mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,5 Tsd.
aktive Profile

#security

411 Beiträge267 Beteiligte30 Beiträge heute

Billions of login credentials may have leaked. Here's how you can protect your accounts
A recent report by Cybernews claimed that 16 billion login credentials were exposed and compiled into datasets online, giving cybercriminals access to accounts for online platforms like Google, Apple and Facebook. While much is still unconfirmed about the leak, ex...
#security #cybercrime #data #leak #News #Business
cbc.ca/news/business/login-cre

github.com/brotheralameen1/Dis

Published Security Advisory for OneTrust SDK V6.33.0 Vulnerable to Prototype Pollution causing DoS in the system by editing Prototype Value. Currently, submitted this to MITRE CVE to request publication of my CVE to the National Vulnerability Database and awaiting their response. You can click the link above to learn more about the exploit.

# OneTrust SDK v6.33.0 - Prototype Pollution Vulnerability via `Object.setPrototypeOf` and `Object.assign` (DoS Impact)

- **Exploit Title**: OneTrust SDK v6.33.0 - Prototype Pollution Vulnerabil...
GitHubOneTrust SDK V6.33.0 Vulnerable to Prototype Pollution causing DoS in the system by editing Prototype Value# OneTrust SDK v6.33.0 - Prototype Pollution Vulnerability via `Object.setPrototypeOf` and `Object.assign` (DoS Impact) - **Exploit Title**: OneTrust SDK v6.33.0 - Prototype Pollution Vulnerabil...

"Noem isn’t doing homeland #security. I’m not sure she knows its meaning. Like habeas corpus, which she thinks is an Ecuadorian offshoot of MS-13. Instead of safety and security, Noem’s turned the agency into the rabid attack dog she wanted Cricket to be"

READ MORE blueamp.co/p/were-all-cricket- #news #usa #politics #dhs #ice #losangeles #la #tv #nato #media #press #russia #ukraine #eu us #unitedstates #america #trump #donaldtrump #cliffschecter #blueamp #cliffsnote #cliffsedge #davidshuster

Blue Amp · We're All Kristi's Dog Cricket, and the United States is Noem’s Gravel PitVon Cliff Schecter

16 billion login records!!

Researchers at Cybernews, an online tech publication, said they had found 30 datasets stuffed with credentials harvested from malicious software known as “infostealers” and leaks.

[...] the datasets had become temporarily available after being poorly stored on remote servers – before being removed again.

theguardian.com/technology/202

The Guardian · Internet users advised to change passwords after 16bn logins exposedVon Dan Milmo

I need advice to secure a web server. I am currently managing an OJS server at my University. This server is often attacked, such as with PHP script injections, to cause malfunction or online gambling contents. What I have done so far:
1. Set permissions (the user owns all PHP scripts instead of www-data, these files are often modified by a third party)
2. File access monitoring ( I log every access that happens in the doc root)
3. daily backup

The Protesters' Guide to #Smartphone #Security
privacyguides.org/articles/202

Very helpful tips for your own protection when you're protesting or even living in failed country like #USA, #Russia, #China, #Hungary, and so forth.

Furthermore, it's impressive how complex it is to protect you from your own #mobile #phone.

As a security pro and despite using #GrapheneOS, I'd rather leave the phone at home than to go through all the tips and still might overlook a thing. 😔

Privacy Guides · The Protesters' Guide to Smartphone Security
Mehr von Jonah Aragon
#Android#iOS#iPhone

Interesting Git repos of the week:

Detection:

* github.com/hdm/ctail - tail CA transparency logs with @hdm
* github.com/sgInnora/sharpeye - another Linux EDR
* github.com/HullaBrian/COMmander - enrich Windows RPC events

Exploitation:

* github.com/e-ago/bitcracker - BitLocker cracker
* github.com/Moopinger/smugglefu - HTTP downgrade fuzzer
* github.com/Ignitetechnologies/ - Windows LPE playbook
* github.com/giuliano108/SeBacku - elevate/collect via SeBackupPrivilege
* github.com/adgaultier/caracal - sneaky bees
* github.com/v-p-b/xer - encoding h3x with @buherator

Hard hacks:

* github.com/zhuowei/cheese - PoC for CVE-2025-21479, affecting Adreno A7xx (Snapdragon 8 Gen 1 / XR2 Gen 2 and newer) devices
* github.com/tomasz-lisowski/sim - evaluate SIM card security

#security, #code, #research

Tail Certificate Transparency logs and extract hostnames - hdm/ctail
GitHubGitHub - hdm/ctail: Tail Certificate Transparency logs and extract hostnamesTail Certificate Transparency logs and extract hostnames - hdm/ctail

Billions of login credentials may have leaked. Here's how you can protect your accounts
A recent report by Cybernews claimed that 16 billion login credentials were exposed and compiled into datasets online, giving cybercriminals access to accounts for online platforms like Google, Apple and Facebook. While much is still unconfirmed about the leak, ex...
#security #cybercrime #data #leak #News #Business
cbc.ca/news/business/login-cre