Search

Items tagged with: infosec


The media in this post is not displayed to visitors. To view it, please go to the original post.

Before You Paste That Into AI, Read This!
youtu.be/H4wIe2xcX9c #CyberSecurity #AI #AIGovernance #DataPrivacy #GenerativeAI #InfoSec

(URL replace addon enabled for X, YouTube, Instagram and some news sites.)



The media in this post is not displayed to visitors. To view it, please go to the original post.

Vivaldi disabled uBlock Origin in the latest browser update, because “it might soon get removed [from Google Web Store]”. Essentially, Google’s enforcement of browser extensions expands way beyond the Chrome browser itself, as most 3rd party Chromium forks are still using Google’s services and infrastructure for web browser extensions.

#infosec #Google #Vivaldi


I cracked a tough project today. It was the culmination of 2 months of work. It was only possible because a sloppy contractor left an unsecured private key in a place he thought I'd never look.

Two lessons:

1. Don't use the same key everywhere. I got the keys to the kingdom in one singular moment.

2. Obscurity is a valid security layer. People can't hit what they can't see. But defence in depth is what works. Obscurity can't be your only layer.

#infosec #cybersecurity #fuckyeah


The media in this post is not displayed to visitors. To view it, please go to the original post.

🟠 CVE-2026-61876 - High (8.8)

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administr...

🔗 thehackerwire.com/vulnerabilit…

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack


This dumb password rule is from University of Texas at Austin.

Because of the last two rules, which ban dictionary words and any
variants using symbol substitutions, *neither* of the passwords
presented in the [xkcd comic](xkcd.com/936/) are allowed.

dumbpasswordrules.com/sites/un…

#password #passwords #infosec #cybersecurity #dumbpasswordrules


The media in this post is not displayed to visitors. To view it, please go to the original post.

🔓 Sommer 2026: Gleich zwei Vertrauensanker der IT-Security geraten ins Wanken.
Drei große VPN-Hersteller (Check Point, Palo Alto, Fortinet) mit kritischen Auth-Bypässen – FortiBleed betrifft über 430.000 Firewalls und speist direkt in Qilin/INC/Lynx-Ransomware ein.
Gleichzeitig: LiteLLM-Lücke macht KI-Gateways selbst zum Einfallstor, plus OAuth-Datenabfluss bei Klue/Salesforce und ein Rekord-Patchday mit 571 CVEs.
Unser Juli-Digest ordnet ein 👇
research.hisolutions.com/2026/…
#InfoSec #CyberSecurity #VPN #Ransomware #AISecurity #ITSecurity


was out at a customer site today doing some work because i do like to get out occasionally. anyway, since i was suspiciously hanging around with four phones and a laptop, when i saw one of their employees walk by, i felt inclined to introduce myself, lest they thought i was some sort of criminal.

we exchanged hellos and i said, “i’m mike and i…”

before i could finish the guy said “they don’t pay me enough to care who you are, go nuts”

so #infosec tip of the day, pay people enough to give a shit





Why are SSL certificates dropping to 47 days? Because revocation is broken.

OCSP fails open. Revocation lists go stale. A stolen certificate stays trusted too long.

Short lifespans are the industry's workaround.

runasradio.com/Shows/Show/1041

#SSL #InfoSec



The media in this post is not displayed to visitors. To view it, please go to the original post.

Kali Linux 2026.2 has arrived with:

✅ GNOME 50
✅ KDE Plasma 6.6
✅ Faster VM boot
✅ Modernized APT sources
✅ 9 new security tools
✅ Kali NetHunter updates

Read our overview:
opensourcefeed.org/kali-linux-…

#KaliLinux #Linux #OpenSource #CyberSecurity #InfoSec


Hey, quick question for the #infosec folks: are you still using securelist.com (the Kaspersky blog)? And if yes, have you looked at your traffic when you browse it?

I just added support for websocket traffic on #lookyloo and it is pretty insane. They use yandex webvisor and afaict, the WS session calls home and sends enough data to replay your whole session (mouse movment, scrolling, ...), on top of everything they can get about your browser.

Example: lookyloo.circl.lu/tree/7849cb0…


The media in this post is not displayed to visitors. To view it, please go to the original post.


The media in this post is not displayed to visitors. To view it, please go to the original post.

Active Directory Pentest Mindmap: Complete Attack Path 🧠

🔥 Telegram: t.me/hackinarticles

The AD Pentest Mindmap is a visual roadmap that helps attackers and defenders understand the full attack lifecycle, from enumeration to domain dominance, in a structured way.

📖 Resource: github.com/Ignitetechnologies/…

#ActiveDirectory #RedTeam #Pentesting #CyberSecurity #EthicalHacking #OSCP #InfoSec


The media in this post is not displayed to visitors. To view it, please go to the original post.

Active Directory Pentest Mindmap: Complete Attack Path 🧠

🔥 Telegram: t.me/hackinarticles

The AD Pentest Mindmap is a visual roadmap that helps attackers and defenders understand the full attack lifecycle—from enumeration to domain dominance—in a structured way.

📖 Resource: github.com/Ignitetechnologies/…

#ActiveDirectory #RedTeam #Pentesting #CyberSecurity #EthicalHacking #OSCP #InfoSec


The media in this post is not displayed to visitors. To view it, please go to the original post.

Anthropic secretly installs spyware when you install Claude Desktop

Anthropic's Claude Desktop silently installs a Native Messaging bridge into seven Chromium browsers, including browsers Anthropic's own documentation says it does not support, and browsers the user has not even installed.

thatprivacyguy.com/blog/anthro…

#ai #privacy #eprivacy #compliance #infosec #gdpr #law #cyber #security #anthropic #claude


The media in this post is not displayed to visitors. To view it, please go to the original post.

🔐 Mein clientseitiger PGP-Keygenerator steht jetzt auch als Offline-Version zum Download bereit.

Die Anwendung erzeugt OpenPGP-Schlüsselpaare vollständig lokal auf deinem Gerät – ohne Serverübertragung und ohne externe Verbindungen. So bleiben Passwörter und Schlüssel jederzeit unter deiner Kontrolle.

🌐 Online:
secunis.de/pgp-keygenerator.ht…

⬇️ Offline-Download:
secunis.de/downloads/pgp-keyge…

📖 Zum Artikel:
secunis.de/clientseitiger-pgp-…

:boost_ok:

#OpenPGP #PGP #Privacy #CyberSecurity #InfoSec #Encryption #Datenschutz #Security #Secunis


Ich bereite gerade einen Workshop zu innovativen Methoden für IT-Sicherheitsschulungen vor und hätte gern gewusst:

Was ist euch von euren Schulungen besonders im Gedächtnis geblieben, positiv wie negativ?

#itsecurity #infosec #lernen #informationsecurity gerne #retoot


Arthur C. Clarke: "Any sufficiently advanced technology is indistinguishable from magic."

Me: "Therefore, any sufficiently complicated technical problem is indistinguishable from a curse."

#infosec #sysadmin #bofh


The media in this post is not displayed to visitors. To view it, please go to the original post.

💔 IT-Nerd sucht BYD für heißes Security-Date in Salzburg! 🚗💻

Bist du BYD-Besitzer aus SZG & nicht eifersüchtig, wenn ich an deinem Infotainment-System rummache? 😉 Für ein IT-Security-Projekt suche ich dein Auto zum Testen.

Keine Sorge: Ich bin zärtlich & mache physisch nichts kaputt. 🛡️

Belohnung: Ewiger Nerd-Dank, IT-Insights & Kaffee/Bier auf mich! ☕🍻

Interesse? DM an mich! Bitte boosten! ⚡

#Infosec #BYD #Salzburg #CyberSecurity #FediDACH


da hilft nur:
KONSEQUENT VERWEIGERN!

Und wenn dass bedeutet dass alle auf XMPP+OMEMO & PGP/MIME über @torproject gehen, dann ist das halt digitale Notwehr & Notwehr gegen Cyberfaschismus!

  • Wir haben lang genug freundlich gefragt - jetzt nicht mehr!
    • Diese Korrosionsstrategie muss aufhören! Ich will meine Menschenrechte zurück, und zwar alle die seit 1949 eingeschränkt wurden - MIT ZINSESZINSEN!


#Verweigerung #ChatControl #NonCompliance #XMPP #OMEMO #PGP #E2EE #Tor #DigitaleNotwehr #DigitaleNothilfe #Cyberfaschismus #Faschismus #Privatsphäre #Menschenrechte #Überwachung #Polizeistaat #Überwachungsstaat #EU #Massenüberwachung #FaschistischeKackshice #EUpol #DEpol #Enshittification #Notwehr #Nothilfe #DigitaleSelbstverteidigung #Neofeudalismus #Zensursula #Politik #Politricks #ITsec #InfoSec #OpSec #ComSec #Korrosionsstrategie #Menschenrechte #Bürgerrechte #FDGO #Freiheit #Rechtsstaatlichkeit


(URL replace addon enabled for X, YouTube, Instagram and some news sites.)



ok back to cooler stuff:

"Western OSINT researchers consistently underperform on China-focused work for one reason: they treat the Chinese-language internet as a translated copy of the English-language web. It isn't. The highest-value records — company registries, procurement awards, court and enforcement data, regulatory penalties, patents, disclosures — are indexed under Chinese names, Chinese pivot terms, Chinese identifiers, and Chinese document conventions, and they surface on different engines and official portals than the ones English-speakers default to.

