GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by BrianKrebs (briankrebs@infosec.exchange)

  1. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 03-Jun-2026 22:05:21 JST BrianKrebs BrianKrebs

    My follower count here seems to have dropped by ~750-1,000 overnight. I'm guessing there was some kind of cleanup done on botted accounts or something? Or maybe I just pissed a lot of people off at once (totally possible).

    In conversation about a day ago from infosec.exchange permalink
  2. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 03-Jun-2026 20:54:09 JST BrianKrebs BrianKrebs
    in reply to
    • Rich Felker

    @dalias They got access to 20 encrypted vaults. They'd still have to work out the master password for those targeted accounts. Theoretically, that could be done offline, as happened w/ the breach at LastPass, but it took many months for a lot of those stolen vaults to be cracked.

    In conversation about a day ago from infosec.exchange permalink
  3. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 03-Jun-2026 20:49:56 JST BrianKrebs BrianKrebs

    RE: https://infosec.exchange/@briankrebs/116670688015956223

    Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for "fewer than 20 personal plan users." Dashlane said there was no evidence of a hack of its own systems, but it hasn't shared yet why or how that 2FA was compromised. The company said “the goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts,” and that it has already notified affected users.

    https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts?7194ef805fa2d04b0f7e8c9521f97343

    In conversation about a day ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.infosec.exchange
      BrianKrebs (@briankrebs@infosec.exchange)
      from BrianKrebs
      Attached: 1 image This looks ominous. The password manager service Dashlane apparently is investigating some strange "Account suspended -- please contact us" emails going out, as well as related login difficulties. I noticed this after a reader and Dashlane user wrote in to say he's on a family plan and he received a notification that they'd locked his account because there was an attempt to add a device and too many MFA failures. Here's what their techs are telling customers: "Thank you for reaching out to us! It's Gustavo from Dashlane Customer Support. I am very sorry for any inconvenience this issue has caused. We are currently investigating an issue regarding unexpected emails with the subject "Account suspended - please contact us", as well as some related login difficulties. Our engineering team is actively working on a resolution. While we investigate, please follow these important recommendations to ensure you retain access to your data: - Do not attempt to change or reset your Master Password at this time. - Do not log out of Dashlane on any device where you are currently logged in. We are treating this with the highest priority and will update you as soon as we have more information or a definitive fix. Thank you for your patience and understanding while we sort this out." Their account status page now says: May 31, 2026 17:50 UTC INVESTIGATING We are continuing to investigate the "Account suspended" notifications. Our engineering teams are actively working on a resolution and investigating the root cause of these messages. We are treating this with the highest priority and will provide further updates here as soon as more information becomes available. Thank you for your continued patience and understanding. May 31, 2026 15:19 UTC INVESTIGATING We have received reports from several users having received an email that their account has been suspended. We have also received reports that some users are experiencing difficulties in logging in to Dashlane after resetting their master password. We are investigating this situation, and we will provide further updates as soon as we have more information. Thank you for your understanding. #dashlane
  4. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Tuesday, 02-Jun-2026 03:17:51 JST BrianKrebs BrianKrebs

    New, by me: A number of high-profile and/or valuable Instagram accounts, including those of the Obama White House and the Chief Master Sergeant for the U.S. Space Force, got hacked and defaced with pro-Iran messaging in the past 24h after people figured out that Meta's AI support assistant could be tricked into resetting account passwords.

    From the story:

    "A video released on Telegram by pro-Iran hackers claimed to document a remarkably simple exploit that appears to have involved using a VPN connection with an IP address that is in or near the target's usual hometown, requesting a password reset for the account, and then choosing to chat with Meta's AI support assistant. From there, the video shows the attacker told the bot to link the account in question to a new email address, after which the bot dutifully sent that address a one-time code that allowed a password reset."

    https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/

    #meta #instagram #hack #ai #security

    In conversation about 3 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/676/069/247/046/679/original/9371ad67d54f3427.png
    2. Domain not in remote thumbnail source whitelist: krebsonsecurity.com
      Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
      The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta's…
  5. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Monday, 01-Jun-2026 05:44:43 JST BrianKrebs BrianKrebs

    Get this man a wambulance. The POTUS is having such a hissy fit over multiple musical artists bowing out of invitations to celebrate our nation's 250th anniversary on July 4 that he's now saying all the performances should be canceled and we should have a big MAGA rally on the mall featuring him blathering on w/ his usual lies and hate.

