Spent yesterday at #UofM to discuss Next Gen Workforce in Cyber Security with a focus on healthcare. Got to see a ton of interesting work that is going on at the college and meet a bunch of cool people.

Got to speak about #memsec and @biohacking_village.

#CyberSec #securiy #nextgen #healthCare

Strange question and I “think” the answer is NO, but I’m looking for #fediverse wisdom. Is there a way to generate a valid #SSL certificate (not self signed, and no private CA) for a device running on the .local domain. It would need to recognised by any browser trying to connect to it without having to “accept the risk”. It’s also probably not a job for let’s encrypt because it would be great if this worked out of the box with zero config by a user after setting up. #linux #opensource #securiy

Maybe i need to post this agaian that everyone does understand me

I AM NOT AGAINST "SIGNAL" MESSENGER

I am just calling their demand of an phone number for registration to be the antithesis of an anonyous secure messenger

In the second when Signal allows anonymous registrations without a phone nuber, im right to join there

#SignalMessenger #Securiy #Anonymousity #BoostsWelcome

Another day, another attack to software dependencies:

https://arstechnica.com/security/2024/07/384000-sites-link-to-code-library-caught-performing-supply-chain-attack/

This is different from the xz story, but the core idea is the same: take ownership of a popular project, and sneakily replace it with malicious code.

#securiy #supplychain #polyfill

384,000 sites pull code from sketchy code library recently bought by Chinese firm

Many website admins, it seems, have yet to get memo to remove Polyfill[.]io links.

Ars Technica
Filmreifer Einbruch bei Los Angeles: Diebe erbeuten 30 Millionen US-Dollar aus Geldspeicher

Sie durchbrachen wohl die Wand und das Dach, knackten dann den Tresor und entkamen mit 30 Millionen Dollar: Dieben ist im San Fernando Valley ein filmreifer Einbruch in ein Gelddepot gelungen.

DER SPIEGEL
Derzeit ist wieder ein #USB Wurm im Umlauf diesmal mit dem Namen #LitterDrifter. Ich finde es spannend das dies immer noch ein Ausbreitungsvector ist und Sinn macht der eigentlich nur noch für #OT Systeme wie Kraftwerke da diese hoffentlich meist gut von anderen Netzen getrennt sind. Vielleicht unterschätze ich aber auch die Nutzung von USB im privaten Bereich 🤷 - via Bruce Schneier - https://www.schneier.com/blog/archives/2023/11/litterdrifter-usb-worm.html #securiy #trojaner #malware
LitterDrifter USB Worm - Schneier on Security

‘Scam-in-a-box’: #MyGov suspends thousands of accounts linked to dark web fraud kits | Australia news | The Guardian

https://www.theguardian.com/australia-news/2023/nov/06/scam-in-a-box-mygov-suspends-thousands-of-accounts-linked-to-dark-web-kits

> Exclusive: #Scams utilise phishing attacks on #Centrelink, #ATO and #Medicare accounts using obtained login details

#securiy #Australia #cyber

‘Scam-in-a-box’: MyGov suspends thousands of accounts linked to dark web fraud kits

Exclusive: Scams utilise phishing attacks on Centrelink, ATO and Medicare accounts using obtained login details

The Guardian
ICYMI: Emotet Reappeared Early This Year, Unfortunately

Emotet resumed operations in March 2023. Trellix monitors it for new infection methods. Blog covers Global Prevalence, Infection Vectors, TTPs, and detection.

GrapheneOS on Twitter

“Our non-profit GrapheneOS Foundation organization now handles donations via Bitcoin, Monero, Zcash, Ethereum and Cardano in addition to PayPal. https://t.co/QL8dNBSpDZ For now, credit card donations can either be made via PayPal or to GrapheneOS developers via GitHub Sponsors.”

Twitter

So I’m replacing my Nest Secure with Abode iota. This is how sensitive the motion detection is. This is video recorded from a false alarm triggered by motion.

I’m going to miss my Nest Secure :(

#abode #securiy #nest