cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #cybersecurity

[?]Fedora Project » 🌐
@fedora@fosstodon.org

How does Fedora process patches for security vulnerabilities? The short answer is that we work to stay on top of the news to implement patches, working in the community and with Red Hat for updates.

The long answer: fedoramagazine.org/how-fedora-

At the end of the day, the best thing you can do is keep your system updated. :)

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from BDO.

    Please nominate a password which contains UPPERCASE, lowercase, numbers and symbols.
    Password should not be the same as the user ID.
    Avoid using consecutive characters such (ex. abc, DEF, 678) and invalid characters such as [!#$%^&';"].

    dumbpasswordrules.com/sites/bd

      [?]Eldritch kcarruthers » 🌐
      @kcarruthers@infosec.exchange

      Why data minimisation matters in the age of -powered cyber attacks: AI is changing the risk profile of , turning data minimisation from a privacy nicety into a frontline defence. The less data you hold, the less there is for AI‑enabled attackers to exploit.

      katecarruthers.com/data-minimi

        Wen boosted

        [?]Steve Loughran » 🌐
        @stevel@hachyderm.io

        This is interesting: UK govt allowing Cybersecurity researchers more freedoms. Hadn't thought about this, but if you do explore a service endpoint to show some auth issue -that's possibly illegal in the Uk right now.
        therecord.media/uk-moves-to-sh

          [?]Dumb Password Rules » 🤖 🌐
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from MyAnimeList.

          Password must be between 6 - 50 characters long and contain at least two of the following: uppercase, lowercase, numbers and symbols.

          dumbpasswordrules.com/sites/my

            Wen boosted

            [?]Steve Loughran » 🌐
            @stevel@hachyderm.io

            Got claude code to identify the vulnerabilities, and fix them in production. Not perfectly, but its a start. Gets to the unit test and then it blows up
            "Claude Code is unable to respond to this request, which appears to violate our Usage Policy (anthropic.com/legal/aup). This request triggered cyber-related safeguards."

            Bit late claude, I'll get copilot to do the test instead

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from Telekom/T-Systems MyWorkplace.

              Telekom's MyWorkplace is a Single Sign On / login hub for their
              Open Telekom Cloud which is basically an Amazon AWS clone. It's
              rather new and especially for business customers. Especially
              because it is for business customers, there's absolutely no reason
              to limit a password to 16 characters. Eve...

              dumbpasswordrules.com/sites/te

                [?]Dumb Password Rules » 🤖 🌐
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from NetBank (Commonwealth Bank of Australia).

                When resetting your NetBank password, the website only informs you that you can create an alphanumeric password, despite the fact that you can use special characters.
                And also, it's password strength calculation is shit.
                An 155 bits of entropy password is "weak."
                Additionally, passwords are case-...

                dumbpasswordrules.com/sites/ne

                  [?]Harry Sintonen » 🌐
                  @harrysintonen@infosec.exchange

                  Local file exposure in linux kernels:

                  github.com/0xdeadbeefnetwork/s

                  Apparently this issue was already identified in 2020 but wasn't fixed back then.

                  Mitigation:
                  - runtime:
                  sudo sysctl -w kernel.yama.ptrace_scope=2
                  - To make the migiration persistent:
                  echo "kernel.yama.ptrace_scope=2" | sudo tee /etc/sysctl.d/01-harden-ptrace.conf

                  WARNING: This migation may break existing functionality. Test before deploying.

                  WARNING 2: While this mitigation does block the currently existing PoC, it may not prevent other attack vectors exploiting this vulnerability.

                    [?]Dumb Password Rules » 🤖 🌐
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from Parnassus Investments.

                    A site responsible for protecting your investments limiting you to a
                    four character range with a bunch of other stupid rules? Shocking.

                    dumbpasswordrules.com/sites/pa

                      [?]Dumb Password Rules » 🤖 🌐
                      @dumbpasswordrules@infosec.exchange

                      This dumb password rule is from Munich Foerdermittel Portal.

                      You register on their funding portal and receive an email with an activation link to set a password.
                      The email further informs you about their password policy:
                      - At least 8, but no more than 20 characters
                      - At least one lowercase and uppercase letter
                      - At least two digits (1,2,3,4,5,6,7,8,9,0) or...

                      dumbpasswordrules.com/sites/mu

                        Leah boosted

                        [?]mc.fly [he/him] » 🌐
                        @mcfly@milliways.social

                        depthfirst.com/nginx-rift

                        Anyone running nginx? Noone does that right?

                          [?]Dumb Password Rules » 🤖 🌐
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from LibraryThing.

                          "Your password cannot be longer than 20 characters"

                          dumbpasswordrules.com/sites/li

                            [?]Dumb Password Rules » 🤖 🌐
                            @dumbpasswordrules@infosec.exchange

                            This dumb password rule is from Aetna Health Insurance.

