GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Zeljka Zorz (zeljkazorz@infosec.exchange)

  1. Embed this notice
    Zeljka Zorz (zeljkazorz@infosec.exchange)'s status on Tuesday, 29-Apr-2025 00:07:10 JST Zeljka Zorz Zeljka Zorz

    When asked what privacy means to him, Altman answered that he “would be too shy to say that in this room.” :blob_gnikniht:

    https://therecord.media/sam-altman-openai-privacy-safeguards

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cms.therecord.media
      Sam Altman: AI privacy safeguards can’t be established before ‘problems emerge’
      “It's very difficult to predict all of this in advance,” said Sam Altman, who has run OpenAI since 2019, at a major privacy conference in Washington, D.C. “Dynamic response is the only way to responsibly figure out the right guardrails for new technology.”
  2. Embed this notice
    Zeljka Zorz (zeljkazorz@infosec.exchange)'s status on Saturday, 08-Feb-2025 03:14:08 JST Zeljka Zorz Zeljka Zorz
    in reply to
    • Kevin Beaumont
    • buherator
    • screaminggoat
    • buherator

    @buherator@infosec.place @GossiTheDog @screaminggoat

    Symantec says their protection bulletin was prompted by the AhnLab blog post.

    I believe @buherator is right. Whether Microsoft found a continuation of the same campaign, with a slightly different approach / toolset, is impossible to tell.

    Judging by the capabilities provided by the Godzilla post-exploitation framework and the Godzilla webshell, I wold venture to say that they are one and the same, only Microsoft used that particular expression (and did not elaborate on it, which means they expect the readers to be familiar with it already - i.e., it's known and documented).

    In conversation about 4 months ago from infosec.exchange permalink
  3. Embed this notice
    Zeljka Zorz (zeljkazorz@infosec.exchange)'s status on Saturday, 08-Feb-2025 03:13:44 JST Zeljka Zorz Zeljka Zorz
    in reply to
    • Kevin Beaumont
    • buherator

    @buherator @GossiTheDog

    Or ASEC: https://asec.ahnlab.com/en/85088/

    They go in more detail, but mention ASP.NET environments with vulnerable configurations.

    Unfortunately, I don't know enough about ASP.NET to make an educated guess whether these attacks could be related.

    In conversation about 4 months ago from gnusocial.jp permalink

    Attachments



  4. Embed this notice
    Zeljka Zorz (zeljkazorz@infosec.exchange)'s status on Saturday, 08-Feb-2025 03:13:44 JST Zeljka Zorz Zeljka Zorz
    in reply to
    • Kevin Beaumont
    • buherator

    @buherator @GossiTheDog

    Is it possible that Broadcom/Symantec spotted these same attacks earlier?

    https://www.broadcom.com/support/security-center/protection-bulletin/godzilla-webshell-deployment-campaign

    In conversation about 4 months ago from infosec.exchange permalink
  5. Embed this notice
    Zeljka Zorz (zeljkazorz@infosec.exchange)'s status on Wednesday, 04-Dec-2024 01:31:47 JST Zeljka Zorz Zeljka Zorz

    A joint investigation team involving French and Dutch authorities has taken down Matrix, yet another end-to-end encrypted chat service created for criminals.

    Matrix – also know as Mactrix, Totalsec, X-quantum, and Q-safe – was first identified by Dutch authorities on the phone of a criminal convicted for the murder of Dutch crime journalist Peter R. de Vries in 2021, and the discovery prompted an investigation into the service.

    https://www.helpnetsecurity.com/2024/12/03/matrix-encrypted-chat-takedown/

    #Cybersecurity #Encryption #Europe

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/589/637/248/815/751/original/8860d75068875dc3.webp
  6. Embed this notice
    Zeljka Zorz (zeljkazorz@infosec.exchange)'s status on Thursday, 07-Sep-2023 22:20:09 JST Zeljka Zorz Zeljka Zorz
    • LibreOffice
    • The Document Foundation

    How does the LibreOffice project work on vulnerabilities, supply chain security, and how is it preparing for the EU Cyber Resilience Act?

    https://www.helpnetsecurity.com/2023/09/07/libreoffice-security-development/

    @libreoffice @tdforg #LibreOffice #Cybersecurity #FOSS #OpenSource

    In conversation Thursday, 07-Sep-2023 22:20:09 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosecmediaeu/media_attachments/files/111/023/808/066/604/591/original/f867e657fc038e52.jpg

User actions

    Zeljka Zorz

    Zeljka Zorz

    Editor-in-Chief of Help Net Security.I use this account for work and privately. Work-related interests: Anything and everything to do with information security and related topics.Personal interests: As above, + hiking, painting/art, development and use of language, human psychology, gardening and plant ecology... Always open to picking up new ones and often falling down internet rabbit holes.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          168521
          Member since
          7 Sep 2023
          Notices
          6
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.