🌱 Ligniform 

@ligniform@infosec.exchange
709 Followers
535 Following
124 Posts

SOC Analyst starting my #InfoSec journey, mainly posting about #Privacy or anything else that interests me.

Posts may contain: #FOSS #Privacy #CyberSecurity #Python #CTF #Security and plenty more.

PronounsHe, Him, His
Pfp byhttps://astroeden.tumblr.com/
SignalQuadratary.03
Bloghttps://ligniform.blog
me: well life's meaningless, just have a good time while you go about it
me: *proceeds to study computer science*

Oh boy! The PineNote is out!

Just €610 :/

Did you know that Microsoft just turns Copilot writing assist on for webpages in Microsoft Edge?
So like, if you type in edit boxes, it just... gets sent to Microsoft? Straight up?
And this is enabled by default?
So first, what the actual hell? Second, why is nobody talking about this? How the hell is right now the first time I find out about this?

We showered my girlfriends cat in the afternoon, and by evening she was grooming herself.

Bitch you're already clean!!!!! Stop licking!!!

A very “surprising pattern” that people don’t want to use fucking shit that doesn’t fucking work and depends on stealing people’s work and fucking lighting the mother-fucking planet on fire while feeding their fucking money into the greedy throats of billionaires.
Memes like these kill me inside a little. I've interacted with too many people who think this is how anyone working in #InfoSec should act.
I just don't understand why they're doing ID card checks for age verification instead of just asking people how their back is ...
Live, laugh, love, grow increasingly deranged yet remain somewhat handsome
stromy is a minimal, customizable and neofetch-like weather CLI for Linux, Unix, macOS & BSD, written in Go lang. Try it out ⤵️
Browser extensions sell what you view to AI companies, GNOME funding, Wayback progresses

💻 Get a Linux computer from our sponsor, Tuxedo💻 https://www.tuxedocomputers.com/en# 👏 Support the show here: 👏 Patreon supporters get the daily Linux & Open Source audio show! https://www.patreon.com/thelinuxexperiment Or you can support me with a one time donation: https://www.paypal.com/paypalme/thelinuxexp https://liberapay.com/TheLinuxExperiment/ 👕 Buy TLE Merch: 👕 https://the-linux-experiment.creator-spring.com/ 📹 Watch Linux videos: 📹 https://www.youtube.com/thelinuxexperiment 🎙️ Leave your feedback here: 🎙️ https://podcast.thelinuxexp.com 02:00 Hundreds of browser extensions use AI library https://secureannex.com/blog/mellow-drama/ https://www.mellowtel.com/blog/responding-to-ars-technica-and-mellow-drama-article 05:55 GNOME Foundation will fund developers https://blogs.gnome.org/steven/2025/07/05/2025-07-05-foundation-update/ 08:15 Wayback is now hosted by Freedesktop.org https://www.phoronix.com/news/Wayback-FreeDesktop.org 10:09 GNOME 49 alpha is out https://discourse.gnome.org/t/gnome-49-alpha-released/29720 https://www.phoronix.com/news/GNOME-49-Alpha 12:12 Bazzite launches their new Flatpak app store https://universal-blue.discourse.group/t/bazzite-july-2025-update-bazaar-z13-kernel-6-15-steam-hardware-survey/9501 13:47 Google forces Gemini integration into Android apps https://arstechnica.com/security/2025/07/unless-users-take-action-android-will-let-gemini-access-third-party-apps/ 15:56 Chromium browsers will get even faster https://blog.chromium.org/2025/07/introducing-skia-graphite-chromes.html 17:42 Plasma Big Screen lives again https://espi.dev/posts/2025/07/plasma-bigscreen/ 20:17 Video game lobby push back against stop killing games https://www.gamingonlinux.com/2025/07/video-games-europe-release-a-statement-on-stop-killing-games/ 23:04 German court finds Meta’s tracking illegal https://therecord.media/german-court-meta-tracking-tech

The Linux Experiment Podcasts
×
Ultra spicy post claiming to be from UK retailer employee (M&S or Co-op) about their experience with TCS on their security incident. https://www.reddit.com/r/cybersecurity/comments/1ll1l6c/scattered_spider_tcs_blame_avoidance/?utm_source=share&utm_medium=mweb3x&utm_name=mweb3xcss&utm_term=1&utm_content=share_button

Marks and Spencer’s CEO says half of their online ordering is still offline after their ransomware incident, they hope to get open in next 4 weeks.

They are also rebuilding internal systems and hope a majority of that will be done by August.

