soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Researchers at the University of Birmingham and the Security Firm Fuzzware shows that a malicious SIM Card can run Attacker Code inside the Modems behind Cellular IoT Devices - Paper at #USENIX WOOT 2026 Conference #Infosec https://www.usenix.org/conference/woot26/presentation/lisowski
Apple iCloud Private Relay can expose Real IPs through WebKit Proxy Bypasses.
IT-Security researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address.
https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/
Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where the request is originating from and what sites are being visited. It's available as part of the iCloud+ subscription.
https://support.apple.com/102602
⚠️Researchers Talal Haj Bakry and Tommy Mysk, who found the issue, said the problem is rooted in three features in Apple's WebKit: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. WebKit is the default web browser engine used by Safari and all third-party browsers on iOS and iPadOS, such as Google Chrome, Microsoft Edge, Mozilla Firefox, Brave and others.⚠️
A proof-of-concept (PoC) website named "leaks.psylo[.]app" has been made available for anyone to check if their real IP address leaks, even when Private Relay is on.
⁉️Apple did not immediately respond to a request for comment. But the company told 404 Media that it's investigating the researchers' report.⁉️
https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/
#apple #icloud #security #privacy #infosec #tech #media #news
This article by #Okta is so bad it's funny:
https://www.okta.com/identity-101/evil-twin-attack/
Not only do they bend over backwards to cram as many "hackers" there as possible (hackers are what editors crave!), but it also seems like they are not aware of HTTPS, HSTS, and how browsers warn users when credentials are being requested via unencrypted connections.
> [attacker] can see all the login details and save them for later use.
Not they can't. Stop parroting stuff that has not been true for a decade.
Jury selection is on Wednesday, with opening statements slated to begin August 18. #Meta founder and CEO #MarkZuckerberg is expected to testify, as is #Instagram head #AdamMosseri.
In terms of potential damages & implications for Meta, the trial is the biggest test yet of youth #socialmedia litigation & comes amid a broader reckoning across the globe over social media's effects on young users.
#law #privacy #infosec #tech #engagement #addiction #MentalHealth #business
The trial in Oakland, expected to last seven weeks, will test Colorado, Kentucky, California & New Jersey's allegations that #Meta designed its platforms to keep young users hooked & misled consumers about their safety. It will also address claims by 29 states that the company illegally collected & used #children's #data in violation of federal law.
#law #privacy #infosec #tech #socialmedia #engagement #addiction #MentalHealth #business
Anybody any news on DNS-PERSIST-01? It would allow me to simplify some things massively, once it's available…
https://letsencrypt.org/2026/02/18/dns-persist-01
I work in #infosec and consider myself pretty well educated on what’s happening with #AI.
But I’m about 33% of the way through @emilymbender and Alex Hanna’s book, “The AI Con”, and I’ve really learned a lot more.
If you’re skeptical or curious about AI, this is a must-read. I’m recommending it to everyone I know.
“The AI Con: How to Fight Big Tech's Hype and Create the Future We Want”, by Emily M. Bender and Alex Hanna
Edit: Added text in this post with the title and authors. It's also in the image's ALT text. Sorry!
In the beginning, there was #TTY and serial ports, and verily did #sysadmins have text-based console access to fix a server falling over. And it was good. Not efficient, and scaled poorly, but for the 80s, it was good.
Then came addon boards and it was…ok. Then upon the world did come Baseboard Management Controller (#BMC), a dedicated, soldered on chip that changed server management from manual, physical troubleshooting to automated, isolated remote control. And it seemed pretty good.
And then pen testers and red teams started reporting flaws and vulnerabilities. For decades. Have those flaws been fixed in all those years?
No, don’t be ridiculous. Where’s the ROI for the MBA?
That said, if your bmc is exposed to the internet, you probably have way bigger #infosec issues.
RE: https://live.acarsdrama.com/@acarsdrama/117072256729860162
WHAT DID YOU ALL DO?!?!?!
Light boostedAir to Ground Message:
NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL
Area: Liberal, KS, USA
Type: Boeing 757-200
A: #aadee4f6c99
F: #fdcd8d51430
Freeradical.zone is a Mastodon server themed around infosec and privacy and technology and leftward politics and cats and dogs.
This server has been online since 2017.
You can find out more at https://freeradical.zone/about or contact the admin account @tek
#FeaturedServer #InfoSec #Privacy #Technology #Mastodon #Fediverse #FreeFediverse
This week Microsoft and ReliaQuest reported attackers using hotel Wi-Fi across the US, India and Saudi Arabia to steal credentials and push malware onto travellers’ devices. Connect to the network and you’re the target.
This is exactly why the network you’re on shouldn’t be something you have to trust. Zerion routes everything over Tor, so a hostile Wi-Fi sees only encrypted traffic, no IP, no metadata, nothing to harvest or inject into.
zerion.chat
While I'm no fan of required password rotations, at that point you might want to consider changing it, or not.
At least add a "9" to the end, or something.
A malicious host can attack your AWS Nitro Enclave through its connection to KMS.
It can't see inside the enclave, but it can swap encrypted data keys in storage, feed the enclave arbitrary plaintext, force the wrong CMK, replay attestations, and more. We wrote down the fixes in the blog: https://blog.trailofbits.com/2026/08/05/a-few-notes-on-aws-nitro-enclaves-kms-integration/
boostedReally exciting news about IFIN and being a non-profit.
IFIN has multiple offerings including a curated news feed / rss. You should check it out.
Patch the Planet update: 1,137 issues found (+279 since July 20), 866 awaiting a patch, 125 fixes open upstream, 146 merged across 46 open-source projects.
New from Cloudflare:
"We're introducing @cloudflare/computer, an agent runtime that dynamically orchestrates between fast, efficient isolates and full Linux containers to give every agent a computer of its own."
"The central piece of @cloudflare/computer is the workspace. A virtual filesystem backed by SQLite that can be populated from various sources including cloud storage and source control."
Cloudflare: Your agent needs a computer, not a container — introducing @cloudflare/computer https://blog.cloudflare.com/cloudflare-computer/ #infosec #bots #Cloudflare #GitHub #Linux
Zerion 3.0 is in its final stage before release. The dev branch, with the native protocol stack, I2P and the Bluetooth mesh, is now being tested by an external party before we ship it.
We don’t release security features on trust. They get checked first, and the whole thing is open source so you can read every line yourself while we do.
This is separate from the independent audit we’re still raising funds for. Both matter.
zerion.chat
Want to detect intruders before they reach your real systems?
OpenCanary is a free, open-source network honeypot that emulates common services and sends instant alerts when someone interacts with them. It's lightweight, easy to deploy, and works on Linux, macOS, Docker, and Raspberry Pi.
More details: https://digitalescapetools.com/tools/tool.html?id=opencanary
#OpenSource #CyberSecurity #InfoSec #Honeypot #SelfHosting #Privacy #Linux #Homelab #FOSS
@w3c This doesn't seem like an open standard to me, although pretends to be one. Why not? Because it supports proprietary lock-in. Lock-in how? Look at section 8, where several hardware attestation methods are listed: https://www.w3.org/TR/2026/CR-webauthn-3-20260526/#sctn-defined-attestation-formats
Is there any guarantee or assurance that a given platform implement support for *all* hardware attestation methods, including ones that are not proprietary? No such assurance. A platform could support, say Android and Apple''s attestation methods **only** (skipping the actual Open Standard of FIDO U2F), and no other.
So my bank could support Android and Apple iOS attestation **only**, eschewing my Yubikey's #FIDO2 U2F, as used from my #Linux desktop. I'm left to the mercy of my bank, as to whether they feel like implementing FIDO U2F or not.
This standard masquerades as an open standard, then allows locking Linux (and other similar #OpenSource) desktops out.
#infosec
Good morning, folks.
We're observing an intensifying set of overlapping campaigns targeting Okta and M365 credentials to facilitate enterprise data exfiltration and ransom. I've pulled some initial thoughts together over at @ifin as well as a refined CSV of 133 suspect domains.
#threatintel #infosec #cybersecurity
Cohesive writeup: https://discourse.ifin.network/t/newly-observed-vishing-phishing-campaign-targeting-retail-finance-fintech-more/702
PATCH THE PLANET BUG SPOTLIGHT: We found a high-severity use-after-free bug in nginx, the web server handling over 30% of all websites in the world. Now patched.
Remote and unauthenticated, it can crash nginx and potentially run code, all through HTTP/3. Engineer Evan Hellman found it with Codex after roughly 14 hours of automated analysis. CVE-2026-42530 in the dashboard: https://trailofbits.com/patch-the-planet/dashboard/
Agentic AI headlines Black Hat's keynotes and DEF CON's main stage next week, and it's a topic we've been researching for years. We've hijacked multi-agent systems with one web page, pulled Gmail data from Perplexity's Comet via prompt injection, and built image-scaling attacks invisible to humans but not models. All documented on blog.trailofbits.com.
We'll be in Vegas Aug 4-6. If you're around, we'd love to chat: https://meetings.hubspot.com/trailofbits/blackhat-defcon-scheduling
Attackers drained $20M+ from protocols built around Uniswap v4 hooks.
The two largest were Cork (~$12M) and Bunni ($8.4M). Neither came from bugs in the PoolManager, Uniswap v4's central contract. The failures came from application and hook code.
We analyzed dozens of audit findings to isolate seven ways hooks break, and created a checklist for keeping these bugs out of production. https://blog.trailofbits.com/2026/07/30/building-secure-uniswap-v4-hooks/
Work situation is so bad I have to start looking at evil companies because my money tree ain’t growing anything.
Drives me nuts seeing so many things happening at crazy speeds and I am just sitting on the sidelines….
US Military letting it's soldiers wear Meta Pervert Glasses and only now considering the Infosec risk of it...
Decentralized browser-based P2P E2EE messaging.
The key detail that sets this apart from other messaging apps is the browser-based client-side cryptography philosophy.
No need to install anything. Your ID is crypto-random and so the app doesnt need to rely on any central registration system like phone numbers. Your ID is unguessable and to connect to someone, you have to explicitly share it.
WebRTC has other nuances like being to route through a shared network for secure/faster transfer.
I hope this project has reached a level i can share the following details. I've made a genuine effort towards documentation and transparancy. I dont think it'll ever be enough and so im still concerned it isnt ready to share. While im using AI throughout. This is not a vibecoded project. There is attention throughout for unit tests and formal-verification. With your feedback, id like to make improvements for clarity throughout.
This version of the app demonstrates a fairly unique approach using a browser-based, local-only and webrtc approach. I know it's impossible for any system to be the "world's most secure", but that isnt a reason to not try. By rigorously implementing an exhaustive list of security features and practices, the aim is to get as close as possible.
* [Enkrypted.Chat](https://enkrypted.chat/)
This is intended to demonstrate client-side managed secure cryptography.
* [Introducing Enkrypted Chat](https://positive-intentions.com/blog/introducing-enkrypted-chat)
* [Whitepaper (work-in-progress)](https://positive-intentions.com/docs/technical/whitepaper/complete-whitepaper)
* [Protocol Spec (work-in-progress)](https://positive-intentions.com/docs/technical/whitepaper/complete-protocol-spec)
* [Roadmap](https://positive-intentions.com/docs/technical/p2p-messaging-technical-breakdown/)
I know ive tried to compress a lot of my journey into one post. The project above is going to be tricky to understand. Feel free to reach out for clarity on any of the details.
IMPORTANT: While this is aiming to provide a secure experience, It is [not audited or reviewed](https://www.reddit.com/r/CyberSecurityAdvice/comments/1su8lir/security_audit_feedback_from_radically_open/). **Shared for testing, feedback and demo purposes only.** Please use responsibly.
#Privacy #OnlinePrivacy #DataPrivacy #Infosec #CyberSecurity #OpSec #DigitalRights #AntiSurveillance #DataOwnership #E2EE #P2P #PeerToPeer #WebRTC #LocalFirst #LocalOnly #NoCloud #NoRegistration #PWA #SignalProtocol #PostQuantum #Cryptography #SecureMessaging #PrivateChat #EncryptedChat #Decentralized #OpenSource #SelfHosted #BetaTesting #FeedbackWelcome #TechDemo #ProofOfConcept #BuildInPublic #IndieDev #DevCommunity
…Tunick’s lawyers argued during the hearing last week that the seizure was unlawful, & that he was targeted because of his #political #activism against #Atlanta’s plan to build a police & fire training center within a 1,000-acre stretch of urban #woodland. Opponents argue that the center, known as #CopCity, would militarize officers & destroy precious #GreenSpace.
A #US Citizen Deleted His #Phone’s #Data. Now He Faces a #Felony Charge.
Federal prosecutors charged a man returning to the United States with #obstruction because he gave them a passcode that erased his #smartphone during a customs search.
#law #InfoSec #privacy
https://www.nytimes.com/2026/07/28/us/duress-password-phone-wipe-charge.html?unlocked_article_code=1.1VA.PB_S.E8UqK3lm4peR&smid=nytcore-ios-share
So, while Sam #Tunick is a specific case where the feds were looking for a reason to get into his phone without a warrant, we need to talk about how much power #CBP / #ICE has accumulated since the passage of the #Patriot Act.
Under the "border search doctrine", ICE and CBP agents have broad power to search people or property at the border. Any search at the border is considered “reasonable,” meaning no warrant or probable cause is required.
That’s further complicated by the fact that the “border” can be broadly defined as a border-functioning location like an international airport or even within 100 miles of the U.S. border as drawn on a map.
Right now, about 2/3rds of Americans live within an area where ICE can search you without a warrant. While carve-outs for phones existed, the 4th circuit just took some of that protection away.
Every Rust bug we submitted through Patch the Planet came from one engineer who ran a variant-analysis pipeline using Codex's /goal. A separate discovery run uncovered two potential high-severity privilege-escalation bugs in Keycloak's SAML component.
Over the past few weeks, our engineers independently converged on three techniques that get the most out of /goal. We wrote them down, with prompts included: https://blog.trailofbits.com/2026/07/28/how-we-use-goal-to-find-bugs-in-patch-the-planet/
A QUESTION TO #INFOSEC TOOTERS
had a friend call me about suspicious emails from their bank. they didn't respond but checked their accounts with the bank’s app. they saw transactions they didn't do but that were marked as done thru the app.
they wanted to know what to do. i told them:
1. call whichever fraud/stolen bank card number they found on the website immediately.
2. freeze the app but don’t uninstall yet
3. go to the bank immediately monday
they did so and called with updates… 🧵
NEW by me:
It appears that Frontier Airlines may have had a third security incident this year. A new group called ExfilSquad claims to have hacked them -- and no, they say they are not connected to ShinyHunters or ScatteredLapsus$Hunters.
NOTE: Frontier Airlines hasn't confirmed this claimed breach. Then again, they haven't denied it, either. They haven't responded to email inquiries.
Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too.
https://databreaches.net/2026/07/27/hackers-breached-an-airline-as-known-vulnerabilities-went-unpatched-now-another-gang-claims-it-hacked-them-too/
#FrontierAirlines #infosec #cybersecurity #vulnerabilities #databreach
Benn Jordan details his hacking and investigation of Flock at a city council meeting in March 2026.
Plexfiltration update: the AI work zone compliance tool has started emailing me thousands of pictures from a (I think) Saudi industrial facility again, to my internaluser.com domain. #infosec
🚨 U.S. folks. There is one day left to comment on the FCC proposed rule to eradicate anonymity on all phone lines!
If they pass this rule government ID, physical address, and alternative phone number will be required for every new phone line. Anonymous phone lines and burner phones will cease to exist. That means no connected privacy via cellular at protests.
** Please add your comment! **
For the first field (proceedings) use these two:
17-59 and 02-278
🚨 We're disclosing a macOS security bug that Apple says is not an issue.
Using a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web—no password or warning is required.
Here's a demo using Signal to steal its encryption key.
📝 Blog with technical details: link in the replies.
Do you think this should be considered a security bug?
🎬👇
#Apple #privacy #infosec #security #macOS
Hot take:
I hate how all these articles talk about how OpenAI’s clanker “broke out” and attacked Hugging Face.
No, OpenAI’s dog slipped its chain because they don’t know what the hell they’re doing, and it bit another dog.
Matthew McPherrin from Let's Encrypt doing a talk next Wednesday at TASK on post quantum readiness, TLS, and many things. Streaming link on site. https://www.task.to/schedule/july2026-business-resilience-post-quantum-tls #TASK #Toronto #Crypto #PostQuantum #PQ #InfoSec
Edit: There are five Wednesdays this month
This is a great list of tips for improving your Signal privacy from @yaelwrites.
