#SecurityFail

Mr Tech Kingmrtechking
2025-04-25

Yikes. Top Trump officials used Signal for classified Yemen strike plans & accidentally added The Atlantic's editor to the chat. Major security questions arise, especially around Defense Sec Hegseth's handling of sensitive info.

Pete Hegseth's Risky Signal Chats Leaked Military Secrets
N-gated Hacker Newsngate
2025-04-22

🔨🎉 BREAKING: BAE Systems achieves monumental success in production—unfortunately, they forgot to secure their website! 🚫📉 The only explosive development here is their web server crashing harder than their test dummies. 💥🙃
baesystems.com/en/article/majo

2025-04-21

Äiti äiti katso miten tärkeä olen!
T. Pikku-Pete

#Hegseth
#hegsethisunfit
#HegsethGate
#securityfail

NY Times: Ministeri Hegseth jakoi tietoja iskuista toisessakin viestiryhmässä – mukana vaimo ja veli
hs.fi/maailma/art-200001118187

Childless Cat Ladychildless_cat_lady
2025-04-08

🚨 While Marco oversees the rendition of innocent men to indefinite detention in foreign prisons, one of his top security personnel is arrested in Brussels for allegedly assaulting cops and hotel staff after demanding a drink after hours. 🍹🚫👮‍♂️

The best people? 🤔 washingtonexaminer.com/news/33

XenoPhage :verified:XenoPhage@infosec.exchange
2025-03-28

Why is it that Home Depot has passkey support and my bank still wants me to answer those three questions?

#security #SecurityFail #FacePalm

Sam Bentdoingfedtime
2025-03-27

This dumpster fire Phantasma Market leaked its clearnet IP on DAY ONE. Zero OpSec. Just handing themselves to feds on a silver platter. youtu.be/t3ebaBn4MVU

Loki the Catloki@jorijn.dev
2025-03-25

📱 When your "super secure" group chat accidentally becomes a press conference...

Signal's president defends app security after US officials mistakenly added a journalist to their military planning chat. Proof that even the most sophisticated security can't prevent the classic "wrong person added" scenario.

#signal #SecurityFail

yro.slashdot.org/story/25/03/2

N-gated Hacker Newsngate
2025-03-23

📬🚫 Oh, the irony! A tech wizard pens a magnum opus on automating mail alerts, only to have their masterpiece blocked by ModSecurity—because apparently, the server had higher standards than their script. 😆🔒
taslim.xyz/blog/2025/sharing-m

Suzanne Aldrich (she/her)suzannealdrich@hachyderm.io
2025-03-23

Critical Next.js Middleware Vulnerability (CVE-2025-29927)

A major auth bypass vulnerability in Next.js middleware (prior to v14.2.25 / v15.2.3) allows attackers to inject the x-middleware-subrequest header and bypass authorization entirely. Exploitable via simple HTTP requests—no user interaction, no special permissions.

Patch. Now. Or block the header manually.

GitHub scored this 9.1 CRITICAL, but the real issue? This flaw exposes a systemic weakness in middleware validation, and some vendors weren’t exactly upfront about the risks.

Details + POC: zeropath.com/blog/nextjs-middl
NVD: nvd.nist.gov/vuln/detail/CVE-2

Security theater is easy. Secure defaults and transparency are harder—but essential.

#infosec #AppSec #NextJS #CVE202529927 #middleware #securityfail

N-gated Hacker Newsngate
2025-03-20

Ah, yes, because nothing screams "security" like a government agency casually asking ex-employees to email their sensitive data. 🦊🔒 Trust us, we promise to keep your info as safe as a toddler with a Sharpie! 🤣📝
krebsonsecurity.com/2025/03/do

Todd A. Jacobs | Pragmatic Cybersecuritytodd_a_jacobs@infosec.exchange
2025-02-22

This isn't Apple's fault, as it still has to follow local laws to sell its products. However, this is a huge #securityfail.

Even though Apple no longer fights for mindshare in the enterprise computing market as it once did, this will force companies that require secure data to either avoid iCloud-enabled apps altogether—which can be hard to do on a Mac—or stop using Macs altogether for anything that processes #PII, #PHI, or even proprietary #sourcecode.

In particular, many #softwaredevelopers prefer #MacBooks since they offer a mainstream user experience but run #Unix under the hood. If they can't use MacBooks anymore for security reasons, companies will have to rethink some of their long-standing laptop and desktop #cybersecurity practices.

bbc.com/news/articles/cgj54eq4

Loki the Catloki@jorijn.dev
2025-02-01

When "open source" wasn't in the roadmap: DeepSeek accidentally shares sensitive data with... everyone! 🙈

Over 1M lines of exposed data including API keys and chat logs. Fixed within an hour, but as researchers note - they probably weren't the first to find it.

#SecurityFail #AI

it.slashdot.org/story/25/02/01

2024-12-27

Ach. Bei #VW sind sie zu blöd, eine S3 Instanz anständig zu konfigurieren. 800k Datensätze zu Autos, frei abrufbar. 420k identifizierbar und mit Positionsdaten. Läuft bei uns. 🙄
Zur Strafe 800k mal Artikel 32 der DSGVO abschreiben.
#infosec #securityfail #datenschutz

Loki the Catloki@jorijn.com
2024-12-23

Imagine choosing an encrypted chat app to avoid the FBI and accidentally picking... the FBI's own app 😹

The "Anom" sting operation caught hundreds of criminal syndicates in 100+ countries. Talk about failing the "Don't Get Caught" test with the answers written on the wall!

#privacy #SecurityFail

https://yro.slashdot.org/story/24/12/23/1736221/government-to-name-key-witness-who-provided-fbi-with-backdoored-encrypted-chat-app-anom

Loki the Catloki@jorijn.com
2024-12-18

Looks like things aren't "Hapn-ing" too well for this GPS tracking company! 😸

The firm that helps you track "valuable possessions" can't even keep track of its own customer data. 8,600+ user records exposed through a basic website bug.

Oh, the irony of a surveillance company failing at... surveillance. 🎯

#Privacy #SecurityFail

https://it.slashdot.org/story/24/12/18/2220247/tracker-firm-hapn-spilling-names-of-thousands-of-gps-tracking-customers

Frank Filipponefrankfil@aus.social
2024-11-19

Was slightly amused earlier today when looking at Task Manager on a Windows server and found a properly ancient version of TeamViewer running on it.

Did I mention this server has direct internet access?

And is part of the security system for this site?

#it #itsecurity #securityfail

Laux Myth (aka Martin)lauxmyth@mastodon.online
2024-10-26

Recently, I found this pair of doors. Two elegant glass doors with a failed strip of insulation between the pair. The internal push bars are held with a bike cable and padlock.

Yes, if this is an emergency exit the cable is a violation. I suspect it is an exit but I did not look to check. On the other hand, this design allows for a trivial bypass to open and this patches the vulnerability.

#SecurityFail

A pair of glass doors with elegant CRL exit devices are held internally by a bike cable lock. The doors also have PULL signs
2024-10-18

Today in terrible password policies: Poundland.

Poundland’s Password Policy Pains:
- maximum length
- restricts symbols
- LIMITS CHARACTER TYPES!?!?

That last one is new to me!

#PasswordPolicies #Password #Passwords #Security #SecurityFail #Poundland

An image displaying password requirements, stating that a new password must be 8-16 characters long and contain at least three out of four categories: lowercase letters, uppercase letters, digits (0-9), and specific symbols.
Dyne.org foundationdyne@toot.community
2024-10-10

In a surprising twist, the very backdoors designed to keep out the badGuys™ were used by the badGuys™.

Who could've seen this coming? It's shocking that no one ever warned the clueless legislators behind these backdoors. If only there were some sort of experts they could listen to. 🤦🔓

#SecurityFail #BackdoorBlunder
reuters.com/technology/cyberse

2024-09-19

Sitze gerade im Zug zum #JoomlaDay nach Hamburg. Neben mir im Zug werden am Telefon alle möglichen Geschäfte und wichtige Informationen ausgetauscht, als wäre niemand da. Das Highlight bisher: Mein Sitznachbar ist aufgestanden und gegangen. Sein Laptop ließ er unbebaufsichtigt und ungesichert, also nicht gesperrt stehen. Jeder hätte den Laptop nehmen und irgendwas installieren können oder einfach mal Nachrichten seines Messengers lesen oder die NDA versenden, die er gelesen hat. 🤷‍♂️ #Securityfail

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst