https:// infosec.exchange/@SwiftOnSecur ity/117192274438003528

https:// infosec.exchange/@SwiftOnSecur ity/117192274438003528

280 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

RE: https:// infosec.exchange/@briankrebs/1 17198218728894705 @ briankrebs again does an excellent job pulling at threads to get to the source of a significant leak of 150+ million driver’s licence im

mastodon:infosec-exchangeother27d ago kagi ↗

RE: https:// infosec.exchange/@briankrebs/1 17198218728894705 @ briankrebs again does an excellent job pulling at threads to get to the source of a significant leak of 150+ million driver’s licence images. Do be extra careful of anyone who contacts you using your ID as proof they are from any authority.

RE: https:// infosec.exchange/@munin/117202 778496831473 the response they gave me is unacceptably corporate and responsibility disclaiming so I am rescinding any endorsement of 1Password, and recomme

mastodon:infosec-exchangeother27d ago kagi ↗

RE: https:// infosec.exchange/@munin/117202 778496831473 the response they gave me is unacceptably corporate and responsibility disclaiming so I am rescinding any endorsement of 1Password, and recommending that people use a different product. I'll figure out a specific endorsement when I have had time to research.

RE: https:// infosec.exchange/@munin/117208 068076907240 hey so if you have overlapping supply chains for your ops tools then you're gonna run into some really complex cold start situations if somethi

mastodon:infosec-exchangeother26d ago kagi ↗

RE: https:// infosec.exchange/@munin/117208 068076907240 hey so if you have overlapping supply chains for your ops tools then you're gonna run into some really complex cold start situations if something goes all the way down. just saying.

RE: https:// infosec.exchange/@mnordhoff/11 7209000236107461 "ICANN and Verisign want to delete over 20,000 domain names for no apparent reason" is the most scandalous thing in gTLD governance I've ev

mastodon:infosec-exchangeother25d ago kagi ↗

RE: https:// infosec.exchange/@mnordhoff/11 7209000236107461 "ICANN and Verisign want to delete over 20,000 domain names for no apparent reason" is the most scandalous thing in gTLD governance I've ever heard of, and there have been some notable scandals! It's just shocking. (There might be some other sorts of ICANN and ccTLD scandals that are equally large.)

RE: https:// infosec.exchange/@sophieschmie g/117209404424922824 Although I couldn't grok all the math, it was interesting to read the thought process for assessing the quality of security properties

mastodon:infosec-exchangeother25d ago kagi ↗

RE: https:// infosec.exchange/@sophieschmie g/117209404424922824 Although I couldn't grok all the math, it was interesting to read the thought process for assessing the quality of security properties in an environment where the boundaries of risk are circumscribed by the limits of our current knowledge (as opposed to my quotidian world where risks are rarely novel, but bite us anyway). I appreciat

RE: https:// infosec.exchange/@DaveFlater/1 17186938981756802 F24 entertains speculation as to how this might work, but in all likelihood, it's bullshit https://www. france24.com/en/middle-east/20 260

mastodon:infosec-exchangeother25d ago kagi ↗

RE: https:// infosec.exchange/@DaveFlater/1 17186938981756802 F24 entertains speculation as to how this might work, but in all likelihood, it's bullshit https://www. france24.com/en/middle-east/20 260903-has-iran-modified-its-rocket-systems-to-fire-mines-into-the-strait-of-hormuz

RE: https:// infosec.exchange/@BleepingComp uter/117212746087862696 microsoft customers are finally seeing the productivity increases they'd hoped for when going with exchange, as ongoing issues throt

mastodon:infosec-exchangeother25d ago kagi ↗

RE: https:// infosec.exchange/@BleepingComp uter/117212746087862696 microsoft customers are finally seeing the productivity increases they'd hoped for when going with exchange, as ongoing issues throttle down the volume of email customers receive.