This repository is a practical, bilingual playbook for doing that work well and lawfully."

#infosec #cybersecurity #threatintel

github.com/ArgeliusLabs/chines…


Ransomware ist längst mehr als „nur“ verschlüsselte Systeme. Angreifer setzen zunehmend auf Datenexfiltration und drohen gezielt mit der Veröffentlichung sensibler Informationen.

Die Frage, die dann oft im Raum steht: Sollte man zahlen, um den Schaden zu begrenzen?

Ich sage klar: nein. Warum das so ist – und wie solche Angriffe tatsächlich ablaufen – habe ich in meinem Beitrag ausführlich behandelt:

➡️ secunis.de/ransomware-druckmit…

:boost_ok:

#Ransomware #Datenschutz #SecurityAwareness #InfoSec #ITSecurity #Deutschland




The media in this post is not displayed to visitors. To view it, please go to the original post.

Ich habe meine Security-Toolbox für mobile Geräte optimiert: Die UI wurde verfeinert, die Usability verbessert und Bedienelemente wie Navigation, Sprachumschaltung und Aktionen angepasst, sodass sich die Tools nun noch intuitiver auf mobilen Geräten nutzen lassen.

😀✌🏼

➡️ secunis.de/security-toolbox.ht…

:boost_ok:

#Tools #PGP #ITSecurity #Datenschutz #Privatsphäre #InfoSec #SecurityToolbox


Weiß irgendjemand aus der IT-Security Bubble, nach welchem Konzept das BSI nachts wegen Sicherheitslücken anruft oder sogar Polizei früh morgens bei Admins klingelt, damit diese Patches einspielen?

Bisher hab ich nur bei einem Produkt davon gehört, aber z.B. nicht bei der Copy Fail Linux Lücke, die ja deutlich mehr Systeme betreffen dürfte. Oder bei all den Leuten, die ungepatchte Windows 7 Systeme am Netz hängen haben?

Vielleicht kann mir @bsi das auch direkt erklären? Mich würde das wirklich interessieren.

heise.de/news/PTC-Windchill-BS…

#infosec #bsi


The media in this post is not displayed to visitors. To view it, please go to the original post.

reminder that "fortibleed" is not a vuln. no CVE. no patch. nothing fucking "bled."

it's a russian-speaking crew firing 1.16 billion creds from old breaches and infostealer logs at every fortigate dumb enough to have its mgmt interface sitting on the public internet. ~50% of internet-facing boxes. half of you.

and before anyone cries "but my password was 28 characters with symbols": it didn't get cracked. it was already chilling in an infostealer dump in plaintext. great entropy, shame about the malware on your sales guy's laptop.

the -bleed suffix is marketing. the real CVE is CVE-2026-YOUREANIDIOT: "admin panel pointed at 0.0.0.0/0, password recycled from a 2022 breach, MFA considered but never enabled."

rotate the creds, yank the mgmt interface off the internet, force MFA, and maybe stop letting threat intel firms name your incidents like they're naming a fucking Marvel villain.

#infosec #fortinet #fortigate



Die Heinlein Gruppe ist auf der GITEX AI Europe 2026 dabei: vom 30.06. bis 01.07.2026 in der Messe Berlin (South Entrance).

Gemeinsam mit @OpenCloud zeigen wir Lösungen für sichere Kommunikation. Im Fokus steht digitale Souveränität: mehr Kontrolle, Transparenz und Unabhängigkeit im Umgang mit sensiblen Daten.

Wir freuen uns auf den Austausch vor Ort.
opentalk.eu/de/news/opentalk-a…

#GITEXEurope #DigitaleSouveränität #Infosec #Cloud


The media in this post is not displayed to visitors. To view it, please go to the original post.

You demonstrate a fileless RCE chain. Complex delivery, in-memory execution, zero detections, confirmed working on multiple devices.

The vendor reviews it twice, involves engineering, then tells you:

"Your research demonstrates a complex chain for delivering and executing code."

...and closes it as 'intended behavior. Not a platform vulnerability.'

Question: is it a vulnerability?

Follow-up: does your answer change if the attack surface exists *between* components — where no single owner's scope definition covers the full chain?

Asking because I have a paper dropping soon about that.