                            - Password cannot be longer than 20 characters
                            - Password cannot have spaces and more 2 characters repeated in a row
                            - Password cannot have user's first name, last name or username

                            dumbpasswordrules.com/sites/ae

                              [?]Dumb Password Rules » 🤖 🌐
                              @dumbpasswordrules@infosec.exchange

                              This dumb password rule is from Minnesota Unemployment Insurance.

                              Locked to *exactly* 6 chars, alphanumeric only, not special chars.

                              dumbpasswordrules.com/sites/mi

                                [?]Dumb Password Rules » 🤖 🌐
                                @dumbpasswordrules@infosec.exchange

                                This dumb password rule is from BBVA.

                                Username is your national ID (easy to find) and your password must have up to **6** alphanumeric characters only.
                                For a bank account with all your money in one of the largest financial institutions in the world.

                                dumbpasswordrules.com/sites/bb

                                  [?]Terence Eden [He/Him/♂/男] » 🌐
                                  @Edent@mastodon.social

                                  [?]mc.fly [he/him] » 🌐
                                  @mcfly@milliways.social

                                  Nothing wakes you up as fast as a good information security incident.

                                  From bed reading infosec news to the computer pressing buttons in like 60 sec.

                                  now 3 hrs later i'll go and make a first coffee...

                                    [?]Dumb Password Rules » 🤖 🌐
                                    @dumbpasswordrules@infosec.exchange

                                    This dumb password rule is from Getin Bank.

                                    The new password should contain at least 10 and a maximum of 20 characters.
                                    The password must contain at least one upper case letter, one lower case
                                    letter and one number. The password cannot contain non-ASCII Polish alphabet
                                    characters, special characters `&<'"` or spaces.

                                    dumbpasswordrules.com/sites/ge

                                      [?]Dumb Password Rules » 🤖 🌐
                                      @dumbpasswordrules@infosec.exchange

                                      This dumb password rule is from ADP.

                                      Forced to change the password during the first login. At least they
                                      could use proper grammar in their rule list.

                                      dumbpasswordrules.com/sites/ad

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from Dnevnik.ru.

                                        Silently (sic!) trim password to 30 symbols.

                                        That causes the stupid case when you could successfully registrate an account with password length of 52 and can't login with the password.

                                        dumbpasswordrules.com/sites/dn

                                          [?]Dumb Password Rules » 🤖 🌐
                                          @dumbpasswordrules@infosec.exchange

                                          This dumb password rule is from Taleo.net.

                                          Oracle Taleo is one of those old-school enterprise Applicant Tracking
                                          Systems (ATS) that half the corporate world still uses even though
                                          everyone hates it.

                                          dumbpasswordrules.com/sites/ta

                                            [?]Dumb Password Rules » 🤖 🌐
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from Express Energy.

                                            Retail Electricity Provider (REP) participating in ERCOT.

                                            Minimum 6, maximum 10. Stated requirement of numbers and letters, but special characters are accepted.

                                            dumbpasswordrules.com/sites/ex

                                              [?]Dumb Password Rules » 🤖 🌐
                                              @dumbpasswordrules@infosec.exchange

                                              This dumb password rule is from Bank Millennium.

                                              Passwords limited to 8 digits.

                                              dumbpasswordrules.com/sites/ba

                                                [?]Dumb Password Rules » 🤖 🌐
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from myezyaccess.com patient portal system.

                                                12-character maximum password length. This is not a single website but a patient portal system used by hundreds of medical facilities via subdomains, with password policy apparently being consistent for all sites.

                                                dumbpasswordrules.com/sites/my

                                                  mc.fly boosted

                                                  [?]mc.fly [he/him] » 🌐
                                                  @mcfly@milliways.social

                                                  Automated scanning.

                                                  What tools do you use to scan your enviroments for security issues? Why?

                                                  Not looking for virusscanners here, more for a bit more enterprisy enviroment?

                                                  Are there things i should have a look at?

                                                  What is your experience in general?

                                                  RT welcome for reach.

                                                    [?]Chewie » 🌐
                                                    @chewie@mammut.gogreenit.net

                                                    Oh great, has been

                                                    I just got an email saying the following:

                                                    "BWH® Hotels, the parent company for WorldHotels™, Best Western® Hotels & Resorts, and Sure Hotels®, takes the privacy and security of our guests’ personal information very seriously. We are writing to let you know that on April 22, 2026, we identified unauthorized activity in one of our web applications that houses certain guest reservation data.

                                                    We have learned that certain guests’ names, email addresses, telephone numbers, and/or home addresses, along with other reservation details (e.g., reservation numbers, dates of stay, and any special requests) for reservations in our system were accessed by an unauthorized third‑party between October 14, 2025 and April 22, 2026, including yours. Importantly, payment and other financial information was not stored in the affected system and therefore was not accessed."

                                                    Edit: This seems different to the hack from back in February, even though it sounds like the "web application" was vulnerable since October 2025: swedenherald.com/article/data-

                                                    This is not their year....

                                                      [?]Dumb Password Rules » 🤖 🌐
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from Waze.

