| Location | Germany |
| Threema | RCRPVWHU |
| Also | @[email protected] |
| Keybase | https://keybase.io/jnievele |
| Location | Germany |
| Threema | RCRPVWHU |
| Also | @[email protected] |
| Keybase | https://keybase.io/jnievele |
Short question to the Texans in here... is the job market swept THAT bare for security people?
My boss put up a job ad for a security manager role in Houston one month ago, and at least on LinkedIn there's only 1 application so far... (in case anyone is looking for a new gig... https://www.linkedin.com/jobs/view/3414530794/ )
Oh, that was a new one.
Got an email from PayPal about a suspicious payment request. I verified the email came from PayPal, but went into PayPal itself to check. Sure enough, suspicious request, and the note indicated it had been flagged, with a number to call.
I called.
And while I was on the call, went to the PayPal "Contact" link... and realized it was a different number.
The attacker was using the INVOICE NOTE to phish for details.
Hoping I didn't expose to much before I figured it out.
I did not see "Raspberry Pi co-founder becomes ridiculous conspiracy theorist" coming but here we are.
You did some bad PR, then handled it incredibly badly when everyone called you on it. That's it. Stop trying to blame everyone but yourselves.
Warning: Do not use Hive Social ⚠️🐝
We found multiple critical security vulnerabilities in the App, leaking private messages, posts, images and user data like phone numbers, emails and birthdates.
Dieser Artikel ist auch auf deutsch erschienen. Update: The vulnerabilities are currently no longer exploitable because Hive deactivated their servers. More details Following the Twitter takeover, a number of services promising to be an alternative gained traction. One of those is “Hive Social”, which reached more than a million users in the last weeks. Of course, we were interested and took a look at Hive from a security standpoint. We found a number of critical vulnerabilities, which we confidentially reported to the company. After multiple attempts to contact the company we finally reached them by phone and they acknowledged the report. After multiple days and multiple reminders by us, they claimed to fix them within the next two days. However after those two days, multiple vulnerabilities we reported were not fixed and still existed at the time of writing. ⚠️ We strongly advise against using Hive in any form in the current state.