GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Ravi Nayyar (ravirockks@infosec.exchange)

  1. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Monday, 05-May-2025 14:02:47 JST Ravi Nayyar Ravi Nayyar

    'In an April 2020 guide ... Signal had been approved ... “official decisions made on this platform must be documented and saved to [the records management system]”.

    '... instructed on how to turn on disappearing messages in Signal ... not to enable chat backup.

    'A separate policy document ... advised employees to “extract, take a screenshot or take note of any official business conducted on a mobile messaging application” for recording'.
    https://www.theguardian.com/australia-news/2025/may/05/home-affairs-let-staff-use-signal-and-disappearing-messages-amid-covid-lockdowns-documents-show

    In conversation about a month ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: i.guim.co.uk
      Australia’s home affairs department has let staff use Signal since Covid lockdowns, documents show
      from https://www.theguardian.com/profile/josh-taylor
      Australian government’s use of Signal comes into focus after Trump administration group chat scandal
  2. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Monday, 05-May-2025 13:40:29 JST Ravi Nayyar Ravi Nayyar

    'A Reuters review of almost 100 Chinese and Hong Kong companies added to the U.S. entity list in 2023 and 2024 found more than a quarter, or 26 entries, contained erroneous details ...

    '... trade in restricted items by some entities, aided by loopholes, paper companies and networks of freight forwarders and shipping agents ...

    'BIS is "woefully under-resourced" ...

    'Makkaveev said he got around his company's blacklisting by setting up two new firms on Hong Kong's Companies Registry, which took less than a week. He said he used e-commerce platforms to process payments after banks shunned him.

    'At one COMSEC firm, Inter Group, a manager surnamed Yang said it still represented hundreds of companies linked to people in Russia'.
    https://www.reuters.com/sustainability/boards-policy-regulation/us-blacklist-china-is-riddled-with-errors-outdated-details-2025-05-02/

    In conversation about a month ago from infosec.exchange permalink

    Attachments


  3. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Thursday, 24-Apr-2025 13:22:25 JST Ravi Nayyar Ravi Nayyar
    in reply to
    • Patrick C Miller :donor:

    @patrickcmiller You can tell how much fun the sub-editor had with the headline - well done.

    In conversation about a month ago from infosec.exchange permalink
  4. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Thursday, 10-Apr-2025 09:53:19 JST Ravi Nayyar Ravi Nayyar

    'Reuters, drawing from a headline on CNBC, published a story ... Reuters has withdrawn the incorrect report and regrets its error.

    'As we [CNBC] were chasing the news of the market moves in real-time, we aired unconfirmed information in a banner'.

    Mainstream media should know better, especially when they keep telling us how they are the defenders of our democracy and stuff.

    Also, an appalling headline which does not mention the root cause being stuff-ups by legacy outlets.
    https://techcrunch.com/2025/04/07/how-one-tweet-wreaked-havoc-on-the-stock-market/

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: techcrunch.com
      How one tweet wreaked havoc on the stock market | TechCrunch
      from Amanda Silberling
      Amid a morning of pandemonium on Wall Street, a popular news aggregator on X, known as Walter Bloomberg, posted a false report declaring that President
  5. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Sunday, 30-Mar-2025 17:57:42 JST Ravi Nayyar Ravi Nayyar

    'If you hit yourself in the face with a hammer, it’s not the hammer’s fault. It’s really on you to make sure you know who you’re talking to.

    '… the use of Signal suggests … were conducting the conversation on internet-connected devices—possibly even including personal ones—since Signal wouldn’t typically be allowed on the official, highly restricted machines intended for such conversations.

    '… the core issue was communicating about incredibly high-stakes, secret military operations using inappropriate devices or software.

    'Multiple sources … noted specifically that downloading consumer apps like Signal to Defense Department devices is highly restricted and often banned … [SECDEF] either obtained an extremely unusual waiver to install Signal on a department [of Defense] device, bypassed the standard process for seeking such a waiver, or was using a non-DOD device for the chat.

    '… Hegseth himself is the classification authority for the information.

    '… establishing an information designation or declassifying information happens through an established, proactive process'.