RE: https:// infosec.exchange/@david_chisna ll/117223744031137592 > The most toxic thing to happen in the F/OSS world is the attitude that some people are so smart (because they’ve created successful

mastodon:hachydermother23d ago kagi ↗

RE: https:// infosec.exchange/@david_chisna ll/117223744031137592 > The most toxic thing to happen in the F/OSS world is the attitude that some people are so smart (because they’ve created successful projects) that you cannot criticise them. The idea that, because someone created something good, they are infallible is disastrous for them, the projects they run, and the broader ecosystem. This also

RE: https:// infosec.exchange/@adfichter/11 7222636753991664 Die Bude war übervoll.. zu meinem grossen Erstaunen. Trotz 27 Grad Sonnenschein und Sonntagmorgen. Aber diese Themen bewegen die Leute...KI

mastodon:infosec-exchangeother22d ago kagi ↗

RE: https:// infosec.exchange/@adfichter/11 7222636753991664 Die Bude war übervoll.. zu meinem grossen Erstaunen. Trotz 27 Grad Sonnenschein und Sonntagmorgen. Aber diese Themen bewegen die Leute...KI, Rechenzentren, Technikfaschismus, Big Tech Macht, Techpolitik...

RE: https:// infosec.exchange/@BadChemical/ 117230570208620865 My dad had a good Panasonic TV that he bought right before everything switched to "smart TVs". When he died a couple of years ago, I kept

mastodon:mstdn-socialother22d ago kagi ↗

RE: https:// infosec.exchange/@BadChemical/ 117230570208620865 My dad had a good Panasonic TV that he bought right before everything switched to "smart TVs". When he died a couple of years ago, I kept it & stuck it under a bed at my mom's because her older TV will die one day soon, & I don't want her dealing with all the privacy issues with the new TVs.

RE: https:// infosec.exchange/@rmceoin/1172 03653471985612 Re-upping this post as this is by far the best way to protect your users from malware using Etherhiding as its C2 channel. (Assumes you don’t

mastodon:infosec-exchangeother22d ago kagi ↗

RE: https:// infosec.exchange/@rmceoin/1172 03653471985612 Re-upping this post as this is by far the best way to protect your users from malware using Etherhiding as its C2 channel. (Assumes you don’t need access to the various block chains from your company’s computers) # cybersecurity

RE: https:// infosec.exchange/@prism/117232 411822241995 The ideas committee for the American printing house for the blind, a thing I have just now learned is real and exists, considered the idea of p

mastodon:infosec-exchangeother22d ago kagi ↗

RE: https:// infosec.exchange/@prism/117232 411822241995 The ideas committee for the American printing house for the blind, a thing I have just now learned is real and exists, considered the idea of printing a tactile map of their city, then--collectively--agreed not to. Great stuff, guys. Amazing.

RE: https:// infosec.exchange/@pwr2/1171944 29371489064 # Pwr2 # LiveWargame # Recommendation ⚔️ 👨‍💼 Communication: honest but restrained Recommendations to last week: - There is no long term benefi

mastodon:infosec-exchangeother21d ago kagi ↗

RE: https:// infosec.exchange/@pwr2/1171944 29371489064 # Pwr2 # LiveWargame # Recommendation ⚔️ 👨‍💼 Communication: honest but restrained Recommendations to last week: - There is no long term benefit to hide an incident. If it becomes public (beacuse attackers very very likely publish it), there will be lots of customer requests. Unfortunately, this is the preferred solution of many companies, s

RE: https:// infosec.exchange/@pwr2/1171944 29371489064 Thank you all, this was a really interesting poll! Not a single participant on Mastodon (expected) or LinkedIn (surprising!) wanted to hide the

mastodon:infosec-exchangeother21d ago kagi ↗

RE: https:// infosec.exchange/@pwr2/1171944 29371489064 Thank you all, this was a really interesting poll! Not a single participant on Mastodon (expected) or LinkedIn (surprising!) wanted to hide the incident. Although in my experience, that is exactly what most companies do. Very common is the "outage unclear, investigation pending" answer. In my best cyber security case (communication-wise), the

RE: https:// infosec.exchange/@krypt3ia/117 235042486070464 "'...violates federal law because it’s not peer-reviewed, and it’s essentially quite an influential dissemination of information,' which cou

mastodon:infosec-exchangeother21d ago kagi ↗

RE: https:// infosec.exchange/@krypt3ia/117 235042486070464 "'...violates federal law because it’s not peer-reviewed, and it’s essentially quite an influential dissemination of information,' which could mean it violates the Information Quality Bulletin, a federal regulation..." so, Nazi White House being Nazis, in other words, egregiously ignoring laws to prep state run violence against target pop

