cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #cybersecurity

[?]Dumb Password Rules » 🤖
@dumbpasswordrules@infosec.exchange

This dumb password rule is from Fidelity National Information Services.

White label online banking provider. Typically appears as `BANK.ibanking-services.com` or `BANK.ebanking-services.com`. If your small local bank has a crappy online banking experience, these guys probably provide it.

`\<>'` and spaces prohibited, upper bound. Passwords of exactly the maximum len...

dumbpasswordrules.com/sites/fi

    [?]Dumb Password Rules » 🤖
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from Mindware.

    You "*may use special characters*", but only some of them - and we won't
    necessarily tell you which ones.

    dumbpasswordrules.com/sites/mi

      [?]Matthew Clover »
      @clovertalk@mastodon.social

      Solid reporting on some serious security vulnerabilities found in all Coros devices that Coros initially did not address appropriately. They have now provided a timeline for updates which hopefully they can hit. Not a great look, and, as the article mentions, pretty typical reactive security versus proactive security that is way too common in this day and age. dcrainmaker.com/2025/06/coros-

        [?]Dumb Password Rules » 🤖
        @dumbpasswordrules@infosec.exchange

        [?]nullagent »
        @nullagent@partyon.xyz

        11. Limited protocol privacy behavior by default responds to certain protocol events unless in specific mode (client_hidden). But they still leak data sometimes, possibly bugs???
        12. Lack of strategy on #11 means once you know a node's ID you can track it trivially both via MQTT or physically or even via BLE or Wifi.

        And if you've seen my defcon talk.... you probably can figure out what I can do with #1, #2 #11 and #12 🤔

          [?]nullagent »
          @nullagent@partyon.xyz

          #13 No conversation privacy in default scalable configuration. Anyone can see your to/from fields and bc #1 it's great metadata.

          Need to verify how bad #13 is, I think you can mitigate but most people use a public channel. The header I think its technically encrypted BUT with a known public key so everyone can see whose talking to whom. I think you can get encrypted headers on the public channel but docs aren't clear and probably limits your hops.

            [?]nullagent »
            @nullagent@partyon.xyz

            Finally I suspect that IF meshtastic ever does fix their routing algo they will suffer from MITM exploits due to issues around #1, #6, #8, and #9.

            Bc when you have MAC as the root of trust I can respond to your MAC and poison the routing table.

            There might even by a solid security downgrade attack here too bc they have backwards compatibility for insecure DMs. So once I clone your MAC I can also downgrade security and ppl are trained to accept downgrades.

              [?]Dumb Password Rules » 🤖
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from BinckBank.

              Between 10 and 16 letters and/or digits. No special characters are allowed.
              Must be renewed at least every 180 days, but you can configure to let the password expire sooner.
              When changing the password, the new password cannot be too similar to the existing password.

              dumbpasswordrules.com/sites/bi

                [?]Scott Wilson »
                @scottwilson@infosec.exchange

                Man, this seems really bad.

                But at least our government isn’t pulling back on the we need to protect this information!

                Whew!

                npr.org/2025/06/29/nx-s1-54096

                  [?]Dumb Password Rules » 🤖
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from Cigna.

                  A max of 12 characters... Can't handle most symbols (only 5 supported). At least they have two factor auth via email or sms **sigh**

                  dumbpasswordrules.com/sites/ci

                    [?]Dumb Password Rules » 🤖
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from LepidaID.

                    Password must:
                    - be 8 to 16 characters in length
                    - contain at least 1 upper-case character
                    - contain at least 1 lower-case character
                    - contain at least 1 number
                    - contain at least 1 non-alphanumeric character
                    - not contain more than 2 of the same consecutive characters
                    - not contain any public da...

                    dumbpasswordrules.com/sites/le

                      [?]Dumb Password Rules » 🤖
                      @dumbpasswordrules@infosec.exchange

                      [?]AA »
                      @AAKL@infosec.exchange

                      Microsoft security advisories, posted yesterday, affecting six Chromium-based Edge vulnerabilities.

                      Microsoft security update guide: msrc.microsoft.com/update-guide

                        [?]Dumb Password Rules » 🤖
                        @dumbpasswordrules@infosec.exchange

                        This dumb password rule is from Arlo.

                        Your password contains characters not listed. Therefore, they do not
                        match.

                        dumbpasswordrules.com/sites/ar

                          [?]Dumb Password Rules » 🤖
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from EON.

                          By the time I'd finished reading the rules I've forgotten all of them.

                          dumbpasswordrules.com/sites/eo

                            [?]CatSalad🐈🥗 (D.Burch) :blobcatrainbow: »
                            @catsalad@infosec.exchange

                            Big list of Bsides and hacker conferences in the fediverse (Updated:2023-10-18) [SENSITIVE CONTENT]

                            InfoSec Events by Region

                            This list only contains accounts for security bsides, events, and conferences found on Mastodon :mastodon: and in the fediverse. I will regular update this post as more events migrate here. For hacker meet-ups and hackerspaces, please refer to the links below.

