soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #infosec

[?]Laurent Cheylus » 🌐
@lcheylus@bsd.network

Researchers at the University of Birmingham and the Security Firm Fuzzware shows that a malicious SIM Card can run Attacker Code inside the Modems behind Cellular IoT Devices - Paper at WOOT 2026 Conference usenix.org/conference/woot26/p

    [?]Olly 👾 » 🌐
    @Olly42@nerdculture.de

    :apple_inc: Apple iCloud Private Relay can expose Real IPs through WebKit Proxy Bypasses.

    IT-Security researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address.

    mysk.blog/2026/08/04/webkit-pr

    Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from and what sites are being visited. It's available as part of the iCloud+ subscription.

    support.apple.com/102602

    ⚠️Researchers Talal Haj Bakry and Tommy Mysk, who found the issue, said the problem is rooted in three features in Apple's WebKit: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. WebKit is the default web browser engine used by Safari and all third-party browsers on iOS and iPadOS, such as Google Chrome, Microsoft Edge, Mozilla Firefox, Brave and others.⚠️

    A proof-of-concept (PoC) website named "leaks.psylo[.]app" has been made available for anyone to check if their real IP address leaks, even when Private Relay is on.

    leaks.psylo.app/

    ⁉️Apple did not immediately respond to a request for comment. But the company told 404 Media that it's investigating the researchers' report.⁉️

    404media.co/apples-private-rel

    Alt...👾The three features "bypass the configured proxy and send traffic directly from the device, which exposes the user's real network," the researchers said. "The same leaks also affect Apple's iCloud Private Relay."👾 The issues also affect macOS, as well as any other WebKit-based browser that relies on WebKit's proxy configuration APIs. In each of these cases, the device's actual IP address is leaked: • DNS prefetching, which resolves hostnames through the device's normal DNS path instead of the proxy set by the browser • WebAuthn Related Origin Requests, which make the operating system's credential service fetch a validation file directly from the device WebTransport, which opens a direct HTTP/3 connection and bypasses the proxy • Given that WebAuthn lets users log into websites using passkeys, any website that claims to support the web standard can view a user's real IP address even if iCloud Private Relay is on. ⁉️"Any website can configure WebAuthn (the API used for passkeys) in a way that causes WebKit to reveal the browser's real IP address, bypassing both proxy configurations and iCloud Private Relay in Safari," Mysk said. "Because of the nature of the bug, the website has to deliberately exploit it to associate the user's current browsing session with the leaked IP address. This does not require any user interaction or the use of passkeys."⁉️

      [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
      @rysiek@mstdn.social

      This article by is so bad it's funny:
      okta.com/identity-101/evil-twi

      Not only do they bend over backwards to cram as many "hackers" there as possible (hackers are what editors crave!), but it also seems like they are not aware of HTTPS, HSTS, and how browsers warn users when credentials are being requested via unencrypted connections.

      > [attacker] can see all the login details and save them for later use.

      Not they can't. Stop parroting stuff that has not been true for a decade.

        [?]Nonilex » 🌐
        @Nonilex@masto.ai

        Jury selection is on Wednesday, with opening statements slated to begin August 18. founder and CEO is expected to testify, as is head .

        In terms of potential damages & implications for Meta, the trial is the biggest test yet of youth litigation & comes amid a broader reckoning across the globe over social media's effects on young users.

          [?]Nonilex » 🌐
          @Nonilex@masto.ai

          The trial in Oakland, expected to last seven weeks, will test Colorado, Kentucky, California & New Jersey's allegations that designed its platforms to keep young users hooked & ‌misled consumers about their safety. It will also address claims by 29 states that the company illegally collected & used 's in violation of federal law.

            [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
            @rysiek@mstdn.social

            Anybody any news on DNS-PERSIST-01? It would allow me to simplify some things massively, once it's available…
            letsencrypt.org/2026/02/18/dns

              soapdog boosted

              [?]Scott Wilson 🌈 » 🌐
              @scottwilson@infosec.exchange

              I work in and consider myself pretty well educated on what’s happening with .

              But I’m about 33% of the way through @emilymbender and Alex Hanna’s book, “The AI Con”, and I’ve really learned a lot more.

              If you’re skeptical or curious about AI, this is a must-read. I’m recommending it to everyone I know.

              “The AI Con: How to Fight Big Tech's Hype and Create the Future We Want”, by Emily M. Bender and Alex Hanna

              Edit: Added text in this post with the title and authors. It's also in the image's ALT text. Sorry!

              “The AI Con: How to Fight Big Tech's Hype and Create the Future We Want”, by Emily M. Bender and Alex Hanna

              Alt...“The AI Con: How to Fight Big Tech's Hype and Create the Future We Want”, by Emily M. Bender and Alex Hanna

                muddle 🥣 boosted

                [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                @MissConstrue@mefi.social

                In the beginning, there was and serial ports, and verily did have text-based console access to fix a server falling over. And it was good. Not efficient, and scaled poorly, but for the 80s, it was good.

                Then came addon boards and it was…ok. Then upon the world did come Baseboard Management Controller (), a dedicated, soldered on chip that changed server management from manual, physical troubleshooting to automated, isolated remote control. And it seemed pretty good.

                And then pen testers and red teams started reporting flaws and vulnerabilities. For decades. Have those flaws been fixed in all those years?

                No, don’t be ridiculous. Where’s the ROI for the MBA?

                That said, if your bmc is exposed to the internet, you probably have way bigger issues.

                arstechnica.com/security/2026/

                  muddle 🥣 boosted

                  [?]Mike Sheward » 🌐
                  @SecureOwl@infosec.exchange

                  RE: live.acarsdrama.com/@acarsdram

                  WHAT DID YOU ALL DO?!?!?!

                  Light boosted

                  [?]ACARS Drama » 🤖 🌐
                  @acarsdrama@live.acarsdrama.com

                  Air to Ground Message:

                  NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL

                  Area: Liberal, KS, USA
                  Type: Boeing 757-200
                  A:
                  F:

                      [?]Pseudo Nym » 🌐
                      @pseudonym@mastodon.online

                      @shodan

                      I haven't used it in quite a while, but totally worth it for anyone in

                        [?]Fedi.Garden » 🌐
                        @FediGarden@social.growyourown.services

                        Freeradical.zone is a Mastodon server themed around infosec and privacy and technology and leftward politics and cats and dogs.

                        This server has been online since 2017.

                        :Fediverse: freeradical.zone

                        You can find out more at freeradical.zone/about or contact the admin account @tek

                          [?]zerionchat » 🌐
                          @zerionchat@mastodon.social

                          This week Microsoft and ReliaQuest reported attackers using hotel Wi-Fi across the US, India and Saudi Arabia to steal credentials and push malware onto travellers’ devices. Connect to the network and you’re the target.

                          This is exactly why the network you’re on shouldn’t be something you have to trust. Zerion routes everything over Tor, so a hostile Wi-Fi sees only encrypted traffic, no IP, no metadata, nothing to harvest or inject into.

                          zerion.chat

                            [?]Pseudo Nym » 🌐
                            @pseudonym@mastodon.online

                            @FritzAdalis @TheJen @kevin

                            While I'm no fan of required password rotations, at that point you might want to consider changing it, or not.

                            At least add a "9" to the end, or something.

                              [?]Trail of Bits » 🌐
                              @trailofbits@infosec.exchange

                              A malicious host can attack your AWS Nitro Enclave through its connection to KMS.

                              It can't see inside the enclave, but it can swap encrypted data keys in storage, feed the enclave arbitrary plaintext, force the wrong CMK, replay attestations, and more. We wrote down the fixes in the blog: blog.trailofbits.com/2026/08/0

                                [?]Pseudo Nym » 🌐
                                @pseudonym@mastodon.online

                                @cR0w

                                Red team told everything else is "out of scope".

                                  [?]Rye 🐍 » 🌐
                                  @rye@ioc.exchange

                                  ... [SENSITIVE CONTENT]

                                  Really exciting news about IFIN and being a non-profit.

                                  IFIN has multiple offerings including a curated news feed / rss. You should check it out.

                                  ifin-intel.org/blog/nonprofit/

                                    [?]Trail of Bits » 🌐
                                    @trailofbits@infosec.exchange

                                    Patch the Planet update: 1,137 issues found (+279 since July 20), 866 awaiting a patch, 125 fixes open upstream, 146 merged across 46 open-source projects.

