The Treasury Department right now. People are turning out against Musk and DOGE staging a takeover of the Treasury’s payment system. This crowd is big. The whole block is packed. “Lock him up,” everyone yells.
04.02.2025 22:43 — 👍 43767 🔁 11142 💬 882 📌 922
A few of us are still out here.
Sorry for the shaky video.
02.02.2025 23:08 — 👍 6520 🔁 1362 💬 257 📌 130
Is anyone else having to block random accounts “following you” that should be classified as bots?
10.01.2025 15:06 — 👍 0 🔁 0 💬 0 📌 0
That’s assuming your browsers are Chrome (which is highly likely considering the market share).
03.01.2025 02:05 — 👍 0 🔁 0 💬 0 📌 0
So is the cheese if you count the cow’s diet.
30.12.2024 02:08 — 👍 1 🔁 0 💬 0 📌 0
If the university is providing the AutoCAD license, I’d check if they’d support installing it on MacOS. Most if not all support Windows & definitely not Linux. I tried running it through wine and that didn’t end well. www.autodesk.com/support/tech...
27.12.2024 20:54 — 👍 1 🔁 0 💬 0 📌 0
Cyberhaven says it was hacked to publish a malicious update to its Chrome extension | TechCrunch
The data-loss startup says it was targeted as part of a "wider campaign to target Chrome extension developers."
“Data-loss prevention startup vendor hacked to steal data”. I wonder if the admin’s system that got popped had the company’s edr software on it…if the company had something at all…or was it a BYOD environment. techcrunch.com/2024/12/27/c...
27.12.2024 20:50 — 👍 0 🔁 0 💬 0 📌 0
Privacy reminder 4 iOS users: There’s a native function that tracks network activity by apps (see what’s up to no good). Go to Settings > Privacy & Security > App Privacy Reports.
There’s no reason for Google Authenticator to call out to Google's servers. It shouldn't be doing it.
Use 2FAS instead!
23.12.2024 06:04 — 👍 0 🔁 0 💬 0 📌 0
Attorney General Mike Hilgers Files Lawsuit Against Change Healthcare for Critical Failures to Protect Consumer Data and Prevent Against Harm from a Widespread Cyberattack | Nebraska Attorney General ...
ChangeHealthcare data breach started on 02/11/24 when creds of an employee were posted in a Telegram group chat. The creds were used to login to Citrix. The external actor was in their system for 9 days, creating admin accounts, installing malware, and exfiltrating terabytes of sensitive data.
17.12.2024 23:11 — 👍 1 🔁 2 💬 1 📌 0
industry
Not ironic at all. I have an appreciation for how the Tesla EV pushes the boundaries of the auto industry. I am not a fan of how they’re manufactured & do wonder what an economic impact report would look like for what it takes to generate a Tesla Model 3. Not to mention how ppl are treated at TSLA.
10.12.2024 02:19 — 👍 0 🔁 0 💬 1 📌 0
I find it ironic that electric vehicles are still delivered mainly by diesel-powered combustion engines. Is it just me?
09.12.2024 20:02 — 👍 0 🔁 0 💬 2 📌 0
Would it be possible for other endpoints with Defender installed within the same vlan or subnet to be able to tell you more about what’s happening, like if the system is online and connected? I do realize this is hyperbole and is more like a Juniper Mist network-sensor system. I’ll read the docs.
07.12.2024 02:45 — 👍 1 🔁 0 💬 1 📌 0
I’m just thinking about cases where something is side-loaded into memory and doesn’t hit disk. The only solution I know of that actively protects against that type of attack is a well-known EDR vendor *not* listed in EDRSilencer’s code.
07.12.2024 02:41 — 👍 1 🔁 0 💬 0 📌 0
And if you can be alerted, I’m assuming you should be able to proactively block this tool from blinding Defender.
07.12.2024 02:10 — 👍 2 🔁 0 💬 1 📌 0
So your only other choice is to stop using the service. It's a rough situation.
06.12.2024 03:02 — 👍 1 🔁 0 💬 0 📌 0
But the reality is most companies that care about security added non sms options 5+ years ago. The only other choice is to stop using the service. Some of these sites are govt and Healthcare & that just isn't an option most of the time. It's a rough situation.
06.12.2024 03:01 — 👍 1 🔁 0 💬 1 📌 0
You can also use a password manager like Bitwarden to manage your mfa and that would be a big step up from sms. If you only have the option for sms? There's not a lot to be done. You can bug customer service about it, maybe they can get word higher up the chain to get them to start caring…
06.12.2024 02:57 — 👍 0 🔁 0 💬 1 📌 0
There's now confirmation of man-in-the-middle happening. What can I do about this? The answer is "it depends. If you have the option to use something other than SMS mfa, you should use it now. Entra Auth is a great phone authenticator, and of course a hardware token would be best like a Yubikey.