                            📌⁠InfoSec Events by Region
                            📌⁠Hacker Meet-ups by Region
                            📌⁠Hackerspaces by Region

                            🐈🥗

                            ⸻ Event Info

                            @cfp_time - Call for Papers ()
                            @InfoCon@defcon.social -
                            @InfoconDB - archive
                            @SecurityBSidesGlobal - Security BSides Global

                            ⸻ Online 🌐

                            @ComfyConAU -
                            @Digit4lOverdose - D.O. Conference
                            @pancakescon -

                            ⸻ Canada 🇨🇦

                            @BSidesCalgary - , AB
                            @BSidesEdmonton - , AB
                            @BSidesFredericton - BSidesFredericton, NB
                            @BSidesMTL - Montreal, QC
                            @BSidesOttawa - , ON
                            @BSidesRegina - , SK
                            @BSidesStJohns- , NL
                            @BSidesTO - Toronto, ON
                            @BSidesVancouver - , BC
                            @BSidesVI - Vancouver Island, BC
                            @hackfest - Québec City, QC
                            @halifaxbsides - , NS
                            @NorthSec - Montréal, QC
                            @polar - POLAR Conf, QC
                            @seqcure - Québec, QC
                            @thelongcon - Winnipeg, MB

                            ⸻ US - Northeast

                            @bsidesboston - , MA
                            @BSidesBuffalo - , NY
                            @BSidesCambridgeMA - , MA
                            @BSidesCharm - Towson, MD
                            @BSidesCT - Hamden, CT
                            @BSidesFloodCity - Johnstown, PA
                            @BSidesHBG - Harrisburg, PA
                            @BSidesNJ - ? NJ
                            @BSidesNYC - New York City, NY
                            @bsidesphilly - Philadelphia, PA
                            @bsidespgh - Pittsburgh, PA
                            @bsidesroc - Rochester, NY
                            @hushcon - New York City, NY
                            @jawncon - Philadelphia, PA
                            @pumpcon - Philadelphia, PA
                            @ShmooCon - Washington, DC
                            @SummerC0n - Brooklyn, NY

                            ⸻ US - Midwest

                            @BlueTeamCon - Chicago, IL
                            @bsides312 - Chicago, IL
                            @BSidesBloomington - , IN
                            @BSides_BTown - Bloomington, IN
                            @bsidesboulder - , CO
                            @bsideschicago - , IL
                            @BSidesColoradoSprings - , CO
                            @BSidesColumbus - , OH
                            @bsidesdayton - , OH
                            @bsidesdenver - , CO
                            @BSidesFtWayne - , IN
                            @bsideskc - Kansas City, MO
                            @BSidesMilwaukee - , WI
                            @BSidesPeoria - , IL
                            @bsidesspfd - Springfield, MO
                            @CircleCityCon - Indianapolis, IN
                            @CypherCon - Milwaukee, WI
                            @GrrCON - Grand Rapids, MI
                            @thotcon - Chicago, IL
                            @WWHackinFest - Deadwood, SD

                            ⸻ US - West

                            @bsidescv - Central Valley, CA
                            @BSidesHawaii - Honolulu, HI
                            @bsidesla - Los Angeles, CA
                            @BSidesPDX - Portland, OR
                            @BsidesSD - San Diego, CA
                            @bsidesseattle - , WA
                            @bsidessf - San Francisco, CA
                            @soups - Symposium on Usable Privacy and Security, Anaheim, CA

                            ⸻ US - Southwest

                            @AustinHackers - Austin, TX
                            @BSidesAlbuquerque - , NM
                            @bsidesaustin - , TX
                            @BSidesDFW - Dallas-Fort Worth, TX
                            @BSidesLV - Las Vegas, NV
                            @BSidesRGV - Rio Grande Valley, McAllen, TX
                            @BSidesSATX - San Antonio, TX
                            @BSidesSantaFe - , NM
                            @BSidesTucson - , AZ
                            @cactuscon - Mesa, AZ
                            @defcon - Las Vegas, NV
                            @DianaInitiative - Las Vegas, NV