                                    trailofbits.com/patch-the-plan

                                      [?]AA » 🌐
                                      @AAKL@infosec.exchange

                                      New from Cloudflare:

                                      "We're introducing @cloudflare/computer, an agent runtime that dynamically orchestrates between fast, efficient isolates and full Linux containers to give every agent a computer of its own."

                                      "The central piece of @cloudflare/computer is the workspace. A virtual filesystem backed by SQLite that can be populated from various sources including cloud storage and source control."

                                      Cloudflare: Your agent needs a computer, not a container — introducing @cloudflare/computer blog.cloudflare.com/cloudflare

                                      @cR0w @ifin

                                        [?]zerionchat » 🌐
                                        @zerionchat@mastodon.social

                                        Zerion 3.0 is in its final stage before release. The dev branch, with the native protocol stack, I2P and the Bluetooth mesh, is now being tested by an external party before we ship it.

                                        We don’t release security features on trust. They get checked first, and the whole thing is open source so you can read every line yourself while we do.

                                        This is separate from the independent audit we’re still raising funds for. Both matter.

                                        zerion.chat

                                          [?]DigitalEscapeTools » 🌐
                                          @xabd@mastodon.social

                                          Want to detect intruders before they reach your real systems?

                                          OpenCanary is a free, open-source network honeypot that emulates common services and sends instant alerts when someone interacts with them. It's lightweight, easy to deploy, and works on Linux, macOS, Docker, and Raspberry Pi.

                                          More details: digitalescapetools.com/tools/t

                                          Screenshot of the OpenCanary project page describing the lightweight network honeypot with passing GitHub test, Docker build, and PyPI badges.

                                          Alt...Screenshot of the OpenCanary project page describing the lightweight network honeypot with passing GitHub test, Docker build, and PyPI badges.

                                            [?]Pseudo Nym » 🌐
                                            @pseudonym@mastodon.online

                                            @badthingsdaily

                                            This would make a good table top exercise.

                                              [?]Owl Eyes Hoo » 🌐
                                              @d1@autistics.life

                                              @w3c This doesn't seem like an open standard to me, although pretends to be one. Why not? Because it supports proprietary lock-in. Lock-in how? Look at section 8, where several hardware attestation methods are listed: w3.org/TR/2026/CR-webauthn-3-2

                                              Is there any guarantee or assurance that a given platform implement support for *all* hardware attestation methods, including ones that are not proprietary? No such assurance. A platform could support, say Android and Apple''s attestation methods **only** (skipping the actual Open Standard of FIDO U2F), and no other.

                                              So my bank could support Android and Apple iOS attestation **only**, eschewing my Yubikey's U2F, as used from my desktop. I'm left to the mercy of my bank, as to whether they feel like implementing FIDO U2F or not.

                                              This standard masquerades as an open standard, then allows locking Linux (and other similar ) desktops out.

                                                [?]Ian Campbell 🏴 » 🌐
                                                @neurovagrant@masto.deoan.org

                                                Good morning, folks.

                                                We're observing an intensifying set of overlapping campaigns targeting Okta and M365 credentials to facilitate enterprise data exfiltration and ransom. I've pulled some initial thoughts together over at @ifin as well as a refined CSV of 133 suspect domains.

                                                Cohesive writeup: discourse.ifin.network/t/newly

                                                CSV: drive.proton.me/urls/1FRBB06NK

                                                  [?]Trail of Bits » 🌐
                                                  @trailofbits@infosec.exchange

                                                  PATCH THE PLANET BUG SPOTLIGHT: We found a high-severity use-after-free bug in nginx, the web server handling over 30% of all websites in the world. Now patched.

                                                  Remote and unauthenticated, it can crash nginx and potentially run code, all through HTTP/3. Engineer Evan Hellman found it with Codex after roughly 14 hours of automated analysis. CVE-2026-42530 in the dashboard: trailofbits.com/patch-the-plan

                                                    [?]Trail of Bits » 🌐
                                                    @trailofbits@infosec.exchange

                                                    Agentic AI headlines Black Hat's keynotes and DEF CON's main stage next week, and it's a topic we've been researching for years. We've hijacked multi-agent systems with one web page, pulled Gmail data from Perplexity's Comet via prompt injection, and built image-scaling attacks invisible to humans but not models. All documented on blog.trailofbits.com.

                                                    We'll be in Vegas Aug 4-6. If you're around, we'd love to chat: meetings.hubspot.com/trailofbi

                                                      [?]R.L. Dane :Debian: :FreeBSD: :OpenBSD: :NetBSD:🍵 :MiraLovesYou: [he/him/my good fellow] » 🌐
                                                      @rl_dane@polymaths.social

                                                      @dalias @khm

                                                      *sigh* this is why I made no attempt to get back into #infosec.

                                                      If I wanted to be in "the theater," I'd act. 😄

                                                        [?]Trail of Bits » 🌐
                                                        @trailofbits@infosec.exchange

                                                        Attackers drained $20M+ from protocols built around Uniswap v4 hooks.

                                                        The two largest were Cork (~$12M) and Bunni ($8.4M). Neither came from bugs in the PoolManager, Uniswap v4's central contract. The failures came from application and hook code.

                                                        We analyzed dozens of audit findings to isolate seven ways hooks break, and created a checklist for keeping these bugs out of production. blog.trailofbits.com/2026/07/3

                                                          muddle 🥣 boosted

                                                          [?]LeeRayl » 🌐
                                                          @leerayl@infosec.exchange

                                                          Work situation is so bad I have to start looking at evil companies because my money tree ain’t growing anything.

                                                          Drives me nuts seeing so many things happening at crazy speeds and I am just sitting on the sidelines….

                                                            muddle 🥣 boosted

                                                            [?]Lazarou Monkey Terror 🚀💙🌈 » 🌐
                                                            @Lazarou@mastodon.social

                                                            US Military letting it's soldiers wear Meta Pervert Glasses and only now considering the Infosec risk of it...

                                                            A service member's Meta smart glasses recorded footage posted to
Instagram showing troops evacuating to a bunker during the July 17
attack — the kind of open-source exposure, Cooper wrote, that forced
Trump to defend the war publicly before the Pentagon could control
the narrative.

                                                            Alt...A service member's Meta smart glasses recorded footage posted to Instagram showing troops evacuating to a bunker during the July 17 attack — the kind of open-source exposure, Cooper wrote, that forced Trump to defend the war publicly before the Pentagon could control the narrative.

                                                              [?]xoron :verified: » 🌐
                                                              @xoron@infosec.exchange

                                                              Decentralized browser-based P2P E2EE messaging.

                                                              The key detail that sets this apart from other messaging apps is the browser-based client-side cryptography philosophy.

                                                              No need to install anything. Your ID is crypto-random and so the app doesnt need to rely on any central registration system like phone numbers. Your ID is unguessable and to connect to someone, you have to explicitly share it.

                                                              WebRTC has other nuances like being to route through a shared network for secure/faster transfer.

                                                              I hope this project has reached a level i can share the following details. I've made a genuine effort towards documentation and transparancy. I dont think it'll ever be enough and so im still concerned it isnt ready to share. While im using AI throughout. This is not a vibecoded project. There is attention throughout for unit tests and formal-verification. With your feedback, id like to make improvements for clarity throughout.

                                                              This version of the app demonstrates a fairly unique approach using a browser-based, local-only and webrtc approach. I know it's impossible for any system to be the "world's most secure", but that isnt a reason to not try. By rigorously implementing an exhaustive list of security features and practices, the aim is to get as close as possible.

                                                              * [Enkrypted.Chat](enkrypted.chat/)

                                                              This is intended to demonstrate client-side managed secure cryptography.

                                                              * [Introducing Enkrypted Chat](positive-intentions.com/blog/i)
                                                              * [Whitepaper (work-in-progress)](positive-intentions.com/docs/t)
                                                              * [Protocol Spec (work-in-progress)](positive-intentions.com/docs/t)
                                                              * [Roadmap](positive-intentions.com/docs/t)

                                                              I know ive tried to compress a lot of my journey into one post. The project above is going to be tricky to understand. Feel free to reach out for clarity on any of the details.

                                                              IMPORTANT: While this is aiming to provide a secure experience, It is [not audited or reviewed](reddit.com/r/CyberSecurityAdvi). **Shared for testing, feedback and demo purposes only.** Please use responsibly.

                                                                [?]Nonilex » 🌐
                                                                @Nonilex@masto.ai

                                                                …Tunick’s lawyers argued during the hearing last week that the seizure was unlawful, & that he was targeted because of his against ’s plan to build a police & fire training center within a 1,000-acre stretch of urban . Opponents argue that the center, known as , would militarize officers & destroy precious .

                                                                  [?]Nonilex » 🌐
                                                                  @Nonilex@masto.ai

                                                                  A Citizen Deleted His ’s . Now He Faces a Charge.

                                                                  Federal prosecutors charged a man returning to the United States with because he gave them a passcode that erased his during a customs search.


                                                                  nytimes.com/2026/07/28/us/dure

                                                                    muddle 🥣 boosted

                                                                    [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                                                    @MissConstrue@mefi.social

                                                                    So, while Sam is a specific case where the feds were looking for a reason to get into his phone without a warrant, we need to talk about how much power / has accumulated since the passage of the Act.

                                                                    Under the "border search doctrine", ICE and CBP agents have broad power to search people or property at the border. Any search at the border is considered “reasonable,” meaning no warrant or probable cause is required.

                                                                    That’s further complicated by the fact that the “border” can be broadly defined as a border-functioning location like an international airport or even within 100 miles of the U.S. border as drawn on a map.

                                                                    Right now, about 2/3rds of Americans live within an area where ICE can search you without a warrant. While carve-outs for phones existed, the 4th circuit just took some of that protection away.

                                                                    aclu.org/know-your-rights/bord

                                                                    eff.org/deeplinks/2026/07/four

                                                                      [?]Trail of Bits » 🌐
                                                                      @trailofbits@infosec.exchange

                                                                      Every Rust bug we submitted through Patch the Planet came from one engineer who ran a variant-analysis pipeline using Codex's /goal. A separate discovery run uncovered two potential high-severity privilege-escalation bugs in Keycloak's SAML component.

                                                                      Over the past few weeks, our engineers independently converged on three techniques that get the most out of /goal. We wrote them down, with prompts included: blog.trailofbits.com/2026/07/2

                                                                        muddle 🥣 boosted

                                                                        [?]your auntifa liza 🇵🇷 🦛 🦦 » 🌐
                                                                        @blogdiva@mastodon.social

                                                                        A QUESTION TO TOOTERS

                                                                        had a friend call me about suspicious emails from their bank. they didn't respond but checked their accounts with the bank’s app. they saw transactions they didn't do but that were marked as done thru the app.

                                                                        they wanted to know what to do. i told them:

                                                                        1. call whichever fraud/stolen bank card number they found on the website immediately.
                                                                        2. freeze the app but don’t uninstall yet
                                                                        3. go to the bank immediately monday

                                                                        they did so and called with updates… 🧵

                                                                          [?]Dissent Doe :cupofcoffee: [She/Her] » 🌐
                                                                          @PogoWasRight@infosec.exchange

                                                                          NEW by me:

                                                                          It appears that Frontier Airlines may have had a third security incident this year. A new group called ExfilSquad claims to have hacked them -- and no, they say they are not connected to ShinyHunters or ScatteredLapsus$Hunters.

                                                                          NOTE: Frontier Airlines hasn't confirmed this claimed breach. Then again, they haven't denied it, either. They haven't responded to email inquiries.

                                                                          Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too.
                                                                          databreaches.net/2026/07/27/ha

                                                                          @bobdahacker @campuscodi

                                                                            [?]salix sericea (@Ripple13216) » 🌐
                                                                            @salixsericea@mastodon.social

                                                                            Benn Jordan details his hacking and investigation of Flock at a city council meeting in March 2026.

                                                                            A short:
                                                                            youtube.com/shorts/I_y7OjsI1Zk

                                                                              [?]Mike Sheward » 🌐
                                                                              @SecureOwl@infosec.exchange

                                                                              Plexfiltration update: the AI work zone compliance tool has started emailing me thousands of pictures from a (I think) Saudi industrial facility again, to my internaluser.com domain.

                                                                              some security camera still showing a group of people in a parking lot in front of a stop sign

                                                                              Alt...some security camera still showing a group of people in a parking lot in front of a stop sign

                                                                                [?]Mark Wyner Won’t Comply :vm: » 🌐
                                                                                @markwyner@mas.to

                                                                                🚨 U.S. folks. There is one day left to comment on the FCC proposed rule to eradicate anonymity on all phone lines!

                                                                                If they pass this rule government ID, physical address, and alternative phone number will be required for every new phone line. Anonymous phone lines and burner phones will cease to exist. That means no connected privacy via cellular at protests.

