes FOSS

Questa voce è stata modificata (16 ore fa)

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

And:

-French authorities take down PlugX botnet, disinfect victims
-New Cronus ransomware
-EvolvedAim Tarkov cheat delivers malware
-Stargazer Goblin group spams GitHub via 3K accounts
-BlackMeta hacktivist group is Anonymous Sudan alternative persona
-Malware reports on SocGolsih, BruteRatel, Flame Stealer
-NVIDIA+Telerik release sec fixes
-Docker AuthZ auth bypass goes unpatched 6 years
-New CFOR vulnerability class
-ConfusedFunction vulnerability in GCP
-Pwnie Awards 2024 nominations are out

Catalin Cimpanu reshared this.

in reply to Catalin Cimpanu

I don't mean to be That Guy but am pretty sure you don't mean LockBit

Lorenzo ha ricondiviso questo.


"Recently, two ex-spy chiefs from the German foreign intelligence agency (BND) rang the alarm in a prominent German news outlet. They argued that the German intelligence community was being reduced to ‘toothless watchdogs’ because of ‘an excess of oversight’ and that ‘policies and courts must no longer denigrate intelligence services as a threat to the rights of German citizens’."

https://bindinghook.com/articles-binding-edge/can-lawyers-lose-wars-by-stifling-cyber-capabilities/

reshared this

in reply to Catalin Cimpanu

from the country that literally created the Gestapo...
in reply to Matt Palmer

@womble what does something from 80 years ago have to do with this?

because at any point some country somewhere did something extremely horrible

in reply to Catalin Cimpanu

the Gestapo was a demonstration of what happens when a governmental agency operates without effective oversight from the people. Now members of a governmental agency are complaining about oversight. Gets my spidey sense tingling.
in reply to Matt Palmer

@womble they have a very valid point... there's more bureaucracy than spying in western countries

you literally have Russian FSB agents traveling to their countries to bribe politicians, and getting caught on camera by amateurs while intel agencies are too busy doing paperwork

in reply to Catalin Cimpanu

Avviso contenuto: depol, BND

Questa voce è stata modificata (21 ore fa)

in reply to Catalin Cimpanu

Reward comes as both CISA and Google/Mandiant have published reports on the group (Andariel=APT45) today:

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a

https://cloud.google.com/blog/topics/threat-intelligence/apt45-north-korea-digital-military-machine

Don't see any sanctions or DOJ indictment yet.

Questa voce è stata modificata (1 giorno fa)
in reply to Catalin Cimpanu

did you see my other toots with pings? Microsoft stated "On July 25, 2024, the United States Department of Justice (DOJ) indicted an individual linked to the North Korean threat actor that Microsoft tracks as Onyx Sleet." so the indictment is imminent for publishing on US DOJ.
in reply to Not Simon 🐐

@screaminggoat no, not really... it's been a busy day... barely looked at social media

Lorenzo ha ricondiviso questo.


French authorities take down PlugX botnet

https://www.linkedin.com/posts/parquet-de-paris_communiqu%C3%A9-de-presse-plugx-activity-7222119504518987778-LRCi/

reshared this


Lorenzo ha ricondiviso questo.


EvolvedAim, a cheat tool for Escape from Tarkov, was caught installing malware on its users' devices.

Final payload was an infostealer. Estimated number of victims is around 1K.

https://www.cyberark.com/resources/threat-research-blog/double-dipping-cheat-developer-gets-caught-red-handed

reshared this



The hybrid multicloud strategies that many Australian enterprises have adopted over the last decade could be made more complex by new AI applications. The only solutions could be rationalisation or an abstraction layer.#abstractionlayer #ai #aiapplications #apisecurity #applicationsecurity #artificialintelligence #hybridmulticloudstrategy



Discover whether NordVPN’s better speeds and extra features are worth the cost, or if you’ll be satisfied with PIA VPN’s more affordable pricing.#VPN
#VPN


Unmanned aircraft systems, more commonly known as drones, have quite literally taken off by performing many new and inventive commercial applications. Delivering packages, recording terrain, reporting news, documenting wildlife and even providing internet access are just a few of the functions drones can offer. The list is sure to grow longer and more diverse as ...