I found this part especially meaningful:
“Turning off biometrics makes it annoying to use your phone…If that’s you, remember that both Android and iOS have a quick lockout that forces a passcode and disables biometrics until you re-enter it: on iPhone, hold the side + volume button until the power-off screen appears, then cancel; on most Androids, hold power and tap Lockdown.”
https://blog.yaelwrites.com/how-to-keep-the-feds-out-of-your-signal-messages
It has been four months since a hacktivist obtained 8.3 million tips submitted to organizations such as Crime Stoppers and Sandy Hook Promise. What the hacktivist found in terms of lack of security was appalling.
In the four months since Navigate360 (the parent company for P3 Global Intel and P3 Campus) learned of the breach, they have made zero public statements after the first day when they said they were investigating. Their wall of silence, and the conspiracy of silence involving programs like Safe2Say, Safe2Tell, SilentWitness, and Crime Stoppers has been unacceptable. No one has been notified, it seems. And we cannot find any state regulator that has been notified, either.
DataBreaches wrote about the disgraceful lack of transparency in a new post this week:
Broken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.
https://databreaches.net/2026/07/20/broken-promises-of-anonymity-four-months-later-still-no-transparency-now-were-seeking-accountability/
In conjunction with that post, I filed a formal FTC complaint against Navigate360 under Section 5 of the FTC Act and also notified the National Association of Attorneys General, saying that states should be protecting their residents by investigating the breach and incident response.
And that's not all. Today, I have filed a complaint with one state attorney general's office and will be filing with others.
I will also be publishing a post this week about the Crime Stoppers data in the dataset and the ridiculous response by legal counsel for Crime Stoppers USA to inquiries by DataBreaches about what was being done to improve security.
I have not written up anything specific to all of the Canadian data in the dataset, but yes, Canadian crime stoppers and police organizations are in there, too.
Take Action:
If you know anyone in a state attorney general's office, encourage them to read up on the breach on my site, where I have also published tables with data for easy reference.
If you know anyone in the FTC, encourage them to read the complaint I filed and to act on it.
If you know any personal injury lawyer who should be handling a massive lawsuit alleging privacy harms, point them to my coverage.
Children and adults who tried to be good citizens and relied on promises of anonymity have been put in harm's way. We cannot allow this to be minimized or covered up.
@zackwhittaker @nytimes @caparsons @douglevin
#databreach #infosec #Navigate360 #CrimeStoppers #Safe2Tell #Safe2Say #SilentWitness #SandyHookPromise #transparency #notification #NAAG #FTC
Who had "getting compromised through plugging an LG monitor in" on their #itsecurity 2026 bingo card? Apparently just plugging an LG monitor into a windows computer is enough for them to install spyware and steal all of your data. But hey you agree to this in their ToS (even without having to click on "I agree", it just installs).
LG TVs and monitors said to surveil users and install bloatware without asking
> Anyone who owns an LG smart TV must inform all guests and family members that they are being monitored – this is required by LG’s current terms of use. Meanwhile, LG monitors install potential malware and surveillance software on a connected Windows computer.
I thought scaling Tor meant adding more relays.
What it actually meant was multiplying failure modes...
I now operate 24 Tor relays and bridges across 15 locations, 11 ASNs and 6 operating systems.
Every new relay brings another provider, firewall, IPv6 route, service manager, identity key, backup and recovery plan.
Some things I learned along the way:
🌍 More countries don’t automatically mean real diversity
🔑 The server is replaceable, the relay identity isn’t
🛠️ Linux, BSD and SunOS need the same outcomes, not the same commands
📊 What I configured isn’t always what the Tor network currently sees
A large fleet is easy to count. A resilient one is much harder to keep alive.
I wrote about what operating Tor across 15 locations actually taught me:
Shufflecake talk at CAW 2026 last May - video now available online!
https://clip.place/w/d7Anz5jbsMCZo1HBg8JkES
https://www.youtube.com/watch?v=21LjKFBIwwY
#shufflecake #caw #eurocrypt #eurocrypt2026 #cryptography #crypto #truecrypt #veracrypt #security #Privacy #infosec #hacktivism #censorship
"The oldest principles in security—auditing, logging, isolation, least privilege—matter more than ever now that actions happen at machine speed, not human speed."—Artem Dinaburg, our chief scientist, on Silver Bullet ep 158.
The full pod covers why prompt injection has no clean fix, how we rebuilt our audits around agents, and why decompilers should work more like language translators.
https://berryvilleiml.com/2026/07/01/silver-bullet-security-podcast-158-artem-dinaburg/