Avoid The Hack!

An initiative promoting the intersection of internet and for all users.

MOVED to infosec.exchange -> @avoidthehack

Avoid The Hack!avoidthehack
2023-07-12

How to share files and sensitive information securely

@bitwarden shows you how to use Bitwarden Send to share files and sensitive information in a more secure way.

In most cases, you should avoid sending sensitive information via email (even if not a file).

bitwarden.com/blog/how-to-shar

Avoid The Hack!avoidthehack
2023-07-12

Avoidthehack updates Comparison Tool

- Added Mullvad @mullvadnet browser
- Added Comodo IceDragon
- Fixed image display issues on some
- Corrected existing information

avoidthehack.com/util/browser-

Avoid The Hack!avoidthehack
2023-07-12

CISA Adds Five Known to Catalog

CVE-2023-32046 Microsoft Windows MSHTML Platform Privilege Escalation
CVE-2023-32049 Microsoft Windows Defender SmartScreen Security Feature Bypass
CVE-2023-35311 Microsoft Outlook Security Feature Bypass
CVE-2023-36874 Microsoft Windows Error Reporting Service Privilege Escalation
CVE-2022-31199 Netwrix Auditor Insecure Object Deserialization

cisa.gov/news-events/alerts/20

Avoid The Hack!avoidthehack
2023-07-12

@briankrebs 😂 😂 😂

Also the WebKit 0-day is tracked as CVE-2023-37450, for anybody wondering.

Avoid The Hack! boosted:
2023-07-12

Microsoft today issued security updates to fix a whopping 130 flaws in Windows etc, including 4 zero-day vulnerabilities. MSFT issued an advisory for but did not patch a fifth zero-day that is being exploited by ransomware crooks reportedly working in support of Russian intelligence operations. Meanwhile, Apple issued and then pulled a patch for a zero-day flaw in iOS and macOS. The Apple flaw is fixed in iOS/iPadOS 16.5.1, macOS 13.4.1, and Safari 16.5.2.

#patchemifyougotem

krebsonsecurity.com/2023/07/ap

A photo of a Macbook half open next to an iphone in a darkened room lit only by the backlights.
Avoid The Hack! boosted:
2023-07-11

Whoa. Sophos researchers just announced that they’ve uncovered 133 malicious drivers signed with legitimate digital certificates, and found 100 of of those 133 drivers were signed by Microsoft.

news.sophos.com/en-us/2023/07/

From the post:

"Today, Microsoft issued Security Advisory ADV230001 as part of their July Windows Update that addresses Sophos’ discovery of more than 100 malicious drivers that had been digitally signed by Microsoft and others, dating as far back as April 2021."

"They also released Knowledge Base article 5029033, which includes new, more detailed information on the technical measures Microsoft has taken to protect against these malicious signed drivers."

msrc.microsoft.com/update-guid

support.microsoft.com/help/502

Today's post about patches from Microsoft and Apple to quash zero-day bugs:

krebsonsecurity.com/2023/07/ap

I wrote recently about one of the bigger names in signing malware as a service:

krebsonsecurity.com/2023/06/as

Avoid The Hack!avoidthehack
2023-07-11

@GossiTheDog Git off yer phone

Avoid The Hack!avoidthehack
2023-07-11

releases emergency to fix zero-day exploited in attacks

CVE-2023-37450 - code execution in the WebKit browser engine (which powers Safari).

bleepingcomputer.com/news/appl

Avoid The Hack!avoidthehack
2023-07-11

Changed Its Policy: Does the Tech Giant Now Use All Your Data to Train Its AI?

From @Tutanota

Color me surprised. đŸ€«

tutanota.com/blog/google-train

Avoid The Hack!avoidthehack
2023-07-10

How to block emails on , Outlook, Proton Mail, Yahoo Mail, and Mail

From @protonmail

proton.me/blog/how-to-block-em

Avoid The Hack!avoidthehack
2023-07-10

@ancatdubh exactly. Connecting to the fediverse for exposure is okay
 but the cost for users to do so (through threads) is very high and concerning


Avoid The Hack!avoidthehack
2023-07-10

New ‘Big Head’ ransomware displays fake Windows update alert

Suspected to be spreading primarily through *gasp* Malvertising.

During the encryption stage, this displays a loading screen similar to a update.

bleepingcomputer.com/news/secu

Avoid The Hack!avoidthehack
2023-07-10

How Threads’ policy compares to Twitter’s (and its rivals’)

has abysmal privacy... just reading the list in this article is exhausting.

I fail to see how it is an "acceptable middleground" for users being introduced into the (with the talk of ActivityPub integration.)

arstechnica.com/security/2023/

Avoid The Hack!avoidthehack
2023-07-08

Critical TootRoot bug lets attackers hijack servers

> bad actor sends malicious toot
> instances process malicious toot
> spawns webshell
> bad actor uses webshell to assume control over the server

There is a patch for this - all Mastodon server admins should update if they haven't already.

bleepingcomputer.com/news/secu

Avoid The Hack!avoidthehack
2023-07-08
Avoid The Hack!avoidthehack
2023-07-07

@dostalcody @briankrebs What I’m gathering is that these are the equivalent of “we’ve been trying to reach you about your car’s extended warranty
” calls. Lol.

Avoid The Hack!avoidthehack
2023-07-07

@bflipp @DaveMasonDotMe

Also, thanks for clarification on the IP address issue. I mentioned it because it would be an issue for the small(er) servers. Same user profile + same IP address (of a small or single-user server) could be an easy identifier. I should have mentioned this when I brought it up.

At the end of the day, they are asking Mastodon admins to federate for *some* reason. They could just scrape what is public, but I don't think that gives them the real time metadata.

Avoid The Hack!avoidthehack
2023-07-07

@bflipp @DaveMasonDotMe

Their business model relies on it. The core of the issue is that this data wouldn't exist in a vacuum - whatever is ingested from interaction with users goes back to Meta.

They are tracking their own millions of users so closely, even while interacting with the fediverse, that it will have implications for users on other instances.

Pile on that the concerns of lack of moderation on the threads platform and high potential for abuse and wow, we have a problem.

Avoid The Hack!avoidthehack
2023-07-07

@bflipp @DaveMasonDotMe

With and the fediverse, over time gives the "how" and "how often." Do you DM? Boosts and favorites? Bookmark? Does the third-party interact with the user? When and how often?

It's the power of metadata and collection + correlation over time I'm stressing here. Still speculation, but I am positive they will use/process/share/sell the metadata - especially because tracking their own users will give them a front row seat, an easy ingestion point.

Avoid The Hack!avoidthehack
2023-07-07

@bflipp @DaveMasonDotMe

I agree with you Mastodon is not private, but it lends itself more to than traditional social media.

There is still absolutely the threat of collection from - just not first-party collection (if you are not on their platform.)

Similar context: you may not use WhatsApp, but I do. I have your contact info... and I share that info with WhatsApp. Well, now WhatsApp has it too. And they can infer we interact.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst