Suche
Beiträge, die mit infosec getaggt sind
📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #13/2025 is out!
It includes the following and much more:
➝ DNA of 15 Million People for Sale in #23andMe Bankruptcy,
➝ #Trump administration accidentally texted a journalist its war plans,
➝ Critical Ingress #NGINX controller vulnerability allows RCE without authentication,
➝ #Cyberattack hits Ukraine's state railway,
➝ Troy Hunt's Mailchimp account was successfully phished,
➝ #OpenAI Offering $100K Bounties for Critical #Vulnerabilities,
➝ #Meta AI is now available in #WhatsApp for users in 41 European countries... and cannot be turned off
Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️
infosec-mashup.santolaria.net/…
🕵🏻♂️ [InfoSec MASHUP] 13/2025
DNA of 15 Million People for Sale in 23andMe Bankruptcy, Trump administration accidentally texted a journalist its war plans, Critical Ingress NGINX controller vulnerability allows RCE without authentication, Cyberattack hits Ukraine's state railway,…X’s InfoSec Newsletter
A wild ZWSP appears!
In case you’re not fluent in Unicode and percent-encoding: %E2%80%8B
is a zero-width-space, an invisible character which helps set line-breaks correctly.
It seems that broken links with ZWSPs or unicode control characters like the left-to-right mark are a widespread problem, opening a door to cybersquatting.
Or may I suggest the name ‘typography squatting’?
#Signal #SignalApp #Android #Google #PlayStore #GrapheneOS #GitHub #TypoSquatting #CyberSquatting #TypographySquatting #InfoSec #Security #CyberSecurity
Do you remember the place .mobi?
Have you read this article? it's so incredible that this was actually possible and simple to become admin of .mobi
I'm re-reading it
labs.watchtowr.com/we-spent-20…
We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
Welcome back to another watchTowr Labs blog. Brace yourselves, this is one of our most astounding discoveries.Benjamin Harris (watchTowr Labs)
Passkeys. 👀
- I don't know (enough) about them (25%, 108 Stimmen)
- I know about them, but don't use them (42%, 178 Stimmen)
- I use them, but find them confusing (12%, 54 Stimmen)
- I use them and find not them confusing (19%, 82 Stimmen)
Mastodon friends, I've heard a few suggestions of companies moving from US cloud providers to those based in the EU, due to risks with the Trump administration/Cloud Act, etc.
Has anyone come across any businesses that have made the leap recently? Feel free to DM or message on Signal, mattburgess.20
Concerned about Microsoft Windows 11 Recall? You should be.
Recall allows Microsoft’s Windows 11 Copilot+ devices to screenshot every action a person takes on their PC.
What can you do? Switching to Linux is the clear answer, but some don't know what distro to try.
DistroSea.com is a website that lets you run and test 60+ Linux distributions straight from your web browser.
Have fun!
Source: distrosea.com/
#Linux #Computer #Windows #DOS #OPSEC #InfoSec #Privacy #Surveillance
Test Linux distros online
Test out popular Linux distributions online for free on your web browser. No installation or live boot needed.DistroSea

#politics #USPol #resist #infosec
Putting out virtual fires in Germany
A community effort to close down potentially 400 exposed servers from Fire Departments around Germany.JayeLTee (The Hub of Stupi.. *misconfigs)
I'm looking for a new job doing security assessments / research.
I spent the last 6 years building advanced security assessment capabilities around hardware/IoT, industrial, marine OT, and x86 platforms. Before that I spent 5 years as a pentester. I excel at weird and novel stuff with no template.
I'm in the UK and I'm looking for a full-time remote role.
CV: poly.nomial.co.uk/graham_suthe…
Please get in touch if you know of any available roles! 😀
Calling #infosec and security-peeps:
We need people to test (also trash^^) a prototype (website + back-end) we're working on & to open/submit issues.
A central index of archives, with metadata about who archived what, when, to be disseminated widely alongside torrent files.
Please contact me on Matrix or Signal:
Matrix: @schoeneh:matrix.org
Signal: upon request via DM
Please boost and share! 🚀🔁
#SafeguardingResearch @SafeguardingResearch
Today is the Data Privacy (Protection) Day! So let us remind you that in #LabPlot, an open-source data analysis and visualization software, Your Data is Yours!
Boosts appreciated! 🙂 🚀
#DataSecurity #DataProtection #DataPrivacy #Privacy #Ownership #InfoSec #DataAnalysis #DataScience #Analytics #Data #DataAnalytics #DataViz #FOSS #FLOSS #SoftwareLibre #OpenSource #OpenScience #Science #Engineering #KDE #Business #Security #Orwell
This just came in. Do they really want to know?
#Facebook #Meta #InfoSec #Cybersecurity #DataBreach #DataLeak
Facebook email disclosure and account takeover - PenTester Nepal - Medium
I have a preference for apps over web when it comes to hunting, so in January I decided to dive deep into apk endpoints hoping to find something juicy. I downloaded bunch of FB and messenger apks of…Rikesh Baniya (PenTester Nepal)
It occurred to me that these days, Chinese citizens are maybe better off. They know who is collecting their data, and largely to what end. To be honest, we've no fucking idea the full extent of what #meta #google #Microsoft and the 357 3rd Party Advertising Partners are doing with our data.
#privacy #infosec #gdpr
Falls euch mal ein USB Keylogger begegnet, ist er vermutlich von der Firma Keelog. Deren Produkte funktionieren so dass das gleichzeitige Drücken von drei Tasten das Gerät zugänglich macht
Hab mal ein BadUSB-Skript geschrieben, dass Tastensequenzen durchprobiert, um das Teil zu entsperren
Stellt sich raus - die Mühe ist unnötig - offenbar alle Keylogger kommen mit einer nicht vom Hersteller dokumentierten Backdoor.
Das Tippen von VSNLPB entsperrt unabhängig von der Konfiguration.
Consider hosting a CryptoParty in 2025.
Please share your knowledge with people interested in learning but may need help getting started.
Email encryption is an example, some people may not realize protecting messages is easier than they imagine. This may also benefit people around the world they communicate with if they already use email encryption.
CryptoParty: wikipedia.org/wiki/CryptoParty
Website: cryptoparty.in
#CryptoParty #Cryptography #Encryption #Privacy #InfoSec #CyberSecurity