GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    :rainbowCrow: (cr0w@infosec.exchange)'s status on Wednesday, 03-Jun-2026 12:52:29 JST:rainbowCrow::rainbowCrow:

    RE: https://infosec.exchange/@cR0w/116682616422398554

    I think what bugs me about this is:

    • They don't care.
    • It's clearly intentional.
    • We all know nothing will change.
    In conversationabout 2 months ago from infosec.exchangepermalink

    Attachments

    1. No result found on File_thumbnail lookup.
      care.it
      This domain may be for sale!
    2. No result found on File_thumbnail lookup.
      cR0w (@cR0w@infosec.exchange)
      from cR0w
      :dumpster_fire_gif: :blobcatpopcorn: :dumpster_fire_gif: https://www.kb.cert.org/vuls/id/615987 >CVE-2026-10629 Verizon IMS deployments were observed transmitting SIP signaling without integrity protection. REGISTER exchanges lacked Security-Client, Security-Server, and Security-Verify headers, and no ESP-encapsulated SIP traffic was detected during subsequent signaling such as INVITE, MESSAGE, BYE, and UPDATE. This pattern persisted across devices, operating systems, and network conditions, indicating a deliberate network configuration rather than a transient issue. >Per 3GPP TS 33.203 and GSMA IR.92, SIP signaling between the UE and P-CSCF must be protected using IPsec ESP following IMS AKA authentication, with negotiation occurring during registration. The absence of this protection allows attackers to manipulate SIP signaling undetected, enabling call hijacking, spoofing, denial-of-service, and misrouting of emergency calls. >Verizon initially acknowledged the issue and stated that integrity support would be available upon request and extended broadly later in the year. However, the company has since ceased participation in coordination, including follow-up discussions and draft review, and has not provided verifiable evidence of mitigation. As remediation remains unconfirmed, this disclosure proceeds to inform users of an ongoing security exposure. >Independent verification would require observation of successful SIP security negotiation, ESP-protected traffic, or official confirmation from Verizon.
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.