                                                      After you request a password reset and you receive an email with instructions and link to reset your password, you are presented with this password reset form. Your password length is limited between 8 and 16 characters. Additionally the form breaks with an error if you use any special characters...

                                                      dumbpasswordrules.com/sites/wa

                                                        [?]Terence Eden [He/Him/♂/男] » 🌐
                                                        @Edent@mastodon.social

                                                        I have a daft question about and

                                                        I have some old Linux appliances which aren't getting updates any more (security cameras, amps, Android tablets etc).

                                                        Assuming I can log in as a normal user, does this mean I can get root on them?

                                                        I guess they need to be sufficiently modern to have these vulnerabilities - but in theory it should work, right?

                                                          [?]FreeBSD Foundation » 🌐
                                                          @FreeBSDFoundation@mastodon.social

                                                          Thank you to Paweł Dawidek and the Fudo Security team for highlighting how they use FreeBSD’s isolation primitives in their security architecture.

                                                          It’s encouraging to see organizations building enterprise security solutions on top of these primitives and applying them in real-world deployments.

                                                            [?]Dumb Password Rules » 🤖 🌐
                                                            @dumbpasswordrules@infosec.exchange

                                                            This dumb password rule is from LINE.

                                                            Password must:
                                                            - be between 8 to 20 characters
                                                            - not contain characters that repeat in a row
                                                            Password must contain three of the following:
                                                            - an upper-case letter
                                                            - a lower-case letter
                                                            - a number
                                                            - a symbol

                                                            dumbpasswordrules.com/sites/li

                                                              [?]ARGVMI~1.PIF » 🌐
                                                              @argv_minus_one@mastodon.sdf.org

                                                              Oh good, another high-severity vulnerability that somebody botched the disclosure of, turning it into a high-severity zero-day.

                                                              Because wasn't bad enough. Now we've got too.

                                                              Can people please stop botching vulnerability disclosure? Thanks.

                                                              github.com/V4bel/dirtyfrag/blo

                                                                [?]Aaron Toponce ⚛️:debian: » 🌐
                                                                @atoponce@fosstodon.org

                                                                Looks like Instructure got pwned by ShunyHunters. I went to the onion address and it's legit. They've got until May 12, 2026 to pay the ransom or the data gets leaked.

                                                                Shown is the screen when logging into Canvas for students to do their homework.

                                                                Screenshot from a hacked Canvas page showing the ransom message from ShinyHunters

                                                                Alt...Screenshot from a hacked Canvas page showing the ransom message from ShinyHunters

                                                                  [?]Open Rights Group » 🌐
                                                                  @openrightsgroup@social.openrightsgroup.org

                                                                  REVEALED: Serious and widespread cyber security issues with Europol’s Computer Forensic Network with many users having admin rights.

                                                                  "These findings might indicate that there are insufficient safeguards to prevent unauthorised personnel from accessing and modifying data” as well as malicious actors.

                                                                  🗣️ @jim, ORG Exec Director.

                                                                  Find out more ⬇️

                                                                  computerweekly.com/news/366642

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Dutch Tax Authorities (Belastingdienst).

                                                                    At least 8 and at most 25 characters, of which at least 3 of the characters were not used in the previous password.
                                                                    No more than 3 of the same characters.
                                                                    At least 1 upper case and 4 lower case characters.
                                                                    No more than 3 special characters.

                                                                    It's not like hashing passwords is a thing or something.

                                                                    dumbpasswordrules.com/sites/du

                                                                      [?]TelH90 » 🌐
                                                                      @kkarhan@c.im

                                                                      @neil yeah.

                                                                      I'd rather recommend to recruit him for and instead prosecute those that designed the system for "gross neglect" since a replay attack with an is way too trivial and should be patched ASAP!
                                                                      furry.engineer/@ret/1165324731

                                                                      - Sueing someone who discovered a security issue like that rather sends the message to future experts that they'd be better off selling their findings on the for instead of

                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                        @dumbpasswordrules@infosec.exchange

                                                                        This dumb password rule is from College Board.

                                                                        Password must be 9-30 characters with at least one upper case letter, one lower case letter, one number and one special character (no spaces) and be different than your username.

                                                                        dumbpasswordrules.com/sites/co

                                                                          [?]Dumb Password Rules » 🤖 🌐
                                                                          @dumbpasswordrules@infosec.exchange

                                                                          This dumb password rule is from Sprint.

                                                                          Sprint "upgraded" their security and disallow special characters.

                                                                          dumbpasswordrules.com/sites/sp

                                                                            [?]nullagent » 🌐
                                                                            @nullagent@partyon.xyz

                                                                            Yo, we're getting close to releasing @dataparty's first small but cutting edge step into the hardware world.

                                                                            If you're excited about mesh radios, ble packet capture and partying on the data I think you're gonna want to get on the mailing list 😉 👇🏿

                                                                            shop.dataparty.xyz

                                                                            @dataparty @rfparty

                                                                              Back to top - More...