#VRP #responsibleDisclosure #semanticGap #infosec #securityResearch


The End of uBlock Origin in Chrome: What's Really Changing and What to Do About It

In early June 2026, it was confirmed that Chrome was also losing its last technical capabilities that had kept…

vsx.global/the-end-of-ublock-o…

#infosec #privacy #opensource #digitalsovereignty


Was für eine Technik benutzen eigentlich TV-Spione in ihren Ohren um miteinander zu kommunizieren? Bluetoothkopfhörer? Umgebaute Hörgeräte? 🤔
Und warum immer diese lächerliche "Tipps ans Ohr"-Geste haha

#Netflix #spy #infosec


@ifin @threatintel Made a consolidated AUR malware checker for the atomic-lockfile supply-chain attack now on GitHub.

Merges detection scripts from the gist[1] and Kidev, BrianCArnold, commonsourcecs, Kacper-Kondracki, quantenProjects, Andre Herbst, ioctl.fail, and Kusoneko into a single repo. Checks known compromised packages, scans pacman.log history, checks for systemd persistence and eBPF rootkit artifacts.

github.com/lenucksi/aur-malwar…

[1] gist.github.com/Kidev/59bf9f5f…

#AUR #ArchLinux #SupplyChainAttack #Malware #InfoSec #atomiclockfile



Angriffswelle im Arch AUR: Angreifer übernahmen Hunderte verwaiste PKGBUILD‑Beschreibungen, fügten npm/Bun‑Abhängigkeiten und Malware (u.a. atomic-lockfile → deps) hinzu. Arch‑Maintainer löschen Einträge und sperren Accounts — AUR‑Nutzung bleibt auf eigenes Risiko. heise.de/news/Angriffswelle-au… #ArchLinux #AUR #InfoSec 🔒🛡️
#ArchBtw


Hola Fediverso 🦙

Soy thebooth97 - mi avatar es una llama porque me identifico con ella: curiosa, resistente y siempre mirando todo.

Estoy aquí para aprender y compartir sobre ciberseguridad, hacking ético, Linux, OSINT/metadatos y open source. Vine por la privacidad, me quedo por la comunidad.

Si compartes writeups, herramientas open source o recursos de infosec, nos seguimos 💻🐧🐦‍🔥🦅🚥🚥🚏🌐💾🖲️

#ciberseguridad #hackingético #infosec #opensource #libertad #metadatos #linux #osint


ALEPH — biologically-inspired AI runtime on embedded hardware.

Security by design: immune system architecture, SHA256 whitelist, stateful iptables, anomaly classifier that distinguishes inference load from DoS.

No cloud. No pretrained weights. No LLM. 407k+ ticks, zero crashes.

Paper (DOI): researchgate.net/publication/4…

#infosec #rustlang #embeddedsystems #AI #AIResearch


The media in this post is not displayed to visitors. To view it, please go to the original post.

#Phishing?
Ich erwarte tatsächlich meine erste #Packstation-Sendung heute vormittag, DKIM, DMARC, SPF passen für dhl.de, fehlerfreier Text (obwohl mit flapsiger Anrede). Link zur Online-Version führt zu DHL.
Aber: Packstation-Service ist bereits aktiviert - und der "Aktivieren"-Link führt nicht zu dhl, sondern zu "depst-mara-prod1-decisionhub.pegacloud.net" (auf der virustotal nix findet).
Versendet DHL echt solche Mails über obskure externe Dienstleister?

#CyberSecurity #Cybercrime #InfoSec


Fascinating, scary and frankly outrageous post (hat tip @klausi for sharing) where an actual software vendor uses *your* TV and *your* internet connection to scrape the web:
blog.includesecurity.com/2026/…

#infosec #iot


Bin gerade im Rahmen des Zweitjob bei einem Arzt im Netzwerk um eine neue Maschine final einzubinden.
Wundere mich über eine zweite IP-Adresse auf dem Interface. Class B. Gucke auf dem Server, liegt da eine Batch Datei.

Was soll ich sagen? DIe #CGM baut jetzt offenbar im Rahmen der "managed" #TI parallele Netzwerke in den Praxen auf.

Das empfinde ich als spannend, da man ja innerhalb der Praxen einen Entry Point hat, der ganz allein unter Kontrolle der CGM bzw. deren Dienstleistern steht.

Gibt's hier jemanden, der das schon einmal in der freien Wildbahn gesehen hat und ein bisschen was dazu sagen kann? Mich würde vor allem interessieren, ob die CGM die Konfig der Watchguard zwecks Reviews zugänglich macht.

#infosec #arztpraxis #digitalisierung


Diese Webseite verwendet Cookies. Durch die weitere Benutzung der Webseite stimmst du dieser Verwendung zu. https://inne.city/tos