GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Metacurity (metacurity@infosec.exchange)

  1. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Thursday, 28-May-2026 02:38:50 JST Metacurity Metacurity

    What could go wrong?

    “The police no longer have to manually review footage. They can feed the system a text prompt, and it finds the footage,” said one executive from Hikvision.
    https://www.ft.com/content/f8fa4739-4359-4720-af77-9be1e8370f82?sharetype=blocked

    In conversation about 12 days ago from infosec.exchange permalink

    Attachments


  2. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Monday, 18-May-2026 22:15:54 JST Metacurity Metacurity

    This is an incredible graphic from CrowdStrike.

    In conversation about 21 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/595/733/298/551/226/original/0462c992f86f70b8.png
  3. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Wednesday, 01-Apr-2026 20:25:15 JST Metacurity Metacurity

    As soon as users log into Perplexity’s home page, trackers are downloaded onto their devices, giving Meta and Google full access to the conversations between them and Perplexity’s AI Machine search engine.
    https://www.bloomberg.com/news/articles/2026-04-01/perplexity-ai-machine-accused-of-sharing-data-with-meta-google

    In conversation about 2 months ago from infosec.exchange permalink

    Attachments


  4. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Wednesday, 25-Feb-2026 20:38:18 JST Metacurity Metacurity
    • bert hubert 🇺🇦🇪🇺🇺🇦

    RE: https://infosec.exchange/@metacurity/116131026500216696

    With great quotes from infosec.exchanges own @bert_hubert

    In conversation about 3 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Metacurity (@metacurity@infosec.exchange)
      from Metacurity
      Exclusive: US orders diplomats to fight data sovereignty initiatives https://www.reuters.com/sustainability/boards-policy-regulation/us-orders-diplomats-fight-data-sovereignty-initiatives-2026-02-25/
  5. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Friday, 13-Feb-2026 04:58:18 JST Metacurity Metacurity

    This would affect about two-thirds of the already dwindled-down CISA workforce, and other valuable DHS components, and that’s not good.

    Otherwise it will eventually make life harder for CBP and ICE and that’s great!

    DHS shutdown imminent as Senate leaves town without deal

    https://www.axios.com/2026/02/12/shutdown-homeland-security-senate-negotiations?stream=politics&utm_source=alert&utm_medium=email&utm_campaign=alerts_politics

    In conversation about 4 months ago from infosec.exchange permalink
  6. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Thursday, 12-Feb-2026 22:11:43 JST Metacurity Metacurity

    Ahead of trade meetings with China, the US has suspended its bans on China Telecom's US operations, domestic sales of routers made by TP-Link, the US internet business of China Unicom and China Mobile, and the sales of Chinese electric trucks and buses in the US.

    https://www.reuters.com/business/media-telecom/us-china-trade-detente-fuels-mothballing-key-china-tech-curbs-2026-02-12/

    In conversation about 4 months ago from infosec.exchange permalink
  7. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Thursday, 12-Feb-2026 07:01:25 JST Metacurity Metacurity

    Those Nest cameras keep videos for three hours on their backend servers even if you're not a subscriber.

    How Google played a key role in recovering the video from Nancy Guthrie’s cameras
    https://www.cnn.com/2026/02/10/tech/google-video-nancy-guthrie

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.cnn.com
      How Google played a key role in recovering the video from Nancy Guthrie’s cameras | CNN Business
      from Hadas Gold, Brian Stelter
      A major breakthrough in the Nancy Guthrie case largely came down to Google’s technical expertise, a person familiar with the investigation told CNN.
  8. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Friday, 06-Feb-2026 07:09:43 JST Metacurity Metacurity

    ICE and CBP’s Face-Recognition App Can’t Actually Verify Who People Are
    https://www.wired.com/story/cbp-ice-dhs-mobile-fortify-face-recognition-verify-identity/

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: media.wired.com
      ICE and CBP’s Face-Recognition App Can’t Actually Verify Who People Are
      from Dell Cameron,Maddy Varner
      ICE has used Mobile Fortify to identify immigrants and citizens alike over 100,000 times, by one estimate. It wasn't built to work like that—and only got approved after DHS abandoned its own privacy rules.
  9. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Friday, 06-Feb-2026 05:16:12 JST Metacurity Metacurity

    It's downright weird that McDonald's is leading a campaign to advise us to use more secure passwords.

    McDonald's is not lovin' your bigmac, happymeal, and mcnuggets passwords
    https://www.theregister.com/2026/02/02/mcdonalds_password_advice/

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: regmedia.co.uk
      McDonald's tells customers to use better passwords
      : Your favorite menu item might be easy to remember but it will not secure your account
  10. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Thursday, 29-Jan-2026 02:56:49 JST Metacurity Metacurity

    App for Quitting Porn Leaked Users' Masturbation Habits
    https://www.404media.co/app-for-quitting-porn-leaked-users-masturbation-habits/

    In conversation about 4 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: images.unsplash.com
      App for Quitting Porn Leaked Users' Masturbation Habits
      from @emanuelmaiberg
      Hundreds of thousands of users told the app intimate details about their sexual urges, which are now exposed.
  11. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Thursday, 08-Jan-2026 04:44:13 JST Metacurity Metacurity

    CORPOELEC calls the munitions that took out power in the attack on Caracas "missiles." Says that it has been able to restore 80% of the lost power.

    Resilience in the face of devastation: CORPOELEC restores electricity service after attack on substations
    https://mppee.gob.ve/?p=103285

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/855/418/947/250/512/original/0632609839936a60.png
    2. Domain not in remote thumbnail source whitelist: mppee.gob.ve
      Resistencia frente a la devastación: CORPOELEC recupera servicio eléctrico tras ataque a subestaciones
      from Prensa
  12. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Monday, 05-Jan-2026 22:07:27 JST Metacurity Metacurity
    • Kevin Beaumont

    @GossiTheDog Confusing, right? But that video shows total obliteration of one of the substations -- why even bother with cyber if you're going to do that?

    In conversation about 5 months ago from infosec.exchange permalink
  13. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Monday, 05-Jan-2026 21:31:53 JST Metacurity Metacurity

    So Venezuela's energy ministry is saying the attack that brought down the power grid in Caracas was a physical assault on substations and not a cyber attack.
    https://mppee.gob.ve/?p=103279

    This contradicts Trump's statement about the US having "expertise" and also the NYT's reporting that the attack "began with a cyberoperation that cut power to large swaths of Caracas." 2/2
    https://www.nytimes.com/2026/01/03/us/politics/trump-capture-maduro-venezuela.html

    Corpoelec's website is not only down for maintenance, it's not accessible at all today. https://corpoelec.gob.ve/

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: mppee.gob.ve
      COMUNICADO | CORPOELEC denuncia ataque perpetrado contra el Sistema Eléctrico Nacional
      from Karla Cotoret


  14. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Monday, 22-Dec-2025 18:59:15 JST Metacurity Metacurity

    Good god

    “At least six career staffers at the Cybersecurity and Infrastructure Security Agency were suspended with pay this summer after organizing a polygraph test that the agency’s acting director, Madhu Gottumukkala, failed.”

    https://www.politico.com/news/2025/12/21/cisa-acting-director-madhu-gottumukkala-polygraph-investigation-00701996?utm_source=dlvr.it&utm_medium=bluesky

    In conversation about 6 months ago from infosec.exchange permalink
  15. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Tuesday, 09-Dec-2025 18:55:57 JST Metacurity Metacurity

    https://www.koreatimes.co.kr/business/companies/20251209/police-raid-coupang-over-massive-data-breach
    This is what happens when you do bad cybersecurity.

    Police reportedly seek to check for possible lapses in Coupang's security, while tracking down the suspect behind the leak. cybersecurity.

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: newsimg.koreatimes.co.kr
      Police raid Coupang over massive data breach - The Korea Times
      from Yonhap
      Police raided the headquarters of e-commerce giant Coupang Inc. on Tuesday over a massive breach of personal information that affected some 34 mill...
  16. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Tuesday, 25-Nov-2025 14:57:41 JST Metacurity Metacurity

    https://www.clickondetroit.com/news/local/2025/11/22/campbell-soup-exec-caught-on-secret-recording-slamming-product-people-who-buy-it/
    The exec caught on the recording was Campbell’s CISO.

    In conversation about 6 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: res.cloudinary.com
      Campbell Soup exec caught on secret recording slamming product, people who buy it
      from Erika Erickson
      An executive with Campbell Soup Company was caught on a secret recording slamming the company’s product and belittling the people who buy it.
  17. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Monday, 24-Nov-2025 18:36:48 JST Metacurity Metacurity

    https://www.theguardian.com/technology/2025/nov/24/civil-liberties-groups-call-for-inquiry-into-uk-data-protection-watchdog

    Dozens of civil liberties campaigners and legal professionals are calling for an inquiry into the UK’s data protection watchdog, after what they describe as “a collapse in enforcement activity” after the scandal of the Afghan data breach.

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Civil liberties groups call for inquiry into UK data protection watchdog
      from https://www.theguardian.com/profile/dianetaylor
      Campaigners including Good Law Project describe ICO ‘collapse in enforcement activity’ after Afghan data breach
  18. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Wednesday, 19-Nov-2025 23:29:00 JST Metacurity Metacurity

    The US and the UK are going after bulletproof hosting companies.