                            ⸻ US - Southeast

                            @bsidesatl - Atlanta, GA
                            @BSidesAugusta - , GA
                            @BSidesBirmingham - , AL
                            @BSidesCharleston - , SC
                            @BSidesCLT - Charlotte, NC
                            @BSidesCHS - Charleston, SC
                            @BSidesCharlotte - , NC
                            @BSidesGVL - Greenville, SC
                            @BSidesHSV - Hunstville, AL
                            @BSidesJAX - , Jacksonville, FL
                            @bsideskc - Kansas City, MO
                            @bsidesknoxville - , TN
                            @BSidesNOLA - BSidesNOLA New Orleans, LA
                            @BSidesNoVA - Arlington, VA
                            @bsidesorlando - , FL
                            @BSidesRoanoke - , VA
                            @BSidesRDU - Raleigh/Durham, NC
                            @bsidesspfd - Springfield, MO
                            @bsidesSTL - St. Louis, MO
                            @BSidesStPete - St. Petersburg, FL
                            @BSidesTampa - , FL
                            @CackalackyCon - Con, Raleigh, NC
                            @CYBERWARCON - Arlington, VA
                            @securityonion - Con, Augusta, GA

                            ⸻ US - Territories

                            @BSidesPR - San Juan, PR 🇵🇷

                            ⸻ Caribbean

                            @BSidesCaymanIslands - , KY 🇰🇾

                            ⸻ Latin America

                            @BSidesArgentina - Jujuy, Argentina 🇦🇷
                            @bsidescdmx - Mexico City, Mexico 🇲🇽
                            @BSidesCO - Bogotá, Colombia 🇨🇴
                            @bsidesjp - , Brazil 🇧🇷
                            @BSidesPeru - Lima, Peru 🇵🇪
                            @BSidesPanama - Panama City, Panama 🇵🇦
                            @BSidesSP - Sao Paulo, Brazil 🇧🇷
                            @BSidesVitória - , Brazil 🇧🇷

                            ⸻ Europe 🇪🇺

                            @botconf - Nice, FR 🇫🇷
                            @brucon - Mechelen, BE 🇧🇪
                            @BSidesAthens - , GR 🇬🇷
                            @BSidesBUD - Budapest, HU 🇭🇺
                            @BSidesCyprus - Limassol, CY 🇨🇾
                            @BSidesDublin - , IE 🇮🇪
                            @BSidesKraków - , PL 🇵🇱
                            @bsideskbh - København, DK 🇩🇰
                            @bsideslisbon - , PT 🇵🇹
                            @bsidesljubljana - , SI 🇸🇮
                            @BSidesMilano - , IT 🇮🇹
                            @BSidesOsijek - , HR 🇭🇷
                            @bsidesoslo - , NO 🇳🇴
                            @BSidesPrishtina - , XK 🇽🇰
                            @BSidesRoma - , IT 🇮🇹
                            @bsidesrvk - , IS 🇮🇸
                            @BSidesSOF - Sofia, BG 🇧🇬
                            @BSidesTallinn - , EE 🇪🇪
                            @BSidesTirana - , AL 🇦🇱
                            @BSidesTransylvania - Cluj-Napoca, RO 🇷🇴
                            @BSidesUmeå - , SE 🇸🇪
                            @bsidesvienna - , AT 🇦🇹
                            @BSidesZurich - , CH 🇨🇭
                            @deepsec - Con, Vienna, AT 🇦🇹
                            @hack_lu - , LU 🇱🇺
                            @passthesaltcon - Pass the SALT Con, Lille, FR 🇫🇷
                            @SEC_T - SEC-T Con, Stockholm, SE 🇸🇪
                            @securitybsidesitalia - IT 🇮🇹
                            @TumpiConIT - Turin area, IT 🇮🇹

                            ⸻ Germany 🇩🇪

                            @BSidesBerlin -
                            @BSidesFrankfurt - am Main
                            @BSidesMunich -
                            @BSidesStuttgart -
                            @elbsides - Hamburg
                            @WEareTROOPERS - TROOPERS Conference, Heidelberg

                            ⸻ United Kingdom 🇬🇧

                            @44CON - London 🏴󠁧󠁢󠁥󠁮󠁧󠁿
                            @AbertayHackers - Abertay, Dundee, 🏴󠁧󠁢󠁳󠁣󠁴󠁿
                            @BSidesBasingstoke -
                            @BSidesBelfast -
                            @BSidesBHAM - Birmingham 🏴󠁧󠁢󠁥󠁮󠁧󠁿
                            @BSidesBristol -
                            @BSidesCambridge -
                            @BSidesCheltenham - 🏴󠁧󠁢󠁥󠁮󠁧󠁿
                            @BSidesDundee -  🏴󠁧󠁢󠁳󠁣󠁴󠁿
                            @BSidesExeter -
                            @BSidesLancashire -
                            @bsidesleeds - 🏴󠁧󠁢󠁥󠁮󠁧󠁿
                            @BSidesNewcastle -
                            @VirusBulletin - VirusBulletin, London 🏴󠁧󠁢󠁥󠁮󠁧󠁿

                            ⸻ Africa

                            @BSidesCapeTown - , South Africa 🇿🇦
                            @BSidesNairobi - , Kenya 🇰🇪

                            ⸻ India 🇮🇳

                            @BSidesAhmedabad -
                            @BSidesBangalore -
                            @BSidesChennai -
                            @BSidesIndore -
                            @BSidesJaipur -
                            @bsidesodisha -

