cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #cybersecurity

[?]Dumb Password Rules » 🤖
@dumbpasswordrules@infosec.exchange

This dumb password rule is from HSA Bank.

- Must be minimum 12 characters
- Must not be one of user's past 5 passwords
- Must contain uppercase and lowercase letters
- Must contain a number
- Must not be the same as user's account number or login/username

But also...
- Cannot be longer than 20 characters

dumbpasswordrules.com/sites/hs

    [?]Dumb Password Rules » 🤖
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from University of Western Australia (Pheme).

    Passwords:
    1. Must contain at least 8 characters;
    2. Must contain at least 3 out of 4 types of characters
    (uppercase letters, lowercase letters, digits, special characters);
    and
    3. Must not contain
    "the user's account name or parts of the user's full name
    that exceed two consecutive characters".
    ...

    dumbpasswordrules.com/sites/un

      [?]Dumb Password Rules » 🤖
      @dumbpasswordrules@infosec.exchange

      This dumb password rule is from IBM TSO/E Logon terminal.

      It might not be a web site, but that does not make it less dumb.
      Since many don't know about IBM mainframes, it seems they don't think you need to up the policies.

      Default old password policy is: 6-8 characters long, A-Z, 0-9

      Over the last few years they have updated their policies a bit, but d...

      dumbpasswordrules.com/sites/ib

        thefathippy boosted

        [?]David Hollingworth »
        @David_Hollingworth@mastodon.social

        Western Sydney University is having a very bad no good security day, with not just hijacked emails, but two!

        The first one is a scam email telling students their qualifications have been revoked, while the second airs a series of scathing allegations against the uni's conduct when it comes to cyber security.

        Both emails have been referred to the police.

        cyberdaily.au/security/12728-w

          [?]Dumb Password Rules » 🤖
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from Microsoft (work accounts).

          What doesn't seem to be a problem for personal accounts, is for work
          accounts from Microsoft (e.g. Office 365 etc.).

          Maximum 16 characters. So forget about using your new fancy diceware
          password here - or really any secure passwords in general.

          Oh - and besides that, please don't use any "exoti...

          dumbpasswordrules.com/sites/mi

            [?]Hacker News » 🤖
            @h4ckernews@mastodon.social

            AI has found 50 bugs in cURL. "AI-native SASTs work well"

            etn.se/72494

              mc.fly boosted

              [?]OrangeCon »
              @orangecon@infosec.exchange

              Ellen Mok closes Orangecon with a look at digital sovereignty, why independence matters and how we can get there.
              Rewatch here: youtu.be/QgV7tVLNATw?si=VqdbI3

                [?]Dumb Password Rules » 🤖
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from Virgin Mobile.

                You can only use PIN as your password.

                dumbpasswordrules.com/sites/vi

                  [?]WICCA »
                  @wicca@infosec.exchange

                  Honoured to partner with Thales for WICCON 2025. Their involvement will help us deliver a magical event!

                    [?]Dumb Password Rules » 🤖
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from Red Hat.

                    Symbols. You keep using that word. I don't think it means what you think
                    it means.

                    dumbpasswordrules.com/sites/re

                      Chewie boosted

                      [?]knoppix »
                      @knoppix95@mastodon.social

                      🇬🇧 UK govt demands access to British Apple users' data, reigniting its privacy dispute with Apple 🔐

                      Apple pulled Advanced Data Protection from UK iCloud, calling the move "gravely disappointing" ⚠️

                      Critics warn secret orders threaten global security 🕵️

                      🧑‍⚖️ Legal hearing set for Jan 2026

                      🔗 bbc.com/news/articles/c740r0m4

                        [?]Dumb Password Rules » 🤖
                        @dumbpasswordrules@infosec.exchange

                        This dumb password rule is from Boligøen (Danish resident renting bureau).

                        Red text: "Your password has to be at least 6 characters, but NOT over 20 characters."