RE: https:// infosec.exchange/@ankit_anubha v/117236997806064724 Idea: a CAPTCHA service that starts with a puzzle solvable only by automation. Human users will click the "that's too hard" button and

mastodon:infosec-exchangeother21d ago kagi ↗

RE: https:// infosec.exchange/@ankit_anubha v/117236997806064724 Idea: a CAPTCHA service that starts with a puzzle solvable only by automation. Human users will click the "that's too hard" button and get a puzzle designed for humans. Now your site can serve different content to those two groups (at least until the automation learns not to solve the first CAPTCHA).

RE: https:// infosec.exchange/@winterknight 1337/117210811067629468 Re-shilling this now that it isn’t the middle of the night. I’m happy with where this tool has gotten. There’s work still planned. A

mastodon:infosec-exchangeother21d ago kagi ↗

RE: https:// infosec.exchange/@winterknight 1337/117210811067629468 Re-shilling this now that it isn’t the middle of the night. I’m happy with where this tool has gotten. There’s work still planned. Azure redirectors and Mythic V4 support are in the pipeline

RE: https:// infosec.exchange/@ifin/1172372 55226103149 The best way to protect against the tactics enabled by this kit is to *require* phishing-resistant MFA to login (PassKeys, security keys like Yu

mastodon:infosec-exchangeother21d ago kagi ↗

RE: https:// infosec.exchange/@ifin/1172372 55226103149 The best way to protect against the tactics enabled by this kit is to *require* phishing-resistant MFA to login (PassKeys, security keys like YubiKeys, or Windows Hello for Business). If it is required by your Conditional Access policy, then an authentication downgrade won’t provide access.

RE: https:// infosec.exchange/@0xabad1dea/1 17239484057326836 I think a lot of us *suspected* this might be the case, but it's nice to have what seems to be confirmation. (With a few papers out recent

mastodon:hachydermother20d ago kagi ↗

RE: https:// infosec.exchange/@0xabad1dea/1 17239484057326836 I think a lot of us *suspected* this might be the case, but it's nice to have what seems to be confirmation. (With a few papers out recently adding to the pile that note that LLMs tend to have extreme reactions to "discovery" - everything is Amazing and The Most Important Thing or treated as gospel - it's a fundamental problem)

RE: https:// infosec.exchange/@darkuncle/11 7242253902295667 Three thoughts: 1. This is very well thought out for “intended use”. 2. In dubious that they have thought about all the ways this could be

mastodon:hachydermother20d ago kagi ↗

RE: https:// infosec.exchange/@darkuncle/11 7242253902295667 Three thoughts: 1. This is very well thought out for “intended use”. 2. In dubious that they have thought about all the ways this could be abused. And it will. Absolutely. 3. God this timeline is bleak

RE: https:// infosec.exchange/@adfichter/11 7247305885170916 Wie eine gute Kollegin den Satz fixte: *Vielleicht hat niemand so sehr unter den sexistischen, misogynen Anfeindungen gelitten, die der Aus

mastodon:infosec-exchangeother19d ago kagi ↗

RE: https:// infosec.exchange/@adfichter/11 7247305885170916 Wie eine gute Kollegin den Satz fixte: *Vielleicht hat niemand so sehr unter den sexistischen, misogynen Anfeindungen gelitten, die der Aussenministerin entgegenschlugen, wie ihre beiden Töchter."

RE: https:// infosec.exchange/@nyanbinary/1 17247757498926875 If anyone wants to play around - domains pulled from Oak 2025H1, grouped by TLD, barely normalized & deduplicated & very outdated: files.n

mastodon:infosec-exchangeother19d ago kagi ↗

RE: https:// infosec.exchange/@nyanbinary/1 17247757498926875 If anyone wants to play around - domains pulled from Oak 2025H1, grouped by TLD, barely normalized & deduplicated & very outdated: files.nyanbinary[.]de/ct-1/ Please avoid pulling larger files, this reverse proxies to a machine in my homelab & my upstream is dogshit, if y'all misbehave I'll have to take it down again.

