130 Followers
259 Following
78 Posts

(Software) Engineer & #Whitehat @ Healthcare business 🇩🇪​🕵️
Interested in #OffSec, #Hospitals, #Healthcare, #Biohacking 🏥
Tinkering/Prototyping 24/7 👨‍💻👾 Sometimes do #CTF's 🏁​ Level 2X

Chat with me! I am here to network! 💬​

⚠️​​opinions expressed are mine ⚠️​​

Anyone from InfoSec Community interested in a BlueSky invite? Contact me. bsky-social-
Great news! Hive #ransomware group got disrupted! Hive attacked multiple #healthcare facilities before. Interestingly, the banner on their darknet page explicitly lists the "Polizeipräsidium #Reutlingen" next to the big 3 letter agencies. Wondering how my neighbors were involved... Anyways, good job! #infosec #cybersecurity #news

For comparison, last I checked the Bitcoin network was computing about 2^64 hashes every 10 minutes and using as much electricity as Argentina.

Bitcoin doesn’t crack passwords, but if it could & the entire Bitcoin network was cracking your 6-word 1Password phrase, it would take about 9.5 years on average.

Another #cybersecurity alert: T-Mobile says #hackers illegally accessed records of 37 million customers.

- Apparently the intrusion started on Nov. 25 but wasn't detected until Jan. 5
- Addresses, names and account info was stolen but financial data wasn't compromised
- No breach of the company's network
- Any malicious activity has since been halted, according to reports

T-Mobile Says Hacker Stole Data for 37 Million Customers https://www.bloomberg.com/news/articles/2023-01-19/t-mobile-tmus-says-hacker-stole-data-for-37-million-customers

#technology #business #security

Successful people do what unsuccessful people are not willing to do.
Don't wish it were easier, wish you were better.

#DailyMotivation #inspiration #motivation #bestadvice #lifelessons #changeyourmindset

Update on #SickKids #ransomware attack 4th January 2023:
3xp0rtblog shared this post by #lockbit. Does LockBit really think there are no computers in a #hospital ?

#infosec #cybersecurity #health #healthcare #canada

Sam Curry and his findings in #automobile #industry. Got Goosebumps reading this. Great article!
https://samcurry.net/web-hackers-vs-the-auto-industry/
#infosec #cyber #cybersecurity #car
Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More

During the fall of 2022, a few friends and I took a road trip from Chicago, IL to Washington, DC to attend a cybersecurity conference and (try) to take a break from our usual computer work. While we were visiting the University of Maryland, we came across a fleet of electric scooters scattered across the

Sam Curry | Web Application Security Researcher

Summary on #mastodon #privacy, people #scraping Mastodon to make #search engines and the illusion that Mastodon is #private. Good read.

My opinion: Mastodon Users ALWAYS should consider information that can be accessed by a unknown amount of people (followers + instance admins) to be no more private. You lie yourself if you think your posts are private because you cant find them over the search.
Mastodon will be scraped. Ofc it will, its a social network. A #threat actor doesnt care about what you personally consider private. Mastodon might be able to make it a bit harder, but not impossible. As soon as you ask for user authentication to make certain #api requests, we will have a bunch of #bots and #fake users. Imo we should make it EASIER to search, so all the instances dont get ddos'ed by search engine creators.

https://www.tbray.org/ongoing/When/202x/2022/12/30/Mastodon-Privacy-and-Search
Written by @timbray

#fedisearch #searchengine #seo #blog

Private and Public Mastodon

ongoing by Tim Bray

Oh goodie, there's a new #Windows #vulnerability (CVE-2022-37958) that can remotely execute code without any authentication, like #EternalBlue (CVE-2017-0144), but more flexible. Fortunately, #Micosoft patched this in September 2022 after #IBM #XForce reported it to them. #IBM will release the full technical details in Q2 2023.

https://securityintelligence.com/posts/critical-remote-code-execution-vulnerability-spnego-extended-negotiation-security-mechanism/

#cybersecurity #infosec #exploit

Critical Remote Code Execution Vulnerability in SPNEGO Extended Negotiation Security Mechanism

A vulnerability in SPNEGO NEGOEX has been reclassified as "Critical" after it was discovered that it could allow attackers to remotely execute code.

Security Intelligence

Thinking more people are going to engage with you on mainstream social media “because everyone’s there” is like thinking people at a stadium concert are there to listen to you. It‘s only true if you’re one of the ones on stage. Not so much when you’re huddled in the nosebleeds.

Forget the numbers. Forget about “going viral” (leave it to the psychopaths in Silicon Valley to make virus-like behaviour aspirational). Embrace the joy of interacting with one another on a human scale.

#ThinkSmall