mastodon.design is one of the many independent Mastodon servers you can use to participate in the fediverse.
A small instance for and by people who make things! We stand for an open, independent, sustainable, inclusive, and accessible web.

Administered by:

Server stats:

337
active users

#infosec

152 posts132 participants0 posts today
Mysk🇨🇦🇩🇪<p>By default, the searches you enter into Safari and Spotlight on both your <a href="https://mastodon.social/tags/iPhone" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iPhone</span></a> and Mac are sent to <a href="https://mastodon.social/tags/Apple" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Apple</span></a> in a way that is not linked to you.<br>To disable it, go to:<br>Settings &gt; Search (on a Mac, Settings &gt; Spotlight) and toggle the switch off.<br><a href="https://mastodon.social/tags/Privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Privacy</span></a> <a href="https://mastodon.social/tags/PrivacyMatters" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PrivacyMatters</span></a> <a href="https://mastodon.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
Matthias Schulze<p>China’s Volt Typhoon Hackers Dwelled in US Electric Grid for 300 Days <a href="https://www.securityweek.com/chinas-volt-typhoon-hackers-dwelled-in-us-electric-grid-for-300-days/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">securityweek.com/chinas-volt-t</span><span class="invisible">yphoon-hackers-dwelled-in-us-electric-grid-for-300-days/</span></a> <a href="https://ioc.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://ioc.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
Renata Rocha ⛄️<p>Hello! I will be at the RSAC in San Francisco from April 28 to May 2nd with <span class="h-card" translate="no"><a href="https://1password.social/@1password" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>1password</span></a></span> ! Excited to see you there! <a href="https://hachyderm.io/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://hachyderm.io/tags/rsac2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>rsac2025</span></a> <a href="https://hachyderm.io/tags/rsac" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>rsac</span></a> <a href="https://hachyderm.io/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
Mark Stosberg<p>Two critical authentication-bypass vulns in the JavaScript `xml-crypto` module have been disclosed.</p><p>If you use `node-saml` or `passport-saml` which use it for XML handling, you should upgrade immediately.</p><p><a href="https://github.com/node-saml/xml-crypto/security/advisories" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/node-saml/xml-crypt</span><span class="invisible">o/security/advisories</span></a></p><p><a href="https://urbanists.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://urbanists.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://urbanists.social/tags/javascript" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>javascript</span></a> <a href="https://urbanists.social/tags/typescript" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>typescript</span></a> <a href="https://urbanists.social/tags/nodejs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nodejs</span></a></p>
AAKL<p>AP: Don’t click on those road toll texts. Officials issue warnings about the smishing scam <a href="https://apnews.com/article/outstanding-toll-scams-smishing-phishing-fbi-c2948f44b810d5160b60738b95486ae9" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">apnews.com/article/outstanding</span><span class="invisible">-toll-scams-smishing-phishing-fbi-c2948f44b810d5160b60738b95486ae9</span></a> <span class="h-card" translate="no"><a href="https://flipboard.com/@AssociatedPress" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>AssociatedPress</span></a></span> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>phishing</span></a></p>
Guillaume Ross<p>Join my <a href="https://irrelephant.co/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> nerds <a href="https://irrelephant.co/tags/Formula1" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Formula1</span></a> semi-private league!</p><p>Teams are getting locked in about 13 hours!</p><p><a href="https://fantasy.formula1.com/en/leagues/join/C5RXS3KBZ03" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">fantasy.formula1.com/en/league</span><span class="invisible">s/join/C5RXS3KBZ03</span></a></p>
sͧb̴ͫƸ̴gͬᵉ<p><span class="h-card" translate="no"><a href="https://cyberplace.social/@GossiTheDog" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>GossiTheDog</span></a></span> <br>There comes a point in every <a href="https://infosec.exchange/tags/CISO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CISO</span></a>:s life when they think ”Maybe, maybe I know enough of <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> to be able to very quietly earn a living on The Dark Side”.</p><p>This event is called The Point Of Recall.</p>
Anna Wasilewska-Śpioch<p>Kończę właśnie "Wielki skok Grupy Lazarus" autorstwa Geoffa White'a i jest to naprawdę dobra książka, tylko denerwuje mnie niepomiernie używanie przez tłumaczkę słowa "wirus" jako odpowiednika angielskiego "malware". Ja wiem, że "złośliwe oprogramowanie" nie jest zbyt poręcznym terminem, ale naprawdę nie wszystko, co atakujący wpuszczają do sieci, można nazwać wirusem. To nie są synonimy :blobfacepalm: </p><p><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/ksiazki" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ksiazki</span></a> <a href="https://infosec.exchange/tags/lazarus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>lazarus</span></a></p>
shellsharks<p>Volume SEVEN of my <a href="https://malici.ous.computer/tags/indieweb" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IndieWeb</span></a>, <a href="https://malici.ous.computer/tags/fediverse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fediverse</span></a> and <a href="https://malici.ous.computer/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> / <a href="https://malici.ous.computer/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infosec</span></a> newsletter, "Scrolls" has landed! You can read and get scrollin' here <a href="https://shellsharks.com/scrolls/scroll/2025-03-14" rel="nofollow noopener noreferrer" target="_blank">https://shellsharks.com/scrolls/scroll/2025-03-14</a>.</p><p>It features the usual awesomeness and also has a vastly improved logo, created by my good friend and super talented artist angryrolypoly (<a href="https://www.instagram.com/angryrolypoly/" rel="nofollow noopener noreferrer" target="_blank">https://www.instagram.com/angryrolypoly/</a>). He's also the genius behind a lot of the other art on my site including my Fedi profile pic!</p><p>Also, special shoutout as well to <span class="h-card"><a href="https://social.lol/@humdrum" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>humdrum</span></a></span> for making some other art for the Scrolls cause 🤗.</p><p>The art and images of Scrolls, as much as the links themselves are what make it such a pleasure to read - one more big THANK YOU to <span class="h-card"><a href="https://mastodon.art/@shaferbrown" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>shaferbrown</span></a></span> &amp; <span class="h-card"><a href="https://mastodon.social/@skeddles" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>skeddles</span></a></span> for being such talented artists. I enjoy seeing everything you post!</p><p>Finally, my mass-shouting-out of everyone else who contributed to this weeks edition! Sharing the cool stuff you find, build and create is what makes the Internet great, and this newsletter so fun to put together.</p><p><span class="h-card"><a href="https://mastodon.social/@Viss" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Viss</span></a></span> <span class="h-card"><a href="https://mastodon.social/@_elena" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>_elena</span></a></span> <span class="h-card"><a href="https://infosec.exchange/@cR0w" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>cR0w</span></a></span> <span class="h-card"><a href="https://4d2.social/@CryogenicNighthawk" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>CryogenicNighthawk</span></a></span> <span class="h-card"><a href="https://mastodon.social/@Daojoan" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Daojoan</span></a></span> <span class="h-card"><a href="https://mstdn.social/@DM_Ronin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>DM_Ronin</span></a></span> <span class="h-card"><a href="https://infosec.exchange/@mubix" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>mubix</span></a></span> <span class="h-card"><a href="https://sonomu.club/@gavcloud" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>gavcloud</span></a></span> <span class="h-card"><a href="https://indieweb.social/@fyr" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>fyr</span></a></span> <span class="h-card"><a href="https://lazybear.social/@hyde" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>hyde</span></a></span> <span class="h-card"><a href="https://xoxo.zone/@artlung" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>artlung</span></a></span> <span class="h-card"><a href="https://mastodon.social/@eddiedale" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>eddiedale</span></a></span> <span class="h-card"><a href="https://mastodon.social/@jgilbert" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jgilbert</span></a></span> <span class="h-card"><a href="https://mastodon.social/@MastodonEngineering" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>MastodonEngineering</span></a></span> <span class="h-card"><a href="https://yatil.social/@yatil" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>yatil</span></a></span> <span class="h-card"><a href="https://gofer.social/@daj" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>daj</span></a></span> <span class="h-card"><a href="https://puz.fun/@dave" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>dave</span></a></span> <span class="h-card"><a href="https://ibe.social/@theresmiling" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>theresmiling</span></a></span> <span class="h-card"><a href="https://mastodon.social/@tomusher" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>tomusher</span></a></span> <span class="h-card"><a href="https://mastodon.me.uk/@coffeenow" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>coffeenow</span></a></span> <span class="h-card"><a href="https://social.lol/@bjhess" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>bjhess</span></a></span> <span class="h-card"><a