                            ⸻ Asia

                            @BSidesMyanmar - , Myanmar 🇲🇲
                            @BSidesSG - Singapore, China 🇨🇳
                            @BSidesTokyo - , Japan 🇯🇵
                            @BSidesYerevan - , Armenia 🇦🇲

                            ⸻ Australasia

                            @bsides_bne - Brisbane, AU 🇦🇺
                            @bsidescbr - , AU 🇦🇺
                            @bsidesmelbourne - , AU 🇦🇺
                            @bsidesperth - , AU 🇦🇺
                            @bsidessydney - , AU 🇦🇺
                            @crikeycon - Brisbane, AU 🇦🇺


                            For other events not in the fediverse try:
                            ➡️⁠securitybsides.com
                            ➡️⁠github.com/xsa/infosec-events by Xavier Santolaria @0x58

                            Feel free use, copy, modify, steal, boost, encrypt, or plagiarize this information anyway you want.
                            :cc_cc:​𝟶 "No Rights Reserved"


                            [?]CatSalad🐈🥗 (D.Burch) :blobcatrainbow: »
                            @catsalad@infosec.exchange

                            Big list of Bsides and hacker conferences in the fediverse (Updated:2025-06-26) [SENSITIVE CONTENT]

                            InfoSec Events by Region

                            This list only contains accounts for security bsides, events, and conferences found on Mastodon :mastodon: and in the fediverse. I will regular update this post as more events migrate here. For hacker meet-ups and hackerspaces, please refer to the links below.

                            📌⁠InfoSec Events by Region
                            📌⁠Hacker Meet-ups by Region
                            📌⁠Hackerspaces by Region

                            🐈🥗

                            Event Info

                            @cfp_time - Call for Papers ()
                            @InfoCon -
                            @InfoconDB - archive
                            @SecurityBSidesGlobal - Security BSides Global

                            Online 🌐

                            @ComfyConAU -
                            @Digit4lOverdose - D.O. Conference
                            @pancakescon -

                            Americas

                            ⸻ Canada 🇨🇦

                            ⸺ CA - Eastern

                            (ɴʙ ɴʟ ɴs ᴏɴ ᴘᴇ ɋᴄ)
                            @BSidesFredericton - , NB
                            @BSidesMTL - MTL Montreal, QC
                            @BSidesOttawa - Ottawa, ON
                            @BSidesStJohns - , NL
                            @BSidesToronto - , ON
                            @hackfest - Québec City, QC
                            @halifaxbsides - , NS
                            @NorthSec - Montréal, QC
                            @polar - POLAR Conf, QC
                            @seqcure - Québec, QC

                            ⸺ CA - Western 🇨🇦

                            (ᴀʙ ʙᴄ ᴍʙ sᴋ)
                            @BSidesCalgary - Calgary, AB
                            @bsidesedmonton - , AB
                            @BSidesRegina - Regina, SK
                            @bsidesyxe - , SK
                            @BSidesVancouver - Vancouver, BC
                            @BSidesVI - Vancouver Island, BC
                            @thelongcon - Winnipeg, MB

                            ⸻ United States 🇺🇸

                            ⸺ US - Northeast

                            (ᴅᴇ ᴄᴛ ᴍᴀ ᴍᴅ ᴍᴇ ɴʜ ɴᴊ ɴʏ ᴘᴀ ʀɪ ᴠᴛ)
                            @bsidesboston - , MA
                            @BSidesBuffalo - , NY
                            @BSidesCambridgeMA - , MA
                            @BSidesCharm - Towson, MD
                            @BSidesCT - Hamden, CT
                            @BSidesDE - Newark, DE
                            @BSidesFloodCity - Johnstown, PA
                            @bsideshbg - Harrisburg, PA
                            @BSidesNJ - ? NJ
                            @BSidesNYC - New York City, NY
                            @bsidesphilly - Philadelphia, PA
                            @bsidespgh - Pittsburgh, PA
                            @bsidesroc - Rochester, NY
                            @hushcon - New York City, NY
                            @jawncon - Philadelphia, PA
                            @pumpcon - Philadelphia, PA
                            @ShmooCon - Washington, DC
                            @SummerC0n - Brooklyn, NY

                            ⸺ US - Midwest

                            (ɪᴀ ɪʟ ᴋs ᴍɪ ᴍɴ ᴍᴏ ɴᴅ ɴᴇ ᴏʜ sᴅ ᴡɪ)
                            @BlueTeamCon - Chicago, IL
                            @bsides312 - Chicago, IL
                            @BSIDESBloomington - , IN
                            @BSides_BTown - Bloomington, IN
                            @bsideschicago - , IL
                            @BSidesColumbus - Columbus, OH
                            @bsidesdayton - , OH
                            @BSidesFtWayne - Ft. Wayne, IN
                            @bsideskc - Kansas City, MO
                            @BSidesMilwaukee - Milwaukee, WI
                            @BSidesPeoria - Peoria, IL
                            @bsidesspfd - Springfield, MO
                            @bsidestc - Minneapolis, MN
                            @CircleCityCon - Indianapolis, IN
                            @CypherCon - Milwaukee, WI
                            @GrrCON - Grand Rapids, MI
                            @thotcon - Chicago, IL
                            @WWHackinFest - Deadwood, SD

                            ⸺ US - West

                            (ᴀᴋ ᴄᴀ ᴄᴏ ʜɪ ɪᴅ ᴍᴛ ɴᴠ ᴏʀ ᴜᴛ ᴡᴀ ᴡʏ)
                            @bsidesboulder - , CO
                            @bsidescv - Central Valley, CA
                            @bsidesdenver - , CO
                            @BSidesHawaii - Honolulu, HI
                            @bsidesla - Los Angeles, CA
                            @BSidesLV - Las Vegas, NV
                            @BSidesPDX - Portland, OR
                            @BsidesSD - San Diego, CA
                            @bsidesseattle - , WA
                            @bsidessf - San Francisco, CA
                            @defcon - Las Vegas, NV
                            @DianaInitiative - Las Vegas, NV
                            @SAINTCON - Provo, UT
                            @soups - Symposium on Usable Privacy and Security, Anaheim, CA

                            ⸺ US - Southwest

                            (ᴀᴢ ɴᴍ ᴏᴋ ᴛx)
                            @AustinHackers - Austin, TX
                            @BSidesAlbuquerque - Albuquerque, NM
                            @bsidesaustin - , TX
                            @BSidesDFW - Dallas-Fort Worth, TX
                            @BSidesRGV - Rio Grande Valley, McAllen, TX
                            @BSidesSATX - San Antonio, TX
                            @BSidesSantaFe - Santa Fe, NM
                            @BSidesTucson - Tucson, AZ
                            @cactuscon - Mesa, AZ

                            ⸺ US - Southeast

                            (ᴀʟ ᴀʀ ᴅᴄ ғʟ ɢᴀ ᴋʏ ʟᴀ ᴍs ɴᴄ sᴄ ᴛɴ ᴠᴀ ᴡᴠ)
                            @bsidesatl - Atlanta, GA
                            @BSidesAugusta - , GA
                            @BSidesBHAM - , AL
                            @BSidesCharleston - , SC
                            @BSidesCLT - Charlotte, NC
                            @BsidesCHS - Charleston, SC
                            @BSidesCharlotte - , NC
                            @BsidesGVL - Greenville, SC
                            @BsidesHSV - Hunstville, AL
                            @bsidesjax - , Jacksonville, FL
                            @bsideskc - Kansas City, MO
                            @bsidesknoxville - , TN
                            @BsidesNOLA - New Orleans, LA
                            @bsidesnova - Arlington, VA
                            @bsidesorlando - , FL
                            @BsidesRoanoke - Roanoke, VA
                            @BSidesRDU - Raleigh/Durham, NC
                            @bsidesspfd - Springfield, MO
                            @bsidesSTL - St. Louis, MO
                            @BsidesStPete - St. Petersburg, FL
                            @BsidesTampa - Tampa, FL
                            @CackalackyCon - Con, Raleigh, NC
                            @CYBERWARCON - Arlington, VA
                            @securityonion - Augusta, GA

                            ⸺ US - Territories

                            @BSidesPR - San Juan, PR 🇵🇷

                            ⸻ Caribbean

                            @BSidesCaymanIslands - Cayman Islands, KY 🇰🇾

                            ⸻ Latin America

                            @BSidesArgentina - Jujuy, Argentina 🇦🇷
                            @bsidescdmx - Mexico City, Mexico 🇲🇽
                            @BSidesCO - Bogotá, Colombia 🇨🇴
                            @bsidesjp - João Pessoa, Brazil 🇧🇷
                            @BSidesPeru - Lima, Peru 🇵🇪
                            @BSidesPanama - Panama City, Panama 🇵🇦
                            @BSidesSP - Sao Paulo, Brazil 🇧🇷
                            @BSidesVitória - Vitória, Brazil 🇧🇷