06.12.2024 02:55 — 👍 0 🔁 0 💬 1 📌 0
Reposting from Sandrockcstm on Mastadon:
People are being kind of smug about the FBI announcent not to text anymore, and I understand why...Your mfa codes that are texted to you are now fully compromised…That's the real story here. We've known for a while sms mfa was insecure.
06.12.2024 02:51 — 👍 0 🔁 0 💬 1 📌 0
Today was spent setting up Ludus.cloud (I’d highly recommend it if you need a test environment!) and attempting to getting Caldera setup on Windows without Defender detecting it (my barrier of entry). Sliver loaded into memory just fine! Tmrw I’m going to attempt to setup OpenBAS which is new to me.
04.12.2024 03:12 — 👍 0 🔁 0 💬 0 📌 0
Thank you John Strand and BHIS!
Sad news for CompTIA.
30.11.2024 04:30 — 👍 0 🔁 0 💬 0 📌 0
Oh that brings back some memories of playing this at a friend’s house!!
28.11.2024 04:26 — 👍 1 🔁 0 💬 1 📌 0
A WARNING!
This generative Al task will require cutting off electricity to one random small city for up to 10 minutes! Continue creating 200 x 200 pixel avatar? Click YES or NO
If only.
27.11.2024 16:42 — 👍 0 🔁 0 💬 0 📌 0
Cybersecurity's effectiveness hinges on collaboration and relationship building, the ability to connect, explain, and persuade…it’s about developing emotional intelligence, learning to read your audience, and adapting your message while keeping its essential truth.
www.greynoise.io/blog/from-he...
27.11.2024 15:24 — 👍 0 🔁 0 💬 0 📌 0
In-depth, independent reporting to better understand the world, now on Bluesky. News tips? Share them here: http://nyti.ms/2FVHq9v
Photographer and digital storyteller roaming the streets of Washington, DC. Drawn to politics and world events. As seen on the other site at aletweetsnews and Instagram at aletakesphotos.
Cybersecurity data storytelling. DBIR at Verizon Business. Previously serial founder and parallel shitposter. He/him.
Security "professional" || Shitposting, once more with feeling || Disaster nerd, neurotic mess, fake grown-ass lady || 🚗 🏍️ 🐈⬛ 🐕 📚 || she/her
Red Brain, Blue Fingers
Malware Analysis, Reverse Engineering, Threat Hunting, Detection Engineering, DFIR, Security Research, Programming, Curiosities, Software Archaeology, Puzzles, Bad dad jokes
https://www.hexacorn.com/blog/
hexacorn@infosec.exchange
Founder of Azeria Labs, Trainer, Author of Blue Fox: Arm Assembly Internals & Reverse Engineering
@Straiker. Ex-Microsoft. Ex-Meta RedTeam, Ex-Endgame, Ex Fireeye. malwareunicorn.org
Senior Cybersecurity Reporter at The Record from Recorded Future News. Send tips to martin.matishak@therecord.media. Signal: mmatishak.80
Cloud Security Response @ Google 🕵️♂️
Husband & dog / cat dad 🐕🐕🦺🐈⬛🐈
Gamer & Music nerd 🎵🎮
using this as a music / thought journal, always happy to chat about DFIR or SecOps stuff, dm me.
Loves Jesus, loves others | Husband, father of 4, security solutions architect, love to learn and teach | Microsoft MVP | @TribeOfHackers | 🐘infosec.exchange@nathanmcnulty
they/she. spreader of virtual kitties. 🐱
reverse engineering ⚫️ threat intelligence ⚫️ malware ⚫️ security research ⚫️ snoring cats
occasionally climbing. good food always. naps are underrated.
@haileys.quest
🌉 bridged from ⁂ https://infosec.town/@blake, follow @ap.brid.gy to interact
DFIR and Adversary Simulation
DFIR, Digital Forensics, Incident Response, Cybersecurity
Digital Forensic Examiner and researcher. CFCE. No, I will not hack into your partner’s phone. Halloween obsessed. Horror artist for fun. Mom to three spawn.
Advances cybersecurity. Grows tech businesses. Fights malware.
CISO at Axonius. Faculty Fellow at SANS Institute. Creator of REMnux.
https://zeltser.com
software engineer @ fintech- content creator @ http://links.ali.dev - threatwire host @hak5 - @breakingthepod - nyc - ex @miteecs - jewish
🕵🏼♂️ ACFE fraud investigation trainer
🧑🏻🔬 HTCIA digital forensics speaker
🥷🏼 Black Hat speaker