                                                                                ** Please add your comment! **

                                                                                For the first field (proceedings) use these two:

                                                                                17-59 and 02-278

                                                                                fcc.gov/ecfs/filings/express

                                                                                  [?]Mysk🇨🇦🇩🇪 » 🌐
                                                                                  @mysk@mastodon.social

                                                                                  🚨 We're disclosing a macOS security bug that Apple says is not an issue.
                                                                                  Using a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web—no password or warning is required.
                                                                                  Here's a demo using Signal to steal its encryption key.
                                                                                  📝 Blog with technical details: link in the replies.
                                                                                  Do you think this should be considered a security bug?
                                                                                  🎬👇

                                                                                  youtu.be/0bOC8S3NQxI

                                                                                    CyberFrog boosted

                                                                                    [?]Scott Wilson 🌈 » 🌐
                                                                                    @scottwilson@infosec.exchange

                                                                                    Hot take:

                                                                                    I hate how all these articles talk about how OpenAI’s clanker “broke out” and attacked Hugging Face.

                                                                                    No, OpenAI’s dog slipped its chain because they don’t know what the hell they’re doing, and it bit another dog.

                                                                                    Little dog biting a person’s finger

                                                                                    Alt...Little dog biting a person’s finger

                                                                                      [?]⠵⠻⠷⠕⠭ 🍥🍉⚪🌹 » 🌐
                                                                                      @z3r0fox@mastodon.social

                                                                                      Matthew McPherrin from Let's Encrypt doing a talk next Wednesday at TASK on post quantum readiness, TLS, and many things. Streaming link on site. task.to/schedule/july2026-busi
                                                                                      Edit: There are five Wednesdays this month

                                                                                        [?]Mark Wyner Won’t Comply :vm: » 🌐
                                                                                        @markwyner@mas.to

                                                                                        This is a great list of tips for improving your Signal privacy from @yaelwrites.

                                                                                        I found this part especially meaningful:

                                                                                        “Turning off biometrics makes it annoying to use your phone…If that’s you, remember that both Android and iOS have a quick lockout that forces a passcode and disables biometrics until you re-enter it: on iPhone, hold the side + volume button until the power-off screen appears, then cancel; on most Androids, hold power and tap Lockdown.”

                                                                                        blog.yaelwrites.com/how-to-kee

                                                                                          muddle 🥣 boosted

                                                                                          [?]Dissent Doe :cupofcoffee: [She/Her] » 🌐
                                                                                          @PogoWasRight@infosec.exchange

                                                                                          It has been four months since a hacktivist obtained 8.3 million tips submitted to organizations such as Crime Stoppers and Sandy Hook Promise. What the hacktivist found in terms of lack of security was appalling.

                                                                                          In the four months since Navigate360 (the parent company for P3 Global Intel and P3 Campus) learned of the breach, they have made zero public statements after the first day when they said they were investigating. Their wall of silence, and the conspiracy of silence involving programs like Safe2Say, Safe2Tell, SilentWitness, and Crime Stoppers has been unacceptable. No one has been notified, it seems. And we cannot find any state regulator that has been notified, either.

                                                                                          DataBreaches wrote about the disgraceful lack of transparency in a new post this week:

                                                                                          Broken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.
                                                                                          databreaches.net/2026/07/20/br

                                                                                          In conjunction with that post, I filed a formal FTC complaint against Navigate360 under Section 5 of the FTC Act and also notified the National Association of Attorneys General, saying that states should be protecting their residents by investigating the breach and incident response.

                                                                                          And that's not all. Today, I have filed a complaint with one state attorney general's office and will be filing with others.

                                                                                          I will also be publishing a post this week about the Crime Stoppers data in the dataset and the ridiculous response by legal counsel for Crime Stoppers USA to inquiries by DataBreaches about what was being done to improve security.

                                                                                          I have not written up anything specific to all of the Canadian data in the dataset, but yes, Canadian crime stoppers and police organizations are in there, too.

                                                                                          Take Action:

                                                                                          If you know anyone in a state attorney general's office, encourage them to read up on the breach on my site, where I have also published tables with data for easy reference.

                                                                                          If you know anyone in the FTC, encourage them to read the complaint I filed and to act on it.

                                                                                          If you know any personal injury lawyer who should be handling a massive lawsuit alleging privacy harms, point them to my coverage.

