#physicalsecurity

2026-01-19

Physical penetration testing highlights a growing overlap between human behavior, AI capabilities, and access control weaknesses.

A seasoned pentester explains how publicly available audio, voice cloning tools, and social engineering can bypass service desks and building security - often without exploiting software vulnerabilities.

The discussion raises an important question for defenders: are awareness programs designed to be memorable and practical, or simply compliant?

Source: cybernews.com/ai-news/physical

Follow TechNadu for continued cybersecurity reporting and practitioner insights.

Engage in the discussion below.

#InfoSec #Pentesting #AIThreats #SocialEngineering #SecurityTraining #PhysicalSecurity #CyberDefense

Physical hacker explains how to break into buildings and why AI is making the job easier
2026-01-19

Card skimming remains a low-complexity, high-impact attack vector driven by physical access and weak inspection cycles.

Recent coordinated inspections demonstrated:
- Broad exposure across POS, ATM, and fuel pump infrastructure
- Ongoing targeting of benefit cards and consumer payment data
- Significant downstream financial and social consequences

This reinforces the importance of layered mitigation: hardware inspection routines, contactless adoption, tamper-evident controls, and behavioral awareness.

What operational controls have proven most effective in your environment for detecting skimmers early?

Follow @technadu for measured reporting on financial-sector cyber risk.

#PaymentFraud #PhysicalSecurity #SkimmingDetection #FinancialCybersecurity #ThreatAwareness #TechNadu

Inside Our Nationwide Crackdown On Card Skimming and Fraud
Jiji, the catjiji@ohai.social
2026-01-06

looking for a new safe for work to store backup rdx cartridges and keys (physical and yubi) in. simple to use for multiple users, so i assume digital pin lock required, but physical key as backup? in the best case it fits into a file cabinet. as secure as possible under these circumstances, but honestly i have no idea about safes and physical security or what to watch out for? :boost_ok: #safe #physicalSecurity #security #askfedi

2025-12-22

Linux Physical Security based on eBPF

By now uses CanaryToken and-or TelegramBot to send notifications

I have in mind some TODOs, one of them is about monitor accelerometers, if someone has accelerometers sensors on the laptop, please send DM I'm very hype to implement this feature.

github.com/carvilsi/caetra

#eBPF #canaryToken #physicalSecurity #monitoring

An interesting read on physical car security for keyless entry and engine starts.

paigehai.github.io/blog/my-key

But I doubt that any of the current mitigation techniques will in broad practice bear any fruit because ... people love the convenience. That's why they buy that sh*t. That's why they use Gmail, etc.

And manufacturers aren't moving fast (or at all), and definitely not on vehicles already sold.

In my books, the main problem mainly originates between the ears of people/customers.

#car #security #keyless #theft #physicalsecurity

A close up of the chrome plated door handle with an in-built traditional cylinder lock of an old school lime green car. It resembles the physical car lock of Mr. Bean on his Mini, with a galvanised metal latch overlapping the car door's lip to the next body panel with a pad lock looped through as an auxiliary lock.
2025-12-18

CISA’s new venue guides provide a structured, non-prescriptive approach to physical security and dependency disruption planning.

They emphasize:
-Risk-based assessments
- Scalable security options
- Cross-sector dependencies (energy, water, comms, transport)
- Collaboration over compliance

How effective do you find voluntary frameworks compared to regulatory controls in physical and cyber-physical security?

Join the discussion and follow @technadu for continued coverage of infrastructure security.

#PhysicalSecurity #CriticalInfrastructure #RiskAssessment #SecurityFrameworks #Resilience

Venue Guides for Security Enhancements and Mitigating Dependency Disruptions
Sonya Lopezsonyalopez25
2025-12-18

Beyond the surface of a steel door lies a world of precision engineering. From internal reinforcements to blast-resistant cores. Ever wondered what makes a security door virtually impenetrable?

We’re peeling back the steel layers to show you.

vocal.media/stories/the-hidden

2025-12-08

New release v5.1.2 for CanaryUSB that fixes a :bug: when building long canaryDNS tokens.

Get a mail notification via, Canary Tokens (DNS) when a USB or SDCard device is connected on a Linux computer.

Also it is possible to de-authorize an USB that is not present on trusted devices list.

github.com/carvilsi/canaryusb/

#usb #linux #security #physicalSecurity #sdcard #canaryToken

2025-11-29

@indietechnews@ioc.exchange @GrapheneOS

Pros of mobile over desktop/tablet/laptop form factor -->

Physical security of your primary cpu and disk is enhanced by the kind of portability you can always keep in your pocket. No evil maid attacks with your (convergence?) daily driver always in sight. No bad usb (rubber ducky) attacks or untrusted peripherals.