    Rather than respond to the artists' complaint that he'd politicized and personalized what should be a cause for national unity, he doubled down.

    "So I am thinking about bringing the Number One Attraction anywhere in the World, the man who gets much larger audiences than Elvis in his prime...and the man who some say is the Greatest President in History (THE GOAT!), DONALD J. TRUMP, to take the place of these highly paid, Third Rate 'Artists.'"

    "Trump said he was ordering aides to assess "the feasibility of doing an AMERICA IS BACK Rally" on the mall, where he would deliver a speech "rallying the Country forward like I have done ever since being President!"

    Oh well, just another venerated tradition, destination and celebration in my hometown garishly marred by the president's unquenchable thirst for attention and power.

    https://www.yahoo.com/news/politics/articles/trump-calls-replacing-us-250th-002946144.html

    In conversation about 4 days ago from infosec.exchange permalink
  6. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Sunday, 31-May-2026 21:44:36 JST BrianKrebs BrianKrebs

    NPR laid off about 4 percent of its content division, including 10 journalists and some veteran reporters.

    ""People love science," NPR Science Correspondent Nell Greenfieldboyce, who was laid off Wednesday, said in an interview for this story. "It's such a break from the political and economic and often grim news to have something more inspiring and curiosity driven. I thought it was a great blessing to have the opportunity to give that to people."

    https://www.npr.org/2026/05/27/nx-s1-5836624/npr-layoffs-job-cuts

    #media #layoffs #journalism

    In conversation about 4 days ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: npr.brightspotcdn.com
      NPR's newsroom shrinks through buyouts and layoffs
      At least 18 NPR journalists have accepted buyouts and another 10 have been laid off as the public media network attempts to save money and reorganize the newsroom.
  7. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Sunday, 31-May-2026 11:01:49 JST BrianKrebs BrianKrebs
    in reply to

    One more thing: I'm looking forward to a hearing in Congress about this. The "Private-CISA" repo included AWS keys for at least two different Nightwing contractors, including terraform scripts from another employee with embedded clear text credentials, suggesting there was a practice of sharing credentials.

    In conversation about 4 days ago from infosec.exchange permalink
  8. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Sunday, 31-May-2026 11:01:49 JST BrianKrebs BrianKrebs
    in reply to

    Somehow I missed this story in my research concerning Nightwing, the Virginia government contractor where the CISA contractor worked.

    May 2, 2025: Raytheon, Nightwing to Pay $8.4 Million in Settlement Over Cybersecurity Failures

    "The US government on Thursday announced that it has reached a settlement with Raytheon, RTX Corporation, and Nightwing Group in a lawsuit over the companies’ alleged failures to meet cybersecurity requirements for defense contractors.

    Raytheon, a subsidiary of RTX Corporation (previously Raytheon Technologies Corporation), and its then-subsidiary Raytheon Cyber Solutions, Inc. (RCSI), allegedly failed to comply with cybersecurity requirements in 29 contracts and subcontracts with the Department of Defense (DoD). Nightwing is a cybersecurity and intelligence company that spun out of RTX.

    According to the settlement, between 2015 and 2021, Raytheon did not implement necessary cybersecurity controls on a system used to perform work on DoD contracts. In 2015, the company landed a DHS cybersecurity contract worth $1 billion.

    Raytheon and RCSI allegedly not only failed to implement a security plan for the internal development system, but also failed to ensure that it complied with other Defense Federal Acquisition Regulation Supplement (DFARS) and Federal Acquisition Regulation (FAR) requirements.

