48 Followers
447 Following
677 Posts
Corporate IT Security _____. Comments are mine and do not reflect the opinion of my employer. Stupid comments are the result of being hacked by an APT.
Meet the humans behind #BSides312: Robert Wagner (Director) 🛡️🏙️
Community curator + Advisory CISO (~20 yrs) defending Fortune 500s, gov, universities & finance. Speaker/teacher: DEF CON, APISec, BSides Tel Aviv, GrrCON + more. Co-founded Hak4Kidz, Chicago ISSA board, BurbSec regular, absolute legend.
⚠️ FOMO: you snooze, you lose.
âś… https://bsides312.org/
đź“… May 16, 2026
🎤 CFP due Feb 28, 2026
#BSides #InfoSec #Chicago #THOTCON #ISSA

After two glorious weeks off , Metacurity is back with a holiday round-up edition of the top infosec developments you should know, including

--Substation destruction and not cyber expertise likely led to Caracas power outages,
--Denmark says Russia was behind destructive cyberattacks,
--CISA staffers suspended after organizing polygraph test of acting director,
--Chinese cyberattacks on Taiwan jumped in 2025,
--OpenAI says prompt injection attack risks are here to stay,
--European Space Agency confirms breach,
--France’s national postal and banking services were DDoS'ed,
--Hackers scraped Spotify’s entire music library,
--Data breach exposed Korean Air's employee data,
--Coupang is offering compensation to customers after breach,
--New Kimwolf botnet is growing rapidly,
--Salt Typhoon likely infiltrated Australia and New Zealand,
--Zoom Stealer affects 2.2m browser users,
--Former customer service agent busted in Coinbase hack,
--Apple supplier was the target of a cyberattack,
--Cardano users are targeted in new phishing campaign,
--Claims administration company Sedgwick is coping with cyber incident,
--New Glassworm campaign emerges to deliver poisoned crypto wallets,
--Chinese short video TikTok rival Kuaishou targeted in cyberattack,
--Resecurity denies breach and says attackers only hit honeypot,
--Rainbow Six Siege (R6) hit with two breaches,
--Trump lifts sanctions on Intellexa executives,
--Trump prison reform law frees Razzlekhan crypto hack money launderer,
--Cisco will reportedly buy Axonius for $2B,
--Palo Alto Networks eyes buying Koi Security for $400m,
--ServiceNow inked deal to buy Armis for $7.75B,
--Palo Alto Networks and Google Cloud sign $10B partnership deal,
--Access Now runs hotline for potential spyware victims,
--Wegmans wants all your biometrics
https://www.metacurity.com/substation-destruction-and-not-cyber-expertise-likely-led-to-caracas-power-outages/

Substation destruction and not cyber expertise likely led to Caracas power outages

Denmark says Russia was behind destructive cyberattacks, CISA staffers suspended after organizing polygraph test of acting director, Chinese cyberattacks on Taiwan jumped in 2025, OpenAI says prompt injection attack risks are here to stay, European Space Agency confirms breach, much more

Metacurity

A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake "Security Alert" issues, tricking developers into authorizing a malicious OAuth app that grants attackers full control over their accounts and code.

https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/

Fake "Security Alert" issues on GitHub use OAuth app to hijack accounts

A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake "Security Alert" issues, tricking developers into authorizing a malicious OAuth app that grants attackers full control over their accounts and code.

BleepingComputer
Bouncing Signals Off Of Satellites Other Than The Moon

The moon is a popular target for ham radio operators to bounce signals since it’s fairly large and follows a predictable path. There are some downsides, though; it’s not always visible …

Hackaday
@troyhunt @haveibeenpwned this is full of ads, but was the original analysis of this type: http://www.datagenetics.com/blog/september32012/
PIN number analysis

A detailed analysis of four character PIN codes

the idea of being visited by aliens lost its appeal when i realized they’d likely just be some other planet’s asshole billionaires

A reminder to all who may have Visa, AmEx, or Master Card gift cards now and in the future. Often you'll wind up with a small balance on them that doesn't make it worthwhile to make a purchase with it online or in a store. Something like US$1.60 or less.

Go to Wikipedia, Archive.org, your local animal shelter, or just about any worthwhile nonprofit and donate that odd amount on their web page.

#donations #nonprofit #giving #Holidays #Christmas #Kwanza

18 hacking books. Name your price. Our Hacking 2024 Humble Bundle is now LIVE. Support the ACLU & @eff while leveling up your security game. #CyberMonday https://www.humblebundle.com/books/hacking-2024-no-starch-books
Humble Tech Book Bundle: Hacking 2024 by No Starch

Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!

Humble Bundle

Amazon Web Services announces declarative policies [One of the coolest things I have seen in a while. Can’t wait to try this out!]

https://aws.amazon.com/about-aws/whats-new/2024/12/aws-declarative-policies/

Amazon Web Services announces declarative policies - AWS

Discover more about what's new at AWS with Amazon Web Services announces declarative policies

Amazon Web Services, Inc.