Researchers from Google and GitGuardian found over 900 TLS certificates used by Fortune 500 firms and governments exposed through leaked private keys on public code platforms like #GitHub.

Read: https://hackread.com/certificates-fortune-500-gov-exposed-key-leaks/

#CyberSecurity #TLS #PrivateKey #Fortune500 #BugBounty

900+ Certificates Used by Fortune 500, Governments Exposed by Key Leaks

Follow us on all social media platforms @Hackread

Hackread - Cybersecurity News, Data Breaches, AI and More
Is anybody using this private key

✨Introducing "Shake for Bitcoin"! ✨ Test your luck by shaking your device to find wallets with non-zero balances! Will you find the needle in the haystack? Download now on Google Play!👇 play.google.com/store/apps/d... #Bitcoin #PrivateKey #CryptoChallenge

Shake For Bitcoin! - Apps on G...
Shake For Bitcoin! - Apps on Google Play

Can you guess the Bitcoin private key?

@hon1nbo @foone yeah, but all these things would essentially necessitate a fundamentally incompatible #Fork of the #USB standard, creating #costs, #fragmentation and lessen the likelyhood of success.

  • Not to mention it'll require significant investments in #UserAwareness, #Training and would still have some issues...

I gues a sort-of "Secure HID Port" that mandates proper authentification and does full #E2EE from the Keyboard Matrix / Pointing Device controller up is an option, but you'd have to expect state-sponsored attackers willing to do "Kamikaze" Hacks...

#TLDW: It requires custom silicon and a hard root of trust

https://infosec.space/@kkarhan/113716442182953660

How a Mini drill tool defeated security on the Xbox 360 | MVG

YouTube

@puppygirlhornypost2 @navi And whilst it's easy to blame #GoldenKeyBoot, a leaked #PrivateKey that was impossible to be removed, the problem is that #Windows is architecturally "insecure-able" because any changes necessary to make this not a problem would inherently mean the end for Windows as it's known to most.

  • In fact, everything is done better by #Linux on the #Desktop for almost two decades, which is why classic #Malware isn't a thing on Linux systems.

Shure, you get some #Cryptojacking and some #CMS|es like #WordPress that are constantly being attacked but generally, the way #updates and #distribution of #Software works on Linux Distros for the most part is completely antithetical to Windows.

And anything #Microsoft could do at this point if they weren't horny for money but avtually cared is to scrap Windows and instead invest into #Wine to ease the transition...

Why is everyone using #base64 to encode their private SSH keys to store them in masked variables in #GitLab CI?! 🤔

⚠️ GitLab cannot effectively mask your private key in CI logs if you only give it a base64-encoded version of it!

Instead I found a solution that stores the *original* private key format from #OpenSSH in a one-line CI variable and recreates the begin/end markers for a valid OpenSSH identity file with commands inside the CI.

https://stackoverflow.com/a/79124959/498634

#ITsecurity #CICD #privatekey

Gitlab masking variables

I can't seem to mask a variable on Gitlab CI - I'm trying to upload a ssh private key and no matter what I do it refuses to mask it. That is I'm trying to store a private key on Gitlab for use ...

Stack Overflow
📬 Criminal Assets Bureau: Zugriff auf 378 Mio. USD in Bitcoin-Wallets verwehrt
#DarkCommerce #Krypto #Bitcoin #CliftonCollins #CriminalAssetsBureau #Irland #PrivateKey #Wallet https://sc.tarnkappe.info/84ffe3
Criminal Assets Bureau: Zugriff auf 378 Mio. USD in Bitcoin-Wallets verwehrt

Das irische Criminal Assets Bureau hat keinen Zugriff auf beschlagnahmte Bitcoins von einem Drogendealer im Wert von 378 Millionen Dollar.

Tarnkappe.info
Dark Skippy: Angriff kapert Hardware-Wallet-Schlüssel

Dark Skippy ist eine Angriffsmethode zum Stehlen der Seed-Phrase von Hardware-Wallets über bösartige Firmware.

Tarnkappe.info