Infosec

/infosec963

Security-related news, software libraries, and researcher AMAs

Go update your Firefox now, or you could be drained without even manually signing a transaction.
https://x.com/pcaversaccio/status/1842860274014917115?t=cOMuVIPAML-vOgadU2yN5g&s=19

security is only attainable by going deeper than the typical social/mobile experience.

then again, the issue may be less consistent copycats with sketchy infra, speaking to more of an attention problem.
Anyone think we're going to see NITRO ZEUS as part of all this Iran chaos?

Supposedly an apocalypse level "cyber weapon" designed to destroy all aspects of Iranian Infrastructure as a contingency plan in case they ever get out of hand.

https://en.wikipedia.org/wiki/Nitro_Zeus
β€œYour boss says "Hey, corporate wants us to become ISO 27thousandsomething certified. I don't know what the fuck that is, I don't care what the fuck that is, and I wouldn't give a shit about any of this were this not tied to my bonus. Here's ten dollars. Go see to it."”

https://crankysec.com/blog/shite/
Protip: to avoid your phone being hijacked by rogue towers, you can go to the dialer on Android and type: *#*#4636#*#*

Then go into "phone information" and hit the dropdown to say "NR Only". This means only connect to anything via 5G. If you live in a more remote area you can enable LTE if you must, but NR Only is ideal. Everything else is danger.
@askgina.eth if you had to supervise a 98% generally-capable autonomous agent that can fluently operate BlackArch Linux, how should it be sandboxed and what red flags would you look out for?
> Any politician that wants to ban or backdoor encrypted chat apps should start by publishing their own private chats for everyone to go through because they surely have nothing to hide.
Google shares insights on APT42 β€” an Iranian-backed cyber espionage group.

> We are also confirming recent reports around APT42’s targeting of accounts associated with the U.S. presidential election.
https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/
These articles that keep talking about SSN leaks of 2.9 billion people are funny. Do they not realize that there are way less than 2.9 billions people on the planet with SSNs? It's 2.9b *records* many of which are dupes or alternate addresses.
https://www.yahoo.com/news/hackers-may-stolen-social-security-100000278.html
Anyone else at DEFCON this weekend? Would be fun to meet more Farcaster people in the infosec community πŸ₯³