cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

Michael boosted

[?]Ben Hardill » 🌐
@ben@bluetoot.hardill.me.uk

Anybody know anything about TuranSec?

A CVE has been raised against a project I'm involved with by them, but I'm currently +95% sure it's a false positive.

Are they considered a trusted source?

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from ADP.

    Forced to change the password during the first login. At least they
    could use proper grammar in their rule list.

    dumbpasswordrules.com/sites/ad

      [?]Dumb Password Rules » 🤖 🌐
      @dumbpasswordrules@infosec.exchange

      This dumb password rule is from Apple.

      Can't contain 3 or more consecutive identical characters, nor can it be more than 63 characters long.

      dumbpasswordrules.com/sites/ap

        [?]ARGVMI~1.PIF » 🌐
        @argv_minus_one@mastodon.sdf.org

        [?]Dumb Password Rules » 🤖 🌐
        @dumbpasswordrules@infosec.exchange

        This dumb password rule is from Moose Mobile.

        Moose mobile is an Australian mobile service provider that imposes poor password requirements.
        "The password must be of minimum 4 and maximum 15 characters. The Confirm Password field may only contain alpha-numeric characters."

        dumbpasswordrules.com/sites/mo

          [?]Dumb Password Rules » 🤖 🌐
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from IBM.

          12-63 characters
          One uppercase character
          One lowercase character
          One number
          Sufficiently Strong
          Special characters are optional.
          Double byte characters are not allowed

          dumbpasswordrules.com/sites/ib

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from La Banque Postale.

            Password must be 6 digits and entered on custom pad.

            dumbpasswordrules.com/sites/la

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from WellStar MyChart.

              Your password must be between 8 and 20 characters.

              dumbpasswordrules.com/sites/we

                [?]Dumb Password Rules » 🤖 🌐
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from Saturn.

                Passwords need to be between 8 and 15 characters.

                dumbpasswordrules.com/sites/sa

                  [?]Mark Wyner Won’t Comply :vm: » 🌐
                  @markwyner@mas.to

                  Here’s something that will blow your mind. Most U.S. water systems have internet-based logic controllers. And a large number of them use NO PASSWORDS OR DEFAULT PASSWORDS.

                  Yeah. Public water systems ready for the hacking. Which came to light because there are signs of attacks. Enough of them that CISA had to issue a warning to all water facilities, recommending they disconnect them or actually use a fucking password.

                  CNN cites about 30 water systems were attacked this week, with six other states having reported related cyber incidents. A security expert in the water sector said “the scale and coordination of the recent cyberattacks targeting Minnesota water suppliers is unprecedented.”

                  cnn.com/2026/07/31/politics/sw

                    [?]Dumb Password Rules » 🤖 🌐
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from Minnesota Unemployment Insurance.

                    Locked to *exactly* 6 chars, alphanumeric only, not special chars.

                    dumbpasswordrules.com/sites/mi

                      [?]Dumb Password Rules » 🤖 🌐
                      @dumbpasswordrules@infosec.exchange

                      This dumb password rule is from Moose Mobile.

                      Moose mobile is an Australian mobile service provider that imposes poor password requirements.
                      "The password must be of minimum 4 and maximum 15 characters. The Confirm Password field may only contain alpha-numeric characters."

                      dumbpasswordrules.com/sites/mo

                        [?]mle✨ » 🌐
                        @mle@infosec.exchange

                        Following the cyberattacks on water & wastewater (WWS) in the U.S. over the last week, we looked at exposure of Rockwell, Siemens, and Schneider Electric devices, as those are vendors explicitly named in CISA’s updated advisory on this activity (cisa.gov/news-events/cybersecu).

                        Rockwell exposures have declined about 21% since we last looked at this in April, primarily driven by a drop in U.S. exposures.

                        While this is encouraging, I want to note this line from CISA’s most recent alert:
                        > Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses.

                        I’ll also note this from an FBI alert about the activity:
                        > At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers.

                        I’m going out on a limb to say this is not the same flavor of hacktivist activity we have seen around WWS in the recent past. This feels distinctly different and potentially more harmful.

                        More details on the exposures:

                        censys.com/blog/cisa-alert-wat

                          [?]mle✨ » 🌐
                          @mle@infosec.exchange

                          New from me: analysis of a June extortion campaign. In a departure from their previous targeting, the data stolen in this campaign may be a bit different than what they've taken in the past. The campaign targeted PTC's Windchill and FlexPLM products, product lifecycle management tools used in manufacturing and industrial engineering.

                          Rather than financial, HR, or customer data, the compromised data in this case may include things like supply chain details, product designs and schematics, and other intellectual property. This is particularly notable given the adoption of Windchill across the energy, electronics, medical device tech, and defense sectors.

                          Read more: censys.com/blog/cl0p-targets-w

                            [?]Dumb Password Rules » 🤖 🌐
                            @dumbpasswordrules@infosec.exchange

                            This dumb password rule is from Ticketmaster.de.

                            Your password length is limited between 8 and 32 characters.

                            dumbpasswordrules.com/sites/ti

                              [?]Dumb Password Rules » 🤖 🌐
                              @dumbpasswordrules@infosec.exchange

                              This dumb password rule is from GoDaddy.

                              Some characters are **too** special.

                              dumbpasswordrules.com/sites/go

                                Tim Hergert boosted

                                [?]Harry Sintonen » 🌐
                                @harrysintonen@infosec.exchange

                                Last night I "discovered" a vulnerability in a very widely used open-source tool. The tool is nearly 40 years old, and the vulnerability is at least 28 years old.

                                Interestingly, Apple has a fix included that dates it back to 2008, but it appears for whatever reason the fix never made it to upstream.

                                Result? Everyone else is vulnerable today. I am not pointing fingers here, but clearly something went wrong.

                                I've now reported the issue upstream, which will hopefully eventually lead to a fix being distributed to every affected platform.

                                I am not going to disclose the details of the vulnerability right now, even though the fix has been public for a very, very long time now. As far as I can tell, most Linux and BSD systems are vulnerable right now, so letting coordinated disclosure happen only makes sense.

                                  [?]Dumb Password Rules » 🤖 🌐
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Hetzner.

                                  - 8 or more characters
                                  - At least one uppercase and one lowercase letter
                                  - At least one number or special character

                                  Okay, fair enough, but after putting in a password with some special characters this message appears:
                                  - Invalid characters, allowed are: A-Z a-z 0-9 ä ö ü ß Ä Ö Ü ^ ! $ % / ( ) = ?...

                                  dumbpasswordrules.com/sites/he

                                    [?]R.L. Dane :Debian: :FreeBSD: :OpenBSD: :NetBSD:🍵 :MiraLovesYou: [he/him/my good fellow] » 🌐
                                    @rl_dane@polymaths.social

                                    @dalias @khm

                                    *sigh* this is why I made no attempt to get back into #infosec.

                                    If I wanted to be in "the theater," I'd act. 😄

                                      [?]Dumb Password Rules » 🤖 🌐
                                      @dumbpasswordrules@infosec.exchange

                                      This dumb password rule is from Crunchyroll.

                                      At least 6 characters.
                                      No spaces allowed.

                                      There is no password complexity required (no special characters, numbers, uppercase or lowercase letters required).
                                      You could make the password 123456. It also lets you change your password to your previously used password.

                                      dumbpasswordrules.com/sites/cr

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from PCPartPicker.

                                        There are no rules for passwords. Passwords can be any length (including one character)
                                        of any complexity. No password change confirmation emails are sent.

                                        dumbpasswordrules.com/sites/pc

                                          Socket boosted

                                          [?]AA » 🌐
                                          @AAKL@infosec.exchange

                                          This was posted yesterday.

                                          Socket: Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers socket.dev/blog/npm-rat-target @SocketSecurity

                                            [?]Dumb Password Rules » 🤖 🌐
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from CenturyLink.

                                            So many bad ideas: a low maximum length, requiring six specific character types while not accepting common symbols,
                                            plus a weird restriction that makes random generation harder.

                                            dumbpasswordrules.com/sites/ce

                                              [?]Dumb Password Rules » 🤖 🌐
                                              @dumbpasswordrules@infosec.exchange

                                              This dumb password rule is from Targobank.

                                              Your password must:
                                              - must not be your username
                                              - must at least eight characters
                                              - must contain at least one number character
                                              - must contain at least one uppercase character and 1 lowercase character
                                              - must not contain spaces
                                              - must not contain three identical characters in a row
                                              - must not conta...

                                              dumbpasswordrules.com/sites/ta

                                                [?]Mike Sheward » 🌐
                                                @SecureOwl@infosec.exchange

                                                Plexfiltration Update: One of the companies I've written to about their use of deleteduser.com (and internaluser.com actually, they are a two-fer) in email notifications, appears to be some sort of managed service desk who provide IT support for lots of smaller businesses

                                                They continually email me support tickets, many of which contain screenshots (see attached) of the systems being worked on - to include creds and things. (There are no creds or otherwise identifying info in the example below).

                                                I have had no response from this company and the tickets continue to flow in.

                                                Screenshot of someone troubleshooting a Microsoft SQL Server

                                                Alt...Screenshot of someone troubleshooting a Microsoft SQL Server

                                                  [?]Dumb Password Rules » 🤖 🌐
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Credit Union Australia (CUA) Health.

                                                  Password must be between 7 and 10 characters, contain both an uppercase and a lowercase letter and have at least one number.

                                                  dumbpasswordrules.com/sites/cr

                                                    [?]Chris 🏃 🐧 » 🌐
                                                    @cr@chaos.social

                                                    Uhm, I got that strange email from Stripe this morning. One of the API keys has been leaked. That API key was used in n8n and then later in Zapier.

                                                    Either way, good job on Stripe detecting this and I highly recommend checking your Zapier and n8n integrations. Something is off here.

                                                      [?]Dumb Password Rules » 🤖 🌐
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from Really Useful Storage Boxes.

                                                      - Have a length between 8 and 20 alphanumeric characters (without accents)
                                                      - Contain at least 1 CAPITAL letter
                                                      - Contain at least 1 lowercase letter
                                                      - Contain at least 1 numeric character
                                                      - Contain at least 1 special character taken from the following list: *$@&()[]{}=#.-!?+/£€%

                                                      dumbpasswordrules.com/sites/re

                                                        [?]your auntifa liza 🇵🇷 🦛 🦦 » 🌐
                                                        @blogdiva@mastodon.social

                                                        A QUESTION TO TOOTERS

                                                        had a friend call me about suspicious emails from their bank. they didn't respond but checked their accounts with the bank’s app. they saw transactions they didn't do but that were marked as done thru the app.

                                                        they wanted to know what to do. i told them:

                                                        1. call whichever fraud/stolen bank card number they found on the website immediately.
                                                        2. freeze the app but don’t uninstall yet
                                                        3. go to the bank immediately monday

                                                        they did so and called with updates… 🧵

                                                          [?]Dumb Password Rules » 🤖 🌐
                                                          @dumbpasswordrules@infosec.exchange

                                                          This dumb password rule is from Combank Digital.

                                                          Only a staggering 8-12 characters allowed with prescribed selection of special characters.

                                                          dumbpasswordrules.com/sites/co

                                                            [?]Dumb Password Rules » 🤖 🌐
                                                            @dumbpasswordrules@infosec.exchange

                                                            This dumb password rule is from Twilio.

                                                            Restriction in inclusion of characters such as 'Twilio' in password. Password must be 16 or more characters & Can't include 3 or more consecutive repeated characters.

                                                            dumbpasswordrules.com/sites/tw

                                                              [?]Wulfy—Speaker to the machines » 🌐
                                                              @n_dimension@infosec.exchange

                                                              @briankrebs

                                                              A full an exhaustive analysis (including the updated version) of the app is here:

                                                              atomic.computer/blog/white-hou

                                                              As a counterpoint, this security firm says "nothing to see here... because everything is shitty in mobile world"
                                                              nowsecure.com/blog/2026/03/31/

                                                              I am going with the 1st source, as it still has major designed-in anti-privacy/malware features.

                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                @dumbpasswordrules@infosec.exchange

                                                                This dumb password rule is from University of Western Australia (Pheme).

                                                                Passwords:
                                                                1. Must contain at least 8 characters;
                                                                2. Must contain at least 3 out of 4 types of characters
                                                                (uppercase letters, lowercase letters, digits, special characters);
                                                                and
                                                                3. Must not contain
                                                                "the user's account name or parts of the user's full name
                                                                that exceed two consecutive characters".
                                                                ...

                                                                dumbpasswordrules.com/sites/un

                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                  @dumbpasswordrules@infosec.exchange

                                                                  This dumb password rule is from Air France.

                                                                  - Between 8 to 12 characters
                                                                  - Should contain capital, lowercase letters and numbers

                                                                  dumbpasswordrules.com/sites/ai

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from CAF (French Family Allowance Fund).

                                                                    You have to enter your 8-digit password using this Frenchy keypad.

                                                                    dumbpasswordrules.com/sites/ca

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from NASA Earth Data.

                                                                      Username must:
                                                                      - Be a Minimum of 4 characters
                                                                      - Be a Maximum of 30 characters
                                                                      - Use letters, numbers, periods, and underscores
                                                                      - Not contain any blank spaces
                                                                      - Not begin, end or contain two consecutive special characters(._)

                                                                      Password must contain:
                                                                      - Minimum of 8 characters
                                                                      - One Uppercase letter...

                                                                      dumbpasswordrules.com/sites/na

                                                                        [?]Mike Sheward » 🌐
                                                                        @SecureOwl@infosec.exchange

                                                                        Plexfiltration update: the AI work zone compliance tool has started emailing me thousands of pictures from a (I think) Saudi industrial facility again, to my internaluser.com domain.

                                                                        some security camera still showing a group of people in a parking lot in front of a stop sign

                                                                        Alt...some security camera still showing a group of people in a parking lot in front of a stop sign

                                                                          [?]Thomas B. Rücker » 🌐
                                                                          @tbr@society.oftrolls.com

                                                                          Well that sure is going to be a "fun time" for the next couple of weeks/months for a lot of people…
                                                                          "Immediate kernel patching and a full reboot are the only reliable mitigations."
                                                                          bleepingcomputer.com/news/linu
                                                                          Is that Host Unknown and their smash hit "I accepted the risk" I'm starting to hear playing in the distance? 🙃

                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from Sephora.

                                                                            Password must be between 6 and 12 characters. No other rules
                                                                            specified.

                                                                            dumbpasswordrules.com/sites/se

                                                                              Socket boosted

                                                                              [?]AA » 🌐
                                                                              @AAKL@infosec.exchange

                                                                              Socket published this yesterday, if you missed it:

                                                                              Socket: Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign socket.dev/blog/github-actions @SocketSecurity

                                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                                @dumbpasswordrules@infosec.exchange

                                                                                This dumb password rule is from KPMG Talent Community.

                                                                                While stating otherwise, the site actually *accepts a backslash* in the password
                                                                                and displays a forward slash as the example of the disallowed backslash
                                                                                Password:
                                                                                - Must be at least 8 characters long
                                                                                - Must contain at least 1 number
                                                                                - Must contain at least 1 letter
                                                                                - Must contain at least 1 spec...

                                                                                dumbpasswordrules.com/sites/kp

                                                                                  Paco Hope boosted

                                                                                  [?]Scott Wilson 🌈 » 🌐
                                                                                  @scottwilson@infosec.exchange

                                                                                  Hot take:

                                                                                  I hate how all these articles talk about how OpenAI’s clanker “broke out” and attacked Hugging Face.

                                                                                  No, OpenAI’s dog slipped its chain because they don’t know what the hell they’re doing, and it bit another dog.

                                                                                  Little dog biting a person’s finger

                                                                                  Alt...Little dog biting a person’s finger

                                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                                    @dumbpasswordrules@infosec.exchange

                                                                                    This dumb password rule is from Dutch Tax Authorities (Belastingdienst).

                                                                                    At least 8 and at most 25 characters, of which at least 3 of the characters were not used in the previous password.
                                                                                    No more than 3 of the same characters.
                                                                                    At least 1 upper case and 4 lower case characters.
                                                                                    No more than 3 special characters.

                                                                                    It's not like hashing passwords is a thing or something.

                                                                                    dumbpasswordrules.com/sites/du

                                                                                      6 ★ 2 ↺
                                                                                      Mike Sheward boosted

                                                                                      [?]Sam » 🌐
                                                                                      @sam@cablespaghetti.dev

                                                                                      Fediverse, I have a rant I need to get off my chest. Groups in Google Workspace is a security nightmare and has been for years! Why has Google STILL not fixed the glaring problems!?

                                                                                      I've had admin powers at 5+ companies' Google Workspace/G Suite over the past decade or so. Every single one had groups which were misconfigured, often so anyone in the whole company could join without approval or see the message history at https://groups.google.com without being a member at all.

                                                                                      This is because for any sensible configuration of Google Groups when using it for email groups you have to use the "Custom" permissions mode. The default Public mode doesn't allow external people to email the group, but does allow the whole company to see all the messages. The default Team mode, has the same problem of everyone being able to see all the messages.

                                                                                      Also let's not forget that dangerous little "Anyone in the organisation can join" toggle at the bottom which is on by default. So any random new starter can join your confidential company directors group and get all the emails sent to it.

                                                                                      Giving Google the benefit of the doubt here, I think the reasoning might be that Google Groups is intended as a kind of company forum, not for private email groups. However that isn't how anyone uses it in my experience...


                                                                                      Screenshot of the default Google Group settings for team mode

                                                                                      Alt...Screenshot of the default Google Group settings for team mode

                                                                                      Screenshot of the default Google Group settings for public mode

                                                                                      Alt...Screenshot of the default Google Group settings for public mode