Legacy security measures, while offering a baseline level of protection, heavily rely on predefined signatures and a narrow definition of the “abnormal.” They often follow a reactive approach, can be siloed, limiting information sharing, and lack the scalability to handle the terabytes of data generated by today’s complex IT systems. This is where artificial intelligence ...

Lorenzo ha ricondiviso questo.


Newsletter: https://news.risky.biz/risky-biz-news-new-russian-ics-malware-cuts-heat-to-600-ukrainian-apartment-buildings/
Podcast: https://risky.biz/RBNEWS312/

-New Russian ICS malware cuts heat to 600 Ukrainian apartment buildings
-Telegram fixes zero-day
-Ofcom to look at telco Global Titles
-FCC to investigate "surveillance pricing"
-Google will not deprecate third-party cookies after all
-Russia to punish phone use on the frontlines
-Pentagon hacker case dropped in Kuwait
-UK takes down DigitalStress DDoS service
-Dutch malware coder sentenced, caught using IMSI catcher

in reply to Catalin Cimpanu

Plus:

-New Vigorish Viper group
-KnowBe4 hired a fake DPRK IT worker
-LA court reeling from ransomware attack
-Israeli newspaper Globes reports massive cyberattack
-Red Art Games got hacked
-CrowdStrike says it developed new recovery technique
-Oracle reaches $115mil privacy lawsuit settlement
-7777-Botnet linked to BEC gang
-Indian company behind Fake-DMCA-takedowns-as-a-service
-APT28 behind Rejetto server attacks
-Wiz leaves Google deal
-Google open-sources Altitude
-BIND security updates

Catalin Cimpanu reshared this.



Australia is among the APAC governments forging closer ties with the private sector due to the realisation that the public sector can no longer fight the increase in cyber criminals alone.#apaccybersecurity #australiacybersecurity #cybersecurity #nationalcybersecurity #philippinescybersecurity #ppps #publicprivatepartnerships #ransomware


Bitwarden’s affordability and extensive MFA options give it the slight edge over Dashlane’s uber-polished password management experience. Read more below.#passwordmanager



Developing and implementing both preventive security protocols and effective response plans is complicated and requires a security architect with a clear vision. This customizable hiring kit, written by Mark W. Kaelin for TechRepublic Premium, provides a framework you can use to find the best candidate for your organization. The kit includes salary details, a job ...


Which VPN is better, Surfshark or CyberGhost? Compare these VPNs with our guide and find out which one is best for you.#VPN
#VPN

Lorenzo ha ricondiviso questo.


Newsletter: https://news.risky.biz/risky-biz-news-crowdstrike-faulty-update-affects-8-5-million-windows-systems/
Podcast: https://risky.biz/RBNEWS311/

-CrowdStrike faulty update affects 8.5 million Windows systems
-US sanctions two Russian hacktivists (Cyber Army of Russia Reborn)
-Spain detains three NoNam057 members
-MGM hacking suspect detained in the UK
-Two LockBit members plead guilty
-FleepBot hacked to post propaganda on Ukrainian channels
-a16z has a data leak
-Rho Markets hacked for $7.6mil
-Nigeria fines Meta a massive $220mil
-Apache to change its logo

reshared this

in reply to Catalin Cimpanu

interesting, only 8.5 million? Either someone is fudging the numbers or we're more screwed than we thought. Because only a small part of that number will be truly critical systems.

Lorenzo ha ricondiviso questo.


Mandiant's Dan Kelly has published a Twitter post about how one member of a Chinese APT hacked dozens of MMORPG gaming companies.

