Wall of Sheep

1.2K Followers
87 Following
192 Posts

This is the official Mastodon account for the Wall of Sheep and Packet Hacking Village at DEF CON.

Our village provides a forum for people of all backgrounds and experience levels to learn about cybersecurity and hacking. We have workshops and challenges for beginner to expert and beyond, and all are welcome.

Websitehttps://www.wallofsheep.com/
Twitterhttps://twitter.com/wallofsheep

The Herculean effort to build a 6.71 terabits per second network — that’s more than 250,000 times faster than the average U.S. household connection — has been years in the making.

https://coloradosun.com/2023/11/13/fastest-internet-service-terabits-denver-sc23/

The world’s fastest temporary internet service gets turned on in Denver for one week only 

At 6.71 terabits per second, the internet speed will be 250,000 times faster than the average U.S. household. SC23 is an annual supercomputing convention, which has built a lasting impression in Colorado.

The Colorado Sun

Anastasia Synn, 48, from Tehachapi, California, now holds the Guinness World Record for the woman with the most technological implants in her body.

https://nypost.com/2023/11/09/lifestyle/anastasia-synn-is-world-record-human-cyborg-with-52-implants/

I am a world-record ‘human cyborg’ — with 52 implants in my body

She’s got a magnetic personality — literally.

New York Post

A new malvertising campaign has been found to employ fake sites that masquerade as legitimate Windows news portal to propagate a malicious installer for a popular system profiling tool called CPU-Z.

https://thehackernews.com/2023/11/new-malvertising-campaign-uses-fake.html?m=1

New Malvertising Campaign Uses Fake Windows News Portal to Distribute Malicious Installers

Malicious sites posing as legit Windows news portals spotted distributing malware disguised as CPU-Z.

The Hacker News

Apple's "Find My" location network can be abused by malicious actors to stealthily transmit sensitive information captured by keyloggers installed in keyboards.

https://www.bleepingcomputer.com/news/apple/apple-find-my-network-can-be-abused-to-steal-keylogged-passwords/

Apple 'Find My' network can be abused to steal keylogged passwords

Apple's "Find My" location network can be abused by malicious actors to stealthily transmit sensitive information captured by keyloggers installed in keyboards.

BleepingComputer

Microsoft Exchange is impacted by four zero-day vulnerabilities that attackers can exploit remotely to execute arbitrary code or disclose sensitive information on affected installations.

https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/

New Microsoft Exchange zero-days allow RCE, data theft attacks

Microsoft Exchange is impacted by four zero-day vulnerabilities that attackers can exploit remotely to execute arbitrary code or disclose sensitive information on affected installations.

BleepingComputer

A fundraiser in support of StilettoedMacgyver's family as they navigate this difficult time.
Please give as your heart directs and as you are able. ♥🐏♥

https://www.gofundme.com/f/lynne-murphy-farrell

Lynne Murphy Farrell, organized by Channing Rossi

Help Us Celebrate the Extraordinary Life of Lynne Murphy Farrell. We come to you with heavy hear… Channing Rossi needs your support for Lynne Murphy Farrell

gofundme.com

It is with great sorrow and love that we pay tribute to one of our Shepherds and a valued member of the #defcon community.
StilettoedMacgyver passed away on October 17, 2023.

If you have pictures or memories that you would like to contribute, please send them in.

https://www.wallofsheep.com/blogs/news/a-tribute-to-stilettoedmacgyver

A tribute to StilettoedMacgyver

It is with great sorrow and love that we pay tribute to one of our Shepherds. StilettoedMacgyver passed away on October 17, 2023. She gave selflessly of her time and energy to help the hacker community, and we are all diminished by her loss.

Wall of Sheep

Researchers have devised an attack that forces Apple’s Safari browser to divulge passwords, Gmail message content, and other secrets by exploiting a side channel vulnerability in the A- and M-series CPUs running modern iOS and macOS devices.

https://arstechnica.com/security/2023/10/hackers-can-force-ios-and-macos-browsers-to-divulge-passwords-and-a-whole-lot-more/

Hackers can force iOS and macOS browsers to divulge passwords and much more – Ars Technica

ZDNET has tested this and can confirm that it can lock up an iPhone running the latest iOS 17.0.3. The issue does not appear to affect iPhones running iOS 16.

https://www.zdnet.com/article/flipper-zero-can-lock-up-an-iphone-running-the-latest-ios-17/

Flipper Zero can be used to crash iPhones running iOS 17, but there's a way to foil the attack

It basically performs a denial of service (DoS) attack on iPhones. Here's how it works and what you can do to protect your phone.

ZDNET

35 vulnerabilities in the Squid caching proxy remain unfixed more than two years after being found and disclosed to the open source project's maintainers, according to the person who reported them.

https://www.theregister.com/2023/10/13/squid_proxy_bugs_remain_unfixed/

Squid games: 35 security holes still unpatched in proxy after 2 years, now public

We'd like to say don't panic … but maybe?

The Register