There have been multiple accounts created with the sole purpose of posting advertisement posts or replies containing unsolicited advertising.

Accounts which solely post advertisements, or persistently post them may be terminated.

securitynews

This magazine is from a federated server and may be incomplete. Browse more on the original instance.

IllNess OP , in “PhishForce” — Vulnerability Uncovered in Salesforce’s Email Services Exploited for Phishing Facebook Accounts In-The-Wild

Guardio’s Email Protection has detected a sophisticated email phishing campaign exploiting a 0-day vulnerability in Salesforce’s legitimate email services and SMTP servers. Guardio Labs’ research team has uncovered an actively exploited vulnerability enabling threat actors to craft targeted phishing emails under the Salesforce domain and infrastructure. Those phishing campaigns cleverly evade conventional detection methods by chaining the Salesforce vulnerability and legacy quirks in Facebook’s web games platform. Guardio Labs has disclosed these findings and worked with Salesforce and Meta to close the vulnerabilities and misuse.

atanu , in Microsoft fixes flaw after being called irresponsible by Tenable CEO

@IllNess Still treating security as a marketing not security issue!

IllNess OP ,

Can you elaborate on what you mean? Is this criticism on my posts?

atanu ,

@IllNess Not a criticism of you. A criticism of M$ that has a history of not dealing with security issues.

IllNess OP ,

Thank you for clearing that up. I appreciate it.

spacedancer ,

They were probably replying to you on mastodon hence the @.

IllNess OP ,

I didn’t know that’s how Mastodon replies works for Lemmy post.

Thank you for the info.

Squizzy ,

Mastodon would be better if I knew how to interact with comments in lemmy

stevedidwhat_infosec , in Microsoft fixes flaw after being called irresponsible by Tenable CEO

L m f a o

They would’ve been better off lying and saying it was really going to take that long

alex_02 , in Microsoft fixes flaw after being called irresponsible by Tenable CEO
@alex_02@infosec.pub avatar

Basically Tenable CEO called Microsoft a bunch of fucking idiots.

IllNess OP , in Colorado Department of Higher Education warns of massive data breach

The data stolen from CDHE is significant, impacting the following students, past students, and teachers who:

  • Attended a public institution of higher education in Colorado between 2007-2020.
  • Attended a Colorado public high school between 2004-2020.
  • Had a Colorado K-12 public school educator license between 2010-2014.
  • Participated in the Dependent Tuition Assistance Program from 2009-2013.
  • Participated in Colorado Department of Education’s Adult Education Initiatives programs between 2013-2017.
  • Obtained a GED between 2007-2011 may be impacted by this incident.

The stolen information includes full names, social security numbers, dates of birth, addresses, proof of addresses (statements/bills), photocopies of government IDs, and for some, police reports or complaints regarding identity theft.

If you are affected, please freeze your credit through the website of the three major credit reporting agencies. Freezing is free but they might spam you. Also if you need to do something that require a credit check, you have to plan ahead and unfreeze your credit. All three services can refreeze your credit after you specify a time frame.

Spellbind0127 , in Colorado Department of Higher Education warns of massive data breach
@Spellbind0127@mstdn.social avatar

deleted_by_author

  • Loading...
  • IllNess OP ,

    I am sorry to hear that.

    If your SSN is part of stolen information, you should freeze your credit and tell anyone else affected to do so.

    remotelove , in Data breach at French govt agency exposes info of 10 million people

    What if I told you that credit agencies have already sold off your data several times over? They keep track of people better than any government could.

    drspod ,

    France does not have credit agencies.

    IllNess OP ,

    The less people that have my data the better. Credit companies are only a part of the puzzle of sold data. The social media companies are the biggest piece.

    alex_02 ,
    @alex_02@infosec.pub avatar

    How does that have to do with a data breach other than making yourself look like an idiot?

    remotelove ,

    People are so rude today. Do you need a hug?

    alex_02 ,
    @alex_02@infosec.pub avatar

    I wasn’t being rude… your comment was just stupid and I rather be a honest person.

    remotelove ,

    I like honesty. Would context help?

    France aside, TransUnion, Equifax, Experian, etc. do sell our data to third parties and access to that data can be available on black markets. The reason for this is that when data is sold to third parties the controls around that data inherently start to degrade. This is not including all the high profile data breaches they experience and get slapped on the wrist for.

    When I was working at some larger financial companies, we had a few people that specifically searched for and in some cases, bought this data.

    My original quip was more focused on my frustration based on my country and my experience and slightly off topic, to be fair.

    IllNess OP , in Free Key Group ransomware decryptor helps victims recover data

    If anyone had the unfortunate experience needing to use this, please let me know how quick the script is. It looks fairly slow.

    Ubermeisters ,

    I’m not clear on the specifics but I’ve FWD’d this to someone I know in this exact scenario currently. Unsure if it’s the same Russian group, or if this is “breaking news” or not (aka if friends have already seen this decrypt solution before this article posted today), but this could make a huge difference to someone out there, even if not them. Thanks for posting.

    happyloaf ,

    You could re-implement this mult-threaded etc if you liked

    scrubbles , in Free Key Group ransomware decryptor helps victims recover data
    @scrubbles@poptalk.scrubbles.tech avatar

    Coming tomorrow, new version with a new password

    nocturne213 , in Apple issues emergency patches.