href="https://labyrinth.social/@nash" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nash</span></a></span> <span class="h-card"><a href="https://mstdn.social/@Nickiquote" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Nickiquote</span></a></span> <span class="h-card"><a href="https://pony.social/@axxuy" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>axxuy</span></a></span> <span class="h-card"><a href="https://mstdn.social/@vonExplaino" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>vonExplaino</span></a></span> <span class="h-card"><a href="https://fosstodon.org/@joel" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>joel</span></a></span> <span class="h-card"><a href="https://social.lol/@jmock" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jmock</span></a></span> <span class="h-card"><a href="https://tilde.zone/@xandra" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>xandra</span></a></span> <span class="h-card"><a href="https://mastodon.social/@DavidMadeThis" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>DavidMadeThis</span></a></span> <span class="h-card"><a href="https://mastodon.sprawl.club/@32x33" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>32x33</span></a></span> <span class="h-card"><a href="https://mastodon.nzoss.nz/@strypey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>strypey</span></a></span> <span class="h-card"><a href="https://mathstodon.xyz/@jskherman" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jskherman</span></a></span> <span class="h-card"><a href="https://mamot.fr/@nhoizey" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nhoizey</span></a></span> <span class="h-card"><a href="https://mementomori.social/@rolle" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>rolle</span></a></span> <span class="h-card"><a href="https://gamedev.lgbt/@renkotsuban" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>renkotsuban</span></a></span> <span class="h-card"><a href="https://infosec.exchange/@emanuelduss" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>emanuelduss</span></a></span> <span class="h-card"><a href="https://merveilles.town/@lrhodes" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>lrhodes</span></a></span> <span class="h-card"><a href="https://fedi.splitbrain.org/@splitbrain" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>splitbrain</span></a></span> <span class="h-card"><a href="https://bookstodon.com/@shannonkay" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>shannonkay</span></a></span> <span class="h-card"><a href="https://mastodon.social/@ricmac" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ricmac</span></a></span> <span class="h-card"><a href="https://infosec.exchange/@timb_machine" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>timb_machine</span></a></span> <span class="h-card"><a href="https://flipboard.social/@Flipboard" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Flipboard</span></a></span> <span class="h-card"><a href="https://mastodon.social/@sylvesterady" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>sylvesterady</span></a></span></p>
BeyondMachines :verified:<p>Ransomware attack disrupts health system network in Micronesia's Yap state <br><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/incident" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>incident</span></a> <a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a><br><a href="https://beyondmachines.net/event_details/ransomware-attack-disrupts-health-system-network-in-micronesia-s-yap-state-s-k-g-9-c/gD2P6Ple2L" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">beyondmachines.net/event_detai</span><span class="invisible">ls/ransomware-attack-disrupts-health-system-network-in-micronesia-s-yap-state-s-k-g-9-c/gD2P6Ple2L</span></a></p>
OWASP Foundation<p>Comprehensive AppSec Training at OWASP Global AppSec 2025 EU in Barcelona!</p><p>2-Day Training | May 27-28, 2025 <br>Level: Beginner | Trainer: Jim Manico </p><p>Join Jim Manico, one of the industry's leading experts, for an in-depth, hands-on AppSec training covering essential topics like input validation, API security, mobile security, cryptography, and more. </p><p>Register now! <br><a href="https://owasp.glueup.com/event/123983/register/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">owasp.glueup.com/event/123983/</span><span class="invisible">register/</span></a></p><p><a href="https://infosec.exchange/tags/Barcelona" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Barcelona</span></a> <a href="https://infosec.exchange/tags/owaspglobalappseceu2025" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>owaspglobalappseceu2025</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/devsecops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>devsecops</span></a> <a href="https://infosec.exchange/tags/securecoding" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>securecoding</span></a></p>
Shouty person<p>Recently, someone on here posted about an alternative, <a href="https://wandering.shop/tags/Mozilla" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mozilla</span></a>-based browser that was better for privacy and security than Firefox. But I can't remember what it was called or who said it. Maybe someone from <a href="https://wandering.shop/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a>-exchange?</p>
wakest ⁂<p>Surprised I haven't seen more <a href="https://social.wake.st/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> people discussing this matter <br><a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">cloud.google.com/blog/topics/t</span><span class="invisible">hreat-intelligence/russia-targeting-signal-messenger</span></a></p>
AAKL<p>Palo Alto updated its Security Advisories yesterday.</p><p>- CVE-2025-0118 GlobalProtect App: Execution of Unsafe ActiveX Control Vulnerability <a href="https://security.paloaltonetworks.com/CVE-2025-0118" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.paloaltonetworks.com/</span><span class="invisible">CVE-2025-0118</span></a></p><p>- CVE-2025-0117 GlobalProtect App: Local Privilege Escalation (PE) Vulnerability <a href="https://security.paloaltonetworks.com/CVE-2025-0117" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.paloaltonetworks.com/</span><span class="invisible">CVE-2025-0117</span></a></p><p>- CVE-2025-0116 PAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted LLDP Frame <a href="https://security.paloaltonetworks.com/CVE-2025-0116" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.paloaltonetworks.com/</span><span class="invisible">CVE-2025-0116</span></a></p><p>- CVE-2025-0115 PAN-OS: Authenticated Admin File Read Vulnerability in PAN-OS CLI <a href="https://security.paloaltonetworks.com/CVE-2025-0115" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.paloaltonetworks.com/</span><span class="invisible">CVE-2025-0115</span></a></p><p>- CVE-2025-0114 PAN-OS: Denial of Service (DoS) in GlobalProtect <a href="https://security.paloaltonetworks.com/CVE-2025-0114" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.paloaltonetworks.com/</span><span class="invisible">CVE-2025-0114</span></a></p><p>- PAN-SA-2025-0007 Chromium: Monthly Vulnerability Update (March 2025) <a href="https://security.paloaltonetworks.com/PAN-SA-2025-0007" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">security.paloaltonetworks.com/</span><span class="invisible">PAN-SA-2025-0007</span></a></p><p>Palo Alto Networks Security Advisories: <a href="https://security.paloaltonetworks.com/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">security.paloaltonetworks.com/</span><span class="invisible"></span></a> <span class="h-card" translate="no"><a href="https://bird.makeup/users/paloaltontwks" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>paloaltontwks</span></a></span> <br><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/PaloAlto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PaloAlto</span></a></p>
beardedtechguy@infosec:~$<p>This news today about SAML is something everyone should be watching closely! I posted about it a little bit ago.</p><p>Nearly all apps and platforms use SAML for authentication and to have this breach can cause some serious ramifications. </p><p>Please be vigilant and security conscious all!</p><p><a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://infosec.exchange/tags/CyberSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSec</span></a> <a href="https://infosec.exchange/@0x40k/114155839375038153" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@0x40k/114155</span><span class="invisible">839375038153</span></a></p>
0x40k<p>Just stumbled across something kinda scary... SAML authentication issues! Now, I know it sounds super technical, but honestly, this affects ANYONE using Single Sign-On. Seriously!</p><p>Think about logging into Netflix, Google, all that stuff – a lot of it uses SAML. What if someone could just waltz right in pretending to be you? SAML's basically the language websites use to confirm you are who you say you are. And Single Sign-On (SSO) makes it so you only log in once to access everything.</p><p>Now, about CVEs, they're like wanted posters for security flaws. CVE-2025-25291, CVE-2025-25292, CVE-2025-25293 are the numbers to remember. The problem lies in how XML is being interpreted. Two programs, same code, totally different results – NOT GOOD. Imagine two bouncers checking the same ID, but one lets everyone in, and the other doesn't. Total chaos!</p><p>As a pentester, I see these "parser differentials" way more often than I'd like. The devil's always in the details, right?</p><p>Big deal? HUGE. Account Takeover is totally possible! Hackers could swipe your identity. This affects the ruby-saml library – which is frequently used in web applications. Affected versions: &lt; 1.12.4 and &gt;= 1.13.0, &lt; 1.18.0.</p><p>Huge shoutout to GitHub Security Lab for finding this! They're lifesavers.</p><p>Good news, though! Updates are here: ruby-saml 1.12.4 and 1.18.0.</p><p>So, check if your web apps are using ruby-saml. And if they are, UPDATE THEM. Like, NOW. This isn't a joke.</p><p>Also, regular pentests are worth their weight in GOLD. Automated tools often miss stuff like this.</p><p>Do you use SAML? What are your experiences with it? How do you secure your web applications? Ever run into similar parsing issues? Let's share info and help keep everyone safe!</p><p><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/pentesting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pentesting</span></a> <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a></p>