                            Europe

                            ⸻ EU 🇪🇺

                            @botconf - Nice, FR 🇫🇷
                            @brucon - Mechelen, BE 🇧🇪
                            @BSidesAthens - Athens, GR 🇬🇷
                            @bsidesba - Bratislava, SK 🇸🇰
                            @BSidesBUD - Budapest, HU 🇭🇺
                            @BSidesCyprus - Limassol, CY 🇨🇾
                            @bsidesdub - , IE 🇮🇪
                            @bsidesgrunn - , NL 🇳🇱
                            @BSidesKrakow - Kraków, PL 🇵🇱
                            @bsideskbh - København, DK 🇩🇰
                            @bsideslisbon - , PT 🇵🇹
                            @bsidesljubljana - , SI 🇸🇮
                            @BSidesLuxembourg - , LU 🇱🇺
                            @bsidesmalaga - , ES 🇪🇸
                            @BSidesMilano - Milano, IT 🇮🇹
                            @BSidesOsijek - Osijek, HR 🇭🇷
                            @bsidesoslo - , NO 🇳🇴
                            @bsidesprg - , CZ 🇨🇿
                            @BSidesPrishtina - Prishtina, XK 🇽🇰
                            @BSidesRoma - Roma, IT 🇮🇹
                            @bsidesrvk - , IS 🇮🇸
                            @SEC_T - SEC-T Con, Stockholm, SE 🇸🇪
                            @BSidesSOF - Sofia, BG 🇧🇬
                            @BSidesTallinn - , EE 🇪🇪
                            @BSidesTirana - Tirana, AL 🇦🇱
                            @BSidesTransylvania - Transylvania Cluj-Napoca, RO 🇷🇴
                            @BSidesUme - Umeå, SE 🇸🇪
                            @bsidesvienna - , AT 🇦🇹
                            @BSidesZurich - , CH 🇨🇭
                            @deepsec - Vienna, AT 🇦🇹
                            @hack_lu - , LU 🇱🇺
                            @leHACK - Paris, FR 🇫🇷
                            @passthesaltcon - Pass the SALT Con, Lille, FR 🇫🇷
                            @securitybsidesitalia - IT 🇮🇹
                            @TumpiConIT - Turin area, IT 🇮🇹

                            ⸺ Germany 🇩🇪

                            @BalCCon - Berlin
                            @BSidesBerlin -
                            @bsidesfra - Frankfurt
                            @bside -
                            @BSidesMunich -
                            @bsidesstuttgart -
                            @elbsides - Hamburg
                            @WEareTROOPERS - TROOPERS Con, Heidelberg

                            ⸺ United Kingdom 🇬🇧

                            @44CON - London 🏴󠁧󠁢󠁥󠁮󠁧󠁿
                            @AbertayHackers - Abertay, Dundee, 🏴󠁧󠁢󠁳󠁣󠁴󠁿
                            @BSidesBasingstoke - Basingstoke
                            @BSidesBelfast - Belfast
                            @BSidesBristol - Bristol
                            @BSidesCambridge - Cambridge
                            @BSidesCheltenham - 🏴󠁧󠁢󠁥󠁮󠁧󠁿
                            @BSidesDundee - Dundee
                            @bsidesexeter - Exeter 🏴󠁧󠁢󠁥󠁮󠁧󠁿
                            @BSidesLancashire - Lancashire
                            @bsidesleeds - 🏴󠁧󠁢󠁥󠁮󠁧󠁿
                            @BSidesNewcastle - Newcastle
                            @VirusBulletin - , London 🏴󠁧󠁢󠁥󠁮󠁧󠁿

                            Africa

                            @BSidesCapeTown - CapeTown, South Africa 🇿🇦
                            @bsidesjoburg - Joburg, South Africa 🇿🇦
                            @BSidesNairobi - Nairobi, Kenya 🇰🇪

                            Asia

                            ⸻ India 🇮🇳

                            @BSidesAhmedabad - Ahmedabad
                            @BSidesBangalore -
                            @BSidesChennai - Chennai
                            @BSidesIndore - Indore
                            @BSidesJaipur - Jaipur
                            @bsidesodisha -

                            ⸻ East Asia

                            @BSidesMyanmar - Myanmar, Myanmar 🇲🇲
                            @BSidesSG - Singapore, China 🇨🇳
                            @BSidesTokyo - Tokyo, Japan 🇯🇵
                            @BSidesYerevan - Yerevan, Armenia 🇦🇲

                            ⸻ Australasia

                            @bsides_bne - Brisbane, AU 🇦🇺
                            @bsidescbr - , AU 🇦🇺
                            @bsidesmelbourne - , AU 🇦🇺
                            @bsidesperth - , AU 🇦🇺
                            @bsidessydney - , AU 🇦🇺
                            @crikeycon - Brisbane, AU 🇦🇺


                            For other events not in the fediverse try:
                            ➡️⁠securitybsides.com
                            ➡️⁠github.com/xsa/infosec-events by Xavier Santolaria @0x58

                            Feel free use, copy, modify, steal, boost, encrypt, or plagiarize this information anyway you want.
                            :cc_cc:​𝟶 "No Rights Reserved"



                            [?]Dumb Password Rules » 🤖
                            @dumbpasswordrules@infosec.exchange

                            This dumb password rule is from T-Mobile.

                            We prefer to not tell you which characters you can use up front.