    Per DFARS and FAR, contractors are required to apply basic safeguarding to systems that process or store federal contract data, and to provide adequate security for those systems, respectively."

    https://www.securityweek.com/raytheon-to-pay-8-4-million-in-settlement-over-cybersecurity-failures/amp/

    In conversation about 4 days ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.securityweek.com
      Raytheon, Nightwing to Pay $8.4 Million in Settlement Over Cybersecurity Failures
      from @https://twitter.com/IonutArghire
      The US government says defense contractor Raytheon and Nightwing agreed to pay $8.4 million to settle False Claims Act allegations.
  9. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Sunday, 31-May-2026 01:59:51 JST BrianKrebs BrianKrebs

    Big companies have an expensive new addiction to AI, and their smack is getting more expensive. Who could have seen this coming? From the WSJ:

    "Use of artificial intelligence by big companies is exploding—and the soaring cost has some of them pumping the brakes in a way that could complicate AI’s triumphal march across the economy.
    Executives across industries this year have urged employees to integrate AI tools into their work, spending freely to encourage experimentation and seeking to send a message to Wall Street that their companies won’t be left behind in a coming wave of disruption."

    "All that enthusiasm has resulted in skyrocketing costs for so-called tokens, the basic unit of measurement for AI computing, as AI model providers seek to balance supply and demand and manage their own costs. Some enterprises have hit their annual budget in just three months or reported seeing their AI spending bills double or triple."
     
    "Now corporate leaders are scrambling to bring down expenses by finding ways to ration AI use in their organizations, steer workers toward cheaper, homegrown tools and help them hone their skills to improve returns." 

    https://www.wsj.com/tech/ai/corporate-america-is-starting-to-ration-ai-as-cost-skyrockets-1eb99d7a (paywall)

    https://archive.ph/v2dwg

    In conversation about 5 days ago from infosec.exchange permalink

    Attachments



  10. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Monday, 25-May-2026 22:48:00 JST BrianKrebs BrianKrebs
    in reply to
    • Kevin Beaumont

    @GossiTheDog Right. Meanwhile, the guy running it just continues to tell the media with a straight face that they never really got any abuse complaints. My response to that is yea that's what happens when your abuse mailbox goes straight to /dev/null/.

    In conversation about 10 days ago from infosec.exchange permalink
  11. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Sunday, 24-May-2026 02:59:57 JST BrianKrebs BrianKrebs

    TIL there is a deleted verse at the end of the song The Day the Music Died, just after the bit about how the man there said the music wouldn't play.

    "And there I stood alone and afraid
    I dropped to my knees, and there I prayed
    And I promised Him everything I could give. If only He would make the music live
    And He promised it would live once more
    But this time one would equal four
    And in five years, four had come to mourn
    And the music was reborn"

    [edited title of song doh]

    In conversation about 12 days ago from infosec.exchange permalink
  12. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Sunday, 24-May-2026 02:21:28 JST BrianKrebs BrianKrebs

    Say hello to Fred. I named him b/c I keep seeing him in the same place on trail walks. At least I think it's the same guy. Okay I don't even know if it's a he. But I still call him Fred. Anyway, he looks big, here, but he's actually just a little bigger than a golf ball.

    #fredtheturtle

    In conversation about 12 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/625/012/184/156/401/original/25ea4c1df5298798.png
  13. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Sunday, 24-May-2026 02:08:55 JST BrianKrebs BrianKrebs

    I'm sort of wimpy around spiders, but I was marveling at this mama wolf spider outside our door. That is, until I realized she was carrying hundreds of copies of herself on her back that will soon invade our home (several days of heavy rain have forced a ton of creepy crawly things indoors). BUT, they will also eat lots of bugs, so..

    In conversation about 12 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/624/972/637/865/985/original/9fb94d15416bc9fd.png
  14. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Saturday, 23-May-2026 02:42:53 JST BrianKrebs BrianKrebs
    in reply to
    • Evan Prodromou

    @evan Obligatory reference: https://www.youtube.com/watch?v=n0wWHTMMuSc

    In conversation about 13 days ago from infosec.exchange permalink

    Attachments

    1. That there's some good in this world, Mr Frodo and it's worth fighting for - The Two Towers
      from Shah
      Frodo : What are we holding onto, Sam?Sam : That there's some good in this world, Mr. Frodo... and it's worth fighting for.J. R. R. Tolkien - The Lord of the...
  15. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Saturday, 23-May-2026 02:40:25 JST BrianKrebs BrianKrebs
    in reply to

    There's a tendency for organizations to react to inadvertently exposing secrets in public code repositories by disabling the repo in question on GitHub, but then taking their time to rotate the exposed credentials. I guess the thinking is that well, maybe nobody noticed. And that's pure folly. From today's story:

    "Ayrey said his company Truffle Security monitors GitHub and a number of other code platforms for exposed keys, and attempts to alert affected accounts to the sensitive data exposure(s). They can do easily on GitHub because the platform publishes a live feed which includes a record of all commits and changes to public code repositories. But he said cybercriminal actors also monitor these public feeds, and are often quick to pounce on API or SSH keys that get inadvertently published in code commits."

    "In practical terms, it is likely that cybercrime groups or foreign adversaries also noticed the publication of these CISA secrets, the most egregious of which appears to have happened in late April 2025, Ayrey said.

    “We monitor that firehose of data for keys, and we have tools to try to figure out whose they are,” he said. “We have evidence attackers monitor that firehose as well. Anyone monitoring GitHub events could be sitting on this information.”"

    In conversation about 13 days ago from infosec.exchange permalink
  16. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Saturday, 23-May-2026 01:41:40 JST BrianKrebs BrianKrebs

    New, by me: Lawmakers Demand Answers as CISA Tries to Contain Data Leak

    "Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials."

    From the story:

    "KrebsOnSecurity has learned that more a week after CISA was first notified of the data leak by the security firm GitGuardian, the agency is still working to invalidate and replace many of the exposed keys and secrets."

    "On May 20, KrebsOnSecurity heard from Dylan Ayrey, the creator of TruffleHog, an open-source tool for discovering private keys and other secrets buried in code hosted at GitHub and other public platforms. Ayrey said CISA still hadn’t invalidated an RSA private key exposed in the Private-CISA repo that granted access to a GitHub app which is owned by the CISA enterprise account and installed on the CISA-IT GitHub organization with full access to all code repositories."

    https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leak/

    In conversation about 13 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/619/204/346/413/400/original/e1050233c912b78d.png
    2. Domain not in remote thumbnail source whitelist: krebsonsecurity.com
      Lawmakers Demand Answers as CISA Tries to Contain Data Leak
      Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets…
  17. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Friday, 22-May-2026 06:56:30 JST BrianKrebs BrianKrebs

    New, from me: Alleged Kimwolf Botmaster 'Dort' Arrested, Charged in U.S. and Canada

    Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns against this author and a security researcher. He now faces criminal hacking charges in both Canada and the United States.

    https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/

    #botnet #ddos #kimwolf #cybercrime

    In conversation about 14 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/614/785/287/827/638/original/7ca0139dd95d9650.png
  18. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Thursday, 21-May-2026 04:25:04 JST BrianKrebs BrianKrebs

    Check it: Sen. Maggie Hassan (D-NH) is demanding answers from CISA and DHS over my reporting this week that a CISA contractor had published on GitHub a number of CISA AWS GovCloud keys and a ton of plaintext passwords, SSH keys, etc. for internal CISA resources.

    ICYMI:

    https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/

    https://www.hassan.senate.gov/news/press-releases/senator-hassan-presses-for-answers-on-major-reported-data-leak-at-leading-cybersecurity-agency

    #cisa #cybersecurity #databreach

    In conversation about 15 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/608/334/268/532/032/original/0f56c047ed3a6bd6.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/608/357/179/484/950/original/1acdf7241bf633c1.png

  19. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Tuesday, 19-May-2026 10:00:37 JST BrianKrebs BrianKrebs

    New, by me: CISA Admin Leaked AWS GovCloud Keys on GitHub

    Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

    https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/

    In conversation about 16 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/597/563/541/512/344/original/8f9a823d2ae9bc9c.png
  20. Embed this notice
    BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 13-May-2026 07:35:08 JST BrianKrebs BrianKrebs

    We've come to an icky time in security when the concern about using outdated, unpatched software starts to become overshadowed by the fear of downloading some backdoored update.

    In conversation about 23 days ago from infosec.exchange permalink
  • Before

User actions

    BrianKrebs

    BrianKrebs

    Independent investigative journalist. Covers cybercrime, security, privacy. Author of 'Spam Nation,' a NYT bestseller. Former Washington Post reporter, '95-'09. Signal: briankrebs.07 krebsonsecurity @ gmail .comLinkedin: https://www.linkedin.com/in/bkrebs

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          21764
          Member since
          9 Nov 2022
          Notices
          630
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.