    Thursday Apple issued three emergency patches for a vulnerability that could be exploited to install spyware. The patches affect macOS Ventura 13.5.2, iOS 16.6.1 and iPadOS 16.6.1, and watchOS 9.6.2. “A maliciously crafted attachment may result in arbitrary code execution,” the company said in its advisories. “Apple is aware of a report that this issue may have been actively exploited.” The report of active exploitation came from the University of Toronto’s Citizen Lab, which found evidence that NSO Group’s Pegasus spyware was being installed in vulnerable devices through a zero-click exploit the Lab calls “BLASTPASS.” The attacks used PassKit attachments sent as iMessage images. These carried the malicious payload. The patches will protect users against BLASTPASS; so will enabling Apple’s Lockdown Mode on the device.

    IllNess OP , in Hackers email stolen student data to parents of Nevada school district

    On October 16, CCSD confirmed it suffered a cyberattack earlier this month, stating threat actors gained access to the district’s email servers.

    Kinda surprised to see this wasn’t related to MOVEit…

    EmperorHenry , in Lockbit Ransomware Cripples Australian Ports, Chinese Bank
    @EmperorHenry@infosec.pub avatar

    digital currency is a good idea…right?

    Not only does it allow the banks to monitor everything we buy, not only does it allow the banks to lock us out of society if we don’t obey, but it’s also hackable.

    I said all this because the nanny-state known as Australia went cashless recently and implemented digital currency made by the banks

    Ultra_Unlimited OP ,

    It’s so complicated. I see it more and more as you frame it here but of course the main selling points are “decentralization” “privacy” focused so it’s kind of twisted and you wonder who is really fleecing who here.

    EmperorHenry ,
    @EmperorHenry@infosec.pub avatar

    crypto currency is good. I’m talking about central-bank-digital-currency being bad.

    The dictatorship of Australia just went cashless and their systems for managing it have failed to work the way they’re supposed to multiple times now.

    Ultra_Unlimited OP ,

    That’s the thing. Crypto by its nature is somewhat murky and we’ve never really known who hold what or how many whale institutional investors have been pumping and dumping coins to circumvent troubling anti money laundering KYC regs etc

    Now that you have actually central banks getting into the mix, pushes for global digital ids and mandating that citizens participate or not have access to free trade is truly dystopian imo though this too was written long ago

    Ultimately I am optimistic but I understand the real hardships being faced by global citizens stuck behind the curtain of oppressive regimes. I watched the shift in the EU and it’s like night and day where things are now compared to a decade ago

    EmperorHenry ,
    @EmperorHenry@infosec.pub avatar

    Crypto by its nature is somewhat murky and we’ve never really known who hold what or how many whale institutional investors have been pumping and dumping coins to circumvent troubling anti money laundering KYC regs etc

    Many crypto currencies that no one has ever heard of are worthless and will always be worthless, but bitcoin, manero and dogecoin are worth something. bitcoin and manero are worth A LOT, dogecoin is worth almost nothing, but its value goes up and down really fast and really drastically every time it changes.

    Also it’s a good thing that no one can track who has what amounts of which crypto currency, don’t you think? That way the banks can’t monitor or control it.

    Ultra_Unlimited OP ,

    It’s a good selling point but I believe the whales have always been able to manipulate markets as a result of these supply chain issues not to say its very different from central banking but I truly question how decentralized control is across the cryptolandscape.

    MrPoopyButthole , in New SSH Vulnerability - Schneier on Security
    @MrPoopyButthole@lemmy.world avatar

    The countermeasure to the attacks we describe in this paper is well known: implementations should validate signatures before sending them. OpenSSH, the most common SSH implementation we observed in this data, implements this countermeasure because it uses OpenSSL to generate signatures, and OpenSSL has included countermeasures against RSA fault attacks since 2001.

    IllNess OP , in Critical 'LogoFAIL' Bugs Offer Secure Boot Bypass for Millions of PCs

    To minimize firmware risk in general, users should stay updated with manufacturer advisories and promptly apply firmware updates, as they often address critical security flaws.

    IllNess OP , in Healthcare software provider data breach impacts 2.7 million

    As of writing, the following healthcare providers are confirmed as impacted by the ransomware attack at ESO:

    • Mississippi Baptist Medical Center
    • Community Health Systems Merit Health Biloxi
    • Merit Health River Oaks
    • ESO EMS Agency
    • Forrest Health Forrest General Hospital
    • HCA Healthcare Alaska Regional Hospital
    • Memorial Hospital at Gulfport Health System
    • Providence St Joseph Health (Providence Kodiak Island Medical Center)
    • Providence Alaska Medical Center
    • Universal Health Services (UHS) Manatee Memorial Hospital
    • Desert View Hospital
    • Ascension Providence Hospital in Waco
    • Tallahassee Memorial
    • Manatee Memorial Hospital
    • CaroMont Health
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • [email protected]
  • lifeLocal
  • goranko
  • All magazines