RE: https:// infosec.exchange/@nyanbinary/1 17248550883052558 actually, real talk, I'm gonna be dumb here: why are we bringing certificate lifetimes down to days? Not all regulations have to be writte

mastodon:infosec-exchangeother19d ago kagi ↗

RE: https:// infosec.exchange/@nyanbinary/1 17248550883052558 actually, real talk, I'm gonna be dumb here: why are we bringing certificate lifetimes down to days? Not all regulations have to be written in blood but, like, I can't really recall any (publicized) attacks that were enabled by excessive cert lifespans that are not also enabled by 47d or even 10d certs?

RE: https:// infosec.exchange/@kawaiicon/11 7249710816212072 wait is there ANOTHER neopets crime ring how many of these were there omfg 😭 (the one I'm thinking of: https:// imgur.com/a/neopets-thread

mastodon:infosec-exchangeother19d ago kagi ↗

RE: https:// infosec.exchange/@kawaiicon/11 7249710816212072 wait is there ANOTHER neopets crime ring how many of these were there omfg 😭 (the one I'm thinking of: https:// imgur.com/a/neopets-thread-by- everestpipkin-on-twitter-Cboev6V )

RE: https:// infosec.exchange/@perfect10_bo t/117252598777398157 “Look, I know they burned us on MoveIT DMZ, ..and ShareFile ..and LoadMaster ..and their weird WAF ..but let’s buy their DevOps automat

mastodon:infosec-exchangeother18d ago kagi ↗

RE: https:// infosec.exchange/@perfect10_bo t/117252598777398157 “Look, I know they burned us on MoveIT DMZ, ..and ShareFile ..and LoadMaster ..and their weird WAF ..but let’s buy their DevOps automation platform, because surely..”

RE: https:// infosec.exchange/@InfoSecSherp a/117249870737737787 Thanks to @ tdotfish for this tip. You can watch "Come From Away" filmed on Broadway on AppleTV. https:// tv.apple.com/us/movie/come-fr

mastodon:infosec-exchangeother18d ago kagi ↗

RE: https:// infosec.exchange/@InfoSecSherp a/117249870737737787 Thanks to @ tdotfish for this tip. You can watch "Come From Away" filmed on Broadway on AppleTV. https:// tv.apple.com/us/movie/come-fro m-away/umc.cmc.262n0v53nmotkz7ulzuuco7rq

RE: https:// infosec.exchange/@BleepingComp uter/117253578830796001 Passkeys experience for the users is such a complex mess that it's simply THE perfect theme for social engineering attacks. The way

mastodon:mstdn-socialother18d ago kagi ↗

RE: https:// infosec.exchange/@BleepingComp uter/117253578830796001 Passkeys experience for the users is such a complex mess that it's simply THE perfect theme for social engineering attacks. The way how I need to repeatedly keep adding and trying passkeys in services prompting for them has slowly trained me to believe "I have no clue how this is even supposed to work". I certainly would have felt

RE: https:// infosec.exchange/@halle/117252 562884104942 This kind of hits the nail on the head of why "but accessibility tho!" bothers the hell out of me as a common ham-fisted last-ditch-effort wedg

mastodon:hachydermother18d ago kagi ↗

RE: https:// infosec.exchange/@halle/117252 562884104942 This kind of hits the nail on the head of why "but accessibility tho!" bothers the hell out of me as a common ham-fisted last-ditch-effort wedge so often reached for by genAI boosters in general

RE: https:// infosec.exchange/@coleens_/117 253687254101607 I guess what I'm trying to say is, I define who I am... not some basketball player, or some author of childrens books, politician, or politi

mastodon:infosec-exchangeother17d ago kagi ↗

RE: https:// infosec.exchange/@coleens_/117 253687254101607 I guess what I'm trying to say is, I define who I am... not some basketball player, or some author of childrens books, politician, or political party not one of them even know me, or you

Stop Doing Swap Partitions

lemmy:lemmy-worldother17d ago kagi ↗

[Credit](https://infosec.exchange/@ryanc/117258448264431005) to @ryanc@infosec.exchange I just did the graphic

RE: https:// infosec.exchange/@metacurity/1 17260011669418502 This was a convenient excuse. The cold truth is the existing numbers would have led to a catastrophic IPO. And that would have started a m

mastodon:infosec-exchangeother17d ago kagi ↗

RE: https:// infosec.exchange/@metacurity/1 17260011669418502 This was a convenient excuse. The cold truth is the existing numbers would have led to a catastrophic IPO. And that would have started a massive economic implosion. He was already being pressured to postpone or cancel. This was his golden opportunity to save face. IMNSHO: he doesn’t give two shits about the danger.

RE: https:// infosec.exchange/@kevinrothroc k/117264211285233011 So the only real outcome of the "peace talks tour" Witkoff and Kushner did in Moscow and Kyiv is that it allowed Putin to go crying to

mastodon:mstdn-socialother16d ago kagi ↗

RE: https:// infosec.exchange/@kevinrothroc k/117264211285233011 So the only real outcome of the "peace talks tour" Witkoff and Kushner did in Moscow and Kyiv is that it allowed Putin to go crying to Trump that Ukraine is fighting back in an effective way. Pathetic. Putin can stop this war at any time. Demanding Ukraine stops fighting back is beyond craven. One geopolitical bully supporting anothe

RE: https:// infosec.exchange/@neillans/110 280993880802469 Still kinda looking for this - if anyone has any ideas for OSS coverage, gimmie a nudge. I find it absolutely unreal that any affordable / a

mastodon:infosec-exchangeother14d ago kagi ↗

RE: https:// infosec.exchange/@neillans/110 280993880802469 Still kinda looking for this - if anyone has any ideas for OSS coverage, gimmie a nudge. I find it absolutely unreal that any affordable / accessible routes dont seem to exist these days.

RE: https:// infosec.exchange/@mttaggart/11 7275354970016643 I didn't add a "What you can do" section to this piece because for most folks, the best thing you can do is not believe these charlatans. B

mastodon:infosec-exchangeother14d ago kagi ↗

RE: https:// infosec.exchange/@mttaggart/11 7275354970016643 I didn't add a "What you can do" section to this piece because for most folks, the best thing you can do is not believe these charlatans. But if you're in a position where you must use or build with these tools, I implore you to build in such a way that their disappearance is not catastrophic. They should never be critical junctures in a

RE: https:// infosec.exchange/@MrJico/11727 6690166679280 Great post on the cost and timing of decisions. Thanks @ GitRon > This is why we start with Django. Not because it is the best framework in so

mastodon:fosstodonother14d ago kagi ↗

RE: https:// infosec.exchange/@MrJico/11727 6690166679280 Great post on the cost and timing of decisions. Thanks @ GitRon > This is why we start with Django. Not because it is the best framework in some abstract sense, but because it comes with a working default for everything that is not business logic... # Django

RE: https:// infosec.exchange/@phishu/11727 5651004654095 Sharing my long-curated source of Phishing Intel with the community, for FREE! Just need your email and you'll get our weekly newsletter that

mastodon:infosec-exchangeother14d ago kagi ↗

RE: https:// infosec.exchange/@phishu/11727 5651004654095 Sharing my long-curated source of Phishing Intel with the community, for FREE! Just need your email and you'll get our weekly newsletter that you can opt out of whenever you'd like. Wanted to do something in time for Cybersecurity Awareness month coming up! https:// PhishU.net/newsletter Oh, and three lucky subscribers will randomly be draw

RE: https:// infosec.exchange/@sambowne/117 281186337426250 At least in my org its hardly as clean as depicted, but holds in essence. Imo patch-management and threat Intel/analysis will (have to) beco

mastodon:infosec-exchangeother13d ago kagi ↗

RE: https:// infosec.exchange/@sambowne/117 281186337426250 At least in my org its hardly as clean as depicted, but holds in essence. Imo patch-management and threat Intel/analysis will (have to) become one in all smol to medium sized orgs.