                            dumbpasswordrules.com/sites/t-

                              Tim Hergert boosted

                              [?]BeyondMachines :verified: » 🤖
                              @beyondmachines1@infosec.exchange

                              Threat group Educated Manticore targets academia and cybersecurity experts

                              CheckPoint reports that the Iranian state-sponsored threat group "Educated Manticore" has escalated cyber espionage operations since mid-June 2025, targeting Israeli academics, journalists, and cybersecurity professionals through social engineering campaigns via email and WhatsApp that exploit Iran-Israel tensions to create urgency. The attacks feature advanced phishing infrastructure with multi-factor authentication bypass capabilities and real-time keystroke logging via WebSocket connections.

                              **Whatever the attack motivation or the initial social engineering, all these attacks end up with an insistence for you to click on something and enter credentials. Be extremely suspicious of unexpected emails or messages, and verify independently - all or email the organization through official contact channel on the official site. NEVER click on links or call numbers in the unexpected message.**

                              beyondmachines.net/event_detai

                                [?]BeyondMachines :verified: » 🤖
                                @beyondmachines1@infosec.exchange

                                Vulnerabilities reported in Brother printers and other vendors, at least one critical

                                Brother Industries and four other major printer manufacturers have disclosed eight security vulnerabilities affecting 748 models of multifunction printers, including a critical authentication bypass flaw (CVE-2024-51978) that allows unauthenticated attackers to generate default administrator passwords using a predictable algorithm and cannot be fully patched through firmware updates.

                                **If you have Brother printers (or multifunction devices from FUJIFILM, Ricoh, Toshiba Tec, or Konica Minolta), immediately change all default administrator passwords since they probably have a flaw that allows attackers to generate these passwords and can't be fully patched. Alsom, make sure the printer are not accessible from the internet. Then apply the latest firmware updates to fix the other flaws.**

                                beyondmachines.net/event_detai

                                  [?]Dumb Password Rules » 🤖
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Techcombank.

                                  Your password must:
                                  - Be between 6 and 8 characters long
                                  - Contains at least 1 number character
                                  - Contains at least 1 lowercase character
                                  - Contains at least 1 uppercase character
                                  - Neither space nor unicode character is allowed. In fact,
                                  NO special characters is allowed
                                  - Must be changed every 9...

                                  dumbpasswordrules.com/sites/te

                                    [?]Dumb Password Rules » 🤖
                                    @dumbpasswordrules@infosec.exchange

                                    This dumb password rule is from Ticketmaster.de.

                                    Your password length is limited between 8 and 32 characters.

                                    dumbpasswordrules.com/sites/ti

                                      2 ★ 0 ↺

                                      [?]sam »
                                      @sam@cablespaghetti.dev

                                      We need regulation on stuff like NOT LINKING THE DRIVE TRAIN OF CARS TO THE INFOTAINMENT! Do these companies have even one infosec person working on their 100mph metal boxes? https://hackaday.social/users/hackaday/statuses/114742241359167235

                                        [?]Dumb Password Rules » 🤖
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from Bloomingdale's.

                                        16 characters maximum, no `.` `,` `-` `|` `/` `=` or `_` allowed.

                                        dumbpasswordrules.com/sites/bl

                                          [?]Dumb Password Rules » 🤖
                                          @dumbpasswordrules@infosec.exchange

                                          This dumb password rule is from MySwissLife.

                                          User ID *has to* be 8 characters exactly, password *has to be* 8 characters and numbers only.

                                          dumbpasswordrules.com/sites/my

                                            [?]Jan Penfrat »
                                            @ilumium@eupolicy.social

                                            Fun times ahead in Europe 🙄

                                            "The @EUCommission has set out its plans to give access to digital information, including by cracking down on “non-cooperative” messaging services [like @signalapp and ] and helping build technologies to break ."

                                              [?]Terence Eden »
                                              @Edent@mastodon.social

                                              🆕 blog! “Reading NFC Passport Chips in Linux”

                                              For boring and totally not nefarious reasons, I want to read all the data contained in my passport's NFC chip using Linux. After a long and annoying search, I settled on roeften's pypassport.

                                              I can now read all the passport information, including biometrics.

                                              👀 Read more: shkspr.mobi/blog/2025/06/readi

                                                [?]Dumb Password Rules » 🤖
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from BMW ConnectedDrive.

                                                Although the prompt suggests good things, after many failed attempts to
                                                set a new password, it turns out you can ONLY use the special characters
                                                shown in the prompt

                                                dumbpasswordrules.com/sites/bm

                                                  [?]Dumb Password Rules » 🤖
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Keimyung University.

                                                  Okay, doesn't looks that hard... But wait, there are hidden rules!

                                                  Hidden rules: your password can't have 3 times the same character in a row or more than 2 consecutive numbers.
                                                  Also if your password is 20 characters or more you won't be able to write it in the mobile app.