LimaCharlie<p>Join us tomorrow, March 14th at 10:30am PT / 1:30pm ET! </p><p>Lead Security Engineer, Wietze Beukema, will showcase <a href="http://argfuscator.net" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">http://</span><span class="">argfuscator.net</span><span class="invisible"></span></a> - a new project that helps you generate obfuscated command lines, enabling you to bypass certain EDR detections. </p><p>Register now: <a href="https://info.limacharlie.io/defender-fridays?utm_source=twitter&amp;utm_medium=organic_social&amp;utm_content=webinar&amp;utm_campaign=defender_fridays&amp;utm_term=&amp;lead_source_detail=mastodon" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">info.limacharlie.io/defender-f</span><span class="invisible">ridays?utm_source=twitter&amp;utm_medium=organic_social&amp;utm_content=webinar&amp;utm_campaign=defender_fridays&amp;utm_term=&amp;lead_source_detail=mastodon</span></a></p><p><a href="https://infosec.exchange/tags/defenders" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>defenders</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
daltux🎙️ Podcast: Tecnopolítica 239 — <a href="https://snac.daltux.net?t=cryptorave" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#CryptoRave</a> <span class="h-card"><a href="https://mastodon.social/users/cryptorave" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@cryptorave@mastodon.social</a></span> : o maior evento de criptografia para defesa de direitos<br><br><a href="https://d3ctxlq1ktw2nl.cloudfront.net/staging/2025-2-11/396394845-44100-2-7e719552478d9.mp3" rel="nofollow noopener noreferrer" target="_blank">⏯️ Arquivo de áudio, 29min (27MB MP3)</a><br><blockquote>Nesse episódio, Sérgio Amadeu <span class="h-card"><a href="https://mastodon.social/users/samadeu" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@samadeu@mastodon.social</a></span> conversou com Rosaju, formada em artes, trabalha com engenharia de software e integra a organização da Cryptorave, maior evento aberto de criptografia, segurança digital e defesa da privacidade. Rosaju explicou como funciona o evento que ocorrerá nos dias 16 e 17 de maio, em São Paulo. A Cryptorave possui mais de 24 horas de oficinas, conversas, debates, apresentações, trocas e formação nas áreas de intersecção entre segurança, privacidade, criptografia e artes. A Cryptorave não aceita patrocínio de empresas. Ouça o episódio e saiba como colaborar com o evento. O link da Cryptorave é: <a href="https://2025.cryptorave.org/" rel="nofollow noopener noreferrer" target="_blank">https://2025.cryptorave.org/</a> Imperdível.<br></blockquote>:rss: <a href="https://anchor.fm/s/f8204060/podcast/rss" rel="nofollow noopener noreferrer" target="_blank">RSS feed para assinar Tecnopolítica em tocador ou agregador</a><br><br><a href="https://snac.daltux.net?t=antennapod" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#AntennaPod</a> <a href="https://snac.daltux.net?t=podcast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#podcast</a> <a href="https://snac.daltux.net?t=tecnopolítica" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#Tecnopolítica</a> <a href="https://snac.daltux.net?t=cr25" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#CR25</a> <a href="https://snac.daltux.net?t=criptografia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#criptografia</a> <a href="https://snac.daltux.net?t=segurança" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#segurança</a> <a href="https://snac.daltux.net?t=privacidade" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#privacidade</a> <a href="https://snac.daltux.net?t=infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#InfoSec</a> <a href="https://snac.daltux.net?t=evento" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#evento</a> <a href="https://snac.daltux.net?t=apoie" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#apoie</a> <a href="https://snac.daltux.net?t=sãopaulo" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#SãoPaulo</a> <a href="https://snac.daltux.net?t=brasil" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#Brasil</a><br>
Riley S. Faelan<p>Modern CAPTCHA is basically an exercise in automated stalking. It asseses your opsec and tries to find out private details about you. If your opsec is too good, you must be a robot.</p><p>The solution is to put out fake private details about you, specifically for the privacy-violating CAPTCHA machines to feel happy about themselves. It's just good manners!</p><p><a href="https://toot.cat/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://toot.cat/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a></p>
Arthur Lutz (Zenika)<p>Ce soir, avec quelques collègues de Zenika Nantes, on va jouer à un "Capture The Flag" organisé par Scalian à Epitech. </p><p><a href="https://www.eventbrite.fr/e/billets-ctf-nantes-capture-the-flag-scalian-1245786463849" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">eventbrite.fr/e/billets-ctf-na</span><span class="invisible">ntes-capture-the-flag-scalian-1245786463849</span></a></p><p>En équipe de 3 (avec un seul ordinateur) va falloir résoudre un maximum de challenges de sécurité... should be fun. </p><p><a href="https://pouet.chapril.org/tags/CTF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTF</span></a> <a href="https://pouet.chapril.org/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://pouet.chapril.org/tags/DevSecOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevSecOps</span></a> <a href="https://pouet.chapril.org/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a></p>