                                                                                          Children and adults who tried to be good citizens and relied on promises of anonymity have been put in harm's way. We cannot allow this to be minimized or covered up.

                                                                                          @zackwhittaker @nytimes @caparsons @douglevin

                                                                                            [?]Klaus Frank » 🌐
                                                                                            @agowa338@chaos.social

                                                                                            Who had "getting compromised through plugging an LG monitor in" on their 2026 bingo card? Apparently just plugging an LG monitor into a windows computer is enough for them to install spyware and steal all of your data. But hey you agree to this in their ToS (even without having to click on "I agree", it just installs).

                                                                                            Excerpt of the LG terms of service that state "You acknowledge and agree that it is your sole responsibility to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members and guests that their voices may be captured and processed, in compliance with applicable wiretapping, eavesdropping, and privacy laws."

                                                                                            Alt...Excerpt of the LG terms of service that state "You acknowledge and agree that it is your sole responsibility to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members and guests that their voices may be captured and processed, in compliance with applicable wiretapping, eavesdropping, and privacy laws."

                                                                                              [?]dallo » 🌐
                                                                                              @dallo@pouet.chapril.org

                                                                                              LG TVs and monitors said to surveil users and install bloatware without asking

                                                                                              notebookcheck.net/LG-TVs-and-m

                                                                                              > Anyone who owns an LG smart TV must inform all guests and family members that they are being monitored – this is required by LG’s current terms of use. Meanwhile, LG monitors install potential malware and surveillance software on a connected Windows computer.

                                                                                                [?]rE-Bo0t.bx1 :tux: :tor: :C_H: :donor: :verified: » 🌐
                                                                                                @r3bo0tbx1@infosec.exchange

                                                                                                :tor: I thought scaling Tor meant adding more relays.

                                                                                                What it actually meant was multiplying failure modes...

                                                                                                I now operate 24 Tor relays and bridges across 15 locations, 11 ASNs and 6 operating systems.

                                                                                                Every new relay brings another provider, firewall, IPv6 route, service manager, identity key, backup and recovery plan.

                                                                                                Some things I learned along the way:

                                                                                                🌍 More countries don’t automatically mean real diversity
                                                                                                🔑 The server is replaceable, the relay identity isn’t
                                                                                                🛠️ Linux, BSD and SunOS need the same outcomes, not the same commands
                                                                                                📊 What I configured isn’t always what the Tor network currently sees

                                                                                                A large fleet is easy to count. A resilient one is much harder to keep alive.

                                                                                                I wrote about what operating Tor across 15 locations actually taught me:

                                                                                                🔗 brokenbotnet.com/2026/07/17/no

                                                                                                  [?]Graham Downs » 🌐
                                                                                                  @GrahamDowns@mastodon.africa

                                                                                                  Proving you're human...

                                                                                                  One of those "Prove you're human" things where you have to identify all of a particular object in a picture. This one shows a wall of code, dividing up into blocks, with the caption, "Select all squares with bugs"

                                                                                                  Alt...One of those "Prove you're human" things where you have to identify all of a particular object in a picture. This one shows a wall of code, dividing up into blocks, with the caption, "Select all squares with bugs"

                                                                                                    [?]The Shufflecake Project » 🌐
                                                                                                    @shufflecake@fosstodon.org

                                                                                                    [?]Trail of Bits » 🌐
                                                                                                    @trailofbits@infosec.exchange

                                                                                                    "The oldest principles in security—auditing, logging, isolation, least privilege—matter more than ever now that actions happen at machine speed, not human speed."—Artem Dinaburg, our chief scientist, on Silver Bullet ep 158.

                                                                                                    The full pod covers why prompt injection has no clean fix, how we rebuilt our audits around agents, and why decompilers should work more like language translators.

                                                                                                    berryvilleiml.com/2026/07/01/s

                                                                                                      [?]Mysk🇨🇦🇩🇪 » 🌐
                                                                                                      @mysk@mastodon.social

                                                                                                      🚨PSA: If you think you're a targeted individual, don't install macOS apps from the web. macOS code signing and TCC are broken. We accidentally found a bug that lets any command modify the binaries of other apps, including Signal, Brave, Chrome, and even Xcode. Watch the demo👇

                                                                                                      Alt...Demo showing how a command replaces the binaries of Signal, Brave, and Slack

                                                                                                        Back to top - More...