These are public posts tagged with #cybersec. You can interact with them if you have an account anywhere in the fediverse.
This news today about SAML is something everyone should be watching closely! I posted about it a little bit ago.
Nearly all apps and platforms use SAML for authentication and to have this breach can cause some serious ramifications.
Please be vigilant and security conscious all!
#InfoSec #Security #CyberSec https://infosec.exchange/@0x40k/114155839375038153
Just stumbled across something kinda scary... SAML…
Infosec Exchangefrom Pia (@cecallinelper.bsky.social)
"layoff of red teams, often among the most specialized in the #cybersec field, could leave critical vulnerabilities open in government networks, and make it more difficult for #CISA & other agencies to spot adversaries working to hack into systems"
https://subscriber.politicopro.com/article/2025/03/red-team-workers-at-nations-cyber-agency-laid-off-as-part-of-doge-cuts-00225256 #natsec
↑
https://bsky.app/profile/cecallihelper.bsky.social/post/3lk74htciu22f
'A contractor for #ICE ... other US govt agencies, has developed a tool that lets analysts more easily pull a target individual’s public data from... sites, #socialnetworks, apps, and services across the web at once, including #Bluesky, OnlyFans... #Meta platforms... In all the list (leaked to 404) names more than 200 sites that the contractor, called #ShadowDragon...'
The 200+ Sites an ICE #Surveillance Contractor is Monitoring
https://www.404media.co/the-200-sites-an-ice-surveillance-contractor-is-monitoring/ #cybersec #persec #cyberstalking
404 Media has obtained the list of sites and services…
404 MediaEra accusato di accessi abusivi, i pm ora fanno analizzare…
Il Fatto QuotidianoNEW -
DCG Domain Blocklist available - last updated 2025/03/06
1692581- Domains blocked with that build !
Supercharging your content blocker to increase privacy and security.
All available lists:
- uBlockOrigin
- Hosts format & Hosts format with wildcards
- dnsmasq with wildcards
Ready to use lists combined from many permissively licensed sources.
https://divested.dev/pages/dnsbl
#divested #DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus #foss
#opensource #android #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #foss
NEW -
DCG real-ucode - 2025-03-09 - 1
New ucode for amd and intel with that one !
https://github.com/divestedcg/real-ucode/
#divested
#DivestedComputingGroup
#fsf #FUTO #Fedora #alpinelinux #hardening #linuxtech #cybersec #cybersecurity #infosec #foss #opensource #android #skynet #linuxsecurity #ucode #vulnerabilities #vulnerability
All the microcodes, but packaged! Contribute to divestedcg/real-ucode…
GitHub#Moody's alerta de que el #sector #financiero debe prevenir la amenaza de los #ordenadores #cuánticos
#comercio #mundial #seguridad #cybersec #qday #cypher #chiffrement #cifrado
NEW -
DCG real-ucode - 2025-03-02 - 1
New ucode for amd and intel with that one !
https://github.com/divestedcg/real-ucode/
#divested
#DivestedComputingGroup
#fsf #FUTO #Fedora #alpinelinux #hardening #linuxtech #cybersec #cybersecurity #infosec #foss #opensource #android #skynet #linuxsecurity #ucode #vulnerabilities #vulnerability
All the microcodes, but packaged! Contribute to divestedcg/real-ucode…
GitHubNEW -
Brace Build 2025/03/06 - 1
Toolkit compatible with multiple Linux distros that allows for installation of handpicked applications, along with corresponding configs that have been tuned for reasonable privacy and security.
Compatibility:
Arch Linux
CentOS 9/Stream
Debian 12
Fedora 39/40/41 (preferred)
openSUSE Tumbleweed
https://codeberg.org/divested/brace
#divested
#DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus #foss
#opensource #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #skynet #foss
Toolkit compatible with multiple Linux distros that…
Codeberg.org'Back in 2019, the #DHS,which runs USCIS, decided anyone looking to enter the US on a work visa or similar had to hand over their #socialmedia handles to the authorities so that they could be looked over for wrongdoing and subversion.
In fact, this goes back to 2014, at least, to one degree or another, and has been SOP for years for foreigners, particularly those on a visa.' #Immigration #Cybersec
USCIS mulls policing social media of all would-be citizens
https://www.theregister.com/2025/03/06/uscis_social_media/
President ordered officials to ramp up vetting 'to…
The RegisterУязвимости получили идентификаторы CVE-2025-22224, CVE-2025-22225 и CVE-2025-22226 и затрагивают продукты VMware ESX, включая VMware ESXi, vSphere, Workstation, Fusion, Cloud Foundation и Telco Cloud Platform.
Эти баги позволяют злоумышленникам, имеющим доступ уровня администратора или root, осуществить побег из песочницы виртуальной машины.
...
Иными словами, если хотя бы ВМ-клиент в уязвимой среде хостинга скомпрометирован, злоумышленник может получить контроль над гипервизором в этой хостинговой среде. То есть если клиент плохо защитил всего одну ВМ, все остальные ВМ в гипервизоре подвергаются риску.
CVE-2025-22224 (9,3 балла по шкале CVSS) представляет собой критическую уязвимость переполнения хипа VCMI, которая позволяет локальным злоумышленникам с правами администратора на целевой ВМ выполнить код от лица процесса VMX, запущенного на хосте. Проблема затрагивает VMware ESXi и Workstation.
CVE-2025-22225 (8,2 балла по шкале CVSS) представляет собой уязвимость произвольной записи в ESXi, которая позволяет процессу VMX инициировать запись произвольных данных в ядро, что приводит к побегу из песочницы. Баг затрагивает VMware ESXi.
CVE-2025-22226 (7,1 балла по шкале CVSS), влияет на VMware ESXi, Workstation и Fusion. Она связана с раскрытием информации в HGFS и позволяет злоумышленникам с правами администратора спровоцировать утечку памяти из процесса VMX.
NEW -
DCG Domain Blocklist available - last updated 2025/03/01
1702715 - Domains blocked with that build !
Supercharging your content blocker to increase privacy and security.
All available lists:
- uBlockOrigin
- Hosts format & Hosts format with wildcards
- dnsmasq with wildcards
Ready to use lists combined from many permissively licensed sources.
https://divested.dev/pages/dnsbl
#divested #DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus #foss
#opensource #android #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #foss
According to @BleepingComputer, there have been two different reports since Friday. One about Cyber Command and one about CISA.
Here is a statement from Cyber Command to Bleeping. Computer:
"Due to operational security concerns, we do not comment nor discuss cyber intelligence, plans, or operations. There is no greater priority to Secretary Hegseth than the safety of the Warfighter in all operations, to include the cyber domain."
Master AI Security at OWASP Global AppSec 2025 Barcelona!
Join Rob van der Veer and gain insights from cutting-edge research, OWASP AI Exchange, and the upcoming EU AI Act security standard.
1-Day Training | May 28, 2025
This intensive training will equip you with the latest AI security knowledge, hands-on experience, and strategies to defend against emerging threats.
Secure your spot, https://owasp.glueup.com/event/123983/register/
#Barcelona #owaspglobalappseceu2025 #cybersec #AI #devsecops #infosec
"Bakdörrslagen kan stoppas av Försvarsmakten (och Trump)"
https://computersweden.se/article/3835684/bakdorrslagen-kan-stoppas-av-forsvarsmakten-och-trump.html
#cybersec #cybersecurity #infosec #privacy #dataskydd #kryptering #svpol #sverige
Omvärldsläget kan sätta käppar i hjulen på regeringens…
Computer SwedenNEW -
D-WRT builds available: 2025-02-26 🪇 update to kernel 6.6.79 🪇
https://divested.dev/unofficial-openwrt-builds/mvebu-linksys
https://codeberg.org/divested/Divested-WRT
#divested
#DivestedComputingGroup
#fsf #FUTO #Fedora #codeberg #hardening #linuxtech #cybersec #cybersecurity #infosec #antivirus #foss
#opensource #android #linuxsecurity #vulnerabilities #vulnerability #alpinelinux #router #skynet #foss
W naszym kraju od wielu lat mało rzeczy na państwowym poziomie działa dobrze, ale akurat kwestie cyfryzacji mają się u nas całkiem niezłe. Mamy nawet państwową usługę do szukania podatności w aplikacjach webowych - tutaj instrukcja, jak z niej skorzystać.
Tackling the challenge of data breaches means taking action on all fronts, to reduce risk across an attack surface which continues to grow with each digital transformation investment, unpatched remote working endpoint, and stolen credential.
Data breaches can cause a loss of revenue and market…
www.welivesecurity.com