soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
🛡️ #Cybersecurity news & tips across the #fediverse
“# Surveillance vendors caught abusing access to telcos to track people's phone locations
# CitizenLab , a digital rights organization which exposes surveillance abuses, published a new report detailing two newly ide...”
https://hachyderm.io/@BenjaminHCCarr/116462180202933128
🤖 via RSS feed. Not an endorsement.
🛡️ #Cybersecurity news & tips across the #fediverse
“RE: https:// flipboard.com/@techradar/vpn-c ybersecurity-securing-your-life-online-lcmnfb0vz/-/a-hl0GxAQ5QkSTHunoY8lhrA%3Aa%3A2416536031-%2F0 ""Rather than enforcing regulations on the companies, we are putting ru...”
https://mastodon.world/@mikill/116461602306210693
🤖 via RSS feed. Not an endorsement.
🛡️ #Cybersecurity news & tips across the #fediverse
“Gmail requires your phone number to create an account. Your phone number is tied to your government ID. Your email is tied to your real identity. By design. There's another way. No phone. No name. No password. 10 seco...”
https://mastodon.social/@qryptymail/116460995409776237
🤖 via RSS feed. Not an endorsement.
AI/ML Security
<https://openssf.org/groups/ai-ml-security/> @openssf @linuxfoundation
"This working group is situated at the intersection between security and artificial intelligence (AI). We explore the security risks associated with Large Language Models (LLMs), Generative AI (GenAI), and other forms of artificial intelligence and machine learning (ML), and their impact on open source projects, maintainers, their security, communities, and adopters. Furthermore, we explore using AI and ML to strengthen the security of other open source projects.
This group in collaborative research and peer organization engagement to explore topics related to AI and security. This includes security for AI development (e.g., supply chain security) but also using AI for security. We are covering risks posed to individuals and organizations by improperly trained models, data poisoning, privacy and secret leakage, prompt injection, licensing, adversarial attacks, and any other similar risks.
This group leverages prior art in the AI/ML space,draws upon both security and AI/ML experts, and pursues collaboration with other communities (such as the CNCF’s AI WG, LFAI & Data, AI Alliance, MLCommons, and many others) who are also seeking to research the risks presented by AL/ML to OSS in order to provide guidance, tooling, techniques, and capabilities to support open source projects and their adopters in securely integrating, using, detecting and defending against LLMs. …"
🛡️ #Cybersecurity news & tips across the #fediverse
“House Bill Proposes Reauthorization of Section 702 Amid Minimal Oversight Changes 📰 Original title: The Latest Push to Extend Key US Spy Powers Is Still a Mess 🤖 IA: It's clickbait ⚠️
👥 Usuarios: It's clickbait ⚠️ ...”
https://mastodon.social/@killbait/116460645382758541
🤖 via RSS feed. Not an endorsement.
🛡️ #Cybersecurity news & tips across the #fediverse
“The Intercept: “We Knew They Were Paying Informants”: SPLC Donors Reject Trump DOJ Fraud Claims https:// theintercept.com/2026/04/24/sp lc-donors-fraud-doj-kash-patel/ Also, Palantir: Palantir Is Helping Trump’s...”
https://infosec.exchange/@AAKL/116460594026987032
🤖 via RSS feed. Not an endorsement.
Right of Access as Reconnaissance, who needs a hack when you can request. In 2019, security researcher James Pavur submitted 150 forged subject access requests at Black Hat USA — using only a target's name and a look-alike email. 24% of responding companies returned sensitive personal data (passwords, home addresses, payment card digits, travel history). 3% deleted the account with no verification at all.
Six years later, I wanted to see whether anything had meaningfully changed.
#privacy #cybersecurity #GDPR #ethics
First part: https://privacyinsightsolutions.com/blog/right-of-access-reconnaissance-gdpr-art-15-gap?utm_medium=info
🛡️ #Cybersecurity news & tips across the #fediverse
“"When he drives through his neighborhood now, Brian Page passes rows of police cars and AI‑powered cameras that track nearly every movement. For most of his life, Page, who goes by “Scapegoat Jones,” felt safest in the ...”
https://tldr.nettime.org/@remixtures/116460311811321320
🤖 via RSS feed. Not an endorsement.
#Surveillance vendors caught abusing access to telcos to track people’s phone locations, researchers say
🛡️ #Cybersecurity news & tips across the #fediverse
“Age verification is expanding from laws into platforms and operating systems, linking access to identity checks across services and devices 🌐
Implementations often require IDs or biometrics, creating centralized data t...”
https://mastodon.social/@knoppix95/116458701680794018
🤖 via RSS feed. Not an endorsement.
We must keep #AgeVerification from killing #anonymity online
https://proton.me/blog/keep-age-verification-from-killing-anonymity-online
🛡️ #Cybersecurity news & tips across the #fediverse
“NEW: # Atlanta now has more # surveillance cameras per person than any city on Earth outside a few in China.
The densest grid is over Black neighborhoods. To grow that AI-fueled network, the city razed a part of ...”
https://zirk.us/@JazzyKindaFella/116457240387312426
🤖 via RSS feed. Not an endorsement.
#iOS 26.4.2 Patches Flaw That Let #FBI Extract Deleted #Signal Messages
https://www.macrumors.com/2026/04/22/ios-26-4-2-notification-database-security-fix/
📜 Scrolls volume 38 is out! Check it out and let me know what you think!
https://shellsharks.com/scrolls/scroll/2026-04-24
Thanks to everyone below. Their work was featured in this week's edition.
@yossarian @readbeanicecream @32x33 @kev @stefan @brennan @mat @beitmenotyou@beitmenotyou.online @mcc @OohOkayKay @catsalad @MxPoesu @jtr @lrhodes @iko @chrisod @n3wjack @benjaminparry @brennan @HughWRoberts @ammaratef45 @brine @sawaba @cR0w @timecowboy @xarkes
#indieweb #fediverse #infosec #cybersecurity
Have a great weekend!
🛡️ #Cybersecurity news & tips across the #fediverse
“Homeland Security is developing glasses that allow federal agents to identify individuals from a distance, according to Ken Klippenstein. # Surveillance # Privacy These advanced glasses aim to enhance identificati...”
https://mastodon.social/@voteinorout/116456733051875939
🤖 via RSS feed. Not an endorsement.
Surveillance vendors caught abusing access to telcos to track people’s phone locations, researchers say
The Citizen Lab found two separate surveillance vendors abusing the backbone of cellular networks to spy on several victims across the world.
#cybersecurity #diameter #israel #location-tracking #privacy #security #ss7 #surveillance
https://techcrunch.com/2026/04/23/surveillance-vendors-caught-abusing-access-to-telcos-to-track-peoples-phone-locations-researchers-say/
#AI Tools Are Helping Mediocre North Korean Hackers Steal Millions
https://www.wired.com/story/ai-tools-are-helping-mediocre-north-korean-hackers-steal-millions/
🛡️ #Cybersecurity news & tips across the #fediverse
“# Palantir Employees Are Starting to Wonder if They're the Bad Guys Interviews with current and former Palantir employees, along with internal Slack messages obtained by WIRED, suggest a workforce in turmoil.
# pri...”
https://mas.to/@PrivacyDigest/116455557461434986
🤖 via RSS feed. Not an endorsement.
🚨 Bitwarden CLI got compromised.
A malicious npm package targeted developers, stealing tokens, SSH keys, and cloud creds through a supply chain attack.
If you installed it, your secrets could be exposed.
Remove it. Rotate everything. Check your CI now.
👉️ https://digitalescapetools.com/2026/04/bitwarden-cli-attack.html
Daily Digest | 24 April 2026
Your daily dose of Privacy, Data Protection, AI & Cybersecurity news.
5 stories you should not miss.
Read more: https://www.nicfab.eu/daily-digest/
For anyone following EU digital regulation, data protection, AI governance, cybersecurity, and digital policy: a daily curated digest of institutional sources — Garante Privacy, EDPB, EUR-Lex, European Commission, ENISA, and more.
Short format, direct links, updated every day. Free.
👉 https://www.nicfab.eu/daily-digest/
Newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now
#DataProtection #AIAct #GDPR #AIgovernance #Cybersecurity #AI
Age verification is expanding from laws into platforms and operating systems, linking access to identity checks across services and devices 🌐
Implementations often require IDs or biometrics, creating centralized data targets and reducing anonymity despite privacy claims 🔐
🔗 https://proton.me/blog/age-verification-explained
#TechNews #AgeVerification #Privacy #DigitalID #Cybersecurity #OpenSource #FOSS #DataProtection #Security #Encryption #Surveillance #Regulation #Infosec #Tech #Identity
UK regulator Ofcom probes Telegram under the Online Safety Act over alleged CSAM sharing, alongside teen chat platform investigations 📱
Case tests compliance powers like fines or blocking, raising tensions between enforcement, encryption, and user privacy rights ⚖️
#TechNews #Telegram #Ofcom #OnlineSafetyAct #Privacy #Cybersecurity #Encryption #ContentModeration #DigitalRights #Surveillance #Regulation #Infosec #DataProtection #UK #Tech #CSAM #Teen #ChildSafety
EU age verification app was declared ready and privacy-presing, but researchers bypassed protections in under 2 minutes despite open-source code 🔍
Flaws in config-stored controls, disabled biometrics, and exposed credentials highlight risks of identity linkage and centralized tracking ⚠️
🔗 https://proton.me/blog/eu-age-verification-app-hacked
#TechNews #EU #Europe #AgeVerification #Privacy #Cybersecurity #OpenSource #FOSS #DataProtection #Security #Encryption #DigitalID #Surveillance #Infosec #Tech #Regulation
🛡️ #Cybersecurity news & tips across the #fediverse
“Episode 23 of Impractical Privacy: Smart vacuums are mapping our homes in incredible detail - but at what cost? We’re talking about the data they collect, how it’s used, and the potential privacy implications. It’s a s...”
https://mastodon.social/@ImpracticalPrivacy/116455343121757393
🤖 via RSS feed. Not an endorsement.
🛡️ #Cybersecurity news & tips across the #fediverse
““Palantir Employees Are Starting to Wonder if They're the Bad Guys “ For smart people, they seem kind of slow on the uptake. https://www. wired.com/story/palantir-emplo yees-are-starting-to-wonder-if-theyre-the-ba...”
https://mastodon.social/@skry/116455278647016977
🤖 via RSS feed. Not an endorsement.
Global #AgeVerification push will mean "the death of anonymity online." #Proton CEO warns, including OS-level age verification laws and bills. #Privacy #PrivacyFirst #StopOSSpies #NoAgeSignals #FirstAmendment #FourthAmendment #BadInternetBills #DigitalFreedom #CyberSecurity #Government #OpenSource
🛡️ #Cybersecurity news & tips across the #fediverse
“What is dynamic pricing at grocery stores? Maryland now bans it surveillance pricing is when a store charges different shoppers different prices for the same item at the same time, based on something the store “knows” a...”
https://mastodon.social/@gtbarry/116455092890645146
🤖 via RSS feed. Not an endorsement.
🛡️ #Cybersecurity news & tips across the #fediverse
“Medical data of half a million Britons listed for sale on # Alibaba The medical data of half a million volunteers to # Biobank , the # UK 's # health information database, has been offered for sale online, the...”
https://mastodon.online/@jonsnow/116454760295520060
🤖 via RSS feed. Not an endorsement.
"Key Findings:
- Multi-Vector Surveillance: We identified actors using multiple techniques to track targets by combining 3G and 4G signalling network protocols with direct device exploitation via SMS.
SIM Card Exploitation: One campaign sent a malicious SMS containing hidden SIM card commands to extract location information, attempting to turn the device into a covert tracking beacon.
- Sophisticated and Customized Tooling: Both actors used customized surveillance tooling to spoof operator identities, manipulate signalling protocols, and steer traffic through specific interconnect network paths to evade defenses and mask attribution.
- Global Network Infrastructure: The attacks leveraged identifiers and infrastructure associated with operators worldwide, including networks based in the UK, Israel, China, Thailand, Sweden, Italy, Liechtenstein, Cambodia, Mozambique, Uganda, Rwanda, Poland, Switzerland, Morocco, Namibia, Lesotho, and the self-governing Island of Jersey, demonstrating extensive global reach.
- Persistent Campaign Activity: Telemetry shared by mobile signalling security provider Cellusys reveals that operator identifiers were reused over multiple years, forming consistent clusters that enabled long-running surveillance operations.
- Weak Intercarrier Provider OPSEC: Weak screening of interconnect traffic allowed attackers to route surveillance messages through trusted operator pathways, enabling access to targeted networks."
https://citizenlab.ca/research/uncovering-global-telecom-exploitation-by-covert-surveillance-actors/
🛡️ #Cybersecurity news & tips across the #fediverse
“https:// citizenlab.ca/research/uncover ing-global-telecom-exploitation-by-covert-surveillance-actors/ Worth a read if you give a shit # privacy # security and # surveillance”
https://mastodon.social/@AlexanderMars/116454593143121278
🤖 via RSS feed. Not an endorsement.
🛡️ #Cybersecurity news & tips across the #fediverse
“Dangerous apps - In the web of data brokers | DW Documentary
# privacy # surveillance # abortion https://www. youtube.com/watch?v=Y07j3hXAI-g”
https://social.vivaldi.net/@rogerc2738/116454458689449737
🤖 via RSS feed. Not an endorsement.
🛡️ #Cybersecurity news & tips across the #fediverse
“"Online privacy has always been tenuous. But with age verification, we’re on the cusp of, once and for all, requiring ID for every single person going online, for any reason, legal or not, adult or not. And that should t...”
https://mastodon.world/@mikill/116453971585227104
🤖 via RSS feed. Not an endorsement.
The rise of #AgeVerification: What governments, platforms, and devices are changing