fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

8.8K
active users

#ITSecurity

30 posts20 participants0 posts today

‼️ Mindestens 10 Millionen Android-Geräte weltweit sind laut #FBI von der #Malware #BadBox2.0 betroffen.

Die #Schadsoftware ist oft bereits beim Kauf in günstigen, meist aus #China stammenden #SmartDevices wie #Streamingboxen oder digitalen #Bilderrahmen vorinstalliert.

Sie ermöglicht kriminelle Aktivitäten wie #Klickbetrug oder #Botnet-Steuerung. Die #FBI empfiehlt, verdächtige Geräte sofort vom Internet zu trennen.

forbes.com/sites/daveywinder/2

ForbesFBI Warning To 10 Million Android Users — Disconnect Your Devices NowCheck to see if your Android device is at risk from this large-scale attack — here’s how.

Bei der US-Tochter von #Allianz wurden durch einen #Cyberangriff Mitte Juli 2025 personenbezogene Daten von Kunden, Beratern und Mitarbeitenden kompromittiert.

Betroffen sein könnten über eine Million Versicherte. Der Zugriff erfolgte über ein Drittanbietersystem mittels #SocialEngineering.

Die Allianz informierte das #FBI und will Betroffene ab dem 1. August benachrichtigen.

golem.de/news/lebensversicheru

Golem.de · Lebensversicherung: Allianz Life - Hacker stehlen Daten der meisten Kunden - Golem.deBy Andreas Donath

DATE: July 25, 2025 at 06:09PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Patients Still Struggle With Full Access to Health Info t.co/ZF07u47fHq

Here are any URLs found in the article text:

t.co/ZF07u47fHq

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: July 25, 2025 at 06:01PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Patients Still Struggle With Full Access to Their #Health Info: Why? t.co/ZF07u47NwY
#HIPAA #CuresAct #HITECH

Here are any URLs found in the article text:

t.co/ZF07u47NwY

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: July 25, 2025 at 05:18PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Swiss-Based #Healthcare Network #AMEOS Responding to Cyberattack t.co/pViSe2Adjy

Here are any URLs found in the article text:

t.co/pViSe2Adjy

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: July 25, 2025 at 08:45AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Whatever happened to #ransomware group #Pysa, which attacked hundreds of #healthcare and other entities just a couple years ago? t.co/qVZhwIlloX

Here are any URLs found in the article text:

t.co/qVZhwIlloX

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

🔐 New on my blog: Why I use OpenPGP and how you can too

In an era where our most personal conversations travel through countless servers, encryption has never been more crucial. In my latest article, I explain why OpenPGP is my go-to tool for secure communication.

✨ What you'll find:

- Clear explanation of OpenPGP fundamentals
- Interactive demo to try it yourself
- Practical setup guides for all platforms
- Real-world insights from IT practice

OpenPGP is more than just encryption - it gives you back control over your digital privacy. No dependency on companies that might change their policies.

Read more: blog.klein.ruhr/why-i-use-open

Matthias Klein · Why I Use OpenPGP and How You Can Too
More from Matthias Klein 🇪🇺|🇩🇪

🚨 Neue Folge von „Die Sicherheits_lücke“ @DieSicherheits_luecke Drohnen & Cybersicherheit – unterschätzte Risiken?

Wir sprechen über rechtliche Grauzonen, private Drohnenflüge, staatliche Akteure – und warum unbemannte Fluggeräte auch ein IT-Sicherheitsproblem sind.

🎧 Jetzt reinhören: sicherheitsluecke.fm

Die Sicherheits_lückeDie Sicherheits_lückeWas macht unsere digitale Welt sicher – und wo bleiben wir verwundbar? Der Podcast Die Sicherheits_lücke hilft dir, Cybersecurity zu verstehen. Prof. Dr. Volker Skwarek (HAW Hamburg) spricht gemeinsam mit Monina Schwarz (LSI Bayern) und Prof. Dr. Ingo Timm (DFKI & Uni Trier) über aktuelle Risiken, technologische Trends und gesellschaftliche Herausforderungen. Du bekommst praxisnahe Einblicke und verständliche Erklärungen – ergänzt durch eine klare Einordnung von Fakten und Meinungen. Der Podcast macht IT-Sicherheit greifbar und verbindet fundierte Inhalte mit unterhaltsamen Gesprächen. Ob du Entscheidungsträger:in, IT-interessiert oder Einsteiger:in bist – die Sicherheitslücke gibt dir die Möglichkeit, digitale Risiken besser einzuschätzen und kluge Entscheidungen zu treffen. Feedback oder Kritik? Wünsche? Schreib uns: post@sicherheitsluecke.fm Die Sicherheits_lücke im Netz: www.sicherheitsluecke.fm Die Sicherheits_lücke ist ein Podcast der Hamburg Open Online University (HOOU) – https://portal.hoou.de Ingo Timm beim DFKI: https://www.dfki.de/web/ueber-uns/mitarbeiter/person/inti01 Volker Skwarek an der HAW Hamburg: https://www.haw-hamburg.de/hochschule/life-sciences/forschung/ftz-cybersec/unser-team/ Produktion und Musik: Christian Friedrich – https://christianfriedrich.org Design: Anne Vogt – https://von-vogt.de Der Podcast ist, soweit nicht anders vermerkt, lizenziert unter CC BY-SA 4.0: https://creativecommons.org/licenses/by-sa/4.0/deed.de

Systemadministratoren sorgen im Verborgenen für Stabilität, Schutz und Reaktionsfähigkeit.
Am heutigen #SysAdminDay erinnern wir daran. Unsere Forschungsprogramme können sie unterstützen. Die @Cyberagentur finanziert Werkzeuge, die Admins helfen, Systeme vorausschauend abzusichern. Forschung für eine sichere digitale Infrastruktur.
Mehr zum Aktionstag: t1p.de/3zdp0
#Systemadministration #ITSecurity #Cyberagentur #Cyberresilienz #DigitaleSouveraenitaet #ForschungFürDieSicherheit

DATE: July 24, 2025 at 05:15PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

@HHSOCR Fines #Surgery Practice $250K in #Ransomware Breach t.co/IznsqqwPdJ #HIPAA #NewYork #Syracuse

Here are any URLs found in the article text:

t.co/IznsqqwPdJ

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

Federal Cybersecurity Cuts Increase the Risks for Your Organization

A sweeping executive order just wiped out key federal cybersecurity mandates—including SBOMs, encryption standards, and phishing-resistant MFA requirements. If your business buys software, handles sensitive data, or supports critical infrastructure, this rollback directly impacts you.

Find out:

▪ Which protections were cut
▪ Why the risk has shifted to your organization
▪ What security leaders must do now to fill the gap

Read our blog: lmgsecurity.com/federal-cybers

Federal cybersecurity cuts image
LMG SecurityFederal Cybersecurity Cuts Raise Risks—Here’s How to Respond | LMG SecurityIn June 2025, an executive order sent shockwaves through the cybersecurity world, gutting key federal cybersecurity protections. We'll share what you need to do to protect your organization.

DATE: July 24, 2025 at 09:08AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Why are U.S. federal authorities warning #criticalinfrastructure sector entities, including #healthcare providers, about the #Interlock #ransomware group now? t.co/K4d9WwXHTp

Here are any URLs found in the article text:

t.co/K4d9WwXHTp

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

Zeroize: The Tiny and Memory-Safe Rust Crate - Sensitive Data in Memory: A Hidden Threat

In a secure environment, one of the most overlooked threats is the presence of sensitive data in memory, such as passwords, tokens, cryptographic keys, or card numbers. Even when using Rust, where we emphasize ownership and thread safety, there's another crucial question to consider: What remains in the heap or stack after we no longer need it?

🛡️ dev.to/riccio8/zeroize-the-tin

DEV CommunityZeroize: The Tiny and Memory-Safe Rust CrateSensitive Data in Memory: A Hidden Threat In a secure environment, one of the most...

8080 - a short story of 4-digit number and EU regulations in pratice 🇪🇺

In Poland, the reporting mechanism via the short number 8080 enables rapid, citizen‑driven identification of smishing and cyber‑fraud attempts. Reporting a malicious message involves simply forwarding the suspicious SMS to 8080, which delivers it directly to CERT Polska for analysis [1].

Upon receipt and confirmation of malicious content, each new SMS pattern is published by CERT and within ~5 minutes, automatically fetched by all cooperating telecom providers, which then block any incoming messages matching it.

The entire system operates under the Act of 5 July 2018 on the National Cybersecurity System [2], which is the Polish implementation of the EU's NIS Directive [3] and tasks CERT with maintaining a registry of malicious SMS patterns and coordinating with telecom operators.

In 2024 alone, 746 new patterns were produced, blocking 1 475 366 fraudulent SMS before they reached users. Citizens filed 354 566 reports, of which 140 659 were classified as malicious [4].

It's difficult for me to assess whether these figures are high or low. The system may still lack sufficient patterns, and the number of blocked messages might be too small relative to the true scale of SMS communication and smishing threats... but hey, it's still better than nothing, isn't it?

[1] cert.pl/baza-wiedzy/falszywe-s
[2] isap.sejm.gov.pl/isap.nsf/DocD
[3] eur-lex.europa.eu/eli/dir/2016
[4] cert.pl/uploads/docs/Raport_CP

Gute, saubere #ITSEC #ITSecurity in heutigen Zeiten: Remote-Überwachung in der #Cloud, Anlagensteuerung AUSSCHLIESSLICH lokal. Vollständige Ebenentrennung, sowas lob ich mir! 👍 (gesehen bei einem lokalen Wasserversorger)

(Natürlich lassen sich die Anlagen auch lokal überwachen, wenn auch mit etwas weniger Komfort.)

DATE: July 23, 2025 at 05:08PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

@FBI, @CISAgov, @HHSGov Warn #Healthcare, Other Sectors of #Interlock #Cyberattack Threats t.co/uBjPNfmPgY

Here are any URLs found in the article text:

t.co/uBjPNfmPgY

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: July 23, 2025 at 10:47AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Should the U.S. Do the Same?
U.K. Government Set to Impose #Ransomware Payment Ban t.co/uOcfXEE0Zo

Here are any URLs found in the article text:

t.co/uOcfXEE0Zo

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: July 23, 2025 at 08:36AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

What would push a medical practice to permanently shut down their business following a #cyberattack?
t.co/z9l8uE3iB4

Here are any URLs found in the article text:

t.co/z9l8uE3iB4

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering