oscarsclaws 

125 Followers
666 Following
22 Posts
IT leader at a major Australian public library. On Yuggera/Turrbal land. Always was, always will be. Views my own unless the kids get my phone. Learning infosec, teenagers and life. Posts autodelete after three months.
Today is World Refugee Day. Here’s a poem called ‘Refugees’.
Hugely important story from Queensland where Indigenous people are being dropped from any positions of influence. This is just the start. www.abc.net.au/news/2026-06...

Qld minister tight-lipped abou...
Qld minister tight-lipped about 'Project Invisibility' Indigenous sackings

Under the direction of Arts Minister John-Paul Langbroek, eight Indigenous directors have disappeared from the boards of south-east Queensland's cultural institutions.

James Doohan (“Scotty”) stormed the beaches of Normandy on this day.

There's a tendency for organizations to react to inadvertently exposing secrets in public code repositories by disabling the repo in question on GitHub, but then taking their time to rotate the exposed credentials. I guess the thinking is that well, maybe nobody noticed. And that's pure folly. From today's story:

"Ayrey said his company Truffle Security monitors GitHub and a number of other code platforms for exposed keys, and attempts to alert affected accounts to the sensitive data exposure(s). They can do easily on GitHub because the platform publishes a live feed which includes a record of all commits and changes to public code repositories. But he said cybercriminal actors also monitor these public feeds, and are often quick to pounce on API or SSH keys that get inadvertently published in code commits."

"In practical terms, it is likely that cybercrime groups or foreign adversaries also noticed the publication of these CISA secrets, the most egregious of which appears to have happened in late April 2025, Ayrey said.

“We monitor that firehose of data for keys, and we have tools to try to figure out whose they are,” he said. “We have evidence attackers monitor that firehose as well. Anyone monitoring GitHub events could be sitting on this information.”"

My bank just emailed me to say that because I haven’t used my two factor auth recently (they only require it for specific actions), they’re disabling it on my account.

What kind of a batshit security posture is that?!!

There's serious panic being caused by AI discovered vulnerabilities behind the scenes, where those finding them are basically using them as marketing. Automated vulnerability hype train again, basically.

A thread on a few of them.

My generated single use random password is only a problem if you leaked it, mygov.

ALP: "Times are hard and we need more money"
People: "Tax the Billionaires! Stop wasting money on AUKUS! Tax gas exports! Stop subsidising oil companies! Get rid of tax breaks for rich property investors!, cut Superannuation breaks for multi-millionaires!"
ALP: "We hear you, and we are going to cut services for disabilities"

#auspol #NDIS

As an immigrant living in Australia I wouid just like to put it on record, on social media, that Angus Taylor is a deadshit.

https://www.abc.net.au/news/2026-04-13/coalition-immigration-policy-angus-taylor-announcement/106559472

Social media checks for all visa applicants under Angus Taylor plan

Social media screening would be introduced for all visa applicants under an immigration policy to be revealed by Opposition Leader Angus Taylor.

Dear National Broadcaster.

The richest woman in Australia has no expertise in war, international or domestic law. She is a private person with no qualifications beyond a high school certificate and an inherited fortune.

What she thinks of Ben Roberts Smith is for her private musings. It is not news and there is no requirement for you to publish her missives on it.