cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #cybersecurity

[?]Dumb Password Rules » 🤖 🌐
@dumbpasswordrules@infosec.exchange

This dumb password rule is from La Banque Postale.

Password must be 6 digits and entered on custom pad.

dumbpasswordrules.com/sites/la

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from State Bank of India (Foreign Travel Card).

    State Bank of India is the largest government operated bank in India.
    They offer "travel" prepaid cards for foreign currencies, this is for
    their portal for the prepaid card users to manage their account.

    Your password must:
    - Be between 8 and 9 characters long
    - Contain at least 1 lowercase c...

    dumbpasswordrules.com/sites/st

      [?]Dumb Password Rules » 🤖 🌐
      @dumbpasswordrules@infosec.exchange

      This dumb password rule is from EllieMae Access.

      Must reset password every 6 months and password requirements are not displayed _anywhere_.
      Reset uses a Security Question, and you have to choose from a list of 5.

      dumbpasswordrules.com/sites/el

        [?]Bitwarden » 🌐
        @bitwarden@fosstodon.org

        Have you saved your seat for the 7th annual Open Source Security Summit?

        opensourcesecuritysummit.com/

        Social graphic for the 2026 Open Source Security Summit, September 17, 2026, 8-10am PT, 11-1 PM ET, 5-7 PM CEST

        Alt...Social graphic for the 2026 Open Source Security Summit, September 17, 2026, 8-10am PT, 11-1 PM ET, 5-7 PM CEST

          [?]Erik Jonker » 🌐
          @ErikJonker@mastodon.social

          Scary retelling of the OpenAI/Huggingface incident,
          dwarkesh.com/p/openai-huggingf

            mc.fly boosted

            [?]FIRST.org » 🌐
            @firstdotorg@infosec.exchange

            Calling all cybersecurity professionals, academics, and CSIRTs to join us in Luxembourg for 2026, FIRST's evolution of Vuln4Cast!

            📆 September 23-25, 2026

            Hosted in partnership with the Computer Incident Response Centre Luxembourg (CIRCL), this year's event theme is "The A-Eyes See All." Keynote speakers Jaya Baloo, COO & CISO at AISLE and a world-renowned top 100 CISO, and Regina Joseph, a leading behavioral scientist and applied forecasting expert, will share actionable strategies for defenders and forecasting teams facing unprecedented levels of change driven by AI.

            The three-day program covers:

            ✅ Global & Open Ecosystems: rethinking vulnerability tracking for an open security landscape
            ✅ Forecasting & Metrics: measuring and forecasting exploitation conditions
            ✅ Policy & Program Futures: what's next for the CVE Program
            ✅ Data & Observable Evidence: what happens when the industry sets its own standards
            ✅ Next-Gen Threat Detection: detecting threats that cannot yet be named

            🎟️ Limited tickets available
            🔗 Learn more about the speaker lineup: go.first.org/kxOHk

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from HDFC Bank.

              Only a maximum of 15 characters and some special characters are not allowed.

              dumbpasswordrules.com/sites/hd

                [?]Dumb Password Rules » 🤖 🌐
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from BMW ConnectedDrive.

                Although the prompt suggests good things, after many failed attempts to
                set a new password, it turns out you can ONLY use the special characters
                shown in the prompt

                dumbpasswordrules.com/sites/bm

                  Wen boosted

                  [?]Steve Loughran » 🌐
                  @stevel@hachyderm.io

                  If you are running an AI coding agent on the CLI
                  - never be stupid enough to run it in "auto accept" mode, trust it to run python or ruby without you looking at what it has created -no matter how hard it tries to convince
                  - set up a sandbox around it, even if they claim to have one.

                  Competitive pressure forces the vendors to focus on features and ease of use over sandbox lockdown and safety/user oversight. You don't want what

                  Never knew of bubblewrap on Linux, which looks good. I have used macos sandbox in the past.

                  youtu.be/7UCpHzFYF40

                    [?]Dumb Password Rules » 🤖 🌐
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from SunTrust.