                                                  dumbpasswordrules.com/sites/ke

                                                    [?]Dumb Password Rules » 🤖
                                                    @dumbpasswordrules@infosec.exchange

                                                    This dumb password rule is from Irodoricomics.

                                                    A website to buy english-localized doujins. The password must be between 4 and 20 characters long

                                                    dumbpasswordrules.com/sites/ir

                                                      [?]Dumb Password Rules » 🤖
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from Bloomingdale's.

                                                      16 characters maximum, no `.` `,` `-` `|` `/` `=` or `_` allowed.

                                                      dumbpasswordrules.com/sites/bl

                                                        [?]Dumb Password Rules » 🤖
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from University of Western Australia (Pheme).

                                                        Passwords:
                                                        1. Must contain at least 8 characters;
                                                        2. Must contain at least 3 out of 4 types of characters
                                                        (uppercase letters, lowercase letters, digits, special characters);
                                                        and
                                                        3. Must not contain
                                                        "the user's account name or parts of the user's full name
                                                        that exceed two consecutive characters".
                                                        ...

                                                        dumbpasswordrules.com/sites/un

                                                          [?]Dumb Password Rules » 🤖
                                                          @dumbpasswordrules@infosec.exchange

                                                          This dumb password rule is from Sharekhan.

                                                          - At least 8 characters.
                                                          - At most 12 characters.

                                                          dumbpasswordrules.com/sites/sh

                                                            [?]Open Rights Group »
                                                            @openrightsgroup@social.openrightsgroup.org

                                                            For ORG's 20th birthday, our partners Surfshark VPN are offering a special gift 🎁

                                                            The first 20 new members will get a free Surfshark One package – VPN, Antivirus, Alternative ID and Alert & Search services, plus much more!

                                                            Join ORG today and support the fight for digital rights in the UK.

                                                            ➡️ openrightsgroup.org/join/

                                                            Typographic image of 'ORG20' in a 3D perspective with a green overlay of the text offset and '20 years' above it. Background of a patterned texture in hot pink and blue. The Open Rights Group logo in the bottom right corner.

                                                            Alt...Typographic image of 'ORG20' in a 3D perspective with a green overlay of the text offset and '20 years' above it. Background of a patterned texture in hot pink and blue. The Open Rights Group logo in the bottom right corner.

                                                              [?]Dumb Password Rules » 🤖
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from Alibaba.

                                                              - At least 2 uppercase letters
                                                              - Plus 2 lowercase letters
                                                              - Plus 2 numbers
                                                              - Plus 2 punctuation marks

                                                              Phew, too many rules, because why not, if [Ma thinks AI stands for Alibaba Intelligence](youtube.com/watch?v=f3lUEnMaiAU),
                                                              then password rules can be equally intelligent too.

                                                              Also, ...

                                                              dumbpasswordrules.com/sites/al

                                                                [?]AI6YR Ben »
                                                                @ai6yr@m.ai6yr.org

                                                                Wheee

                                                                Axios: Massive data breach reportedly leaks 16 billion passwords

                                                                axios.com/2025/06/20/data-brea?

                                                                  [?]Dissent Doe :cupofcoffee: »
                                                                  @PogoWasRight@infosec.exchange

                                                                  Aflac notifies SEC of breach suspected to be work of Scattered Spider:

                                                                  databreaches.net/2025/06/20/af

                                                                  They're the third U.S. insurer breach we know about this month.

                                                                    Tim Hergert boosted

                                                                    [?]Taggart »
                                                                    @mttaggart@infosec.exchange

                                                                    Here's my go-to cheatsheet for troubleshooting issues in Fedora:

                                                                    1. Disable SELinux

                                                                    Thanks for reading!

                                                                      [?]AA »
                                                                      @AAKL@infosec.exchange

                                                                      The disclosure post was published today, June 20. The intrusion was "detected" on June 12. But nowhere does it say WHEN the intrusion began. And the company probably doesn't even know that yet.

                                                                      "Preliminary findings indicate that the unauthorized party used social engineering tactics to gain access to our network."

                                                                      "Potentially impacted files contain claims information, health information, social security numbers, and/or other personal information, related to customers, beneficiaries, employees, agents, and other individuals in our U.S. business."

                                                                      The Record: Aflac says it stopped attack launched by ‘sophisticated cybercrime group’ therecord.media/aflac-cyberatt @therecord_media @jgreig

                                                                      Posted today, Aflac Incorporated Discloses Cybersecurity Incident prnewswire.com/news-releases/a

                                                                        [?]🌱 Ligniform :donor: »
                                                                        @ligniform@infosec.exchange

                                                                        If I make tabletop exercise scenarios should I just make a public repo for all to enjoy, or is there somewhere that can get more reach? I just wanna make something cool

                                                                          Back to top - More...