Kelly says the individual appears to have been running a secret game cheating service that used his access to the gaming company's database to increase in-game currency for users—some of which were Twitch and YouTube streamers.

https://x.com/int0x00/status/1813937234640617964

reshared this


Lorenzo ha ricondiviso questo.


I wonder how many customers CrowdStrike is gonna lose. Cause I'm already seeing a few people saying they're removing it for good

reshared this

in reply to Allan Chow

@grumpasaurus @Sempf depends on the number of insurance claims and lawsuits that will be initiated. People missed meetings, appointments, opportunities & travel arrangements and that can get very expensive, very quickly.

Lorenzo ha ricondiviso questo.


What MSM is focusing on after the CrowdStrike outage:

Automatic updates are bad!

...le sigh! :jennpls: :pensive_party_blob:

reshared this



Lorenzo ha ricondiviso questo.


The CrowdStrike outage is also impacting the Mercedes F1 team they're sponsoring... who are in the middle of the Hungarian GP right now :KEKW:

https://www.youtube.com/watch?v=qm735NyExZQ

reshared this


Lorenzo ha ricondiviso questo.


Newsletter: https://news.risky.biz/risky-biz-news-trickbot-dev-arrested-in-moscow/
Podcast: https://risky.biz/RBNEWS310/

-Trickbot dev arrested in Moscow
-Indian crypto exchange hacked for $235mil
-Judge dismisses most of SolarWinds SEC lawsuit
-UK wants mandatory ransomware reporting
-new Port Shadow attack on VPNs
-Fractal ID breach impacts cryptoland
-300+ fraud suspects detained
-AstroStress admin sentenced to 9 months
-2 hackers arrested for hacking... and torturing a third one for his money
-PyPI malware linked to Iraqi crew

reshared this

in reply to Catalin Cimpanu

Plus:

-SocGolish BOINC campaign
-New R0BL0CH0N TDS
-Cloudflare WARP abuse
-FIN7 behind AvNeutralizer tool
-Doppelganger infrastructure taken down
-APT reports on Kimsuky, Patchwork, UAC-0180, Ghost Emperor, APT17, APT41
-Security updates from Oracle, Cisco, Ivanti, Atlassian, Sonicwall
-Two Cisco bugs are just... something else
-SAPwned vulnerability impacts AI systems
-Traffic lights vulnerabilities
-Pwn2Own Toronto moves to Cork, Ireland
-x33fcon and BlueHat IL videos

Catalin Cimpanu reshared this.


Lorenzo ha ricondiviso questo.


wtf Crowdstrike... my gym ID scanner is down... get your s**t together

reshared this


Lorenzo ha ricondiviso questo.


Two Foreign Nationals Plead Guilty to Participation in LockBit Ransomware Group

-Ruslan Magomedovich Astamirov (АСТАМИРОВ, Руслан Магомедовичь), 21, a Russian national of Chechen Republic, Russia
-Mikhail Vasiliev, 34, a dual Canadian and Russian national of Bradford, Ontario

https://www.justice.gov/usao-nj/pr/two-foreign-nationals-plead-guilty-participation-lockbit-ransomware-group

reshared this


Lorenzo ha ricondiviso questo.


La Consulta non elimina il requisito del “trattamento di sostegno vitale” per essere aiutati a morire, ma fa passi avanti, nonostante le richieste del Governo. Siamo pronti ad affrontare i nuovi processi e disobbedienze civili.

https://www.associazionelucacoscioni.it/notizie/comunicati/fine-vita-la-corte-costituzionale-ha-depositato-la-sentenza


in reply to Catalin Cimpanu

paywall on the intelligenceonline.com article. Do you have a list of what Chengdu 404 is hiring for?

Lorenzo ha ricondiviso questo.


Hackney ransomware attack initial access

RDP on the kiosk/kiosk account 🤦‍♂️

Source: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/07/london-borough-of-hackney-reprimanded-following-cyber-attack/

cc: @GossiTheDog

Questa voce è stata modificata (1 settimana fa)

reshared this

in reply to Catalin Cimpanu

“Hackney Council”
Questa voce è stata modificata (1 settimana fa)

Lorenzo ha ricondiviso questo.


