
Updated: Because vulnerability management has nothing to do with national security, right?

A community for discussion about cybersecurity, hacking, cybersecurity news, exploits, bounties etc.
Rules :
Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient
Updated: Because vulnerability management has nothing to do with national security, right?
Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!
Cryptography DEEPEST LORE
(AKA Marutukku) Backup of Assange's deniable cryptosystem. - sporkexec/rubberhose
Long live Julian Assange.
Microsoft starts developing tools to prevent another global IT outage
Microsoft is creating new capabilities that will let security vendors operate outside of the root of Windows operating systems.
Infection corrals devices running AOSP-based firmware into a botnet.
Researchers still don’t know the cause of a recently discovered malware infection affecting almost 1.3 million streaming devices running an open source version of Android in almost 200 countries.
DroidFS v2.2.0
Encrypted overlay filesystems implementation for Android. Also available on GitHub: https://github.com/hardcore-sushi/DroidFS
cross-posted from: https://lemmy.ml/post/18512730
DroidFS is an Android application providing rootless support for gocryptfs and CryFS encrypted file systems. It features an encrypted camera, biometric unlocking, integrated secure file viewers and allows decrypted files to be exposed to other applications. It is 100% FLOSS and developed voluntarily.
This new version...
- aims to improve the user interface
- implements a foreground service to keep volumes open in the background
- allows tweaking the file export method used for sharing content with other apps
- adds new Turkish, Simplified Chinese and Hebrew translations
- and of course, fixes a few bugs
Official APKs are available for download now. It should land on F-Droid very soon, with a new per-ABI APKs split which will reduce quite a bit the download as well as the installed app size.
Feel free to give some feedback, open bug reports, ask f
Keys were labeled “DO NOT TRUST.” Nearly 500 device models use them anyway.
Doing language agnostic automated unit test generation with LLMs and contextually aware mutation testing to remove code vulnerabilities
Open Source, Language Agnostic Mutation Testing. Contribute to codeintegrity-ai/mutahunter development by creating an account on GitHub.
Hey Community, I figured that I could strengthen existing automated unit test generation quality by integrating mutation testing results as a metric to determine the quality of my unit tests. Figured everyone should be unit testing their code now especially after the recent Crowdstrike fiasco.
Check it out here https://github.com/codeintegrity-ai/mutahunter
Please star if you like it :)
Microsoft IT outage latest: Airports, businesses and banks including Sky News experiencing issues worldwide
A software update has resulted in worldwide IT chaos, causing cancelled flights, healthcare disruption and potential payroll problems. The firm responsible has apologised, but an industry expert warns it could take weeks to fix "blue screens of death" and endless loops.
Caused by security firm CrowdStrike that issued an update.
CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems
Regression in signal handler.
This vulnerability is exploitable remotely on glibc-based Linux systems, where syslog() itself calls async-signal-unsafe functions (for example, malloc() and free()): an unauthenticated remote code execution as root, because it affects sshd's privileged code, which is not sandboxed and runs with full privileges.
Cloudflare's recent blog regarding polyfill shows that Cloudflare never authorized Polyfill to use their name in their product
polyfill.io, a popular JavaScript library service, can no longer be trusted and should be removed from websites
Contrary to what is stated on the polyfill.io website, Cloudflare has never recommended the polyfill.io service or authorized their use of Cloudflare’s name on their website. We have asked them to remove the false statement, and they have, so far, ignored our requests. This is yet another warning sign that they cannot be trusted.
The restriction of sales will begin next month
If it ain't 'murican we ban 'em!
Guess all foreign cars should be next, what with all the telemetry and all...
A 22-year-old man from the United Kingdom arrested this week in Spain is allegedly the ringleader of Scattered Spider, a cybercrime group suspected of hacking into Twilio, LastPass, DoorDash, Mailchimp, and nearly 130 other organizations over the past two years.
how much would/should/could it cost to get my app security assessed?
im working on a decentralized chat app. i open sourced it to get feedback on the implementation.
for a project like this, its important for it to be open source in order to gain user confidence in the security. but i find that the project is too complicated for pro-bono security assessment work (which is understandable).
fiverr probably isnt the best place to find reputable support, but i wanted to see the prices. it seems to range from 50 to 5k+
i wont be getting the support any time soon, but id like guage an estimate. i havent done something like this before so any/all advice is appriciated.
i created a threat-model which may help: https://positive-intentions.com/docs/research/threat-model/
to explain my app in more detail: https://medium.com/@positive.intentions.com/introducing-decentralized-chat-377c4aa37978
github repo: https://github.com/positive-intentions/chat
This is a lightly edited transcript of my presentation today at the ACCSS/NCSC/Surf seminar ‘Cyber Security and Society’. I want to thank the organizers for inviting me to their conference & giving me a great opportunity to talk about something I worry about a lot. Here are the original slides with ...
KrebsOnSecurity has been in intermittent contact with LockBitSupp for several months over the course of reporting on different LockBit victims. Reached at the same ToX instant messenger identity that the ransomware group leader has promoted on Russian cybercrime forums, LockBitSupp claimed the authorities named the wrong guy.
LockBitSupp, who now has a $10 million bounty for his arrest from the U.S. Department of State, has been known to be flexible with the truth.
Like it or not, email is a critical part of our digital lives. It’s how we sign up for accounts, get notifications, and communicate with ...
A few years ago, minimalism was all the rage. Marie Kondo was on every TV, The Minimalists were in everyone's podcast feed, and I found m...