ASN: AS4685
Location: Yokohama, JP
Added: 2025-07-19T19:28
ASN: AS4685
Location: Yokohama, JP
Added: 2025-07-19T19:28
#Google introduces OSS Rebuild — OSS Rebuild is a new project aimed at enhancing trust in open source software by creating reproducible builds of packages to prevent supply chain attacks. It provides tools and automation for security teams to verify package integrity without burdening the original developers. This initiative seeks to improve transparency and security in open source ecosystems, starting with popular package registries like PyPI, npm, and Crates.io.
https://security.googleblog.com/2025/07/introducing-oss-rebuild-open-source.html
ASN: AS10013
Location: Sapporo, JP
Added: 2025-07-19T18:17
Security Week: Vulnerabilities Expose Helmholz Industrial Routers to Hacking https://www.securityweek.com/vulnerabilities-expose-helmholz-industrial-routers-to-hacking/ @SecurityWeek #cybersecurity #infosec
Lately has become my favorite emoji, not just because of the weather.
"Microsoft knew of SharePoint server exploit but failed to effectively patch it"
"Microsoft subsequently said in a July 8 security update that it had identified, opens new tab the bug, listed it as a critical vulnerability, and released patches to fix it.
Around 10 days later, however, cybersecurity firms started to notice an influx of malicious online activity targeting the same software the bug sought to exploit: SharePoint servers".
New sophisticated phishing technique “PoisonSeed” tricks users into scanning malicious QR codes, bypassing FIDO key MFA protections via cross-device sign-in!
Users must stay vigilant & organizations should strengthen monitoring. Full details: https://cyberinsider.com/new-poisonseed-attack-bypasses-fido-key-security-using-qr-codes/ #CyberSecurity #MFA #FIDO #PhishingAlert #InfoSec #newz
Is this the single good thing coming out of the current US Administration?
PeopleCheck reports data breach caused by ransomware attack
PeopleCheck, an Australian background screening provider, suffered a data breach via compromised login credentials that was claimed by the Everest ransomware group. The hackers claim to have stolen 4.3 GB of SQL data including client profiles, payment details, and sensitive personal information of individuals processed between June 2024-June 2025. PeopleCheck is offering 24 months of complimentary identity monitoring services.
****
#cybersecurity #infosec #incident #ransomware
https://beyondmachines.net/event_details/peoplecheck-reports-data-breach-caused-by-ransomware-attack-9-h-7-j-g/gD2P6Ple2L
ASN: AS4713
Location: Ōtsu, JP
Added: 2025-07-19T18:36
Oh, also, the email #HackerOne sent out this morning contradicts itself. In the subject it says people have to enable 2FA "to Avoid Account Lockout." Then in the body it says, "Without 2FA set up, you won’t be able to access your account after July 29."
But then elsewhere in the body it says, "If you don’t make this change by July 29, 2025, you’ll be prompted to complete the setup before you are able to access the platform and submit reports."
That's not "lockout," idiots.
#infosec
All the positive #userExperience points #HackerOne earned for how they were rolling out mandatory #2FA were just erased by them sending out reminder email to all of their users about configuring 2FA without filtering out the users who had already done it.
That's some lazy, user-hostile bullshit, is what that is.
When you know which users have already followed your instructions, you don't need to waste their time making them go back and check. #smdh
#infosec #MFA #UX
ASN: AS2518
Location: Tokyo, JP
Added: 2025-07-19T19:27
This article @Forbes has now been updated with an interesting counterpoint from @Paul__Walsh.
ASN: AS2497
Location: Fukuoka, JP
Added: 2025-07-19T21:14
ASN: AS1136
Location: Winschoten, NL
Added: 2025-07-19T20:36
In this heartfelt and wide-ranging conversation on the Chasing Entropy Podcast, I get to sit down with my friend, legendary storyteller, and community-builder Jack Daniel
Link: https://www.buzzsprout.com/2497520/episodes/17535159
#AI #Cybersecurity #Infosec #AgenticAI #JackDaniel @1password
Gadi Evron and Knostic are doing another Prompt Pit event:
"...if you made AI useful and you're willing to show your work, then come join us. We prefer security topics, but anything goes...
We don’t care if it’s reversing, GRC, coding, threat hunting, budget building, or poem writing, let’s show off our prompts (it's okay for them to be broken), learn, and punch miscreants (or at least have fun trying)."
https://docs.google.com/forms/d/e/1FAIpQLSd8QrQ1FyB0OG9qX943RT7G0PZ6m-PPYwNlkUggTX-DCmbVFg/viewform
@aria : nice to meet you!
Not meaning to be blunt, but *please* prepend links with https:// instead of http://.
Let me know if you'd like me to explain why!