#cyberSecurity

2025-12-19

UK government data has been hacked again. Ministers say the risk is “low” — but want us to trust them with digital ID.

On what evidence?

Mmmmmmm.....

Pablo: Their donors PAID a shedful of crypto pence? They brushed their fangs?
They hide when caught out?

#DataBreach #DigitalID #Privacy #CyberSecurity #UKPolitics
thewhipline.substack.com/p/uk-

IT InsightsITinsights
2025-12-19

Nieuwe cybercrime strijd ontketend door grensconflict! 🌐💻 Wie wint deze digitale oorlog?  
itinsights.nl/cybersecurity/gr

urlDNA.io :verified:urldna@infosec.exchange
2025-12-19

Possible Phishing 🎣
on: ⚠️hxxps[:]//gpfcuonl[.]weebly[.]com
🧬 Analysis at: urldna.io/scan/6945556d3b77500
#cybersecurity #phishing #infosec #urldna #scam #infosec

CyberNetsecIOnetsecio
2025-12-19

📰 China-Linked Hackers Exploit Critical Cisco Email Gateway Zero-Day

🇨🇳 A China-linked APT is exploiting a critical 10.0 CVSS zero-day (CVE-2025-20393) in Cisco Email Gateways for root-level RCE. CISA has added it to the KEV catalog. Patch immediately! 🛡️

🔗 cyber.netsecops.io/articles/ch

2025-12-19

Vụ tấn công chuỗi cung ứng nhắm vào X, Vercel, Cursor, Discord cảnh báo: phụ thuộc phần mềm dễ bị khai thác. Đừng quên chạy npm audit, dùng Dependabot, Snyk và thiết lập CI/CD kiểm tra bảo mật. Xây dựng văn hoá bảo mật trong dev! #SupplyChainAttack #Cybersecurity #DevSecOps #BảoMật #PhátTriển #DependencyConfusion

dev.to/technoblogger14o3/we-pw

2025-12-19

🛡️ Đợt “tổng duyệt” định kỳ lực chuyên trách bảo vệ an ninh mạng Bộ Công an đã diễn ra trong Diễn tập An ninh mạng quốc gia 2025, khẳng định năng lực sẵn sàng ứng phó với các nguy cơ mạng. #AnNinhMạng #CyberSecurity #BộCôngAn #Vietnam #CyberDefense #SecurityForce

vietnamnet.vn/dot-tong-duyet-d

2025-12-19

Security Bits with @bart for your reading pleasure, including a deep dive into Google’s new agentic AI browser security framework. No, it’s not what you’re thinking — it looks good!

podfeet.com/blog/2025/12/sb-20

#CyberSecurity

urlDNA.io :verified:urldna@infosec.exchange
2025-12-19

Possible Phishing 🎣
on: ⚠️hxxps[:]//site-qkrhxpjb3[.]godaddysites[.]com
🧬 Analysis at: urldna.io/scan/69454d483b77500
#cybersecurity #phishing #infosec #urldna #scam #infosec

Conan the Sysadminconansysadmin@mstdn.social
2025-12-19

There are merchants who promise to store your scrolls safely in their mountain redoubts. But can they be trusted? #cybersecurity cromwell-intl.com/cybersecurit

Kaifi 🇵🇸kq@ieji.de
2025-12-19

As a Muslim researching about #cybersecurity, I wondered: what does Islam teach about privacy?

Turns out, a lot. Here's a hadith from 1400 years ago: “When a man peeps into your house without permission, and you throw a stone at him and injure his eye, you will not be blamed.”

Digital surveillance is the modern peeping. Your phone is your house.

I wrote about this + my journey from Telegram fanboy to Signal advocate here:

kaifisahil.substack.com/p/your

#Privacy #Signal #Encryption #Islam #DigitalRights

OWASP Foundationowasp@infosec.exchange
2025-12-19

🎉 Big news! Early Bird tickets for OWASP Global AppSec Vienna 2026 are here!
25 years of OWASP ✨ Stunning Vienna 🇦🇹 World-class training 🧠 & a conference like no other 🔥
Why wait? Register now for early bird pricing: owasp.glueup.com/event/162243/
#appsec #owasp #cybersecurity #securebydesign

2025-12-19

This dumb password rule is from TwinSpires.

You can gamble on our site. We'll keep your money secure with a 12 character password!

dumbpasswordrules.com/sites/tw

#password #passwords #infosec #cybersecurity #dumbpasswordrules

Paco Ho Ho Hope 🎄paco@infosec.exchange
2025-12-19

Who's got the latest? I dunno. I think Joe edited it last. Here's the version he emailed me last week. Ask what he's got.

They've got a book of loans like this. Hundreds of millions of pounds, and a few folks keeping track with ad hoc valuations and a spreadsheet they email around.

Naturally, the SEC urged them to do this with a system.

So they made the code freeze and got the thing deployed with no authorization.

The sad thing is, my contract there ended shortly after that, so I really couldn't tell you how it all played out. Did they add authorization in January? June? next December? I dunno. I'm sure they did eventually.

#cybersecurity #finserv #fintech

4/fin

Paco Ho Ho Hope 🎄paco@infosec.exchange
2025-12-19

This season reminds me of a time when I was doing #cybersecurity for a financial firm in London. The firm goes into "code freeze" in the first or second week of December until January to minimize the possibility of problems during the holidays.

I was doing #security architecture analysis on an important system. Basically the US SEC had demanded they start using a purpose-built system to track certain numbers (I'll explain in a reply to this) instead of just emailing spreadsheets around. So they had basically built a system that was a spreadsheet in a website. They had one year to comply. This system had not yet launched. If it didn't go live in this last possible week, they'd have to explain to the SEC how, 12 months on, they had failed to deploy anything at all in response to the requirement. (I'm sure I'm being imprecise here, that's the gist of it)

1/

urlDNA.io :verified:urldna@infosec.exchange
2025-12-19

Possible Phishing 🎣
on: ⚠️hxxps[:]//kku-account[.]weebly[.]com
🧬 Analysis at: urldna.io/scan/69455f0c3b77500
#cybersecurity #phishing #infosec #urldna #scam #infosec

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst