#securityfail

Dmytro (Dima) Oliinykdima@dol.social
2026-01-07

Me: Tries to access my personal stuff on the work machine (which is allowed!).

The laptop security: "I'm afraid I can't let you do that."

Looks like the SSL inspector is feeling a bit overprotective today.

#techfail #corporateit #tlsfail #funny #infosec #worklaptop #privacy #securityfail #humor #proton #fediverse

N-gated Hacker Newsngate
2025-12-04

🚨 ALERT! 🚨 finally achieved what we all thought impossible: a CVSS 10.0 vulnerability! 🎯 Bravo, they've hit the bullseye of FAIL! 🙈 It's always heartwarming when devs leave the open for to make themselves at home. 🏠🔓
nextjs.org/blog/CVE-2025-66478

2025-11-26

This is a "fun" read.

I've never really understood why sites like the ones covered in this article exist, since they cater to people who should be pretty comfortable with command-line linting/pretty-printing tools. But now I know that they survive (thrive on ad revenue, even!) because so many of their users are a few bits short of a byte.

labs.watchtowr.com/stop-puttin

#facepalmSec #cybersecurity #infosec #SecurityFail #WTFsec #facepalm

Solarbird :flag_cascadia:moira@mastodon.murkworks.net
2025-11-23

I have never felt better about a bicycle being my primary form of transport.

"What the fuck, Flock?"

It's so much worse than you may've heard. The clown show is _spectacular_. It's a five-season arc in progress of only the most upper level, purest clownery.

Here's a very high view on The WAN Show (jump to 3:12:09 if the time stamp start doesn't work):

youtube.com/live/Vzgimftolys?t

Here's the original source with much more details:

youtube.com/watch?v=uB0gr7Fh6lY

#Flock #FuckFlock #HolyShit #surveillance #fascism #SurveillanceSociety #incompetence #RubberDucky #SecurityFail #security #HilariousIncompetence #shenanigans #clowns #ClownShow #TempestAttack #EveryAttack #AuthenticationInPlainText #EverythingThatCanBeWrongIsWrong

Mojo ♻️mojo@aus.social
2025-11-11

Oh wow, the Louvre’s surveillance password was literally Louvre. Nothing says world class security like using the museum’s own name 😜
Thieves: $102M in jewels, 7-minute heist, cherry picker exit
Louvre: We couldn’t have foreseen this

*My professional #cybersecurity tip: try password123 next upgrade

#louvre #heist #securityfail #france #arttheft #itsecurity #itsec

abcnews.go.com/International/p

N-gated Hacker Newsngate
2025-11-09

🍾🤡 , the high-tech innovation to , because who needs robust security when you can just pop your way to safety? 🎈✨ Welcome to the future of sandboxing: as strong as the packaging your last Amazon delivery came in. 🚀🛍️
blog.netbsd.org/tnf/entry/gsoc

2025-11-06

Sicherheitsbewusstsein bei Privatpersonen ist ja oft ein Witz, aber "Louvre" als Passwort zu wählen, ist fast schon Kunst. 😬🖼️

srf.ch/kultur/gesellschaft-rel

#louvre #password #securityfail

N-gated Hacker Newsngate
2025-09-23

Veria Labs has discovered that MCP's authentication is about as secure as a wet paper towel, leading to in Claude Code and Gemini CLI 🤦‍♂️💻. The article is a rollercoaster of jargon trying to sound important while basically saying, "Oops, we broke everything!" 🤷‍♀️🔧. Meanwhile, the rest of the industry is scrambling like headless chickens to patch this mess 🐔🔥.
verialabs.com/blog/from-mcp-to

Soren Mogensen 🇩🇰🏴󠁧󠁢󠁳󠁣󠁴󠁿🇵🇸🇪🇺soren@mastodon.scot
2025-09-05

Trying to book a vaccination through boots.com and navigating through the calendar looking for available appointments results in the request being blocked by their security service.

Maybe test your security service with normal functionality on your site before rolling it out.

#SecurityFail #DesignFail #WebsiteFailure

Screenshot of browser error:

"Sorry, your access to this site is not possible at this time

What happened?
This request was blocked by our security service"
2025-09-02

Time to complain about MS Teams again. Locked me out of my account last week for "suspicious activity" which was a bug on their end which kept asking me to login. But still dutifully sends me email updates from Teams #SecurityFail

N-gated Hacker Newsngate
2025-08-26

🧠🔒 So, an "elite" Air National Guard member thinks $250/month for plugging laptops into random networks is a steal? 🙄 Welcome to the world of 'legal botnets', where your top secret clearance means you can be legally clueless. 🔌💸
krebsonsecurity.com/2025/08/ds

N-gated Hacker Newsngate
2025-08-19

Ah, the SSO Hall of Shame: where companies treat essential security like a preposterous premium add-on. 🎟️ Why bother with proper authentication when you can nickel and dime clients in the name of "luxury"? 🙄 Because who needs security when you have profits to make, right? 💸
sso.tax/

In 2005, Sony shipped audio CDs with copy protection that secretly installed a rootkit on Windows PCs. This hidden software cloaked itself, opened security holes, and resisted removal, sparking outrage when researchers exposed it. The backlash was massive, forcing Sony to recall millions of discs and forever tainting the company’s reputation in the security community.

#SonyRootkit #SecurityFail #DigitalRights #MalwareHistory #CorpoGarbage

2025-06-15

> Your password must be between 8 and 16 characters. It must also include at least one number, one capital letter, and one symbol.

I keep failing because my passwords are too long. #securityfail

#ebay needs to update their #GeoIP database.

I've just logged on from an old computer in my house, and it's sent me an email saying someone has logged in from Shropshire, which is over 100miles away, when most sites think I am based in North London (which is still wrong, but my ISP is at least based there).

No other site seems to ever think I'm in Shropshire.

I wish companies would just list the IP address and browser details in their "a new device had logged in to you account" emails, any other details seem to be totally wrong, and therefore useless 🤬

#SecurityFail #SecurityTheatre

Mr Tech Kingmrtechking
2025-04-25

Yikes. Top Trump officials used Signal for classified Yemen strike plans & accidentally added The Atlantic's editor to the chat. Major security questions arise, especially around Defense Sec Hegseth's handling of sensitive info.

Pete Hegseth's Risky Signal Chats Leaked Military Secrets
N-gated Hacker Newsngate
2025-04-22

🔨🎉 BREAKING: BAE Systems achieves monumental success in production—unfortunately, they forgot to secure their website! 🚫📉 The only explosive development here is their web server crashing harder than their test dummies. 💥🙃
baesystems.com/en/article/majo

2025-04-21

Äiti äiti katso miten tärkeä olen!
T. Pikku-Pete

#Hegseth
#hegsethisunfit
#HegsethGate
#securityfail

NY Times: Ministeri Hegseth jakoi tietoja iskuista toisessakin viestiryhmässä – mukana vaimo ja veli
hs.fi/maailma/art-200001118187

Childless Cat Ladychildless_cat_lady
2025-04-08

🚨 While Marco oversees the rendition of innocent men to indefinite detention in foreign prisons, one of his top security personnel is arrested in Brussels for allegedly assaulting cops and hotel staff after demanding a drink after hours. 🍹🚫👮‍♂️

The best people? 🤔 washingtonexaminer.com/news/33

XenoPhage :verified:XenoPhage@infosec.exchange
2025-03-28

Why is it that Home Depot has passkey support and my bank still wants me to answer those three questions?

#security #SecurityFail #FacePalm

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst