#ictsecurity

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2025-02-01

[en] UK: Should #ransomware payments be banned?

"Governments underestimate the impact of #cybercrime at their peril."

"... without a ban covering the private as well as the public sector, threat actors would likely gravitate to the former."

"... we may see ... a potential evolution in the business model itself ... perhaps they would look to other options ..."

techmonitor.ai/comment-2/unint

#cybersecurity #ictsecurity #cyberthreat #cyberthreat #exploit #trojan #spyware #vulnerability

2024-04-19

Linux Foundation Open Source Summit North America:
"Linus Torvalds and his good friend Dirk Hohndel ... conversation about Linux development and related issues"

Interesting - They also talked about #security, XZ Utils incident, #LLMs, #hardware, RISK-V, #Git ...

zdnet.com/article/linus-torval

#gnulinux #linux #riskv #xz #xzutil #xzutils #llm #torvalds #hohndel #cybersecurity #ictsecurity #itsecurity #exploit #spyware #vulnerability #infosec #ai #aihype #linuxfoundation #opensourcesummit

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2024-03-28

[en] Voting: Weaknesses of Electronic Voting Machines (Prof. Appel, Schneier & Co.)

"Rather than assert that each component of the process can be made perfectly secure on its own, ... the goal of each component of the elections process is to validate every other component."

"... the hallmarks of a reliable and optimal election process are hand-marked paper ballots ..."

[Not "e-voting"]

freedom-to-tinker.com/2024/03/

#voting #votingmachine #ballot #election #evoting #ictsecurity #infosec #security

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2024-03-28

[en] Commercial spyware firms make mobile phones and devices increasingly insecure

"Nearly two thirds of mobile and browser flaws were used by spyware firms".

"... in 2023, spyware produced by commercial surveillance vendors (CSVs) were responsible for 64% of known exploited mobile and browser zero-day vulnerabilities."

cyberscoop.com/spyware-zero-da

#zeroday #spyware #csv #cyberthreat #exploit #vulnerability #cybersecurity #ictsecurity #itsecurity #infosec #mobile #mobilephone

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2024-03-21

[en] Serious security vulnerabilities in electronic RFID locks from dormakaba

"... identified weaknesses allow an attacker to unlock all rooms in a hotel using a single pair of forged keycards. Over [3m] hotel locks in 131 countries are affected."

"As of 03/2024, ... 36% of the impacted locks have been updated or replaced."

unsaflok.com/

#ResearchHighlights #dormakaba #kaba #saflok #unsaflok #privacy #rfid #rfidlock #cybersecurity #ictsecurity #itsecurity #infosec #security

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2024-03-09

[en] Microsoft Goes Open Source 😄 - Not Really Intentionally

"... breach was worse than initially understood and that the Russian hackers accessed Microsoft source code."
"... string of breaches affecting the company that have raised major questions in Washington about Microsoft’s security posture."

cyberscoop.com/microsoft-cozy-

#MediaHighlights #microsoft #opensource #oss #foss #sourcecode #hacking #hacker #breach #insecure #security #cybersecurity #infosec #ictsecurity #itsecurity #threat

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2023-08-21

A post claims that "Hackers increasingly abuse Cloudflare Tunnels for stealthy connections"

#Cloudflare Tunnels are supposed to create outbound-only connections to the Cloudflare network but are apparently also used "for nefarious purposes, such as gaining stealthy persistent access to the victim's network, evading detection, and exfiltrating compromised devices' data."

bleepingcomputer.com/news/secu

#abuse #cloud #cloudtunnel #cybersecurity #ictsecurity #itsecurity #infosec #security

🛡 H3lium@infosec.exchange/:~# :blinking_cursor:​H3liumb0y@infosec.exchange
2023-07-24

🚨 Data Breach Alert 🚨
🇳🇴​ Norsk Dept. of Security & Service Org. 🇳🇴​ discloses a data breach in the ICT platform of 12 govt. departments. Investigation underway 🕵️‍♂️. Collaborating with Natl. Security Authority & police to address the issue. Precautions in place. Stay tuned for updates. #DataBreach #CyberSecurity 🛡️

📅 On July 24, 2023, a breach was detected in a supplier's software, exploited by an unknown party. 🛡️ DSS takes immediate action to secure data & ensures govt. ops continue as usual. Further security measures under consideration. 🕵️‍♂️ #DataSecurity

🔒 Ongoing investigation to determine the extent of the attack and responsible party. Police & Data Protection Authority notified. 🚓 #InvestigationInProgress

💻 DSS briefing, with Minister Sigbjørn Gjelsvik & Director Erik Hope, streamed live. Updates on the situation & inquiries to follow to maintain transparency. 📡 #StayInformed

👉 regjeringen.no/no/aktuelt/pres

On July 24, 2023, the Departmental Security and Service Organization revealed a data breach on the ICT platform of 12 government departments. The incident is currently under investigation by the police. The breach was detected in the software of one of their suppliers and exploited by an unknown party.

In response to the attack, the Departmental Security and Service Organization (DSS) has taken immediate action and is closely collaborating with the National Security Authority and the police. They have implemented various security measures to address the breach and are continuously monitoring the situation. The affected government departments are now unable to access DSS's shared services on mobile devices, including email. However, they can continue to work normally on office computers or from home.

Minister of Municipal and District Affairs, Sigbjørn Gjelsvik, emphasized that despite the incident, the government's operations are ongoing as usual. DSS is committed to securing the information on the ICT platform and will consider further security measures as needed.

The investigation into the data breach is ongoing, and the responsible party and the extent of the attack are yet to be determined. The authorities have notified the police and the Data Protection Authority regarding the incident.

The briefing held by DSS, featuring Minister Sigbjørn Gjelsvik, DSS Director Erik Hope, and representatives from the National Security Authority, was streamed live and covered the measures taken to handle the situation. Further information regarding the incident and ongoing investigations will be released in due course to avoid jeopardizing the inquiry.

It is worth noting that the ICT platform affected by the data breach is used by all government departments except the Prime Minister's Office, the Ministry of Defense, the Ministry of Justice and Emergency Preparedness, and the Ministry of Foreign Affairs. The situation remains under close observation, and additional measures will be implemented if necessary.

#DataBreach #CyberSecurity #DataSecurity #InvestigationInProgress #StayInformed #GovernmentSecurity #ICTSecurity #DataPrivacy #SecurityMeasures #NorskDept #DSS #NationalSecurity #DataProtection #GovernmentDepartments #OnlineSafety #DataPrivacyMatters #GovernmentOps #DataSecurityAlert #DataBreachNews #DataBreachUpdate

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2023-05-22

[en] Android: Logging of Sensitive Data and Leak to Third Parties

"Logging of sensitive data in the Android ecosystem ..."
"... Logging of “activity” names can inadvertently reveal information about users through their app usage. "

Paper Prepub:
usenix.org/system/files/sec23f

Media EL PAÍS:
english.elpais.com/science-tec

#MediaHighlights
#ResearchHighlights

#android #dataleak #leak #mobilesecurity #ictsecurity #itsecurity #infosec #itsec #privacy #security #thirdparty

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2023-04-04

[en] Longread: Birth and Making of Surveillance Technology, Backdoors etc., Presumably to Oppress Racial Minorities etc.

Interesting read. Apparently shows involvement of Hikvision, Huawei, Dahua, according to the text. Might help the rest of the world to better understand why the US is inclined to ban such companies ...

#MediaHighlights

wired.com/story/surveillance-c

#hikvision #huawei #dahua #surveillance #backdoor #ictsecurity #itsecurity #infosec #privacy #security

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2023-03-29

[de] E-Voting CH: Prof. A. Appel: "Von Hand" ist einzig sichere Methode

"Der aktuelle Stand der IT-Security-Wissenschaften lässt uns ... auf absehbare Zeit zum Schluss kommen, dass bei Wahlen Papierstimmzettel, die von Hand ausgefüllt ... nachgezählt ..., die einzig sichere Methode sind ..."

"... Eine Schwachstelle, die es Hackern ermöglicht, Schadsoftware auf Tausenden von Geräten von Wählern zu installieren."

inside-it.ch/e-voting-reihe-wi

#onlinevoting #evoting #ictsecurity #infosec #security

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2023-03-29

[en] Online voting provider paid for academic research in attempt to sway U.S. lawmakers

According to Cyberscoop, "Democracy Live [a voting technology company] directed academic research aimed at demonstrating its product's security and used that material in lobbying campaigns."

cyberscoop.com/democracy-live-

#onlinevoting #evoting #ictsecurity #infosec #security #democracylive

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2023-03-10

"The notion of security doesn’t exist in a vacuum - it’s always about protecting something from someone or something else."

Prof. Carmela Troncoso, EPFL 2022 Best Teacher in Computer Science and Communication Systems is an international figure in data security and privacy.

actu.epfl.ch/news/it-wouldn-t-

#ResearchHighlights
#datasecurity #ictsecurity #itsecurity #infosec #itsec #privacy #security #epfl

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2023-02-14

Cryptography (sort of): Chromo-encryption method encodes secrets with color

"Crucially, in the chromo-encryption method, only the correct combination of polarization directions would reveal the secret message; light polarized in any other direction would reveal a series of colors corresponding to a nonsense message."

actu.epfl.ch/news/chromo-encry

#cryptography #encryption #chromoencryption #ictsecurity #itsecurity #infosec #security #epfl #eth

Research Network Digi-Oek.chDigiOekCH@social.tchncs.de
2022-12-24

A picture says it all: How to build invincibly elegant and unbeatable #ictsecurity

Ein Bild sagt alles: Inspiration für unschlagbare, absolute #ITsicherheit

#satire
#cybersecurity #itsecurity #itsicherheit #infosec #itsec #security #sicherheit

Inspired by
Inspiriert von
@Grantscheam

ICT Security
Inspired by/Inspiriert von Grantscherm

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst