gyptazy.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Only tech related content - nothing else!
Admin email
contact@gyptazy.com
Admin account
@gyptazy@gyptazy.com@gyptazy.com

Search results for tag #security

AodeRelay boosted

[?]Script Kiddie » 🌐
@scriptkiddie@anonsys.net

A Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

source: wired.com/story/a-security-pro…

Given the danger of those breaches—both in terms of the exposure of sensitive data and the ongoing theft of cryptocurrency enriching the North Korean regime—the real concern shouldn’t necessarily be the companies Stykas has named but rather the ones he hasn’t. Those companies include hundreds that never responded to his warnings, he says, as well as more added to the list every day.


And this, folks, is called security theater. Companies know that cyber threats are real.
They know that attack them every day. But many companies respond with checklists. Someone has to tick the boxes. Again and again. Often, these people have little cybersecurity training. They may not fully understand what they are checking.
The checklist may be outdated. And sometimes, nobody in the company even knows why the checklist exists. It looks like security. But looking secure is not the same as being secure. This is where things can get almost absurd.

Companies may spend huge amounts of money on expensive security software. Sometimes, the software is not even very good. Sometimes, it creates more complexity and more possible ways for attackers to get in. But that is not always the real goal. The real goal can be to say later: “We did everything we could.” It is like putting a security camera on the front door, never checking whether it works, and then pointing at it after the robbery. The company wants to prove that it did not act carelessly. Real security becomes secondary. In cybersecurity, this is the difference between security and security theater. And even the biggest idiot should notice the problem when there is nobody left in the company to deal with the warnings. That is exactly what can happen. The security system sends alerts. Nobody reads them. Nobody investigates them. Nobody has the time, the skills, or sometimes even the job to deal with them. So the alerts are simply ignored.

And here is the really strange part. The internet still works. It works partly because, for cybercriminals, stealing from badly protected companies is often more profitable than destroying the whole system. It is like a city where every door is unlocked. Criminals do not need to burn down the city. They can simply walk inside and take what they want.

That may be the biggest lesson of all: Cybersecurity is not about having the right boxes checked. It is about knowing what can go wrong, finding the real risks, and making sure that someone is actually there when the alarm goes off.

Location: Matrix

    [?]GrapheneOS » 🌐
    @GrapheneOS@grapheneos.social

    GrapheneOS version 2026080500 released:

    grapheneos.org/releases#202608

    See the linked release notes for a summary of the improvements over the previous release.

    Forum discussion thread:

    discuss.grapheneos.org/d/40968

      AodeRelay boosted

      [?]Peter N. M. Hansteen » 🌐
      @pitrh@mastodon.social

      AodeRelay boosted

      [?]LinuxNews.de » 🌐
      @linuxnews@social.anoxinon.de

      AodeRelay boosted

      [?]LWN.net » 🌐
      @lwn@fedi.lwn.net

      An LLM agent attempts to compromise a project on GitHub

      lwn.net/Articles/1087162/

        AodeRelay boosted

        [?]Steven Saus [he/him] » 🌐
        @StevenSaus@faithcollapsing.com

        Hackers steal over $130M by exploiting bug in offline hardware wallets

        A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $13...

        Archive: ia: s.faithcollapsing.com/h1rwe


        techcrunch.com/2026/08/04/hack

        Hackers steal over 30M by exploiting bug in offline hardware wallets

        Alt...Hackers steal over 30M by exploiting bug in offline hardware wallets

          AodeRelay boosted

          [?]ツ ュ テ フ ァ ン ・ ツ ュ ー マ ツ ハ ー » 🌐
          @cryptomancer@fediverse.cryptomancer.de

          Ich werde dieses Jahr auf der meinen Workshop zum Laptop absichern in einer aktualisierten Version halten:
          Wir bauen uns einen Congress-Laptop: härten für Einsteiger https://programm.froscon.org/froscon2026/talk/9bef50ee-9fb4-469d-85f0-bf5c224276eb/

          Spannung, Spiel und Spaß u.a. mit Secure und Attested Boot, als Vertrauensanker, und , , und

          Rechtzeitig zur Veranstaltung werde ich eine Anleitung/Doku zum nachlesen und mittippen veröffentlichen.

          @FrOSCon@bonn.social

            AodeRelay boosted

            [?]Peter N. M. Hansteen » 🌐
            @pitrh@mastodon.social

            AodeRelay boosted

            [?]LinuxNews.de » 🌐
            @linuxnews@social.anoxinon.de

            AodeRelay boosted

            [?]Kagan MacTane (he/him) » 🌐
            @kagan@wandering.shop

            Researchers say a fundamental flaw in LLMs makes it easy to trick them into doing things they shouldn’t — like telling you how to sabotage an aircraft’s navigation system.

            "There’s a real probability that this is going to be a problem that’s fundamentally unsolvable," says one of the paper's coauthors.

            technologyreview.com/2026/07/3

              AodeRelay boosted

              [?]Alice Stollmeyer » 🌐
              @AliceStollmeyer@eupolicy.social

              "Dozens of young people set out to sea, chasing a vision they'd seen online, now being sent back to Morocco in coffins."

              Have migrants been 'weaponised'? By whom?

              Enjoying the results: (far)right, Trump, Russia.

              How created a political storm - whipped up by .

              bbc.co.uk/news/articles/c62vl9

                AodeRelay boosted

                [?]dadamsda » 🌐
                @dadamsda@mstdn.social

                AodeRelay boosted

                [?]Steven Saus [he/him] » 🌐
                @StevenSaus@faithcollapsing.com

                Claude published malicious code to the Internet and attacked 3 real companies

                Had the hacks used conventional methods, someone would likely go to prison.

                -&-it
                arstechnica.com/security/2026/

                An image pulled automatically from the post for decorative purposes only.

                Alt...An image pulled automatically from the post for decorative purposes only.

                  AodeRelay boosted

                  [?]Marcel Stritzelberger » 🌐
                  @marzlberger@neander.social

                  Also wirklich, niemand, wirklich niemand sollte ein ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

                  "Mehr als 24.000 Server mit BMC per CVE-2013-4786 gefährdet
                  Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

                  borncity.com/blog/2026/08/01/m