    Core issue with Signalgate = Governance, governance, governance!
    https://www.wired.com/story/signalgate-isnt-about-signal/

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.wired.com
      SignalGate Isn’t About Signal
      from Andy Greenberg,Lily Hay Newman
      The Trump cabinet’s shocking leak of its plans to bomb Yemen raises myriad confidentiality and legal issues. The security of the encrypted messaging app Signal is not one of them.
  6. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 15:01:20 JST Ravi Nayyar Ravi Nayyar

    '... researcher with no prior malware coding experience successfully tricked popular generative AI (GenAI) tools—including DeepSeek, Microsoft Copilot, and OpenAI’s ChatGPT—into developing malware that can steal login credentials from Google Chrome'.

    Well done, mate.
    https://www.catonetworks.com/blog/2025-cato-ctrl-threat-report-top-4-ai-predictions-for-the-year-ahead/

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.catonetworks.com
      2025 Cato CTRL™ Threat Report: Top 4 AI Predictions for the Year Ahead
      from Etay Maor
      Cato CTRL outlines the top 4 AI predictions in 2025, including AI agent exploits. Stay ahead — read now!
  7. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 14:43:50 JST Ravi Nayyar Ravi Nayyar

    '[MSFT] has walked away from new data center projects in the US and Europe ... about 2 gigawatts of electricity ... attributed the pullback to an oversupply of the [computing] clusters ...

    '... reflected the company’s choice to forgo some new business from ChatGPT maker OpenAI ...

    '... Google had stepped in to grab some leases Microsoft abandoned in Europe ... while [Meta] ... had scooped up some of the freed capacity in Europe.

    '... we [MSFT] are well positioned to meet our current and increasing customer demand ... added more capacity than in any other year in its history.

    'After a frantic expansion to support OpenAI and other artificial intelligence projects, the company expects spending to shift from new construction to fitting out data centers with servers and other equipment.

    '... believe the lease cancellations and deferrals of capacity points to data center oversupply relative to its current demand forecast ...'
    https://archive.md/7Lae0

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: archive.md
      Microsoft Abandons Data Center Projects, TD Cowen Says - Bloomberg
      archived 29 Mar 2025 01:18:57 UTC
  8. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 14:08:22 JST Ravi Nayyar Ravi Nayyar

    Three words: The right call.
    https://www.malaymail.com/news/malaysia/2025/03/25/not-even-five-seconds-to-decide-anwar-says-rejected-us10m-ransom-demand-after-mahb-hacking/170765

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.malaymail.com
      ‘Not even five seconds to decide’: Anwar says rejected US$10m ransom demand after MAHB ‘hacking’
      from Muhammad Yusry
      KUALA LUMPUR, March 25 — Prime Minister Datuk Seri Anwar Ibrahim today revealed that an alleged hacker recently demanded US$10 million from the government after a cyber-attack...
  9. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:52:20 JST Ravi Nayyar Ravi Nayyar
    in reply to

    'On February 21, in Helsinki, Finland, Executive Vice-President Henna Virkkunen presented the Joint Communication of the Commission and the HRVP to strengthen the security and resilience of submarine cables'.

    Missed this.
    https://digital-strategy.ec.europa.eu/en/news/commission-and-high-representative-present-strong-actions-enhance-security-submarine-cables

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: digital-strategy.ec.europa.eu
      Commission and the High Representative present strong actions to enhance security of submarine cables
      On February 21, in Helsinki, Finland, Executive Vice-President Henna Virkkunen presented the Joint Communication of the Commission and the HRVP to strengthen the security and resilience of submarine cables.
  10. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:52:20 JST Ravi Nayyar Ravi Nayyar

    Ah: https://therecord.media/finland-eagle-s-tanker-released-3-crew-still-detained

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cms.therecord.media
      Finland releases Russian ‘spy’ ship but continues to detain three crew members as suspects
      Finnish authorities have released the oil tanker Eagle S but are detaining three crew members as the investigation continues into the undersea infrastructure damage caused by the vessel.

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/102/291/530/926/744/original/59929c49998aaf32.png
  11. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:52:20 JST Ravi Nayyar Ravi Nayyar

    ‘The owner of the cable, Finnish telecom operators Cinia, said it detected minor damage to its fibre-optic cable but added it was still functioning as usual.

    ‘Cinia also said it is the third time this cable has been damaged in recent months’.

    Again?
    https://www.bbc.com/news/articles/cy5nydr9rqvo

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: ichef.bbci.co.uk
      Sweden investigates suspected sabotage of undersea telecoms cable
      A Baltic Sea cable has been damaged for the third time in recent months, Finnish telecom operators say.
  12. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:52:20 JST Ravi Nayyar Ravi Nayyar
    in reply to

    'We welcome that NATO has launched the enhanced Vigilance Activity “Baltic Sentry” to improve situational awareness and deter hostile activities ... NATO´s Maritime Centre for the Security of Critical Undersea Infrastructure and NATO´s Critical Undersea Infrastructure Network will support efforts ...

    'As an example, the Commander Task Force-Baltic works towards establishing an integrated regional picture on critical infrastructure in the Baltic Sea that contributes to NATO’s work in protecting critical undersea infrastructure.

    'We will also take actions for accountability and stronger enforcement against those responsible for damaging undersea infrastructure, including compensation for damage. [What if it's China?]

    'We will take further steps to enhance resilience of our communications network and energy infrastructure, including reliable supply chains, enhancing physical and cybersecurity measures, developing European undersea surveillance capabilities and swift repair capacity, engaging with the private sector.

    'In close coastal state co-operation, we are increasing surveillance of the vessels, including the inspections of vessel insurance certificates'.

    No mention of China in here. Only Russia.
    https://www.presidentti.fi/joint-statement-of-the-baltic-sea-nato-allies-summit/

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.presidentti.fi
      Joint Statement of the Baltic Sea NATO Allies Summit - Presidentti
      from Katja Uusi-Hakala
      President of Finland Alexander Stubb, Prime Minister of Estonia Kristen Michal, Prime Minister of Denmark Mette Frederiksen, Federal Chancellor of Germany Olaf Scholz, President of Latvia Edgars Rinkēvičs, President of Lithuania Gitanas Nausėda, Prime Minister of Poland Donald Tusk and Prime Minister of Sweden Ulf Kristersson have issued a joint statement in the presence of […]
  13. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:52:20 JST Ravi Nayyar Ravi Nayyar
    in reply to

    'The suspected culprit behind the damage, the Eagle S, has been seized and transferred to the oil port of Kilpilahti in Porvoo, east of Helsinki, while investigators continue to analyze devices from the ship and question its crew on suspicion of aggravated criminal mischief. Last week, the NBI said eight of the ship’s crew — an increase from the initial seven — had been issued with travel bans so they could continue to be questioned'.
    https://therecord.media/finland-russia-spy-ship-anchor

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cms.therecord.media
      Finland finds Russian ‘spy’ ship anchor as subsea cable company demands ship’s seizure for compensation
      Finnish authorities investigating a series of submarine cable breaks have retrieved an anchor suspected of being dragged along the Baltic Sea floor by an alleged Russian spy ship.
  14. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:51:50 JST Ravi Nayyar Ravi Nayyar

    ‘… the communications cable between Lithuania and Sweden was also damaged.

    ‘Meanwhile, data transmission between Finland and Germany was completely interrupted.

    ‘The failure of the only link between Finland and Central Europe …’
    https://www.lrt.lt/en/news-in-english/19/2416006/undersea-cable-between-lithuania-and-sweden-damaged-telia

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.lrt.lt
      Undersea cable between Lithuania and Sweden damaged – Telia
      from https://www.facebook.com/lrtlt
      A telecommunications cable running between Lithuania and Sweden in the Baltic Sea has been damaged, Telia Lietuva, a Swe...
  15. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:51:49 JST Ravi Nayyar Ravi Nayyar
    in reply to

    SHOCKING!
    https://www.reuters.com/world/europe/finland-finds-drag-marks-baltic-seabed-after-cable-damage-2024-12-29/

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


  16. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:51:49 JST Ravi Nayyar Ravi Nayyar
    in reply to

    Good, but if only the Swedes could have lawfully seized the Yi Peng 3 re that cable cut.

    Of course, ‘can’t upset the Chinese’ despite their sponsorship of the Russians.
    https://www.abc.net.au/news/2024-12-27/finland-seizes-tanker-after-underwater-power-cable-outage/104765296

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: live-production.wcms.abc-cdn.net.au
      Finland seizes tanker suspected of causing underwater power cable outage
      The Nordic country's National Bureau of Investigation says the ship is suspected of towing an anchor that caused damage to a source of electricity powering Estonia.
  17. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:51:49 JST Ravi Nayyar Ravi Nayyar
    in reply to

    👇🏼
    https://blog.cloudflare.com/resilient-internet-connectivity-baltic-cable-cuts

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


    1. Invalid filename.
  18. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:51:49 JST Ravi Nayyar Ravi Nayyar
    in reply to

    'Danish authorities appear to have narrowed down a possible culprit to Chinese bulker Yi Peng 3, which traveled over the reported incident site at the time of the failure. Its AIS track shows the vessel drifting back and forth for around an hour the morning of November 18.

    'By the time Yi Peng 3 reached Danish waters the country’s Navy had dispatched several vessels shadowing the vessel. Online reports suggest that a Danish pilot was placed onboard the vessel during the afternoon of November 19 as it continued passing through Danish Straits.

    'The Finnish investigation of the [earlier] NewNew Polar Bear incident concluded that the vessel dropped its anchor during a storm dragging it over the Balticonnector pipeline. The vessel had been spotted with a missing anchor during its first port call following the incident'.
    https://gcaptain.com/details-of-baltic-sea-cable-incident-remain-murky-as-danish-coast-guard-shadows-chinese-vessel/

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: gcaptain.com
      Details of Baltic Sea Cable Incident Remain Murky as Danish Navy Shadows Chinese Vessel
      from @gcaptain
      A day after the C-Lion1 and BCS subsea data cables in the Baltic Sea, connecting Finland and Germany as well as Sweden and Lithuania, were damaged, specifics of the incident remain unconfirmed. 
  19. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:51:48 JST Ravi Nayyar Ravi Nayyar

    Ah.
    https://therecord.media/sweden-releases-ship-suspected-cable-sabotage

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cms.therecord.media
      Sweden releases suspected ship, says cable break ‘clearly’ not sabotage
      Sweden's Prosecution Authority said a Baltic Sea cable break was a "combination of weather conditions and deficiencies in equipment and seamanship" and not sabotage.
  20. Embed this notice
    Ravi Nayyar (ravirockks@infosec.exchange)'s status on Saturday, 29-Mar-2025 10:51:48 JST Ravi Nayyar Ravi Nayyar
    in reply to

    From an excellent piece by James Corera and Jakub Janda:

    'Once could be an accident, and twice might be a coincidence. But three instances look like a trend that we shouldn’t ignore or tolerate, especially since we know malign actors like Beijing and Moscow also have the capability to disrupt our critical infrastructure through prepositioned malware.

    'Since China has persistently breached the same convention in the South China Sea, its disregard for the interests of other countries in the Yi Peng 3 case comes as no surprise.

    'A refusal to comply with international investigative norms also encourages other states to act similarly.

    'These incidents show how the Russia-China axis is increasingly working in sync to the peril of the rules-based liberal order'.
    https://www.aspistrategist.org.au/baltic-subsea-sabotage-china-gets-away-with-non-cooperation/

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.aspistrategist.org.au
      Baltic subsea sabotage: China gets away with non-cooperation | The Strategist
      from Jakub Janda
      On Christmas Day, one of two cables connecting Finland’s electricity grid to Estonia, Latvia and Lithuania was cut. Four data cables—three linking Finland and Estonia and one between Finland and Germany—were broken at the same ...
  • Before

User actions

    Ravi Nayyar

    Ravi Nayyar

    Critical Software + Critical Infrastructure Law | PhD Candidate at the University of Sydney | Fellow and Research Contributor at the Australian Strategic Policy Institute | Associate Fellow at the Social Cyber Institute | Blogging at A Techno-Legal Update | Cricket, #Bloods, Bharatiyata | #StillRomancingWithLife

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          164635
          Member since
          29 Aug 2023
          Notices
          69
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.