                        dumbpasswordrules.com/sites/bo

                          [?]Alexandre Dulaunoy »
                          @a@paperbay.org

                          So age determination is not a security risk ? It is and it will be more for future. The latest Discord incident might be an eye opener for some.

                          🔗 discord.com/press-releases/upd

                          The unauthorized party also gained access to a small number of government-ID images (e.g., driver’s license, passport) from users who had appealed an age determination. If your ID may have been accessed, that will be specified in the email you receive.

                          Alt...The unauthorized party also gained access to a small number of government-ID images (e.g., driver’s license, passport) from users who had appealed an age determination. If your ID may have been accessed, that will be specified in the email you receive.

                            [?]Dumb Password Rules » 🤖
                            @dumbpasswordrules@infosec.exchange

                            This dumb password rule is from T-Mobile.

                            We prefer to not tell you which characters you can use up front.

                            dumbpasswordrules.com/sites/t-

                              [?]Dumb Password Rules » 🤖
                              @dumbpasswordrules@infosec.exchange

                              This dumb password rule is from University of California San Diego.

                              Passwords must be between 8 and **11** characters long!

                              dumbpasswordrules.com/sites/un

                                Tim Hergert boosted

                                [?]Harry Sintonen »
                                @harrysintonen@infosec.exchange

                                Broadcom has stopped delivering automated updates to Fusion and Workstation. All updates have to be downloaded and installed manually from the Broadcom Support Portal (as a side note: This portal is one of the worst corporate "support" websites I've seen in the last decade).

                                This is terrible. It will lead to tens of thousands of VMware installations remaining vulnerable to trivially exploitable flaws, for example, local privilege escalation via CVE-2025-41244 support.broadcom.com/web/ecx/s

                                BTW, Please note that to fix CVE-2025-41244 you must now manually download the correct VMware Tools package from the support portal, unpack the zip, mount the ISO image, and then execute the setup.exe from the mounted ISO image. There is currently no VMware releases that include the fixed VMware Tools, so if you create any new VMs you MUST install the update manually to each new VM. Did I already mention this is terrible?

                                VMWare Tools vulnerable to CVE-2025-41244 installed.

                                Alt...VMWare Tools vulnerable to CVE-2025-41244 installed.

                                  [?]Dumb Password Rules » 🤖
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Suncorp.

                                  To "improve security" and "be password savvy", passwords must:
                                  - be six to eight characters long
                                  - Contain both numbers and letters
                                  - Include upper and lowercase letters

                                  dumbpasswordrules.com/sites/su

                                    [?]Henry »
                                    @hl@social.lol

                                    If this isn't the wake up call that we need to take more seriously, I don't know what is. Cyber attacks are now affecting production: bbc.com/news/articles/c0r0y14l

                                      [?]Dumb Password Rules » 🤖
                                      @dumbpasswordrules@infosec.exchange

                                      This dumb password rule is from BinckBank.

                                      Between 10 and 16 letters and/or digits. No special characters are allowed.
                                      Must be renewed at least every 180 days, but you can configure to let the password expire sooner.
                                      When changing the password, the new password cannot be too similar to the existing password.

                                      dumbpasswordrules.com/sites/bi

                                        [?]Alexandre Dulaunoy »
                                        @adulau@infosec.exchange

                                        I see some people with high expectations for the EU CRA regulation, thinking the number of vulnerable or compromised devices will go down.

                                        That’s just a pipe dream, like expecting the DSA to shut down every social network spreading hate speech.

                                          [?]nullagent »
                                          @nullagent@partyon.xyz

                                          The new VPN from Tor is pretty interesting.

                                          Still in beta so it may not actually be production ready yet, but its got some very exciting features.

                                          Each app gets its own separate tor circuit, or can be excluded from the VPN.

                                          play.google.com/store/apps/det

                                          @torproject

                                            [?]Dumb Password Rules » 🤖
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from Pam360.