                    At least there are a variety of special characters to choose from.

                    dumbpasswordrules.com/sites/su

                      JP boosted

                      [?]Violet Blue » 🌐
                      @violetblue@mastodon.social

                      Hey everyone, it's time to take a stand, this is one of the easy ways: patreon.com/violetblue/posts/h

                        Wen boosted

                        [?]Steve Loughran » 🌐
                        @stevel@hachyderm.io

                        The hadoop security model says submitters have to be able to explain a CVE in their own words otherwise we give credit to the AI tool and not the meat proxy. I'm wondering if we should pull that up to say "in the initial submission, you, the human being, must be able to explain what the issue is and you think it matters".

                        - submitter may learn about the system rather than blindly email reports
                        - submitter may act as a filter on AI slop reports, rather than making maintainers the primary filter here.

                        I will bounce back the next slop report with a query for more detail rather than immediate rejection, so that they learn for themselves why it's invalid.

                        github.com/apache/hadoop/secur

                          [?]Dumb Password Rules » 🤖 🌐
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from Lenovo.

                          - **Between 8 and 20 characters, not more.**
                          - 1 alphabetic letter
                          - 1 number (0-9)
                          - **1 symbol ($!#&)**

                          dumbpasswordrules.com/sites/le

                            Wen boosted

                            [?]Brian Greenberg :verified: » 🌐
                            @brian_greenberg@infosec.exchange

                            Brian Krebs found his own driver's license for sale on a Russian crime forum this week. The timestamp on the scan matched the day he rented a car to attend a family funeral. His mom's license was there too, scanned a few seconds after his.

                            The service is called Nexus. It claims over 153 million driver's licenses from the US and Canada, and the count grew by nearly 400,000 in a single day. Krebs traced the scans back to an identity verification vendor that checks IDs for rental car companies, big retailers, and over 1,000 marijuana dispensaries. The FBI opened an investigation on Tuesday.

                            Most of the people in that database never dealt with the vendor. They handed a license to a clerk at a counter. The clerk ran it through a scanner. Nobody mentioned that the scanner belonged to a different company, or that a copy might stick around long enough to get stolen. If your company scans customer IDs, you own the risk of how your vendor uses those images, whether the contract says so or not.

                            Two things worth thinking about:

                            - Every new "show us your ID" rule, including the ones sold as protecting kids online, pushes more license scans into more vendors. Each one is another place to lose them.

                            - A driver's license is still what banks use to open credit. A scan with the photo, front and back, in infrared and ultraviolet, is close to a master key.

                            I would love to see ID scans deleted the moment a check is done. Until then, ask whether your license will be scanned or just looked at before you hand it over. And freeze your credit at all three bureaus. It's free. It takes about ten minutes.

                            krebsonsecurity.com/2026/09/fb

                              [?]Dumb Password Rules » 🤖 🌐
                              @dumbpasswordrules@infosec.exchange

                              This dumb password rule is from Eurocircuits.

                              Minimum 4 and maximum 30 chars. Use only letters (a-z), numbers (0-9) and underscore (_)

                              dumbpasswordrules.com/sites/eu

                                mc.fly boosted

                                [?]Ivy Cyber » 🤖 🌐
                                @ivycyber@privacysafe.social

                                🛡️ news & tips across the

                                “📡 The BSSID Black Market: Who's Selling Home WiFi Maps?→ telegra․ph/The-BSSID-Black-Market-Whos-Selling-Home-WiFi-Maps-08-17 ⌗wifi ⌗surveillance ⌗privacy ⌗infosec”

                                infosec.exchange/@monniele/117

                                🤖 via RSS feed. Not an endorsement.

                                  [?]Dumb Password Rules » 🤖 🌐
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Dwr Cymru (Welsh Water).

                                  Limits password length to a maximum of 16 characters

                                  dumbpasswordrules.com/sites/dw

                                    [?]Dumb Password Rules » 🤖 🌐
                                    @dumbpasswordrules@infosec.exchange

                                    This dumb password rule is from Very.co.uk.

                                    Password field allows *only* the listed Special Characters ($ . , ! % ^ \*).
                                    You're also forced to use both upper, and lower letters, as well as a number.

