fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

#security

753 posts448 participants0 posts today
Flipboard News Desk<p>It’s normally a routine annual meeting about threats to the United States and global security. But today’s U.S. Senate Intelligence Committee hearing came a day after Trump administration officials were revealed to have mistakenly included a journalist on chat group discussing war plans. <span class="h-card" translate="no"><a href="https://flipboard.com/@politico" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>politico</span></a></span> breaks down the heated questioning.<br><a href="https://flip.it/77hGxm" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">flip.it/77hGxm</span><span class="invisible"></span></a><br><a href="https://flipboard.social/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://flipboard.social/tags/Senate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Senate</span></a> <a href="https://flipboard.social/tags/Intelligence" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Intelligence</span></a> <a href="https://flipboard.social/tags/Gabbard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Gabbard</span></a> <a href="https://flipboard.social/tags/CIA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CIA</span></a> <a href="https://flipboard.social/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a></p>
PrivacyDigest<p><a href="https://mas.to/tags/Ticketmaster" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ticketmaster</span></a> May Have Violated <a href="https://mas.to/tags/ConsumerProtection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ConsumerProtection</span></a> Laws - Slashdot <br><a href="https://mas.to/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://mas.to/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a></p><p><a href="https://slashdot.org/story/25/03/25/1556254/ticketmaster-may-have-violated-consumer-protection-laws?utm_source=rss1.0mainlinkanon&amp;utm_medium=feed" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">slashdot.org/story/25/03/25/15</span><span class="invisible">56254/ticketmaster-may-have-violated-consumer-protection-laws?utm_source=rss1.0mainlinkanon&amp;utm_medium=feed</span></a></p>
PrivacyDigest<p><a href="https://mas.to/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> head defends messaging app's <a href="https://mas.to/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> after US war plan <a href="https://mas.to/tags/leak" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>leak</span></a> <br><a href="https://mas.to/tags/signalgate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>signalgate</span></a></p><p><a href="https://www.yahoo.com/news/signal-head-defends-messaging-apps-155649305.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">yahoo.com/news/signal-head-def</span><span class="invisible">ends-messaging-apps-155649305.html</span></a></p>
CBC Canada<p>Carney says we must 'look out for ourselves' in wake of U.S. intelligence leak on Yemen strike<br>Liberal Leader Mark Carney says the leak by top U.S. national security officials of plans for&nbsp;military strikes in Yemen&nbsp;— and the shifting security priorities of the Trump administration — mean "we have to look out&nbsp;for ourselves."<br><a href="https://mastodon.hongkongers.net/tags/politics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>politics</span></a> <a href="https://mastodon.hongkongers.net/tags/military" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>military</span></a> <a href="https://mastodon.hongkongers.net/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mastodon.hongkongers.net/tags/Yemen" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Yemen</span></a> <a href="https://mastodon.hongkongers.net/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <br><a href="https://www.cbc.ca/news/politics/carney-intelligence-yemen-strike-1.7492736?cmp=rss" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">cbc.ca/news/politics/carney-in</span><span class="invisible">telligence-yemen-strike-1.7492736?cmp=rss</span></a></p>
PrivacyDigest<p>What Is <a href="https://mas.to/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> , the App Involved in a War Plans <a href="https://mas.to/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://mas.to/tags/Breach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Breach</span></a> ? </p><p>The app, which was introduced in 2014 and has hundreds of millions of users, is widely viewed as the safest messaging tool because of its <a href="https://mas.to/tags/encryption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>encryption</span></a> technology.</p><p><a href="https://www.nytimes.com/2025/03/25/technology/signal-app-security-leak.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">nytimes.com/2025/03/25/technol</span><span class="invisible">ogy/signal-app-security-leak.html</span></a></p>
PrivacyDigest<p><a href="https://mas.to/tags/Privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Privacy</span></a> Self-Defense Workshop and <a href="https://mas.to/tags/Immigration" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Immigration</span></a> Resource Fair</p><p>April 12, 2025 - 10:00am to 4:00pm PDT<br>Oakland, CA<br>Secure Justice (not EFF) will host this event. EFF's Bill Budington will be speaking.</p><p>Bill Budington, Senior Staff Technologist at <span class="h-card" translate="no"><a href="https://mastodon.social/@eff" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>eff</span></a></span> , will be speaking at the privacy workshops covering smartphone, laptop, online, and vehicle data <a href="https://mas.to/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> and easy-to-understand technical privacy-protecting product recommendations and solutions. </p><p><a href="https://www.eff.org/event/privacy-self-defense-workshop-and-immigration-resource-fair" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">eff.org/event/privacy-self-def</span><span class="invisible">ense-workshop-and-immigration-resource-fair</span></a></p>
ThinkingSapien<p>I knew they didn't really care about her e-mails!</p><p><a href="https://mstdn.social/tags/USA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>USA</span></a> <a href="https://mstdn.social/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a></p>
Pyrzout :vm:<p>Satellite Navigation Systems Facing Rising Jamming and Spoofing Attacks <a href="https://hackread.com/satellite-navigation-systems-jamming-spoofing-attacks/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">hackread.com/satellite-navigat</span><span class="invisible">ion-systems-jamming-spoofing-attacks/</span></a> <a href="https://social.skynetcloud.site/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://social.skynetcloud.site/tags/Vulnerability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vulnerability</span></a> <a href="https://social.skynetcloud.site/tags/CyberAttacks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberAttacks</span></a> <a href="https://social.skynetcloud.site/tags/CyberAttack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberAttack</span></a> <a href="https://social.skynetcloud.site/tags/Technology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Technology</span></a> <a href="https://social.skynetcloud.site/tags/Satellite" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Satellite</span></a> <a href="https://social.skynetcloud.site/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://social.skynetcloud.site/tags/Maritime" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Maritime</span></a> <a href="https://social.skynetcloud.site/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://social.skynetcloud.site/tags/Spoofing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Spoofing</span></a> <a href="https://social.skynetcloud.site/tags/Jamming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Jamming</span></a> <a href="https://social.skynetcloud.site/tags/GNSS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GNSS</span></a> <a href="https://social.skynetcloud.site/tags/GPS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GPS</span></a></p>
Pyrzout :vm:<p>Hackers Are Using Microsoft’s .NET MAUI to Spread Android Malware <a href="https://hackread.com/net-maui-exploited-in-advanced-malware-campaigns-mcafee-labs/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">hackread.com/net-maui-exploite</span><span class="invisible">d-in-advanced-malware-campaigns-mcafee-labs/</span></a> <a href="https://social.skynetcloud.site/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://social.skynetcloud.site/tags/CyberAttack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberAttack</span></a> <a href="https://social.skynetcloud.site/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://social.skynetcloud.site/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://social.skynetcloud.site/tags/Android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a> <a href="https://social.skynetcloud.site/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://social.skynetcloud.site/tags/mcafee" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mcafee</span></a> <a href="https://social.skynetcloud.site/tags/TROJAN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TROJAN</span></a></p>
Pyrzout :vm:<p>Medusa Ransomware Disables Anti-Malware Tools with Stolen Certificates <a href="https://hackread.com/medusa-ransomware-anti-malware-tools-stolen-certificates/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">hackread.com/medusa-ransomware</span><span class="invisible">-anti-malware-tools-stolen-certificates/</span></a> <a href="https://social.skynetcloud.site/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://social.skynetcloud.site/tags/CyberAttacks" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberAttacks</span></a> <a href="https://social.skynetcloud.site/tags/Certificate" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Certificate</span></a> <a href="https://social.skynetcloud.site/tags/CyberAttack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberAttack</span></a> <a href="https://social.skynetcloud.site/tags/Ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ransomware</span></a> <a href="https://social.skynetcloud.site/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://social.skynetcloud.site/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://social.skynetcloud.site/tags/Medusa" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Medusa</span></a> <a href="https://social.skynetcloud.site/tags/China" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>China</span></a></p>
Pyrzout :vm:<p>Staying Safe with In-Game Skins: How to Avoid Scams and Malware <a href="https://hackread.com/staying-safe-in-game-skins-how-to-avoid-scams-malware/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">hackread.com/staying-safe-in-g</span><span class="invisible">ame-skins-how-to-avoid-scams-malware/</span></a> <a href="https://social.skynetcloud.site/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://social.skynetcloud.site/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://social.skynetcloud.site/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://social.skynetcloud.site/tags/Malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Malware</span></a> <a href="https://social.skynetcloud.site/tags/Gaming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Gaming</span></a> <a href="https://social.skynetcloud.site/tags/gaming" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gaming</span></a> <a href="https://social.skynetcloud.site/tags/Fraud" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fraud</span></a> <a href="https://social.skynetcloud.site/tags/Scam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Scam</span></a></p>
Alkaris :verified_trans: :verified:<p>When you go to Steam and finding a game to play, you expect the games uploaded to Valve's servers to be clean, and at the very least be audited before they can be published to the Steam Store. Yet another info stealer somehow makes its way on to Steam yet again.</p><p>And for those that don't know, to upload a game to Steam you need to pay a $100 fee as a developer, but you get that back if your game makes a number of sales past a certain threshold. Which would seem pretty dumb for people uploading malware games to Steam, because you'll never get that back, and you would be suspended from Valve's Developer Program as a result, and most likely have your account banned also.</p><p>Does make me think Valve should be putting in extra security audits for new games uploaded to their servers to check for malware bundled in a game. But the big problem being AV's ignoring large files for malware on purpose. I really think that sort of behavior scanning should be changed and scan large files anyway. Yes it would take a while to scan the file, but in order to protect people from stuff like this, it's a necessary step given how complex new info stealers are becoming, and this shouldn't be on your worry list when you visit the Steam Store.</p><p><a href="https://www.youtube.com/watch?v=O9wcu6E2L_Y" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">youtube.com/watch?v=O9wcu6E2L_Y</span><span class="invisible"></span></a></p><p><a href="https://meow.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://meow.social/tags/steam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>steam</span></a> <a href="https://meow.social/tags/valve" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>valve</span></a></p>
Tim (Wadhwa-)Brown :donor:<p>Interesting Git repos of the week:</p><p>Detection:</p><p>* <a href="https://github.com/tstromberg/ucd" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/tstromberg/ucd</span><span class="invisible"></span></a> - hunt for unauthorised changes<br>* <a href="https://github.com/mnrkbys/fjta" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/mnrkbys/fjta</span><span class="invisible"></span></a> - check for anomalies in your FS timeline</p><p>Exploitation:</p><p>* <a href="https://github.com/hardenedlinux/tzram-audit" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/hardenedlinux/tzram</span><span class="invisible">-audit</span></a> - audit your TrustZone implementatation</p><p>Nerd:</p><p>* <a href="https://gist.github.com/halcy/b4f455ef05c4c36906107e9367b8dd63" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">gist.github.com/halcy/b4f455ef</span><span class="invisible">05c4c36906107e9367b8dd63</span></a> the Fediverse in FUSE</p><p><a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a>, <a href="https://infosec.exchange/tags/research" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>research</span></a>, <a href="https://infosec.exchange/tags/code" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>code</span></a></p>
Helma<p>Morgen. <a href="https://mastodon.social/tags/OZON" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OZON</span></a> in onderwijsland. Cybercrisisoefening.Veel plezier, succes en wijsheid allemaal, ik heb er zin in! <a href="https://mastodon.social/tags/MBO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MBO</span></a> <a href="https://mastodon.social/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a> <a href="https://mastodon.social/tags/Privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Privacy</span></a></p>