                                            "Enterprise privileged access management has never been easier."

                                            - Must be 8 to 16 characters in length
                                            - Must have mixed case alphabets
                                            - Must have at least 1 upper and 1 lower case character(s)
                                            - Must have at least 1 number(s)
                                            - Must have at least 1 special character(s)
                                            - Must star...

                                            dumbpasswordrules.com/sites/pa

                                              [?]AI6YR Ben »
                                              @ai6yr@m.ai6yr.org

                                              Oh yeah, that's smart... sell all your phone calls for AI training. Account numbers, personal info, everything /s

                                              engadget.com/apps/viral-app-ne?

                                                [?]Miguel Afonso Caetano »
                                                @remixtures@tldr.nettime.org

                                                "Cybersecurity researchers have discovered two Android spyware campaigns dubbed ProSpy and ToSpy that impersonate apps like Signal and ToTok to target users in the United Arab Emirates (U.A.E.).

                                                Slovak cybersecurity company ESET said the malicious apps are distributed via fake websites and social engineering to trick unsuspecting users into downloading them. Once installed, both the spyware malware strains establish persistent access to compromised Android devices and exfiltrate data.

                                                "Neither app containing the spyware was available in official app stores; both required manual installation from third-party websites posing as legitimate services," ESET researcher Lukáš Štefanko said. Notably, one of the websites distributing the ToSpy malware family mimicked the Samsung Galaxy Store, luring users into manually downloading and installing a malicious version of the ToTok app."

                                                The ProSpy campaign, discovered in June 2025, is believed to have been ongoing since 2024, leveraging deceptive websites masquerading as Signal and ToTok to host booby-trapped APK files that claim to be upgrades to the respective apps, namely Signal Encryption Plugin and ToTok Pro."

                                                thehackernews.com/2025/10/warn

                                                  [?]Dumb Password Rules » 🤖
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Mobility.

                                                  The username is the customer number, which is sequential and cannot be changed, currently 7 digits long for new customers.
                                                  The password has to be exactly 6 digits long, only numbers allowed.

                                                  dumbpasswordrules.com/sites/mo

                                                    [?]hugovangalen 🤖 🕹️ 😼 »
                                                    @hvangalen@mastodon.nl

                                                    October is Cybersecurity Awareness Month!

                                                    Celibrate below by posting your mother's maiden name!

                                                      [?]Danny Palmer »
                                                      @dannyjpalmer@infosec.exchange

                                                      Thinking of this classic* @smbccomics during Cybersecurity Awareness Month

                                                      *From 2012 (!?)

                                                      smbc-comics.com/?id=2526

                                                      Top panel: Movie hacking...

Man sitting at a PC says "If I can just overclock the unix django, I can basic the DDoS root. Damn. No Nice. But wait... if I disencrypt their kilobytes with a backdoor handshake then... jackpot"

Bottom panel: Real hacking...

Left: A man on the phone at a computer says "Hi, this is Robert Hackerman. I'm the county password inspector."
Right: The man he's calling, who seems to be working in an office,  responds "Hi bob! How can I help you today?"

                                                      Alt...Top panel: Movie hacking... Man sitting at a PC says "If I can just overclock the unix django, I can basic the DDoS root. Damn. No Nice. But wait... if I disencrypt their kilobytes with a backdoor handshake then... jackpot" Bottom panel: Real hacking... Left: A man on the phone at a computer says "Hi, this is Robert Hackerman. I'm the county password inspector." Right: The man he's calling, who seems to be working in an office, responds "Hi bob! How can I help you today?"

                                                        [?]Wolfie »
                                                        @wolfie@blahaj.social

                                                        Might as well try this - anyone looking for a fully remote role that would suit a Senior DevOps/DevSecOps/Platform/Cybersecurity Engineer in the UK who’s great at problem solving and has real golden retriever energy?

                                                          [?]Dumb Password Rules » 🤖
                                                          @dumbpasswordrules@infosec.exchange

                                                          This dumb password rule is from E-Redes.

                                                          Portuguese power distribution company, which requires short passwords (10 to 15 characters), no repetition of the same character, not using the username, the word "PASS" or the word "SAP" in the password, and limiting which special characters can be used.

                                                          dumbpasswordrules.com/sites/e-

                                                            [?]Dumb Password Rules » 🤖
                                                            @dumbpasswordrules@infosec.exchange

                                                            This dumb password rule is from Rushmore Loan Management Services.

                                                            Hmmm.. why are they afraid of double and single quotes in my passwords?

                                                            dumbpasswordrules.com/sites/ru

                                                              [?]Danny Palmer »
                                                              @dannyjpalmer@infosec.exchange

                                                              Happy Cybersecurity Awareness Month everyone. 💀

                                                              According to the FT, the UK Home Office issued a new order to Apple in early September to create a backdoor into its cloud storage service, this time focused on UK users... (£)

                                                              ft.com/content/d101fd62-14f9-4

                                                                [?]Danny Palmer »
                                                                @dannyjpalmer@infosec.exchange

                                                                Schools are swotting up on security yet still flunk recovery when cyberattacks strike

                                                                Schools and colleges hit by cyberattacks are taking longer to restore their networks — and the consequences are severe, with students' coursework being permanently lost in some cases.

                                                                New figures from the Office of Qualifications and Examinations Regulation (Ofqual), which regulates school qualifications, examinations, and assessments in England, reveal a troubling trend: more teachers are receiving cybersecurity training, yet institutions struck by attacks are increasingly struggling to recover.

                                                                Me, for The Reg

                                                                theregister.com/2025/10/01/sch

                                                                  [?]Dumb Password Rules » 🤖
                                                                  @dumbpasswordrules@infosec.exchange

                                                                  This dumb password rule is from Parnassus Investments.

                                                                  A site responsible for protecting your investments limiting you to a
                                                                  four character range with a bunch of other stupid rules? Shocking.

                                                                  dumbpasswordrules.com/sites/pa

                                                                    [?]Dumb Password Rules » 🤖
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Sprint.

                                                                    Sprint "upgraded" their security and disallow special characters.

                                                                    dumbpasswordrules.com/sites/sp

                                                                      [?]Dumb Password Rules » 🤖
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Bank Millennium.

                                                                      Passwords limited to 8 digits.

                                                                      dumbpasswordrules.com/sites/ba

                                                                        [?]Danny Palmer »
                                                                        @dannyjpalmer@infosec.exchange

                                                                        [?]Dumb Password Rules » 🤖
                                                                        @dumbpasswordrules@infosec.exchange

                                                                        This dumb password rule is from Aetna Health Insurance.

                                                                        - Password cannot be longer than 20 characters
                                                                        - Password cannot have spaces and more 2 characters repeated in a row
                                                                        - Password cannot have user's first name, last name or username

                                                                        dumbpasswordrules.com/sites/ae

                                                                          [?]Dumb Password Rules » 🤖
                                                                          @dumbpasswordrules@infosec.exchange

                                                                          This dumb password rule is from Westpac Live Online Banking.

                                                                          Password rules:
                                                                          - be between 8 and 30 characters
                                                                          - include at least 1 number, 1 letter and 1 special character (@#%^ etc)
                                                                          - have no more than 2 repeating characters (AAB not AAA)
                                                                          - not contain spaces
                                                                          - not be the same as your last 3 passwords

                                                                          dumbpasswordrules.com/sites/we

                                                                            [?]Dumb Password Rules » 🤖
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from NordVPN.

                                                                            - Password cannot be longer than 48 characters.

                                                                            dumbpasswordrules.com/sites/no

                                                                              [?]Dumb Password Rules » 🤖
                                                                              @dumbpasswordrules@infosec.exchange

                                                                              This dumb password rule is from Wells Fargo Identity Theft Protection.

