dobbs.town is one of the many independent Mastodon servers you can use to participate in the fediverse.
Church of the SubGenius Members-Only MastoDobbs.

Server stats:

139
active users

#cybersecurity

301 posts163 participants7 posts today
Replied in thread

…It was…unclear if #Starlink communications were #encrypted. At a minimum, the system allows for a network separate from existing WH servers that people on the grounds are able to use, keeping that data separate.

“It’s super rare” to install Starlink or another #internet provider as a replacement for existing govt #infrastructure that has been vetted & secured, said Jake Williams, a VP for R&D at Hunter Strategy, a #cybersecurity consultancy. “I can’t think of a time that I have heard of that.”

Israeli-Russian citizen Rostislav Panev, a developer for the LockBit ransomware group, has been extradited to the U.S. to face charges related to global cyberattacks that caused $500 million in damages across 2,500 victims in 120+ countries. Investigators linked Panev to LockBit via credentials found on his device granting access to repositories storing the malware, and he allegedly received $230,000 in cryptocurrency for his work. LockBit, known for its ties to Russian intelligence, has targeted governments, corporations, hospitals, and critical infrastructure using advanced ransomware techniques. Panev, arrested in Haifa in August 2024, was denied FBI questioning in Israel, and a gag order was imposed to prevent further suspects from fleeing. He is the third LockBit affiliate arrested, following Mikhail Vasiliev (Canada) and Ruslan Astamirov (U.S.), while the U.S. offers $10M for the capture of LockBit’s leader, Dmitry Khoroshev. #CyberSecurity #Ransomware ynetnews.com/article/by9yfx4hy

ynetnews · Israeli-Russian hacker extradited to US over global ransomware attacksBy Itamar Eichner, Daniel Edelson, New York

Data overload got you down?

Tune into our latest
@sharedsecurity podcast episode as we explore mastering vulnerability remediation with insights from experts Dahvid Schloss and Dan DeCloss from PlexTrac.

Watch on YouTube:
youtu.be/_6B-zEp54a8

Listen and subscribe!
sharedsecurity.net/2025/03/17/

sharedsecurity.net/subscribe

It would appear as if Wiz may have discovered another supply-chain compromise:

wiz.io/blog/new-github-action-

The attack involved compromising the v1 tag of reviewdog/action-setup between March 11th 18:42 and 20:31 UTC. Unlike the tj-actions attack that used curl to retrieve a payload, this attack directly inserted a base64-encoded malicious payload into the install.sh file. When executed, the code dumped CI runner memory containing workflow secrets, which were then visible in logs as double-encoded base64 strings. The attack chain appears to have started with the compromise of reviewdog/action-setup, which was then used to compromise the tj-actions-bot Personal Access Token (PAT), ultimately leading to the compromise of tj-actions/changed-files. Organizations are advised to check for affected repositories using GitHub queries, examine workflow logs for evidence of compromise, rotate any leaked secrets, and implement preventive measures like pinning actions to specific commit hashes rather than version tags.

wiz.io · GitHub Action supply chain attack: reviewdog/action-setup | Wiz BlogA supply chain attack on tj-actions/changed-files leaked secrets. Wiz Research found another attack on reviewdog/actions-setup, possibly causing the compromise.

New Open-Source Tool Spotlight 🚨🚨🚨

Covenant is an open-source Command and Control framework designed for red team operations. Built in .NET Core, it supports cross-platform compatibility and multiple operators working simultaneously. It's a powerful tool, but keep in mind its ethical use depends on the intention behind it. #CyberSecurity #RedTeam

🔗 Project link on #GitHub 👉 github.com/cobbr/Covenant

#Infosec #Cybersecurity #Software #Technology #News #CTF #Cybersecuritycareer #hacking #redteam #blueteam #purpleteam #tips #opensource #cloudsecurity

✨
🔐 P.S. Found this helpful? Tap Follow for more cybersecurity tips and insights! I share weekly content for professionals and people who want to get into cyber. Happy hacking 💻🏴‍☠️

So, Cloudflare analyzed passwords people are using to log in to sites they protect and discovered lots of re-use.

Let me put the important words in uppercase.

So, CLOUDFLARE ANALYZED PASSWORDS PEOPLE ARE USING to LOG IN to sites THEY PROTECT and DISCOVERED lots of re-use.

[Edit with H/T: benjojo.co.uk/u/benjojo/h/cR4d]

blog.cloudflare.com/password-r

benjojo.co.ukbenjojo:It feels quite uncomfortable that cloudflare is somewhat openly admitting to analysing login credentials that are going through the reverse proxy, and providing...

Android Banking Trojan OctoV2 Disguising As DeepSeek AI

Pulse ID: 67d844602d283f1e5f071363
Pulse Link: otx.alienvault.com/pulse/67d84
Pulse Author: cryptocti
Created: 2025-03-17 15:48:48

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

Newly Discovered Ebyte Ransomware Targets Windows Users

Pulse ID: 67d8457d0f7af00bed6d15c2
Pulse Link: otx.alienvault.com/pulse/67d84
Pulse Author: cryptocti
Created: 2025-03-17 15:53:33

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

'LAPD knew protests were coming: 2 days earlier, the dept received👉advanced warning 👈on #Dataminr, a socialmedia #surveillance firm ...and👉“official partner” of X👈.

....LosAngeles #ACAB Department emails obtained via public records show city police used Dataminr to track Gaza-related demonstrations and other constitutionally protected #freespeech.'

"#LAPD Surveilled #Gaza #Protests Using #SocialMedia Tool"

theintercept.com/2025/03/17/la #CyberSecurity #DomesticSpying #CyberStalking @palestine

The Intercept · LAPD Surveilled Gaza Protests Using This Social Media ToolBy Sam Biddle