Oneironaut

@Oneironaut@infosec.exchange
16 Followers
124 Following
1.6K Posts
GRC advocate. Cyber adjacent. Celine Dion fan

NPR 1A doing a show on GPTs and damn. People are thinking these things are friends and confidants and lovers. That their β€œrelationships" with them are healthy... Straight-faced β€œIt's fine”

It. is. not. fine.

This is dangerous.

#ai

NEW, by me: Uzbekistan exposed its nationwide license plate surveillance system to the web, no password needed.

The system reveals around a hundred locations around the country where banks of cameras have been placed, including big cities and rural areas. The system contains raw video footage of millions of vehicles and their occupants.

https://techcrunch.com/2025/12/23/inside-uzbekistans-nationwide-license-plate-surveillance-system/

Exclusive: Inside Uzbekistan's nationwide license plate surveillance system

The Uzbek government's national license plate scanning system was discovered exposed to the internet for anyone to access without a password.

TechCrunch

So I hacked my way into being Cyber Policy Initiative Senior Fellow at the University of Chicago's Harris School of Public Policy. I'm workin on rural water critical infrastructure cybersecurity.

Do you even hack utilities? Please chat w me. I need to quickly find out where I"m wrong about some of my assumptions.

Still very entertained by the fact that I *finally* got into the University of Chicago. :D

https://cpi.harris.uchicago.edu/2025/12/23/harris-cyber-policy-initiative-taps-top-hacker-to-design-new-security-model-for-water-utilities/

Harris Cyber Policy Initiative Taps Top Hacker to Design New Security Model for Water Utilities | Cyber Policy Initiative

New from 404 Media: Flock exposed some of its AI-powered cameras to the internet. We know because we tracked ourselves with them. These cameras zoom in on passersby, sometimes so close we could read a random person's phone screen. Required no login to view cameras
https://www.404media.co/flock-exposed-its-ai-powered-cameras-to-the-internet-we-tracked-ourselves/
This is a wild hack. a16z gave a million dollars to startup called Doublespeed. They use a phone farm to flood social media with AI generated influencers and ads. A hacker remotely broke into the phone farm, unmasking the AI influencers/fake accounts, gave us the data https://www.404media.co/hack-reveals-the-a16z-backed-phone-farm-flooding-tiktok-with-ai-influencers/
Hack Reveals the a16z-Backed Phone Farm Flooding TikTok With AI Influencers

A hacker gained control of a 1,100 mobile phone farm powering covert, AI-generated ads on TikTok.

404 Media

Texas sues five smart TV makers for using ACR technology on their devices to screenshot what people are watching

Lawsuits have been filed against Sony, Samsung, LG, Hisense, and TCL

https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-sues-five-major-tv-companies-including-some-ties-ccp-spying-texans

Attorney General Paxton Sues Five Major TV Companies, Including Some with Ties to the CCP, for Spying on Texans

Attorney General Ken Paxton has filed suit against five major television companies for spying on Texans by secretly recording what consumers watch in their own homes.

Texas Attorney General

#PSA: If someone says they accidentally reported you, it's a scam.

If someone says you need to verify your Mastodon account, it's a scam.

If someone says you need to change the email address on your account, it's a scam.

If someone tries to lure you off-platform to Discord or Telegram, it's a scam.

If someone jumps into your replies or DMs with a mutual aid request, it's a scam.

If someone from mastodon.social sends you an unsolicited DM, it's a scam.

---

Telltale signs of a scam:

- wants you to move off-site
- wants you to change account settings
- wants you to click something
- unsolicited private interactions
- new account
- under ~20 followers and over ~5:1 follow ratio
- sense of urgency
- appeals to your compassion
- piggybacks on a trending post or event

#KnowTheSigns #Report #Scams

American IT software company Ivanti warned customers today to patch a newly disclosed vulnerability in its Endpoint Manager (EPM) solution that could allow attackers to execute code remotely.

https://www.bleepingcomputer.com/news/security/ivanti-warns-of-critical-endpoint-manager-code-execution-flaw/

Ivanti warns of critical Endpoint Manager code execution flaw

American IT software company Ivanti warned customers today to patch a newly disclosed vulnerability in its Endpoint Manager (EPM) solution that could allow attackers to execute code remotely.

BleepingComputer

Because age verification is really just there to:

- suppress queer information
- restrict abortion access
- gatekeep sexual education
- slurp up more personal data for marketing

"But think of the children!"

Maybe we should think about the corporations that prey on their attention-spans and self-esteem instead.

Sign stuff here:
https://www.stoponlineidchecks.org

Info on how to help here:
https://docs.fightforthefuture.org/s/637497e2-8a61-42aa-82fe-1b847e113ebb#h-what-are-online-id-checks-and-why-are-they-a-threat

#CallToAction #Activism #InternetSafety

ONLINE ID CHECKS WILL RUIN THE INTERNET

Fight for the Future