gyptazy.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
A #Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
source: wired.com/story/a-security-pro…
Given the danger of those breaches—both in terms of the exposure of sensitive data and the ongoing theft of cryptocurrency enriching the North Korean regime—the real concern shouldn’t necessarily be the companies Stykas has named but rather the ones he hasn’t. Those companies include hundreds that never responded to his warnings, he says, as well as more added to the list every day.
And this, folks, is called security theater. Companies know that cyber threats are real.
They know that #cybercriminals attack them every day. But many companies respond with checklists. Someone has to tick the boxes. Again and again. Often, these people have little cybersecurity training. They may not fully understand what they are checking.
The checklist may be outdated. And sometimes, nobody in the company even knows why the checklist exists. It looks like security. But looking secure is not the same as being secure. This is where things can get almost absurd.
Companies may spend huge amounts of money on expensive security software. Sometimes, the software is not even very good. Sometimes, it creates more complexity and more possible ways for attackers to get in. But that is not always the real goal. The real goal can be to say later: “We did everything we could.” It is like putting a security camera on the front door, never checking whether it works, and then pointing at it after the robbery. The company wants to prove that it did not act carelessly. Real security becomes secondary. In cybersecurity, this is the difference between security and security theater. And even the biggest idiot should notice the problem when there is nobody left in the company to deal with the warnings. That is exactly what can happen. The security system sends alerts. Nobody reads them. Nobody investigates them. Nobody has the time, the skills, or sometimes even the job to deal with them. So the alerts are simply ignored.
And here is the really strange part. The internet still works. It works partly because, for cybercriminals, stealing from badly protected companies is often more profitable than destroying the whole system. It is like a city where every door is unlocked. Criminals do not need to burn down the city. They can simply walk inside and take what they want.
That may be the biggest lesson of all: Cybersecurity is not about having the right boxes checked. It is about knowing what can go wrong, finding the real risks, and making sure that someone is actually there when the alarm goes off.
#cybersecurity #security #software #news #northkorea #crypto #cyberattack #fail #internet #economy #warning #danger #securitytheater #hack #hacker #crime #network #cyberspace #knowledge #knowhow #cybercrime #cyberattack #cyber
Location: Matrix
GrapheneOS version 2026080500 released:
https://grapheneos.org/releases#2026080500
See the linked release notes for a summary of the improvements over the previous release.
Forum discussion thread:
https://discuss.grapheneos.org/d/40968-grapheneos-version-2026080500-released
Dead Software Walking: The ongoing evolution of relayd(8) and httpd(8) https://undeadly.org/cgi?action=article;sid=20260805083816 #openbsd #relayd #httpd #development #webserver #loadbalancing #security #cryptography #modernsoftware #freesoftware #libresoftware
Wenn KI-Agenten aus der Backdoor-Historie lernen
https://linuxnews.de/wenn-ki-agenten-aus-der-backdoor-historie-lernen/ #ai #ki #security #opensource #linuxnews
Hackers steal over $130M by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $13...
Archive: ia: https://s.faithcollapsing.com/h1rwe
#bitcoin #blockchain #cryptocurrency #cybercrime #hackers #security
https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/
Spannung, Spiel und Spaß u.a. mit Secure und Attested Boot, #TPM2 als Vertrauensanker, #HardenedKernel und #IOMMU, #USBGuard, #Firejail und #Yubikey
Rechtzeitig zur Veranstaltung werde ich eine Anleitung/Doku zum nachlesen und mittippen veröffentlichen.
#froscon2026 #froscon26 #security #hardening #linux @FrOSCon@bonn.social
Call for testing: OpenBSD vmm(4)/vmd(8) fd-ification https://www.undeadly.org/cgi?action=article;sid=20260804054218 #openbsd #vmm #vmd #virtualization #virtualmachines #testing #newcode #development #security #freesoftware #libresoftware
Arch Linux User Repository (AUR) ist erneuten Angriffen ausgesetzt
https://linuxnews.de/arch-linux-user-repository-aur-ist-erneuten-angriffen-ausgesetzt/ #archlibux #aur #security #linux #linuxnews
Researchers say a fundamental flaw in LLMs makes it easy to trick them into doing things they shouldn’t — like telling you how to sabotage an aircraft’s navigation system.
"There’s a real probability that this is going to be a problem that’s fundamentally unsolvable," says one of the paper's coauthors.
"Dozens of young people set out to sea, chasing a vision they'd seen online, now being sent back to Morocco in coffins."
Have migrants been 'weaponised'? By whom?
Enjoying the results: (far)right, Trump, Russia.
How #Ceuta created a political storm - whipped up by #socialmedia.
„Fühle ich mich hier nicht mehr sicher“: Wacken-Besucherin muss Anti-AfD-Patch abreißen
Claude published malicious code to the Internet and attacked 3 real companies
Had the hacks used conventional methods, someone would likely go to prison.
#ai #anthropic #biz-&-it #claude #security
https://arstechnica.com/security/2026/07/likely-illegally-claude-gained-access-to-3-networks-will-anthropic-be-held-to-account/
Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.
"Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet
Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"