soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #cybersecurity

[?]Flipboard Tech Desk » 🌐
@TechDesk@flipboard.social

Google has confirmed that hackers have stolen the Salesforce-stored data of more than 200 companies in a large-scale supply chain hack. On Thursday, The nebulous hacking group known as Scattered Lapsus$ Hunters claimed responsibility. Read more from @Techcrunch:

flip.it/zDONb5

    CyberFrog boosted

    [?]BeyondMachines :verified: » 🤖 🌐
    @beyondmachines1@infosec.exchange

    Critical remote code execution flaw reported in Emerson Appleton UPSMON-PRO

    Emerson's Appleton UPSMON-PRO UPS monitoring system contains a critical stack-based buffer overflow vulnerability (CVE-2024-3871) that allows remote attackers to execute arbitrary code with SYSTEM privileges via malicious UDP packets to port 2601. The product has reached End of Life with no security patches available.

    **Make sure all Emerson Appleton UPSMON-PRO devices are isolated from the internet and accessible from trusted networks only. Since this product is End of Life and no security patches are available, block UDP port 2601 and isolate the monitoring network until you can migrate. Plan a replacement with a supported UPS monitoring solution.**

    beyondmachines.net/event_detai

      [?]AI6YR Ben » 🌐
      @ai6yr@m.ai6yr.org

      Oooh, it's my time to leap into cybersecurity.

      "Adversarial Poetry as a Universal Single-Turn Jailbreak Mechanism in Large Language Models"

      "...Abstract

      We present evidence that adversarial poetry functions as a universal single-turn jailbreak technique for large language models (LLMs). Across 25 frontier proprietary and open-weight models, curated poetic prompts yielded high attack-success rates (ASR), with some providers exceeding 90%. Mapping prompts to MLCommons and EU CoP risk taxonomies shows that poetic attacks transfer across CBRN, manipulation, cyber-offence, and loss-of-control domains. Converting 1,200 MLCommons harmful prompts into verse via a standardized meta-prompt produced ASRs up to 18 times higher than their prose baselines. ..."

      arxiv.org/html/2511.15304v1

        [?]MistressPrime :verified: » 🌐
        @MistressPrime@anti-social.online

        A listing on a dark web forum claims that a full database from Beckett Collectibles, the U.S.-based marketplace for trading cards and memorabilia, is being sold through a third-party marketplace.


        databreach.io/breaches/beckett

          [?]AI6YR Ben » 🌐
          @ai6yr@m.ai6yr.org

          Privacy, Sex, Religion [SENSITIVE CONTENT]

          I'm going to go out there and say using an app to track (and share) how much you are using porn and getting off is NOT a great cybersecurity posture. (On the other hand, if you wanted to SELL porn, this data would be a goldmine)

          Wired: Young Mormons Built an App to Help Men Quit Gooning

          wired.com/story/young-mormons-

          Wired: Young Mormons Built an App to Help Men Quit Gooning

          Alt...Wired: Young Mormons Built an App to Help Men Quit Gooning

            [?]Jerry on Mastodon » 🌐
            @Jerry@hear-me.social

            Please, if you are using a free VPN, other than ProtonVPN, stop!!! If you need a VPN then pay for it. And don't pick some cheap one with no reputation either. Pick a reputable one.

            They are hugely expensive to run and if they are free, run by some unknown, they are getting their profits in ways you won't like.

            cybersecuritynews.com/maliciou

              [?]adison verlice » 🌐
              @adisonverlice@tweesecake.social

              let me tell you, Wisconsin's ban is simply is nothing but because it doesn't work!
              first off, the federal government literally recommends VPNs. in fact, if you see this document and this document you can see that the government literally recommends VPNs.
              so this would go against the federal governments own recommendations.
              second off, this violates the first and forth amendments.
              o, and this doesn't work at all.
              in fact, in order for this to even work, they would have to implement the of architecture, where they'd have to censor everything coming from the internet, or they'd have to do something similar to which, again, would violate the first and forth amendments.
              and knowing providers like / , / , ISPs are too lazy to implement deep packet inspection themselves, meaning they'd very likely just block VPN sites at the DNS level, which, keep in mind, doesn't work.

                [?]AI6YR Ben » 🌐
                @ai6yr@m.ai6yr.org

                Oh look, the opportunity to trade all my personal data to Google for "up to" $540 🙄

                Google details on monitoring your phone

                Alt...Google details on monitoring your phone

                  [?]The Linux Foundation » 🌐
                  @linuxfoundation@social.lfx.dev

                  🧱 You're already building infrastructure, apps, and cloud systems. Now build your cybersecurity muscle. We make it fast, easy and free with the Cybersecurity Skills Framework from Linux Foundation Education & OpenSSF.

                  The Cybersecurity Skills Framework helps:
                  🔸 Developers
                  🔸 IT admins
                  🔸 SREs
                  🔸 Network engineers
                  🔸 And more

                  Understand the risks. Identify the skills. Strengthen your team. Start here, it's FREE! Try it now: cybersecurityframework.io

                    Blau :neocat_floof_w_: :therian: boosted

                    [?]nullagent » 🌐
                    @nullagent@partyon.xyz

                    Was just going on a grey-beard rant about how Rust give developers a false sense of security.

                    I didn't even notice the TARMageddon vulnerability until now and well this grey beard really only can say "told you so".

                    This is -precisely- the class of bugs I was describing, and -exactly- due to the reasons I outlined.

                    The blast radius of this thing is also freaking epic, almost anything that used tar in Rust is vulnerable to possible RCEs lmao.

                    edera.dev/stories/tarmageddon

                      [?]Erik Jonker » 🌐
                      @ErikJonker@mastodon.social

                      Goed om te herhalen, data residency is niet hetzelfde als digitale soevereiniteit.
                      Voor meer informatie zie deze Linkedin post: linkedin.com/posts/anco-scholt

                      data residency is niet hetzelfde als digitale soevereiniteit.

                      Alt...data residency is niet hetzelfde als digitale soevereiniteit.

                        [?]Plaid [He/His] » 🌐
                        @plaidtron3000@jorts.horse

                        Just got what I'm pretty sure is a phishing text on my phone.

                        It claimed to be from Apple, and said that someone had found my iPhone, and I should sign into Apple to claim it.

                        Except that I was holding that phone in my hand. I received the text on it.

                        I don't think someone thought that one through very well.

                          [?]Tuta » 🌐
                          @Tutanota@mastodon.social

                          The Louvre’s surveillance password was literally… “Louvre.” 😳

                          Here are 3 password manager tips from Tuta you need to hear 👇

                          Tip 1: Use strong, unique passwords
                          Tip 2: Never reuse passwords
                          Tip 3: Enable 2FA (two-factor authentication)

                          Alt...Hanna acting as two people trying to figure out the Louvre's password to the CCTV footage.

                            [?]Erik Jonker » 🌐
                            @ErikJonker@mastodon.social

                            [?]nullagent » 🌐
                            @nullagent@partyon.xyz

                            Yikes, excellent blog post on why companies really need to erase all of the data off of network equipment they send to recycle.

                            @alyx

                              [?]The Linux Foundation » 🌐
                              @linuxfoundation@social.lfx.dev

                              🔐 You don't need another compliance tool. You need a way to build real cybersecurity readiness across your team — fast.

                              That’s why the new Cybersecurity Skills Framework matters:
                              🔹 Customize critical skills by role and level
                              🔹 It’s free, open, and flexible
                              🔹 Helps you spot and fix gaps before attackers do

                              The best part? You can apply it in hours, not weeks. Check it out: cybersecurityframework.io

                                [?]Taggart :ifin: » 🌐
                                @mttaggart@infosec.exchange

                                I finally did it.

                                I unfollowed . It had become terminally LinkedInified here. Absolutely nothing of substance was being shared.

                                  [?]knoppix » 🌐
                                  @knoppix95@mastodon.social

                                  Austria’s Ministry of Economy kicks out Microsoft, moving 1,200 staff to Nextcloud in 4 months 🕒

                                  EU-based cloud ensures GDPR & NIS2 compliance 🇪🇺
                                  Hybrid setup keeps Teams only for external use; all internal collaboration now on Nextcloud 🔒
                                  Smooth rollout earns positive employee feedback 👍

                                  🔗 news.itsfoss.com/austrian-mini

                                    [?]AI6YR Ben » 🌐
                                    @ai6yr@m.ai6yr.org

                                    Oops

                                    BleepingComputer: Hyundai AutoEver America data breach exposes SSNs, drivers licenses

                                    "...Its role is to supply IT solutions and services tailored to the automotive industry, particularly for Hyundai and Kia affiliates, including vehicle telematics, OTA (over-the-air) updates, maps, vehicle connectivity, embedded systems, and autonomous driving systems...."

                                    bleepingcomputer.com/news/secu

                                      [?]AI6YR Ben » 🌐
                                      @ai6yr@m.ai6yr.org

                                      dory boosted

                                      [?]Space Rogue » 🌐
                                      @spacerog@mastodon.social

                                      I've decided to stop pussy footing around and I am now openly looking for my next challenge.
                                      Interested in a company on the small to mid-size range with a cool story. Ideal position would be a combination of customer outreach, marketing and thought leadership. What ya got?

                                        [?]Flipboard Tech Desk » 🌐
                                        @TechDesk@flipboard.social

                                        When hackers hit a company with a ransomware attack, another company that specializes in negotiating with the perpetrators may step in. Two such specialists were recently charged by the U.S. Dept. of Justice for carrying out ransom attacks of their own. @Techcrunch has more:

                                        flip.it/H-1Vkb

                                          [?]⚯ Michel de Cryptadamus ⚯ » 🌐
                                          @cryptadamist@universeodon.com

                                          one of the largest crypto protocols is currently being robbed, $88 million stolen and counting. it will probably turn out to be (because it's almost always north korea) but TBD.

                                          one of the fun things about crypto is that when someone robs a bank you can watch the getaway car drive away just by clicking on some links in a blockchain explorer.

                                          [edit] details of the bug that was exploited if you’re into that kind of thing: x.com/moo9000/status/198526273

                                          [edit] ended up being a ~$130 million heist.

                                          UPDATE: The attack is ongoing. The estimated loss is ~$88M on multiple chains
Quote
PeckShieldAlert
@PeckShieldAlert
·
38m
#PeckShieldAlert @balancer has been drained ~$70.8M worth of cryptos, including 6,851.12 $osETH (~$27M), 6,587.44 $WETH (~$24.5M) & 4,259.84 $wstETH (19.3M)

                                          Alt...UPDATE: The attack is ongoing. The estimated loss is ~$88M on multiple chains Quote PeckShieldAlert @PeckShieldAlert · 38m #PeckShieldAlert @balancer has been drained ~$70.8M worth of cryptos, including 6,851.12 $osETH (~$27M), 6,587.44 $WETH (~$24.5M) & 4,259.84 $wstETH (19.3M)

                                            [?]jbz » 🌐
                                            @jbz@indieweb.social

                                            ⚠️ Vibe Coding Is the New Open Source—in the Worst Way Possible | WIRED

                                            “If you ask the exact same LLM model to write for your specific source code, every single time it will have a slightly different output. One developer within the team will generate one output and the other developer is going to get a different output. So that introduces an additional complication beyond open source”

                                            wired.com/story/vibe-coding-is

                                              [?]AI6YR Ben » 🌐
                                              @ai6yr@m.ai6yr.org

                                              Why the heck is there a call to bash and install dependencies / npm install embedded in the FAA's TFR pages? (Updated: amused to learn, informally, there's already a ticket filed against this one at the FAA).

                                              view-source:tfr.faa.gov/tfr3/?page=detail_

                                              content with descape to bash install dependencies npm install

                                              Alt...content with descape to bash install dependencies npm install

                                                [?]CosicBe » 🌐
                                                @CosicBe@mastodon.social

                                                Exciting news! 🎉 COSIC Professor Vincent Rijmen has been selected as one of the finalists for the Belgian Cyber Security Awards 2025, a great recognition of his lasting impact and expertise in the Belgian cybersecurity community.🔐

                                                  [?]The Linux Foundation » 🌐
                                                  @linuxfoundation@social.lfx.dev

                                                  🔐 Every design decision hides a security lesson.
                                                  Learn to identify risks early and build resilient systems with “Threat Modeling Essentials (SKF401)”—where technical skill meets leadership growth.
                                                  👉 Enroll: training.linuxfoundation.org/t

                                                    [?]MeaTLoTioN » 🌐
                                                    @meatlotion@mas.erb.pw

                                                    I was shared a link to a video ... youtu.be/sMCtZjen2JU?si=BuIrkq

                                                    What do y'all make of it? Is it real? Is it massively exaggerating a situation? Or is it entirely false?

