FC

@fatalisticcritic@ioc.exchange
28 Followers
308 Following
2.2K Posts
Mostly re-hashing. Yeah and fuck Orban, Putin, Trump and that Isräraely guy

#FediBlock

The server mastodon.arell.ai is copying the account details of people, and then posting AI nonsense as them.

It likely scrapes the profile information to make the account. So a server block is likely needed.

Wake up bae, new attack surface just dropped. Works outside UNC paths too, and MS don’t appear to own the domain 🤣
https://chaos.social/@karotte/114875319621020657
Lukas (@karotte@chaos.social)

Mildly cursed factoid about UNC paths: - UNC Paths can contain IP addresses such as \\192.168.1.1\share - IPv6 addresses are supported as well - IPv6 addresses contain colons - can't have colons in Windows paths since colons are reserved for drive letters So Microsoft came up with the the ipv6-literal.net domain that's special-cased by Windows so you can to write IPv6 addresses in UNC paths as 2a0e-3c0--21.ipv6-literal.net without it hitting any resolvers.

chaos.social

Silicon Valley’s alliance with Donald Trump was a mask off moment and showed the world we can’t depend on US tech companies.

For the past few months, I’ve been trying to get off US tech and I put together a guide so you find alternatives too. I hope you find it helpful!

https://www.disconnect.blog/p/getting-off-us-tech-a-guide

#tech #politics #digitalsovereignty #alttech #donaldtrump

Getting off US tech: a guide

I’m in the process of dropping US tech services. Here’s how I did it, and options you should consider.

Disconnect

In a historic gathering, 12 countries announce #Israel sanctions and renewed legal action to end Gaza #genocide

https://mondoweiss.net/2025/07/30-countries-announce-israel-sanctions-and-renewed-legal-action-to-end-gaza-genocide/

30 countries announce Israel sanctions and renewed legal action to end Gaza genocide

Meeting in Bogotá, Colombia, representatives from over 30 states, including China, Brazil, Spain, Mexico, Turkey, and Qatar, announced sanctions against Israel to cut the flow of weapons facilitating genocide and war crimes in Gaza.

Mondoweiss
Read more about using IP search engines in Awesome IP Search Engines Github repository https://github.com/cipher387/awesome-ip-search-engines and Netlas Cookbook https://github.com/netlas-io/netlas-cookbook
You're allowed one (1) Star Trek technology to make it into real life. What do you choose?
Warp drive
13.4%
Transporter
26.6%
Replicator
45.9%
Holodeck
5.2%
Artificial gravity
2.8%
Tricorder
6.1%
Poll ended at .

🚨 #DeerStealer Delivered via Obfuscated .LNK and #LOLBin Abuse.
A new phishing campaign delivers #malware through a fake PDF shortcut (Report.lnk) that leverages mshta.exe for script execution, which is a known LOLBin technique (MITRE T1218.005).
⚠️ The attack begins with an .lnk file that covertly invokes mshta.exe to drop scripts for the next stages. The execution command is heavily obfuscated using wildcard paths.

🔗 Execution chain:
.lnk ➡️ mshta.exe ➡️ cmd.exe ➡️ PowerShell ➡️ DeerStealer

To evade signature-based detection, #PowerShell dynamically resolves the full path to mshta.exe in the System32 directory. It is launched with flags, followed by obfuscated Base64 strings. Both logging and profiling are disabled to reduce forensic visibility during execution.

🚀 #ANYRUN’s Script Tracer reveals the full chain, including wildcard LOLBin execution, encoded payloads, and network exfiltration, without requiring manual deobfuscation.

Characters are decoded in pairs, converted from hex to ASCII, reassembled into a script, and executed via IEX. This ensures the #malicious logic stays hidden until runtime.

👾 The script dynamically resolves URLs and binary content from obfuscated arrays, downloads a fake PDF to distract the user, writes the main executable into AppData, and silently runs it. The PDF is opened in Adobe Acrobat to distract the user.

👨‍💻 See analysis session:
https://app.any.run/tasks/02dd6096-b621-49a0-a7ef-4758cc957c0f?utm_source=mastodon&utm_medium=post&utm_campaign=deerstealer_lolbin&utm_content=linktoti&utm_term=170725

🔍 Use these TI Lookup search requests to find similar threats to enrich your company's detection systems:
🔹 https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=deerstealer_lolbin&utm_content=linktoti&utm_term=170725#%7B%2522query%2522:%2522threatName:%255C%2522susp-lnk%255C%2522%2522,%2522dateRange%2522:180%7D%20
🔹 https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=deerstealer_lolbin&utm_content=linktoti&utm_term=170725#%7B%2522query%2522:%2522commandLine:%255C%2522%7C%2520IEX%255C%2522%2522,%2522dateRange%2522:180%7D
🔹 https://intelligence.any.run/analysis/lookup?utm_source=mastodon&utm_medium=post&utm_campaign=deerstealer_lolbin&utm_content=linktoti&utm_term=170725#%7B%2522query%2522:%2522commandLine:%255C%2522powershell*%2520-E%2520%255C%2522%2522,%2522dateRange%2522:180%7D%20

#IOC:
https[:]//tripplefury[.]com/
fd5a2f9eed065c5767d5323b8dd928ef8724ea2edeba3e4c83e211edf9ff0160
8f49254064d534459b7ec60bf4e21f75284fbabfaea511268c478e15f1ed0db9

⚡️ With real-time and deep visibility into script execution, process details, and network behavior, #ANYRUN simplifies dynamic analysis of evasive threats like DeerStealer.

