GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices tagged with cybersecurity, page 5

  1. Embed this notice
    The New Oil (thenewoil@mastodon.thenewoil.org)'s status on Saturday, 19-Apr-2025 03:41:17 JST The New Oil The New Oil

    #Chrome extensions with 6 million installs have hidden tracking code

    https://www.bleepingcomputer.com/news/security/chrome-extensions-with-6-million-installs-have-hidden-tracking-code/

    #privacy #cybersecurity

    In conversation about 2 months ago from mastodon.thenewoil.org permalink
  2. Embed this notice
    br00t4c (br00t4c@mastodon.social)'s status on Friday, 18-Apr-2025 19:04:19 JST br00t4c br00t4c

    CVE fallout: The splintering of the standard vulnerability tracking system has begun

    #CVE #Cybersecurity #Commentary #IT #Standardization

    https://go.theregister.com/feed/www.theregister.com/2025/04/18/splintering_cve_bug_tracking/

    In conversation about 2 months ago from mastodon.social permalink
  3. Embed this notice
    AAKL (aakl@infosec.exchange)'s status on Friday, 18-Apr-2025 07:09:40 JST AAKL AAKL

    CISA has updated the KEV catalogue.

    - CVE-2025-31200: Apple Multiple Products Memory Corruption Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-31200

    - CVE-2025-31201: Apple Multiple Products Arbitrary Read and Write Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-31201

    - CVE-2025-24054: Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-24054 #CISA #cybersecurity #infosec #Apple #Microsoft

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      https://www.cve.org/CVERecord?id=CVE-2025-31200-
    2. No result found on File_thumbnail lookup.
      https://www.cve.org/CVERecord?id=CVE-2025-31201
    3. No result found on File_thumbnail lookup.
      https://www.cve.org/CVERecord?id=CVE-2025-24054
  4. Embed this notice
    br00t4c (br00t4c@mastodon.social)'s status on Friday, 18-Apr-2025 04:50:22 JST br00t4c br00t4c

    Krebs throws himself on the grenade, resigns from SentinelOne after Trump revokes clearances

    #Trump #Cybersecurity #SentinelOne #ChrisKrebs #ExecutiveOrder

    https://go.theregister.com/feed/www.theregister.com/2025/04/17/krebs_quits_sentinelone/

    In conversation about 2 months ago from mastodon.social permalink
  5. Embed this notice
    Brian Clark (deepthoughts10@infosec.exchange)'s status on Thursday, 17-Apr-2025 13:08:56 JST Brian Clark Brian Clark
    • Sophos X-Ops
    • Sean Gallagher :verified: 🐀 :donor:

    Security Firm @SophosXOps published another report, this one on incidents at small and medium-sized businesses by @thepacketrat and Anna Szalay. One of the things I always look for in these reports are easy #cybersecurity wins -- and this report has a bunch of them.

    First off - take a look at this chart: Top 15 dual-use tools. Imagine the pain you can cause threat actors by blocking the use of these tools and disrupting their playbooks!

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/350/603/475/705/098/original/35b29599747d242d.webp
  6. Embed this notice
    Nonilex (nonilex@masto.ai)'s status on Thursday, 17-Apr-2025 08:04:13 JST Nonilex Nonilex

    For #cybersecurity experts, that spike in #data leaving the system is a key indicator of a #breach, Berulis explained.

    When Berulis asked his IT colleagues whether they knew why the data was exfiltrated or whether anyone else had been using containers to run code on the system in recent weeks, no one knew anything about it or the other unusual activities on the network….

    #criminal #law #Trump #Musk #DOGE #InfoSec #NationalSecurity

    In conversation about 2 months ago from masto.ai permalink
  7. Embed this notice
    Nonilex (nonilex@masto.ai)'s status on Thursday, 17-Apr-2025 08:04:04 JST Nonilex Nonilex
    in reply to

    Russ Handorf, who served in the #FBI for a decade in various #cybersecurity roles, also reviewed Berulis' extensive technical forensic records & analysis….

    "All of this is alarming," he said. "If this was a publicly traded company, I would have to report this [breach] to the Securities and Exchange Commission…."

    #criminal #law #Trump #Musk #DOGE #InfoSec #NationalSecurity

    In conversation about 2 months ago from masto.ai permalink
  8. Embed this notice
    br00t4c (br00t4c@mastodon.social)'s status on Thursday, 17-Apr-2025 06:02:27 JST br00t4c br00t4c

    CVE, global source of cybersecurity info, was hours from being cut by DHS

    #DHS #Cybersecurity #LastMinuteSave #CyberthreatIntelligence #Takeover

    https://arstechnica.com/security/2025/04/crucial-cve-flaw-tracking-database-narrowly-avoids-closure-to-dhs-cuts/

    In conversation about 2 months ago from mastodon.social permalink
  9. Embed this notice
    Joe Ortiz (joeo10@mastodon.sdf.org)'s status on Thursday, 17-Apr-2025 04:37:39 JST Joe Ortiz Joe Ortiz
    in reply to

    In the very last minute, CISA extends funding to ensure 'no lapse in critical CVE services' for the next 11 months. Potential catastrophe of epic proportions averted....for now.

    https://www.bleepingcomputer.com/news/security/cisa-extends-funding-to-ensure-no-lapse-in-critical-cve-services/

    #cve #security #mitre #infosec #cybersecurity #cisa

    In conversation about 2 months ago from mastodon.sdf.org permalink
  10. Embed this notice
    Apple Security Updates (applsec@infosec.exchange)'s status on Thursday, 17-Apr-2025 02:48:21 JST Apple Security Updates Apple Security Updates

    📣 EMERGENCY UPDATES 📣

    Apple pushed updates for 2 new zero-days that may have been actively exploited.

    🐛 CVE-2025-31200 (CoreAudio),
    🐛 CVE-2025-31201 (RPAC):
    - iOS and iPadOS 18.4.1
    - macOS Sequoia 15.4.1
    - tvOS 18.4.1
    - visionOS 2.4.1

    #apple #cybersecurity #infosec #security #ios

    In conversation about 2 months ago from infosec.exchange permalink
  11. Embed this notice
    br00t4c (br00t4c@mastodon.social)'s status on Wednesday, 16-Apr-2025 22:09:54 JST br00t4c br00t4c

    Russians lure European diplomats into malware trap with wine-tasting invite

    #Malware #CozyBear #CyberSecurity #ProvenTactics #RussianHacking

    https://go.theregister.com/feed/www.theregister.com/2025/04/16/cozy_bear_grapeloader/

    In conversation about 2 months ago from mastodon.social permalink
  12. Embed this notice
    Cybernews (cybernews@infosec.exchange)'s status on Wednesday, 16-Apr-2025 21:57:10 JST Cybernews Cybernews

    Hackers retain access to over 14,000 Fortinet VPNs, public scans by Shadowserver Foundation have revealed.

    #hack #cybersecurity #Fortinet #VPN

    https://cnews.link/fortinet-hackers-maintaining-access-despite-patches-1/

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/335/454/801/604/617/original/32b2b94e36b0c1f8.png

  13. Embed this notice
    Vegard Nossum 🥑 (vegard@mastodon.social)'s status on Wednesday, 16-Apr-2025 15:30:39 JST Vegard Nossum 🥑 Vegard Nossum 🥑

    The CVE program going away is the least of my worries. Not saying it's not important, it absolutely is. But compared to secret police and concentration camps it's nothing.

    #CVE #mitre #cybersecurity

    In conversation about 2 months ago from mastodon.social permalink
  14. Embed this notice
    Joe Ortiz (joeo10@mastodon.sdf.org)'s status on Wednesday, 16-Apr-2025 08:26:36 JST Joe Ortiz Joe Ortiz

    Holy Shit (for the second time today)!