                                                      [?]Jerry on Mastodon » 🌐
                                                      @Jerry@hear-me.social

                                                      OMG. No!! And not good for . Ads can carry dangerous payloads.

                                                      Lock screen ads are coming to some U.S. smartphones

                                                      lifehacker.com/tech/lock-scree

                                                        [?]Erik Jonker » 🌐
                                                        @ErikJonker@mastodon.social

                                                        Tuta boosted

                                                        [?]Tuta » 🌐
                                                        @Tutanota@mastodon.social

                                                        is OFF the table for now. 💪

                                                        But the Danish Minister of Justice and chief architect of the current Chat Control proposal, Peter Hummelgaard, wants to bring it back in December.

                                                        😡 He now even claims your activism was paid for by Big Tech! 😡

                                                        We must keep fighting for and our right to 🔒️

                                                        Source: netzpolitik.org/2025/absurd-un

                                                        Danish Minister of Justice and chief architect of the current Chat Control proposal, Peter Hummelgaard, wants to bring it back in December

                                                        Alt...Danish Minister of Justice and chief architect of the current Chat Control proposal, Peter Hummelgaard, wants to bring it back in December

                                                          [?]Sam Chavez (she/they/he) 🌈🤠 » 🌐
                                                          @rootschange@federate.social

                                                          To all my ladies and they’dies, DO NOT give your private health info to an app!

                                                          In our Wild West Tech world, hope regulations is long gone. App can do pretty much whatever they want with your data once you “consent”

                                                          Just Say No, Bro to tech apps.

                                                          I use a paper calendar instead 😉

                                                          404media.co/women-dating-safet

                                                            [?]Coalition for Networked Info » 🌐
                                                            @cni@mastodon.social

                                                            Hear from CNI at the Annual Conference this week in Nashville, TN.

                                                            On Tuesday, CNI Executive Director Kate Zwaard will provide an overview of current CNI initiatives; and explore CNI’s possible future programmatic priorities, such as and infrastructure.

                                                            On Wednesday, Karen Estlund, CNI steering committee member, will represent CNI on the panel: "State of the Ecosystem: National Perspectives on Research Computing and Data”

                                                            Conference info: events.educause.edu/annual-con

                                                              [?]Flipboard Tech Desk » 🌐
                                                              @TechDesk@flipboard.social

                                                              23 common tech myths: Busted once and for all.

                                                              From @PCMag: "How many of these doozies are you still falling for? Let our experts set you straight."

                                                              flip.it/PjY5Js

                                                                [?]AI6YR Ben » 🌐
                                                                @ai6yr@m.ai6yr.org

                                                                Must. Resist. Hacking... to display Never Gonna Give You Up.

                                                                Electronic display with instructions on configuring it

                                                                Alt...Electronic display with instructions on configuring it

                                                                  [?]Neil Brown [he/him/his] » 🌐
                                                                  @neil@mastodon.neilzone.co.uk

                                                                  # Supply chain resilience against ransomware

                                                                  > This guidance is to help organisations build resilience into their supply chains, reducing the likelihood and impact of ransomware incidents.

                                                                  > It’s issued by the Counter Ransomware Initiative, an international partnership for collective defence against ransomware.

                                                                  New today.

                                                                  gov.uk/government/publications

                                                                    [?]Nonilex » 🌐
                                                                    @Nonilex@masto.ai

                                                                    Another activist, , who spread debunked claims about voting machines in Georgia when she was the chairwoman of the DeKalb County Party, was named in May to be the director of public affairs at the & Infrastructure Security Agency, or , which is housed in .

                                                                      [?]Nonilex » 🌐
                                                                      @Nonilex@masto.ai

                                                                      Heather Honey, a leader in that movement until her appointment in August as deputy assistant secretary for *election integrity*, complained that her department’s experts tasked with combating about had “strayed from their mission.”

                                                                        [?]AI6YR Ben » 🌐
                                                                        @ai6yr@m.ai6yr.org

                                                                        Back to top - More...