    United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware
    https://home.treasury.gov/news/press-releases/sb0319

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: home.treasury.gov
      United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware
      .caption > figcaption { text-align: center; font-style: italic; } WASHINGTON — Today, the Department of the Treasury’s Office of Foreign Assets Control (OFAC), Australia’s Department of Foreign Affairs and Trade, and the United Kingdom’s Foreign Commonwealth and Development Office are announcing coordinated sanctions targeting Media Land, a Russia-based bulletproof hosting (BPH) service provider, for its role in supporting ransomware operations and other forms of cybercrime.  OFAC is also designating three members of Media Land’s leadership team and three of its sister companies in coordination with the Federal Bureau of Investigation. BPH service providers sell access to specialized servers and other computer infrastructure specifically designed to evade detection and defy law enforcement efforts to disrupt malicious cyber activities.In addition, OFAC and the United Kingdom are designating Hypercore Ltd., a front company of Aeza Group LLC (Aeza Group), a BPH service provider designated by OFAC earlier this year. OFAC, in coordination with its UK partners, is also designating two additional individuals and two entities that have led, materially supported, or acted for Aeza Group.“These so-called bulletproof hosting service providers like Media Land provide cybercriminals essential services to aid them in attacking businesses in the United States and in allied countries,” said Under Secretary of the Treasury for Terrorism and Financial Intelligence John K. Hurley.  “Today’s trilateral action with Australia and the United Kingdom, in coordination with law enforcement partners, demonstrates our collective commitment to combatting cybercrime and protecting our citizens.”Media Land: a key Launching pad for ransomwareMedia Land LLC (Media Land), headquartered in St. Petersburg, Russia, has provided BPH services to criminal marketplaces and ransomware actors, including prolific ransomware actors such as Lockbit, BlackSuit, and Play.  Media Land infrastructure was also utilized in multiple distributed denial-of-service (DDOS) attacks against U.S. victim companies and critical infrastructure.ML Cloud is a Media Land sister company whose technical infrastructure is often used in conjunction with Media Land, including in ransomware and DDOS attacks.Aleksandr Volosovik (Volosovik) is the general director of Media Land and has frequently advertised the Media Land business on cybercriminal forums under the alias “Yalishanda.”  He has provided servers and conducted troubleshooting for ransomware and DDOS actors. Figure 1: Zatolokin Kirill Zatolokin (Zatolokin) is a Media Land employee who is responsible for collecting payment from customers and coordinating with other cyber actors.  He also works closely with Volosovik on Media Land’s overall operations. OFAC is designating Media Land, ML Cloud, Volosovik, and Zatolokin pursuant to Executive Order (E.O.) 13694, as amended by E.O. 13757, E.O. 14144, and E.O. 14306 (“E.O. 13694, as further amended”), for being responsible or complicit in, or having engaged in, directly or indirectly, cyber-enabled activities originating from, or directed by persons located, in whole or in part, outside the United States that are reasonably likely to result in, or have materially contributed to, a threat to the national security, foreign policy, or economic health or financial stability of the United States, and that have the purpose of or involve causing a disruption to the availability of a computer or network of computers or compromising the integrity of the information stored on a computer or network of computers. Figure 2: Volosovik and Pankova Yulia Pankova (Pankova) is aware of Volosovik’s illicit activity, has assisted Volosovik with legal issues, and has handled his finances.  OFAC is designating Pankova pursuant to E.O. 13694, as further amended, for having materially assisted, sponsored, or provided financial, material, or technological support for, or goods, and services to or in support of, Volosovik.Media Land Technology (MLT) and Data Center Kirishi (DC Kirishi) are 100 percent-owned subsidiaries of Media Land.  OFAC is designating MLT and DC Kirishi pursuant to E.O. 13694, as further amended, for being owned or controlled by, or having acted or purported to act for or on behalf of, directly or indirectly, Media Land.Maintaining Pressure on Aeza GroupAfter OFAC’s designations of Aeza Group (Aeza) and its leadership on July 1, 2025, Aeza leadership initiated a rebranding strategy focusing on removing any connections between Aeza and their new technical infrastructure.  OFAC’s designations today serve as a reminder that OFAC will take all possible steps to counter sanctions evasion activity by malicious cyber actors and their enablers. Hypercore Ltd. (Hypercore) is a UK company registered and utilized by Aeza Group after its designation to move its IP infrastructure and evade sanctions.  OFAC is designating Hypercore pursuant to E.O. 13694, as further amended, for being owned or controlled by, or having acted or purported to act for or on behalf of, directly or indirectly, Aeza.Maksim Vladimirovich Makarov (Makarov) is the new director of Aeza.  He has made key decisions regarding Aeza Group’s attempt to evade sanctions.  OFAC is designating Makarov pursuant to E.O. 13694, as further amended for being a leader, official, senior executive officer, or member of the board of directors of Aeza.Ilya Vladislavovich Zakirov (Zakirov) helped establish new companies and payment methods to obfuscate Aeza’s continuing activity.  OFAC is designating Zakirov pursuant to E.O. 13694, as further amended, for having materially assisted, sponsored, or provided financial, material, or technological support for, or goods or services to or in support of, Aeza.Smart Digital Ideas DOO (Smart Digital) and Datavice MCHJ (Datavice) and are Serbian and Uzbek companies utilized by Aeza to evade sanctions and set up technical infrastructure that is not publicly associated with the Aeza brand.OFAC is designating Smart Digital pursuant to E.O. 13694, as further amended, for having materially assisted, sponsored, or provided financial, material, or technological support for, or goods or services to or in support, of Aeza.OFAC is designating Datavice pursuant to E.O. 13694, as further amended, for being owned or controlled by, or having acted or purported to act for or on behalf of, directly or indirectly, Aeza.Additionally, the Cybersecurity and Infrastructure Security Agency, in conjunction with law enforcement and international partners, released guidance with further information on how to mitigate risks presented by bulletproof hosting providers. For further information, please click here.SANCTIONS IMPLICATIONSAs a result of today’s action, all property and interests in property of the designated persons described above that are in the United States or in the possession or control of U.S. persons are blocked and must be reported to OFAC.  In addition, any entities that are owned, directly or indirectly, individually or in the aggregate, 50 percent or more by one or more blocked persons are also blocked. Unless authorized by a general or specific license issued by OFAC, or exempt, OFAC’s regulations generally prohibit all transactions by U.S.  persons or within (or transiting) the United States that involve any property or interests in property of designated or otherwise blocked persons.In addition, financial institutions and other persons that engage in certain transactions or activities with the sanctioned entities and individuals may expose themselves to sanctions or be subject to an enforcement action.  The prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any designated person, or the receipt of any contribution or provision of funds, goods, or services from any such person.Violations of OFAC regulations may result in civil or criminal penalties.  OFAC’s Economic Sanctions Enforcement Guidelines provide more information regarding OFAC’s enforcement of U.S. sanctions, including the factors that OFAC generally considers when determining an appropriate response to an apparent violation.The power and integrity of OFAC sanctions derive not only from OFAC’s ability to designate and add persons to the SDN List, but also from its willingness to remove persons from the SDN List consistent with the law.  The ultimate goal of sanctions is not to punish, but to bring about a positive change in behavior.  For information concerning the process for seeking removal from an OFAC list, including the SDN List, please refer to OFAC’s Frequently Asked Question 897 here.  For detailed information on the process to submit a request for removal from an OFAC sanctions list, please click here.Click here for more information on the individuals and entities designated today.
  19. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Wednesday, 19-Nov-2025 15:34:55 JST Metacurity Metacurity

    https://world.kbs.co.kr/service/news_view.htm?lang=e&Seq_Code=197518
    Crazy times in South Korean cyber.

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: worldimg.kbs.co.kr
      Police Raid KT Offices in Data Breach Investigation
      The police raided KT’s offices in Seoul and Gyeonggi Province as part of an investigation into a recent data breach at the mobile carrier.The anti-corruption and economic ...
  20. Embed this notice
    Metacurity (metacurity@infosec.exchange)'s status on Saturday, 15-Nov-2025 21:02:47 JST Metacurity Metacurity

    "The German government is set to get new powers to bar risky Chinese technology suppliers from its critical infrastructure."

    https://www.politico.eu/article/germany-lines-up-new-powers-to-fend-off-chinese-tech/

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www.politico.eu
      Germany lines up new powers to fend off Chinese tech
      New law set to come into place as Germany toughens its stance on China.
  • Before

User actions

    Metacurity

    Metacurity

    Metacurity.com (https://metacurity.com) is the one-stop destination for leading infosec news and cybersecurity developments. Run by infosec writer and columnist Cynthia Brumfield, Metacurity draws from thousands of sources every day to deliver aggregated summaries of the latest infosec developments. If anyone wants to get in touch with me, on or off the record, you can reach me at cynthia [at] digitalcrazytown.com or on Signal via Cynthia.507. Sign up for our free daily emails at https://www.metacurity.com. Searchable

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          22589
          Member since
          10 Nov 2022
          Notices
          93
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.