79 Followers
245 Following
108 Posts
CloudSec, ProdSec, Automation, old man yelling at cloud.
Security learner, interested in everything.
Keybasehttps://keybase.io/ldurufle
starting in the pending #curl 8.16.0, curl will default to TLS 1.2 as a minimum even if the TLS library can do lower versions
whoami 🤣

Just signed the papers....

There may be no future, but there will be another fwd:cloudsec.

June 30th - July 1st 2025 in Denver CO

So, we can finally tell you more about tickets! There will be two rounds of tickets with the first round being 23.10@13:37 o'clock. Be quick, historically they got sold out pretty quickly.
Don’t use CSAM as the acronym for Cybersecurity Awareness Month. Just trust me on this one

Some possible good news for a change: T-Mobile settled with The Federal Communications Commission (FCC) and agreed to pay a paltry $31.5 million over multiple data breaches that compromised the personal info of millions of US consumers.

But that's not the good news: Under the settlement, T-Mobile has agreed to require multifactor authentication for their bajillion employees.

https://www.bleepingcomputer.com/news/security/t-mobile-pays-315-million-fcc-settlement-over-4-data-breaches/

We'll see if and how soon this happens, and if it's decent multifactor. It's still progress. Last year I reported that three different criminal SIM-swapping groups had phished or breached access to T-Mobile employee accounts in more than 100 separate incidents throughout 2022.

https://krebsonsecurity.com/2023/02/hackers-claim-they-breached-t-mobile-more-than-100-times-in-2022/

It's unclear whether T-Mobile's competitors will be held to the same standard.

T-Mobile pays $31.5 million FCC settlement over 4 data breaches

The Federal Communications Commission (FCC) announced a $31.5 million settlement with T-Mobile over multiple data breaches that compromised the personal information of millions of U.S. consumers.

BleepingComputer

By me:

Chief among them: mandatory resets, required or restricted use of certain characters, and the use of security questions

https://arstechnica.com/security/2024/09/nist-proposes-barring-some-of-the-most-nonsensical-password-rules/

NIST proposes barring some of the most nonsensical password rules

Proposed guidelines aim to inject badly needed common sense into password hygiene.

Ars Technica

🚀Introducing OpenRelik: Open-source platform for digital forensic investigations. Modular workflows, collaboration, central artifact repository and easily extendable to support new tools in a clean, easy to use interface.

https://openrelik.org

Community discussion: https://github.com/orgs/openrelik/discussions/1

#DFIR

20 dollars pour récupérer la gestion du .MOBI : derrière l’amusement, un réel #danger
https://next.ink/149905/20-dollars-pour-recuperer-la-gestion-du-mobi-derriere-lamusement-un-reel-danger/
#TLD
20 dollars pour récupérer la gestion du .MOBI : derrière l’amusement, un réel danger - Next

C’est une histoire abracadabrante que raconte la société de sécurité watchTowr Labs. Les chercheurs ont en effet réussi à s’emparer de l’ancienne adresse utilisée pour les requêtes WHOIS du domaine de premier niveau MOBI. La manipulation, qu’ils décrivent comme très simple, met en évidence ce type de danger pour les TLD (top-level domains). Les chercheurs […]

Next