#cybersecurity #infosec

🚨 NEW RESEARCH: #NVIDIAscape AI vulnerability uncovered!

Wiz Research discovered a critical vulnerability (CVE-2025-23266) in the NVIDIA Container Toolkit, the glue connecting containers to GPUs across major cloud providers.

🧱 With just three lines of code, attackers can escape containers and gain full root access to the host. That's your models, data, and GPU workloads — exposed.

NVIDIA rated it 9.0. We think it's a sign: AI infra needs stronger walls.

🛠️ Full technical breakdown + mitigation steps in our latest blog:

👉 https://www.wiz.io/blog/nvidia-ai-vulnerability-cve-2025-23266-nvidiascape

Cisco Talos has uncovered a Malware-as-a-Service operation that leverages fake GitHub accounts and public repositories to deliver a wide range of malicious payloads: https://blog.talosintelligence.com/maas-operation-using-emmenhtal-and-amadey-linked-to-threats-against-ukrainian-entities

this is because everywhere has gone "DX" - or "optimizing for the developer experience above all else, at the cost of everyone else. "

make things as easy as possible for the devs/devops, we dont care how bad the security becomes, how many layers of abstraction get installed, how many dozen new js frameworks appear this afternoon, how public the data is, how bad the architecture is - burn the building down

just make sure the devs are comfy

×

Not all heroes wear capes.

“I truly hope that people understand what’s happening. I’m a UN pro bono official — I’m not even paid. Yet suddenly I’m a threat to the global economy. Why? Because I asked big tech to comply with international law and stop profiteering from genocide.”

Francesca Albanese

#NoTechForGenocide #GazaHolocaust

@fkamiah17 I’m guessing you’ve seen this?

I’m far from convinced by the efficacy of online petitions but with so many avenues of protest or solidarity being crushed, screaming into the void feels marginally more than nothing 😱

https://secure.avaaz.org/campaign/en/stand_with_francesca_loc/?copy&utm_source=copy&utm_medium=social_share&utm_campaign=54807&share_location=campaign_page

Nobel Peace Prize for Francesca Albanese and the doctors of Gaza

Netanyahu just nominated Trump for the Nobel peace prize. Let’s show that the world thinks - Francesca and Gaza doctors deserve it instead!

Avaaz

@gvlx @fkamiah17

Indeed, citation source needed.

Googling this "quote" I find it to be all over social media, but I'm getting no pointers to when and where she actually said it.

Frankly, it looks like it's made up.

@sibrosan @gvlx @fkamiah17 It's from an interview in Middle Eastern Eye - I found a video of it on Facebook ... (No need to login to see it - I don't have facebook account ) https://m.facebook.com/watch/?v=1076809704395875&vanity=fforbiddennews
Facebook

@stephenhomewood @gvlx @fkamiah17

Thanks for the link Stephen!

I watched the video. It's not an exact transcription, but in essence that's what she says there.

So I'm satisfied that it is real, and not made up.

Watching this video again makes clear how mrs. Albanese deserves our utmost respect.

#Israel #Gaza #Palestine #Genocide #Albanese

@fkamiah17

Makes it very clear what the global economy runs on! Because complying with the law and not profiting from genocide *would* be a massive threat to the global economy.

"Global economy" => "rich people's yacht money"

"Every transaction in the developed economies of the West can be interpreted as an act of aggression against the economic losers in the worldwide game."
- Dr. Rowan Williams, Archbishop of Canterbury

@RhinosWorryMe Poor choice of quote there - the Church of England has plenty of investments in genocide-profiteering companies. I know he's not Archbish any more, but it's not like it started on Oct. 7, or that poor investment decisions are the only crime of the Anglican church (or any church, for that matter).

@fkamiah17

Fair enough. It just struck me as a surprisingly radical thing to hear from such a mainstream source.

@RhinosWorryMe Sorry, that was pretty mean of me. He's actually fairly radical and pretty cool, as far as Archbishops of Canterbury go, and was, even when he was in post.
I'm pretty militant about these things. It's all very well being slightly more outspoken than usual when you're making a massive salary while actively covering for paedophiles and profiting from climate-destroying investments. Doesn't get any applause from me, I'm afraid.

@fkamiah17

No apology needed, you make excellent points! It's mainly useful for catching the attention of mainstream people who would automatically respect him.

So not Mastodon!

@RhinosWorryMe 🤣
He's actually a pretty interesting guy. He did a translation of the Gododdin, a medieval poem in Old Welsh, with the Welsh poet laureate, Gillian Clarke, a few years ago. I think he's written his own poems too.

@fkamiah17

As it is indeed...