"Over the last few years, our consumer-focused Pwn2Own event took place in the Trend Micro office in Toronto. However, that office closed, so we needed to find a new home. This isn’t unusual for this event, as it moved from Amsterdam to Tokyo to Austin to Toronto. We’re moving again. This year, we are heading to our offices in Cork, Ireland!"

https://www.zerodayinitiative.com/blog/2024/7/16/announcing-pwn2own-ireland-2024

reshared this


Lorenzo ha ricondiviso questo.


Orange CERT has discovered a previously known traffic-distribution system (TDS) used to redirect traffic from hacked sites to affiliate marketing scams.

Named R0BL0CH0N, Orange says the TDS has impacted more than 110 million Internet users.

https://www.orangecyberdefense.com/global/blog/cert-news/r0bl0ch0n-tds-a-deep-dive-into-the-infrastructure-of-an-affiliate-marketing-scam

reshared this

in reply to Catalin Cimpanu

Thanks for sharing! Just to clarify, I have never seen a network of compromised sites that redirect to this TDS. The first redirect step is handled by a dedicated infrastructure of the affiliate's choice.

However I already seen affiliates leveraging hacked websites and SEO poisoning to promote affiliate offers (on other network).


Lorenzo ha ricondiviso questo.


A new report claims that Google appears to have switched to a no-index default policy and is refusing to crawl new content unless it deems it necessary

https://www.vincentschmalbach.com/google-now-defaults-to-not-indexing-your-content/


Lorenzo ha ricondiviso questo.


The Ukrainian government says that a threat actor known as UAC-0180 has been targeted local defense enterprises with spear-phishing emails using the topic of UV purchases as lures

https://cip.gov.ua/en/news/kiberzlochinci-vikoristovuyut-tematiku-zakupivel-bpla-dlya-atak-na-oboronni-pidpriyemstva

reshared this

in reply to Catalin Cimpanu

I prefer CERT-UA's link: https://cert.gov.ua/article/6280099

This one contains IOC and a more detailed analysis of the infection chain.


Lorenzo ha ricondiviso questo.


Blockchain identity platform Fractal ID suffered a data breach on July 14.

The company says that a threat actor gained access to an employee account and ran an API script that collected personal data from customer accounts.

At least four crypto platforms (Gnosis Pay, Polygon, Ripple, and NEAR) have confirmed that their users were impacted.

PDF: https://app.fractal.id/documents/id/breach-notification.pdf

reshared this


Lorenzo ha ricondiviso questo.


Talks from the BlueHat IL 2024 security conference, which took place in May, are now available on YouTube

https://www.youtube.com/watch?v=KhdzIPPW4W0

reshared this


Lorenzo ha ricondiviso questo.


European hosting companies Hetzner and Hostinger suspended accounts linked to Russian disinformation group Doppelganger.

The web hosting accounts were exposed in a hoint report last week by Correctiv and the Qurium Foundation.

The suspension has impacted around 35% of the group's web hosting infrastructure.

https://correctiv.org/aktuelles/russland-ukraine-2/2024/07/18/nach-correctiv-recherche-russische-propaganda-kampagne-geraet-ins-stocken/

reshared this


Lorenzo ha ricondiviso questo.


Cado Security has discovered threat actors abusing Cloudflare's WARP service to launch scanning and reconnaisance attacks.

Cado says the attacks are leveraging a common misconfiguration where system administrators are allowlisting all of Cloudflare's IP ranges instead of just those specific to a given service.

The company says it has observed crypto-mining and SSH brute-force groups use this technique to bypass Cloudflare security defenses.

https://www.cadosecurity.com/news-and-events/warpscan-cloudflare-warp-abused-to-hijack-cloud-services

reshared this