    Mitre says their US government funding for CVE expires tomorrow and this is going to be a total catastrophe of epic proportions.

    https://www.nextgov.com/cybersecurity/2025/04/mitre-backed-cyber-vulnerability-program-lose-funding-wednesday/404585/

    #cve #security #mitre #infosec #cybersecurity

    In conversation about 2 months ago from mastodon.sdf.org permalink
  15. Embed this notice
    Kat O’Brien (obrien_kat@mastodon.world)'s status on Wednesday, 16-Apr-2025 03:31:11 JST Kat O’Brien Kat O’Brien
    • NPR

    Outstanding and alarming reporting by @npr here on what appears to be major violations of security and data privacy protocol by the DOGE folks on National Labor Relations Board Data. Big props to the brave whistleblower, Daniel Berulis, who has come forward despite receiving threatening notes with personal information and pictures taken from overhead (drones?) of him walking his dog.
    https://www.npr.org/2025/04/15/nx-s1-5355896/doge-nlrb-elon-musk-spacex-security
    #cybersecurity #doge #privacy

    In conversation about 2 months ago from mastodon.world permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: npr.brightspotcdn.com
      A whistleblower's disclosure details how DOGE may have taken sensitive labor data
      A whistleblower tells Congress and NPR that DOGE may have taken sensitive labor data and hid its tracks. "None of that ... information should ever leave the agency," said a former NLRB official.
  16. Embed this notice
    AAKL (aakl@infosec.exchange)'s status on Wednesday, 16-Apr-2025 02:56:36 JST AAKL AAKL
    • BrianKrebs

    From yesterday.

    KrebsonSecurity: Trump Revenge Tour Targets Cyber Leaders, Elections https://krebsonsecurity.com/ @briankrebs #cybersecurity #infosec

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: krebsonsecurity.com
      Krebs on Security
      In-depth security news and investigation
  17. Embed this notice
    Joe Ortiz (joeo10@mastodon.sdf.org)'s status on Wednesday, 16-Apr-2025 02:45:02 JST Joe Ortiz Joe Ortiz

    Holy Shit!

    This is a huge must-read on a brave whistleblower revealing DOGE staff disabling monitoring tools, deleted logs, and even one staffer tried to log in via a Russian IP address.

    https://www.npr.org/2025/04/15/nx-s1-5355896/doge-nlrb-elon-musk-spacex-security

    #privacy #security #whistleblower #infosec #cybersecurity

    In conversation about 2 months ago from mastodon.sdf.org permalink
  18. Embed this notice
    Nonilex (nonilex@masto.ai)'s status on Tuesday, 15-Apr-2025 22:24:57 JST Nonilex Nonilex
    in reply to

    & data has nothing to do w/making the govt more efficient or cutting spending.

    Meanwhile, acc/to the disclosure & records of internal comms, members of the #DOGE team asked that their activities not be logged on the system & then appeared to try to cover their tracks behind them, turning off monitoring tools & manually deleting records of their access—evasive behavior several #cybersecurity experts compared to what #criminal or #StateSponsored #hackers might do.

    #law #Trump #Musk #InfoSec

    In conversation about 2 months ago from masto.ai permalink
  19. Embed this notice
    Nonilex (nonilex@masto.ai)'s status on Tuesday, 15-Apr-2025 22:24:54 JST Nonilex Nonilex
    in reply to

    The #whistleblower's account is corroborated by internal documentation & was reviewed by 11 technical experts across other govt agencies & the private sector. In total, NPR spoke to >30 sources across govt, private sector, #labor movement, #cybersecurity & #law enforcement who had their own concerns about how #DOGE & the #Trump admin might be handling sensitive #data, & the implications for its exposure. The following account comes from the whistleblower's ofcl disclosure & interviews w/ #NPR.

    In conversation about 2 months ago from masto.ai permalink
  20. Embed this notice
    Nonilex (nonilex@masto.ai)'s status on Tuesday, 15-Apr-2025 22:24:52 JST Nonilex Nonilex
    in reply to

    For #cybersecurity professionals, a failure to log activity is a cardinal sin & contradicts best practices as recommended by the National Institute of Standards & Technology [#NIST] & the #DHS's #CISA, as well as the #FBI & the #NSA.

    "That was a huge red flag," said Berulis. "That's something that you just don't do. It violates every core concept of security & best practice."

    #criminal #law #Trump #Musk #DOGE #InfoSec #NationalSecurity

    In conversation about 2 months ago from masto.ai permalink
  • After
  • Before

Feeds

  • Activity Streams
  • RSS 1.0
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.