Lobsters<p>Mobile Cyberattacks Conducted by US Intelligence Agencies <a href="https://lobste.rs/s/gxuxuo" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">lobste.rs/s/gxuxuo</span><span class="invisible"></span></a> <a href="https://mastodon.social/tags/pdf" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pdf</span></a> <a href="https://mastodon.social/tags/android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>android</span></a> <a href="https://mastodon.social/tags/ios" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ios</span></a> <a href="https://mastodon.social/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a><br><a href="http://www.news.cn/world/20250325/02ba448744ac4b75a81df613a88b4d26/2025032522b55fd15b244a5fac54e424c62be9b7_1616350dfed1c44ba786a82d574c86c30f.pdf" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">http://www.</span><span class="ellipsis">news.cn/world/20250325/02ba448</span><span class="invisible">744ac4b75a81df613a88b4d26/2025032522b55fd15b244a5fac54e424c62be9b7_1616350dfed1c44ba786a82d574c86c30f.pdf</span></a></p>
The New Oil<p><a href="https://mastodon.thenewoil.org/tags/Trump" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trump</span></a> administration accidentally texted secret bombing plans to a reporter</p><p><a href="https://arstechnica.com/tech-policy/2025/03/trump-administration-accidentally-texted-secret-bombing-plans-to-a-reporter/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">arstechnica.com/tech-policy/20</span><span class="invisible">25/03/trump-administration-accidentally-texted-secret-bombing-plans-to-a-reporter/</span></a></p><p><a href="https://mastodon.thenewoil.org/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://mastodon.thenewoil.org/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://mastodon.thenewoil.org/tags/OPSEC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OPSEC</span></a> <a href="https://mastodon.thenewoil.org/tags/politics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>politics</span></a> <a href="https://mastodon.thenewoil.org/tags/Yemen" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Yemen</span></a> <a href="https://mastodon.thenewoil.org/tags/Signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Signal</span></a> <a href="https://mastodon.thenewoil.org/tags/journalism" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>journalism</span></a></p>
scy<p>Oh, great. <a href="https://chaos.social/tags/Pixelfed" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Pixelfed</span></a> had a broken implementation of "follower-only" posts, _and_ fucked up the disclosure&nbsp;/ bugfix release process.</p><p><a href="https://fokus.cool/2025/03/25/pixelfed-vulnerability.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">fokus.cool/2025/03/25/pixelfed</span><span class="invisible">-vulnerability.html</span></a></p><p>Summary of the bug: If you have a protected account (on Pixelfed, Mastodon, GTS, whatever) and a Pixelfed user followed you and got approved by you, _all_ users on that instance were now able to see your followers-only posts, not just the one you approved.</p><p><a href="https://chaos.social/tags/Fediverse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fediverse</span></a> <a href="https://chaos.social/tags/ActivityPub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ActivityPub</span></a> <a href="https://chaos.social/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://chaos.social/tags/fail" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fail</span></a></p>
Simple Nomad<p>I’m not saying Signal is bad, in fact it is my messenger app of choice. But it has not been evaluated and approved for classified communications. That’s bad. They all should have known better. The fact that someone had invited a reporter - someone without security clearance - into a discussion that clearly involved highly classified material is an insane <a href="https://rigor-mortis.nmrc.org/tags/opsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opsec</span></a> failure.</p><p>Despite it being non-approved, I still recommend <a href="https://rigor-mortis.nmrc.org/tags/signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>signal</span></a> and continue to keep using it.</p><p><a href="https://rigor-mortis.nmrc.org/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://rigor-mortis.nmrc.org/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a></p>
Alex Kidman<p>I’ll be talking Scams with Nic Healey on ABC Victoria Statewide Mornings just after 9:30am this morning — tune in!<br><a href="https://aus.social/tags/Scams" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Scams</span></a> <a href="https://aus.social/tags/Australia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Australia</span></a> <a href="https://aus.social/tags/Security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Security</span></a><br><a href="https://www.abc.net.au/listen/programs/vic-statewide-mornings" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">abc.net.au/listen/programs/vic</span><span class="invisible">-statewide-mornings</span></a></p>
nzie0z<p>The Trump Administration: wE'rE gOiNg To CrAcK dOwN hArD oN lEaKeRs!!1!</p><p>Also the Trump Administration: We invite journalists to unauthorized chat rooms where we share classified data we keep on our private cell phones.</p><p><a href="https://infosec.exchange/tags/uspol" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>uspol</span></a> <a href="https://infosec.exchange/tags/signal" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>signal</span></a> <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://infosec.exchange/tags/morons" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>morons</span></a></p>