48 Followers
447 Following
677 Posts
Corporate IT Security _____. Comments are mine and do not reflect the opinion of my employer. Stupid comments are the result of being hacked by an APT.
Meet the humans behind #BSides312: Robert Wagner (Director) 🛡️🏙️
Community curator + Advisory CISO (~20 yrs) defending Fortune 500s, gov, universities & finance. Speaker/teacher: DEF CON, APISec, BSides Tel Aviv, GrrCON + more. Co-founded Hak4Kidz, Chicago ISSA board, BurbSec regular, absolute legend.
⚠️ FOMO: you snooze, you lose.
âś… https://bsides312.org/
đź“… May 16, 2026
🎤 CFP due Feb 28, 2026
#BSides #InfoSec #Chicago #THOTCON #ISSA

After two glorious weeks off , Metacurity is back with a holiday round-up edition of the top infosec developments you should know, including

--Substation destruction and not cyber expertise likely led to Caracas power outages,
--Denmark says Russia was behind destructive cyberattacks,
--CISA staffers suspended after organizing polygraph test of acting director,
--Chinese cyberattacks on Taiwan jumped in 2025,
--OpenAI says prompt injection attack risks are here to stay,
--European Space Agency confirms breach,
--France’s national postal and banking services were DDoS'ed,
--Hackers scraped Spotify’s entire music library,
--Data breach exposed Korean Air's employee data,
--Coupang is offering compensation to customers after breach,
--New Kimwolf botnet is growing rapidly,
--Salt Typhoon likely infiltrated Australia and New Zealand,
--Zoom Stealer affects 2.2m browser users,
--Former customer service agent busted in Coinbase hack,
--Apple supplier was the target of a cyberattack,
--Cardano users are targeted in new phishing campaign,
--Claims administration company Sedgwick is coping with cyber incident,
--New Glassworm campaign emerges to deliver poisoned crypto wallets,
--Chinese short video TikTok rival Kuaishou targeted in cyberattack,
--Resecurity denies breach and says attackers only hit honeypot,
--Rainbow Six Siege (R6) hit with two breaches,
--Trump lifts sanctions on Intellexa executives,
--Trump prison reform law frees Razzlekhan crypto hack money launderer,
--Cisco will reportedly buy Axonius for $2B,
--Palo Alto Networks eyes buying Koi Security for $400m,
--ServiceNow inked deal to buy Armis for $7.75B,
--Palo Alto Networks and Google Cloud sign $10B partnership deal,
--Access Now runs hotline for potential spyware victims,
--Wegmans wants all your biometrics
https://www.metacurity.com/substation-destruction-and-not-cyber-expertise-likely-led-to-caracas-power-outages/

Substation destruction and not cyber expertise likely led to Caracas power outages

Denmark says Russia was behind destructive cyberattacks, CISA staffers suspended after organizing polygraph test of acting director, Chinese cyberattacks on Taiwan jumped in 2025, OpenAI says prompt injection attack risks are here to stay, European Space Agency confirms breach, much more

Metacurity

A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake "Security Alert" issues, tricking developers into authorizing a malicious OAuth app that grants attackers full control over their accounts and code.

https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/

Fake "Security Alert" issues on GitHub use OAuth app to hijack accounts

A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake "Security Alert" issues, tricking developers into authorizing a malicious OAuth app that grants attackers full control over their accounts and code.

BleepingComputer
Bouncing Signals Off Of Satellites Other Than The Moon

The moon is a popular target for ham radio operators to bounce signals since it’s fairly large and follows a predictable path. There are some downsides, though; it’s not always visible …

Hackaday
@troyhunt @haveibeenpwned this is full of ads, but was the original analysis of this type: http://www.datagenetics.com/blog/september32012/
PIN number analysis

A detailed analysis of four character PIN codes

the idea of being visited by aliens lost its appeal when i realized they’d likely just be some other planet’s asshole billionaires

A reminder to all who may have Visa, AmEx, or Master Card gift cards now and in the future. Often you'll wind up with a small balance on them that doesn't make it worthwhile to make a purchase with it online or in a store. Something like US$1.60 or less.

Go to Wikipedia, Archive.org, your local animal shelter, or just about any worthwhile nonprofit and donate that odd amount on their web page.

#donations #nonprofit #giving #Holidays #Christmas #Kwanza

@hacks4pancakes ack
Health care should be more like OT environments They can’t harden a lot of their shit even if they want to. Too much red tape.

@hacks4pancakes
I remember discussions about this from over 20 years ago. Really old issue to get upset about. lol

Key points about using different firewall vendors in corporate environments since around 2003.

Theory behind it:

The primary rationale was that if a critical vulnerability was discovered in one vendor's firewall software, the other vendor's firewall might not be affected, offering redundancy in security.

Challenges with this approach:

Management complexity: Configuring and managing two different firewall systems from different vendors could be significantly harder, leading to potential misconfigurations and security gaps.

Troubleshooting difficulties: Identifying the source of a network issue could become complex when dealing with two different firewall logs and behaviors.

Vendor support issues: Depending on the vendors involved, getting unified support for troubleshooting across both firewalls could be challenging.

Modern perspective:

Standardization is preferred: Today, most security professionals recommend using a single firewall vendor for consistency and easier management, while still implementing other security measures to achieve defense in depth.

18 hacking books. Name your price. Our Hacking 2024 Humble Bundle is now LIVE. Support the ACLU & @eff while leveling up your security game. #CyberMonday https://www.humblebundle.com/books/hacking-2024-no-starch-books
Humble Tech Book Bundle: Hacking 2024 by No Starch

Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!

Humble Bundle