                                    dumbpasswordrules.com/sites/ve

                                      [?]Dumb Password Rules » 🤖 🌐
                                      @dumbpasswordrules@infosec.exchange

                                      This dumb password rule is from GoDaddy SFTP.

                                      Max 14 characters for the most important password in your shared hosting environment.

                                      dumbpasswordrules.com/sites/go

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from Raiffeisen Bank Serbia.

                                        There are a couple of password limitations when creating a new account (and
                                        changing existing password) on Raiffeisen Bank Serbia on-line banking portal.
                                        Password length is limited to minimum 8 and maximum 32 characters. Also, minimum
                                        uppercase letters 1, minimum lowercase letter 1, minimum digit...

                                        dumbpasswordrules.com/sites/ra

                                          [?]Dumb Password Rules » 🤖 🌐
                                          @dumbpasswordrules@infosec.exchange

                                          This dumb password rule is from HDFC Bank.

                                          Only a maximum of 15 characters and some special characters are not allowed.

                                          dumbpasswordrules.com/sites/hd

                                            [?]Dumb Password Rules » 🤖 🌐
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from NordVPN.

                                            - Password cannot be longer than 48 characters.

                                            dumbpasswordrules.com/sites/no

                                              [?]Dumb Password Rules » 🤖 🌐
                                              @dumbpasswordrules@infosec.exchange

                                              This dumb password rule is from CAF (French Family Allowance Fund).

                                              You have to enter your 8-digit password using this Frenchy keypad.

                                              dumbpasswordrules.com/sites/ca

                                                Tim Hergert boosted

                                                [?]BugsToday » 🌐
                                                @BugsToday@mastodon.social

                                                [?]Chris » 🌐
                                                @Chris@mast.social

                                                Bitwarden Password Manager almost doubled their price...? 💵 🤔

                                                I do not remember a notification...? 🧾 🤔

                                                Hmmm... 🤔 🤨

                                                [EDIT] ➡️ People have since sent Me a link:
                                                itsfoss.com/news/bitwarden-qui

                                                  [?]Dumb Password Rules » 🤖 🌐
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from NVV (Nordhessische VerkehrsVerbund).

                                                  Password length must be 4 to 10 characters with only a few special characters allowed.

                                                  dumbpasswordrules.com/sites/nv

                                                    [?]Dumb Password Rules » 🤖 🌐
                                                    @dumbpasswordrules@infosec.exchange

                                                    This dumb password rule is from Itaú Bank.

                                                    I know, it's in spanish, let me translate this monstrosity for you.

                                                    - Allowed characters: letters A to Z uppercase or lowercase (ñ is not allowed), number 0 to 9, #, $, %, &, +, -, . :, ;, _.
                                                    - You must use 8 characters.
                                                    - The password must contain at least one letter and at least one number.
                                                    - ...

                                                    dumbpasswordrules.com/sites/it

                                                      WTL boosted

                                                      [?]AskPippa🇨🇦 » 🌐
                                                      @AskPippa@c.im

                                                      If this sale goes through, I for one will move all my banking and investments to a bank not involved with this. needs to become less entangled with US ownership. The timing of this is very concerning. Do read this article. If you also will move your accounts, be public about it.
                                                      What will you do?

                                                      cbc.ca/news/politics/moneris-d

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from E-Redes.

                                                        Portuguese power distribution company, which requires short passwords (10 to 15 characters), no repetition of the same character, not using the username, the word "PASS" or the word "SAP" in the password, and limiting which special characters can be used.

                                                        dumbpasswordrules.com/sites/e-

                                                          [?]Dumb Password Rules » 🤖 🌐
                                                          @dumbpasswordrules@infosec.exchange

                                                          [?]Open Rights Group » 🌐
                                                          @openrightsgroup@social.openrightsgroup.org

                                                          Encryption keeps us safe and secure online.

                                                          A backdoor is only possible by breaking encryption. And then anybody can abuse that cybersecurity weakness.

                                                          The government's last attempt to force Apple to build a backdoor into our accounts failed.

                                                          We'll fight the latest order.

                                                          Find out more ⬇️

                                                            [?]Open Rights Group » 🌐
                                                            @openrightsgroup@social.openrightsgroup.org

                                                            Shadowy attempts to break our right to privacy are completely rejected:

                                                            ⚫️ Only 12% believe the government should be able to issue secret orders to gain access to private data.

                                                            ⚫️ 87% believe there should be a legal obligation to tell people if their private conversations have been accessed.

                                                              [?]Open Rights Group » 🌐
                                                              @openrightsgroup@social.openrightsgroup.org

                                                              The UK government is trying yet again to ram a backdoor into Apple's encrypted products.

                                                              But you ask the UK public and over 90% say they should have a right to private conversations online.

                                                              New polling by the Center for Democracy & Technology makes it clear that attacks on encryption aren't backed by public opinion.

                                                              Read more ⬇️

                                                              computerweekly.com/news/366649

                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                @dumbpasswordrules@infosec.exchange

                                                                This dumb password rule is from Zurich.

                                                                Password must be EXACTLY 8 characters long.

                                                                Alpha numeric characters ONLY.

                                                                The first character must be alphabetic.

                                                                NO spaces.

                                                                The new Password cannot be the same as the last 32 passwords you have used. (they actually store your last 32 passwords)

                                                                dumbpasswordrules.com/sites/zu

                                                                  Wen boosted

                                                                  [?]BrianKrebs » 🌐
                                                                  @briankrebs@infosec.exchange

                                                                  Today's story is the result of an ungodly amount of research, and I am very glad to finally be able to share it with you.

                                                                  Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

                                                                  In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”

                                                                  The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.

                                                                  krebsonsecurity.com/2026/08/tw

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Polytechnique Montreal.

                                                                    Passwords must have a minimum length of 8 characters

                                                                    Passwords must have a maximum length of 30 characters

                                                                    Passwords must contain a minimum of 2 digits

                                                                    Passwords must contain a minimum of 2 letters

                                                                    Password must be different than the last one used

                                                                    Passwords may contain these special characte...

                                                                    dumbpasswordrules.com/sites/po

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from University of Windsor.

                                                                      The password policy applies to alumni as well. Must be at least 10
                                                                      characters long, with at least 1 upper case and 1 lower case
                                                                      character, at least 1 number, at least 1 special character. Password
                                                                      expires every 120 days, and you can't reuse an old one.

                                                                      dumbpasswordrules.com/sites/un

                                                                        Wen boosted

                                                                        [?]Ian Campbell 🏴 » 🌐
                                                                        @neurovagrant@masto.deoan.org

                                                                        Hello friends, I've seen the below image come up a few times elsewhere and am going to expound a little!

                                                                        While the hyperlinks in the image display correctly, those aren't actually the addresses of those sites! Instead, they're the Internationalized Domain Name replacements - examples of what are called IDN Homograph Attacks.

                                                                        It's incredibly hard to include all characters from all active alphabets in the mechanisms that resolve domain names - so currently that letter set is restricted, and instead uses a translation system called Punycode to move between a visual URL with the correct characters and a domain name your computer can actually resolve to a website.

                                                                        So while neurovagrant[.]com is fine either way, nӘ̃urovagrant[.]com isn't! The actually domain would be xn--nurovagrant-rkg322d[.]com.

                                                                        Notice that xn-- ! That's what tells browsers and other software that it's an IDN domain, and to try and translate it.

                                                                        Attackers use this to their benefit. So:

                                                                        xn--mcrosoft-security-teams-1ec[.]com can appear in your email, on your twitter feed, in other places visually as: mícrosoft-security-teams[.]com

                                                                        You may think you're signing in to check your retirement at vanguarɗ[.]com but it's actually sent you to xn--vanguar-4cd[.]com

                                                                        A link that appears as vḙnmo[.]com actually sends you to the website xn--vnmo-q64a[.]com

                                                                        They even target kids! Take a look at xn--rblox-jua[.]com - which looks like röblox[.]com in most settings. Note the diacritical mark above the first o.

                                                                        If anything looks off, there's a reason. Always view links with skepticism, don't click on things unnecessarily, and always sign into the sites you use by going to the domain name you know.

                                                                        Stay frosty out there, friends.

                                                                        Screenshot that says "Spot the difference" and shows two different maybank and citibank addresses - one that is legitimate, and one that uses a cyrillic 'a' to send you to an illegitimate site.

                                                                        Alt...Screenshot that says "Spot the difference" and shows two different maybank and citibank addresses - one that is legitimate, and one that uses a cyrillic 'a' to send you to an illegitimate site.

                                                                          [?]Dumb Password Rules » 🤖 🌐
                                                                          @dumbpasswordrules@infosec.exchange

                                                                          This dumb password rule is from Munich Foerdermittel Portal.

                                                                          You register on their funding portal and receive an email with an activation link to set a password.
                                                                          The email further informs you about their password policy:
                                                                          - At least 8, but no more than 20 characters
                                                                          - At least one lowercase and uppercase letter
                                                                          - At least two digits (1,2,3,4,5,6,7,8,9,0) or...

                                                                          dumbpasswordrules.com/sites/mu

                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from Jaa Lifestyle.

                                                                            When we try to change password and accidentally gave a wrong password for confirm password.
                                                                            Lets try to read and figure out what they are trying to point out.

                                                                            dumbpasswordrules.com/sites/ja

                                                                              [?]Dumb Password Rules » 🤖 🌐
                                                                              @dumbpasswordrules@infosec.exchange

                                                                              This dumb password rule is from Sephora.

                                                                              Password must be between 6 and 12 characters. No other rules
                                                                              specified.

                                                                              dumbpasswordrules.com/sites/se

                                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                                @dumbpasswordrules@infosec.exchange

                                                                                This dumb password rule is from KPMG Talent Community.

                                                                                While stating otherwise, the site actually *accepts a backslash* in the password
                                                                                and displays a forward slash as the example of the disallowed backslash
                                                                                Password:
                                                                                - Must be at least 8 characters long
                                                                                - Must contain at least 1 number
                                                                                - Must contain at least 1 letter
                                                                                - Must contain at least 1 spec...

                                                                                dumbpasswordrules.com/sites/kp

                                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                                  @dumbpasswordrules@infosec.exchange

                                                                                  This dumb password rule is from Sparkasse.

                                                                                  „Sparkasse“ is a group of banks which is pretty popular in Germany. It
                                                                                  calls its passwords „PIN“ („persönliche Identifikations-Nummer“ —
                                                                                  personal identification number), the rules are pretty horrific and its
                                                                                  not even a number, even though it is called as such! Here is a
                                                                                  screenshot from the branch...

                                                                                  dumbpasswordrules.com/sites/sp

                                                                                    [?]Rich Stein (he/him) » 🌐
                                                                                    @RunRichRun@mastodon.social

                                                                                    Iranian hackers shut down UK power plant last month in an unprecedented cyber attack. The attack, believed to be the most successful cyber attack of its kind, took place at the same time as a series of attacks on US water infrastructure, which affected 12 states.
                                                                                    bbc.com/news/articles/ce9793g3

                                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                                      @dumbpasswordrules@infosec.exchange

                                                                                      This dumb password rule is from Easyjet.

                                                                                      No more than 20 characters, use any symbols you like... Oh except #, &, +, or space of course.

                                                                                      dumbpasswordrules.com/sites/ea

                                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                                        @dumbpasswordrules@infosec.exchange

                                                                                        This dumb password rule is from LINE.

                                                                                        Password must:
                                                                                        - be between 8 to 20 characters
                                                                                        - not contain characters that repeat in a row
                                                                                        Password must contain three of the following:
                                                                                        - an upper-case letter
                                                                                        - a lower-case letter
                                                                                        - a number
                                                                                        - a symbol

                                                                                        dumbpasswordrules.com/sites/li

                                                                                          [?]Dumb Password Rules » 🤖 🌐
                                                                                          @dumbpasswordrules@infosec.exchange

                                                                                          This dumb password rule is from Replit.

                                                                                          Forces to use minimum 8 characters in the password and it must contain at least one uppercase.

                                                                                          dumbpasswordrules.com/sites/re

                                                                                            Back to top - More...