I get asked a lot lately what the I think people who want to get into cyber security should focus on. My go to answer is incident response, since it seems like the mountains of vibe code and half-assed zero trust architectures is creating galactic scale potential breach energy. Would that be called vibe responders? Or is that for when we figure out how to hand over IR to AI as well?
If you find the fediverse useful, donโt forget to support your instance (assuming they accept support). While the software is free, running instances is far from it. I am glad to be part of the community and want to see it continue on as a viable alternative. Thank you all for being here and I hope you have a good holiday season.
Itโs Friday, which obviously means today is the day to push all your untested vibecode to prod before the weekend, but remember that (at least for those of us in the US), next week is a short week presenting one of the best opportunities for code pushes. ๐ฆ๐๐๐
I do feel like MS/Azure, AWS, and Cloudflare need to do a better job of coordinating their outages so some of yall can get some much needed time away from IT
I don't remember the last time I was at a security conference... I'm looking forward to BSides Atlanta on Saturday, where I'll apparently be making a guest appearance in a presentation about the Fediverse. Hopefully, I am not too embarrassing.
@GossiTheDog Iโve seen plenty of romance scam accounts trying to lure people to telegram or other DM, but I hadnโt seen this class of account doing that. I may just not be looking though.
@GossiTheDog thereโs about 12,000 of those lately on mastodon.social. I canโt yet tell what the game is, but my best guess is account farming to build and the. sell high follower accounts, like happens on twitter, instagram, and so many others. Little do they know how few people are actually here.
There have been a deeply disappointing number of mastodon account takeovers in the past few weeks used to spam out malicious links in the guise of porn. Iโm guessing most or all are abandon accounts, so the owner doesnโt even realize.
Please please please enable two factor authentication on your mastodon accounts regardless of which instance you are on or how sensitive or not you think the stuff you post is.
Thereโs been an oppressive amount of spam originating from what appears to be compromised mastodon accounts posting links that appear to be porn, but lead to various badness depending on the location, IP address, browser, and operating system of the visitor. Donโt click on tinyurl or other link shortened links promising to, er, satisfy your porn needs. And for the love of $deity, please enable 2fa authentication on your accounts AND stop using the same damn password everywhere. Thank you for your attention in this matter.
Recovering CISOMay have an orchid problem Bad photographyWorse dad jokesThe worst Infosec hot takes Podcast: https://defensivesecurity.orgBlog: https://infosec.engineeringTwitter: @maliciouslinkhttps://Infosec.Exchange Admin#infosec #security #cybersecurity #risk #fedi22โฆand for fucks sake, be nice to each other. We are only here for a brief time. Make it enjoyable.To help support the costs associated with running this instance, please consider donating. You can set up recurring donations here: Patreon: https://www.patreon.com/infosecexchangeKo-Fi: https://ko-fi.com/infosecexchangeLiberapay: https://liberapay.com/Infosec.exchange/You can also support with a one-time donation using PayPal to "jerry@infosec.exchange".