                                                                              Your password on an Identity Theft Protection service is limited to
                                                                              between 8 and 20 characters. Your username is allowed to be longer than
                                                                              your password.

                                                                              dumbpasswordrules.com/sites/we

                                                                                Adrianna Tan boosted

                                                                                [?]AI6YR Ben »
                                                                                @ai6yr@m.ai6yr.org

                                                                                From 2020, but this is hilarious (someone who hacked a coffee maker and replaced it with their own firmware)

                                                                                gendigital.com/blog/insights/r

                                                                                  [?]Dumb Password Rules » 🤖
                                                                                  @dumbpasswordrules@infosec.exchange

                                                                                  This dumb password rule is from Thames Water.

                                                                                  Can only use the "special" characters on that very limited list, excluding symbols so exotic as an underscore, even. This is despite their own strength checker saying the password is strong.

                                                                                  dumbpasswordrules.com/sites/th

                                                                                    [?]Dumb Password Rules » 🤖
                                                                                    @dumbpasswordrules@infosec.exchange

                                                                                    This dumb password rule is from NVV (Nordhessische VerkehrsVerbund).

                                                                                    Password length must be 4 to 10 characters with only a few special characters allowed.

                                                                                    dumbpasswordrules.com/sites/nv

                                                                                      [?]Dumb Password Rules » 🤖
                                                                                      @dumbpasswordrules@infosec.exchange

                                                                                      This dumb password rule is from Major League Baseball.

                                                                                      When creating a new account they enforce some password rules like: length must be
                                                                                      between 8 and 15 characters and there must be one upper case, one lower case letter
                                                                                      and one number.

                                                                                      dumbpasswordrules.com/sites/ma

                                                                                        [?]Dumb Password Rules » 🤖
                                                                                        @dumbpasswordrules@infosec.exchange

                                                                                        This dumb password rule is from Apple.

                                                                                        Can't contain 3 or more consecutive identical characters, nor can it be more than 32 characters long.

                                                                                        dumbpasswordrules.com/sites/ap

                                                                                          [?]Dumb Password Rules » 🤖
                                                                                          @dumbpasswordrules@infosec.exchange

                                                                                          This dumb password rule is from BCV.

                                                                                          Username is randomly generated, example: 'H2487414'. The password must have **6** digits only.

                                                                                          Password can only be changed from the mobile application:

                                                                                          dumbpasswordrules.com/sites/bc

                                                                                            [?]Dumb Password Rules » 🤖
                                                                                            @dumbpasswordrules@infosec.exchange

                                                                                            This dumb password rule is from AmiAmi.

                                                                                            Your password needs to be between 6 and 12 characters long, must contain only letters and numbers.

                                                                                            dumbpasswordrules.com/sites/am

                                                                                              [?]Mark Gardner »
                                                                                              @mjg@mastodon.phoenixtrap.com

                                                                                              Just got my first via someone tagging me along with hundreds of others in a series of pull requests. Fraudulent scam, of course.

                                                                                              Reported and blocked.

                                                                                              Remember how insecure “formmail” CGI scripts became open email relays in the 1990s? This is the same exploit, only now GitHub has done the legwork of verifying the recipients already.

                                                                                              and other services are probably also vulnerable.

                                                                                              /cc @github @Codeberg @forgejo

                                                                                                [?]Fedora Project »
                                                                                                @fedora@fosstodon.org

                                                                                                This guide provides a step-by-step walk-through for integrating a uTrust FIDO2 security key (Identiv uTrust) with Fedora 42 to secure:

                                                                                                * LUKS2 full disk encryption (FDE)
                                                                                                * Graphical login (LightDM + Cinnamon)
                                                                                                * Sudo elevation

                                                                                                Learn more: fedoramagazine.org/integrating

                                                                                                  Back to top - More...