Lesson: mass contain early. M&S didn’t. Co-op did.

https://www.reuters.com/business/retail-consumer/ms-ceo-most-cyberattack-impact-will-be-behind-us-by-august-2025-07-01/

17 and two 19 year old teens picked up over Co-op and M&S hacks, and a 20 year old woman.

Pretend to be surprised.

https://www.bbc.com/news/articles/cwykgrv374eo

Four arrested in connection with M&S and Co-op cyber attacks

Three men and one woman - aged between 17 and 20 - have been arrested in London and the Midlands.

If you ever doubted the link between Scattered Spider(tm) and LAPSUS$ - one of the people arrested today was a key part of the LAPSUS$ attacks a few years ago.
After almost 3 months, Marks and Spencer recruitment system came back online just now. First 4 jobs posted.

. @briankrebs has broken the story that the key member (and teenager) of LAPSUS$ runs Scattered Spider

https://krebsonsecurity.com/2025/07/uk-charges-four-in-scattered-spider-ransom-group/

@GossiTheDog One would think they would post for cyber security engineers or something
@GossiTheDog Seems like hiring security people should be a higher priority than social media managers 😆
@GossiTheDog kek and no SECURTY STRATEGIST xD
@GossiTheDog scared to list jobs in case the hackers applied but now they're arrested it's safe?
@GossiTheDog did they get caught and sentenced at the time?
Four arrested in connection with M&S and Co-op cyber attacks

Three men and one woman - aged between 17 and 20 - have been arrested in London and the Midlands.

@GossiTheDog Sweet holy mother of surprise, I nearly raised an eyebrow 😁
@GossiTheDog that took longer than expected
@GossiTheDog at this point I'm much more surprised when someone over 25 gets picked up for hacking stuff, I think some dude was helping gangs smuggle drugs into Rotterdam via hacking into the port logistical systems, they were like 41 with kids, that was way more unexpected to me lol

https://www.occrp.org/en/project/narcofiles-the-new-criminal-order/inside-job-how-a-hacker-helped-cocaine-traffickers-infiltrate-europes-biggest-ports
Inside Job: How a Hacker Helped Cocaine Traffickers Infiltrate Europe’s Biggest Ports

Europe’s commercial ports are top entry points for cocaine flooding in at record rates. The work of a Dutch hacker, who was hired by drug traffickers to penetrate port IT networks, reveals how this type of smuggling has become easier than ever.

OCCRP
@GossiTheDog I’m certainly no IT security expert, but if your system is getting popped by three kids, does that perhaps indicate that you may have missed a few opportunities for improvement in the past? 🤔
@slothrop @GossiTheDog yes, but also, this is every computer system on earth

they all suck, and they've always sucked, in the '90s teenagers were hacking nuclear power plants in India, these days kids hack solar farms and water treatment plants and traffic light systems for fun, very little has changed tbh
@froge as long as security, helpdesk and IT in general is seen as a cost center that needs to be continually stripped this will not stop. We will get the same song and dance we had for the last 30 years, including the snake oil salesman with their: fixitallsolution now with 100% more AI.
It's all so tiresome.
@lfzz @froge give me ai so i can fire all those hangers on - pretty much management attitude, i buy it, it is happening in enterprise will eat its way down to smb. people will riot but that is just change in action, they will get over it willingly or unwillingly
@slothrop @GossiTheDog as someone who was involved with a UK schools programme to get teenagers into cyber security, I can say with absolute certainty that you should not assume that just because they're young doesn't mean that it wasn't sophisticated. Doesn't mean it was, either, but some kids are ridiculously talented.

@GossiTheDog kids these days 🙄

Just stay away from my bins!

@GossiTheDog it’s an older meme sir, but it checks out
@GossiTheDog is the 17 year old going to be tried as an adult here? Idk laws in the UK

@GossiTheDog At least the companies used sophisticated defense in depth.

“The BBC later discovered from the criminals that the company disconnected the internet from IT networks in the nick of time to stop the hackers from deploying ransomware and so causing even more disruption.

"Shortly after Co-op announced it had been attacked, luxury retailer Harrods said it too had been targeted and had been forced to disconnect IT systems from the internet to keep the criminals out.”

@GossiTheDog It was a lot easier for the IT folk in The Co-op to make that call to pull the plug after they'd just seen what happened to M&S!
@GossiTheDog this doesn't surprise me, in india TCS is seen as a spring board job. You join to gain experience. Stay for a few months maybe a year or two(if you're really desperate). grit your teeth deal with a horrible boss and then move to a better paying job. They have pretty high turnovers so training new staff is probably super low on the priority.

@GossiTheDog I'd be very curious to know what the breakdown is between TCS dropping the ball and lying about it and M&S/Co-op not actually insisting on adequate procedure.

It's not terribly uncommon for people to only care about time-to-resolution with some lip service to user satisfaction when it comes to helpdesk metrics; and tacitly discourage things that are slow and unpleasant like hassling people for ID, at least until that becomes a visibly terrible idea.

@GossiTheDog fun that this is the same TCS who are working on the DWP Child Maintenance Scheme and run the Teachers Pension Scheme for the DfE.
@RichBartlett @GossiTheDog TCS has not yet taken over TPS ops, another year+ before Capita is gone
@grievousangel @GossiTheDog thanks, feels a bit like frying pan > fire moving from Capita to TCS!
@RichBartlett yes, very likely. Many in DfE would say TPS likely to be an upgrade in this instance but the bar is desperately low.

@GossiTheDog

"M-SThrowaway" might indicate M&S?

Or is that too obvious or deliberate obfuscation? 🙂🤷‍♂️

@GossiTheDog as someone who has been subjected to Tata on multiple occasions going back over a decade?

This isn't nearly spicy enough. I don't even describe them as a 'body shop' because they'd gladly route you to a corpse and try to charge extra for '24x7 coverage.'

When one employer did a basic security audit of their helpdesk services, Tata failed so severely that the contract was pulled for cause before the audit was even completed. They moved it all back in-house.

@GossiTheDog and lo, I found my notes! And, hooboy, hang onto your hats kiddos. Things they failed at (which caused me work):

- resetting passwords without verifying identities
- removing 2FA from accounts (not allowed period; there was a procedure)
- removing or updating 2FA without verifying identities (so a LOT of 2FAs had to be assumed compromised)
- adding users to groups directly instead of directing them to the appropriate request

@GossiTheDog The root problem here isn't that TCS are shockingly bad (they are, just about everyone knows that).

The root problem is that "management decisions" constantly overrule those that raise concerns about their service and tell any remaining internal IT and security staff to "deal with it as best you can."

I'm very much of the view that, yes, the outsourced provider can be the cause of an incident, they can provide a shockingly bad service, they can cost your business millions of pounds. But the decision to continue to use them when you already know this is a real possibility - that's a decision by senior management within the company. That's on you.

@Cyberoutsider @GossiTheDog Totally agree. You can outsource the work but never the accountability.

Here is (yet another) example of risk management failures, the management under cost pressures find affordable solutions, celebrated for cost savings but the implicit risks are not understood nor uncovered during sourcing process.

There are ways to compensate however there is any way a significant risk trade off that needs to be made consciously, rather than implicitly like today.

(Experience from enterprise offshore outsourcing +15 years)

@GossiTheDog ATOS in the past have operated in a similar way (my experience). But if a post mortem investigation finds that the IT contractor was at fault and created an attack vector, as perhaps is being implied here, then I believe that any current business insurance policy might not cover the financial losses. I guess that the affected businesses might need to pursue legal action. What a mess 🤦
@GossiTheDog
This is epically bad for TCS. Good work.

@GossiTheDog Interesting. I don't have the background on this specific attack, but I'm reminded of the Target credit card theft. An HVAC company near me was the point of entry for the attackers; they had high-access keys to Target's intranet because they install and maintain shopping-mall-grade HVAC and can remote-override it for maintenance and schedule reasons (nation-scale chain stores with giant footprints save not-inconsequential money on things like "Don't power up the HVAC to normal capacity on days nobody is here").

They had the keys on the same machine running their webserver.

(Meanwhile, Target actually did get an SEC slap-on-the-wrist for one specific thing: the HVAC intranet piece wasn't firewalled from the financial transactions and cash register source code pieces).

@GossiTheDog @tdp_org

If it is the case then the leaders of businesses like M&S who outsource these services to the lowest cost providers should also be held to account

It’s typical of British business management to know the cost of technology but not the value of it

@GossiTheDog I wonder what the liquidated damages cap is in the contract.
@GossiTheDog And who brought them in and kept them? Culpa in eligendo.

@GossiTheDog K. Krithivasan, also known as Krithi, aka the face of quality IT, that you can trust.

Hash tag

These Indian, "IT", call centers probably do double time as scamming operations.

Hilarious twist would be that it was an inside job, faked to look like a compromise.

@GossiTheDog

Why does an offshore call center even have access to administrator passwords?

@resuna they run the IT for M&S and Co-op, it’s outsourced