Probablynothelping

8 Followers
122 Following
122 Posts
I was using bird site to see memes and threat intel/tips. Doing the same here, I don’t post much. My work is infosec, my passions are coffee and friends. I am ALWAYS willing to engage about coffee beans/brew methods/ or tech.
@iagox86 @tychotithonus knowbe4 forces their customers to allow them to have direct to inbox access, bypassing all security, thereby rendering their entire service meaningless, since none of their shit could ever make it past real filtering
Man pulls off daring scuba heist of Disney paddleboat restaurant, netting $10K-$20K before successfully escaping into the water from whence he came.
https://www.jalopnik.com/1970971/scuba-thief-steals-thousands-floating-disney/
Scuba Thief Steals Thousands From Floating Disney Restaurant, Then Disappears Into Water

Have you ever wanted to pull off the perfect heist, something that would make Steven Soderbergh green with envy?

Jalopnik
Someone has apparently registered a Boost mobile phone plan to an email group at my company like security@company[.]com. I’ve verified emails ARE coming from boost servers and the links seem to go to legit boost urls - what’s the scam? #socialengineering #infosec
Why is there no open source hardware/software solution to the Sonos problem yet?
this is the world they took from us
My brother just got hit by a really insidious bank scam. Scammers spoofed caller ID with citibank’s real online banking number and tell him “there was a fraudulent Zelle transfer from your account. Call Zelle at this number.” Fake-Zelle rep confirms fake case numbers that fake-Citi gave him, dazzles with still more bullshit and gets him to actually transfer money to them under some plausible sounding “fix” pretext. Slick. Citi says it’s a new one on them and are investigating ASAP.

A new Plex feature shows you what your friends and family are watching, horrifies users:

"one of my friends is apparently watching a ton of cheesy, soft porn stuff"

"Discover Together and Week in Review emails are a MASSIVE breach of privacy and trust!"

"I just got an email about a friend’s watching habits which he definitely didn’t want to share."

"a certain percentage of people want to know what kind of porn grandma likes, but I’m hoping it’s not the majority"

https://www.404media.co/plex-users-fear-discover-together-week-in-review-feature-will-leak-porn-habits-to-their-friends-and-family/

Plex Users Fear New Feature Will Leak Porn Habits to Their Friends and Family

"I can see that one of my friends is apparently watching a ton of cheesy, soft porn stuff," a user said of Plex's Week in Review email and Discover Together feature.

404 Media

A new Plex feature shows you what your friends and family are watching, horrifies users:

"one of my friends is apparently watching a ton of cheesy, soft porn stuff"

"Discover Together and Week in Review emails are a MASSIVE breach of privacy and trust!"

"I just got an email about a friend’s watching habits which he definitely didn’t want to share."

"a certain percentage of people want to know what kind of porn grandma likes, but I’m hoping it’s not the majority"

https://www.404media.co/plex-users-fear-discover-together-week-in-review-feature-will-leak-porn-habits-to-their-friends-and-family/

Plex Users Fear New Feature Will Leak Porn Habits to Their Friends and Family

"I can see that one of my friends is apparently watching a ton of cheesy, soft porn stuff," a user said of Plex's Week in Review email and Discover Together feature.

404 Media
Security Bulletin NR23-01 — Security Advisory | New Relic Documentation

Final update to Security Bulletin NR23-01

Update your iPhones and iPads. Enable Lockdown Mode if you're at risk of advance spyware targeting you. And take note of this. https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/
BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild - The Citizen Lab

Citizen Lab found an actively exploited zero-click vulnerability being used to deliver NSO Group’s Pegasus mercenary spyware while checking the device of an individual employed by a Washington DC-based civil society organization with international offices. We refer to the exploit chain as BLASTPASS. The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim.

The Citizen Lab