#SecureBoot protections only necessary realistically in very narrow circumstances like border crossings or seizures.

#PhysicalSecurity #AEM #BadUSB #Mobile #Convergence #RFHardened

2025-11-11

When the Louvre was robbed in just seven minutes, most people blamed the thieves. But leaked audit reports told another story — one of weak passwords, ignored warnings, and outdated systems.

In this episode of Cyberside Chats, Sherri Davidoff and Matt Durrin reveal how the same security blind spots behind the heist also threaten hospitals, banks, and critical infrastructure today and what practical steps you can take to avoid becoming the next headline.

Listen now and learn how to lock down your organization.

Podcast: chatcyberside.com/e/louvre-hei

Video: youtu.be/3ErXdXv_bN8

#Cybersecurity #PhysicalSecurity #Security #Authentication #PasswordSecurity #PenetrationTesting #RiskManagement #Louvre #Infosec

Schneier on Security RSSSchneier_rss@burn.capital
2025-11-10

New Attacks Against Secure Enclaves

Encryption can protect data at rest and data in transit, but does nothing for data in use. What we have are secure enclaves. I’ve written about thi... schneier.com/blog/archives/202

#physicalsecurity #cloudcomputing #dataprotection #Uncategorized #hardware

2025-11-10

Minor release for canaryusb; Fixes check for permissions for de-atuhorize a device when using config file.

github.com/carvilsi/canaryusb/

#linux #security #usb #hardening #monitoring-tool #security-automation #security-tools #physicalSecurity

Henry Fisherhenry@techlore.tv
2025-04-15

The Basics of Physical Privacy & Security | Go Incognito 5.2

techlore.tv/w/toBYTxuJNZzzzmci

2025-10-31

Happy to share the new release of canaryusb; right now apart of sending a mail via #canaryToken powered by @ThinkstCanary the new feature deauth_devices (on config file or on cli argument `-d`) allows to de-authorize a USB device attached that does is not on the trust devices list.

github.com/carvilsi/canaryusb/

The de-authorize thingy based on kernel.org/doc/html/v5.15/usb/

Of course this new feature requires to execute it as root user (all the thing explained on README if you want to run it as a service)

Also fixed a bug related with cli args parsing ;)

<3 hack the planet!

#linux #security #usb #hardening #monitoring-tool #security-automation #security-tools #physicalSecurity

2025-10-06

I'm going to be at BSides NoVA this Saturday, Oct 11th hanging out and assisting in the Breach Village.

Come by for demos, discussions, and challenges centered around Breaking and Entering and bypassing physical security.

(for those that follow me for my solarpunk and food and mutual aid content... uhhh... by trade I'm a hacker, burglar, and thief. So. Umm... Yeah.)

Anyhow. Come hang out!

#BSides #BSidesNoVA #BSidesNoVA2025 #infosec #physicalSecurity #pentesting

bsidesnova.org

Breach Village: bsidesnova-2025.sessionize.com

BSides Orlando - September 26-27, 2025bsidesorlando@infosec.exchange
2025-09-14

Step into the Lockpick Village and get hands-on with the art of lockpicking!

Join Dylan Baklor "The Magician" as he gives two exciting talks:
Intro to Lockpicking
Intro to Physical Security

Whether you're brand new or just curious about how locks work, this is the perfect chance to learn the basics, practice your skills, and explore the fascinating world of physical security.

#BSidesOrlando #LockpickVillage #PhysicalSecurity #Lockpicking

bsorl.org/tickets

SpaceCoastSecspacecoastsec
2025-09-09

🚀💻 Join us tomorrow, Sept 10th, 6:30PM Eastern for Crack the Locks. RSVP - meetup.com/spacecoastsec/event 💻🚀

SpaceCoastSecspacecoastsec
2025-09-01

🚀💻 Join SpaceCoastSec Wednesday, 9/10, at 6:30PM for Crack The Locks. Learn about Locksport with hands-on activities! RSVP - meetup.com/spacecoastsec/event 💻🚀

@metacurity

A few years back while working in the office fitting business in Sydney, I would walk in and out of offices, as many times as needed. No questions asked — just because I was wearing a tradie t-shirt.

Sometimes the easiest way in is through the front door.👨🏻‍🔧🚨

#CyberSecurity #PhysicalSecurity #socialengineering

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst