cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
This dumb password rule is from CAF (French Family Allowance Fund).
You have to enter your 8-digit password using this Frenchy keypad.
https://dumbpasswordrules.com/sites/caf-french-family-allowance-fund/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from NASA Earth Data.
Username must:
- Be a Minimum of 4 characters
- Be a Maximum of 30 characters
- Use letters, numbers, periods, and underscores
- Not contain any blank spaces
- Not begin, end or contain two consecutive special characters(._)
Password must contain:
- Minimum of 8 characters
- One Uppercase letter...
https://dumbpasswordrules.com/sites/nasa-earth-data/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Plexfiltration update: the AI work zone compliance tool has started emailing me thousands of pictures from a (I think) Saudi industrial facility again, to my internaluser.com domain. #infosec
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
Also found:
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
Well that sure is going to be a "fun time" for the next couple of weeks/months for a lot of people…
"Immediate kernel patching and a full reboot are the only reliable mitigations."
https://www.bleepingcomputer.com/news/linux/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/
Is that Host Unknown and their smash hit "I accepted the risk" I'm starting to hear playing in the distance? 🙃
#infosec
This dumb password rule is from Sephora.
Password must be between 6 and 12 characters. No other rules
specified.
https://dumbpasswordrules.com/sites/sephora/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Socket published this yesterday, if you missed it:
Socket: Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation @SocketSecurity #infosec #threatresearch #GitHub
This dumb password rule is from KPMG Talent Community.
While stating otherwise, the site actually *accepts a backslash* in the password
and displays a forward slash as the example of the disallowed backslash
Password:
- Must be at least 8 characters long
- Must contain at least 1 number
- Must contain at least 1 letter
- Must contain at least 1 spec...
https://dumbpasswordrules.com/sites/kpmg-talent-community/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Hot take:
I hate how all these articles talk about how OpenAI’s clanker “broke out” and attacked Hugging Face.
No, OpenAI’s dog slipped its chain because they don’t know what the hell they’re doing, and it bit another dog.
This dumb password rule is from Dutch Tax Authorities (Belastingdienst).
At least 8 and at most 25 characters, of which at least 3 of the characters were not used in the previous password.
No more than 3 of the same characters.
At least 1 upper case and 4 lower case characters.
No more than 3 special characters.
It's not like hashing passwords is a thing or something.
https://dumbpasswordrules.com/sites/dutch-tax-authorities-belastingdienst/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Everyone: “nobody uses DNS tunneling in the real world, it’s a CTF meme.”
TrickBot 2026: hiding C2 payloads in the high 6 bits of IPv4 responses at 30 KB/s while your DNS logs sit unread in a bucket nobody has queried since 2023.
That’s not exfil, that’s a dial-up modem with extra steps. And it’s still faster than your change advisory board.
https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2
This dumb password rule is from NetBank (Commonwealth Bank of Australia).
When resetting your NetBank password, the website only informs you that you can create an alphanumeric password, despite the fact that you can use special characters.
And also, it's password strength calculation is shit.
An 155 bits of entropy password is "weak."
Additionally, passwords are case-...
https://dumbpasswordrules.com/sites/netbank-commonwealth-bank-of-australia/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/
LG announces to ban apps that turn your tv into a proxy for third parties.
Like: allow everyone that paid for it to use your home internet connection (and enables people to attack your home network)
https://openai.com/index/hugging-face-model-evaluation-security-incident/the new OpenAI model "accidentally" hacked Hugging Face, another AI company using AI in the build pipeline.
they say this will become more common.
"Last week, Hugging Face disclosed a new kind of security incident(opens in a new window) after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models.
(...)
We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities (...)"
This dumb password rule is from Arbeitnehmeronline.
Service for managing employment documents of the German company Datev.
Only the following character categories are allowed: Letters, numbers and this special
characters set: !#$%&()*+,-./:;<=>?@[\]^_`{|}~äöüßÄÖÜ
https://dumbpasswordrules.com/sites/arbeitnehmeronline/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Waze.
After you request a password reset and you receive an email with instructions and link to reset your password, you are presented with this password reset form. Your password length is limited between 8 and 16 characters. Additionally the form breaks with an error if you use any special characters...
https://dumbpasswordrules.com/sites/waze/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from BBVA.
Username is your national ID (easy to find) and your password must have up to **6** alphanumeric characters only.
For a bank account with all your money in one of the largest financial institutions in the world.
https://dumbpasswordrules.com/sites/bbva/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Hello People.
This is my first fediverse post, featuring my first #assembly64 program in #linux. I am a #student who is just getting into #cybersecurity and love contributing to #infosec, #lowlevel stuffs and #linuxkernel.
I love to program in #c, and use #archlinux btw. Looking for people to connect. I installed LinkedIn a few days ago for connecting with people and figured out that it was a #scam in jobmarket, just data feed into companies. (No offense, just in my opinion).
I was suggested to start learning #assembly64 by a random reddit user when I asked some questions about #c programming and how to get better at it. Currently learning #syscalls in linux, and I guess assembly programming alongside with c programming is helpful - I can understand syscalls and registers (for some extent).
Looking forward for friends to connect. Follow me and I will follow you back - provided that we have same or similar interests. I am also interested in #russian arts, languages and techs - I am not a Russian btw.
I need suggestions \ #help on how to get started in fediverse, cybersecurity and low level stuffs. You can see my profile for more information.
Here's one for anyone curious about the technical ins and outs of why Telstra's network went down. Andrew Colley and Juha Saarinen provide as detailed an explanation as you're likely to find in any Australian media outlet:
https://www.itnews.com.au/news/telstra-broke-its-network-with-undocumented-time-fix-627442
RE: https://chaos.social/@vogelchr/116953057618621110
You gotta be kidding me. Not only can you pwn root, you can steal, burn down buildings, and who the hell knows what else.
#infosec #calamity #ev #chargers
Haha. CCS2 electrical vehicle chargers communicate by running powerline commnication (yes, a full IP networking stack) over the wires plugged in your vehicle. And yes, some charging stations have a ssh listening, with default credentials (root/root).
https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers
(thanks @faheus for pointing me to it)
Is there an (better) alternative to privacy.sexy? It has stopped updating since last year.
Meanwhile, Windows 10 is still getting updates. And from privacy.sexy GitHub, apparently there are new issues caused by windows update since 2025 remain unaddressed.
Boost appreciated.
(Anyone who mentions Linux - thank you for contributing to the gatekeeping-not-helping fedi experience)
This dumb password rule is from Battle.net.
8 to 16 characters, at least one number and one letter and last but not least NO special characters, and can't have a password that looks like your username too. Oh, and passwords are NOT case sensitive.
A real time travel adventure through the password rules of 2005!
https://dumbpasswordrules.com/sites/battle-net/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Looks like nextcloud.com has been hacked (now down).
https://www.reddit.com/r/NextCloud/comments/1v0wxw7/nextcloudcom_cloudbox/
This dumb password rule is from United Kingdom Post Office.
Will not allow you to copy-paste your password into the text box (e.g. from a password manager). Because allowing people to copy their passwords over will defintely not result in weak passwords :)
https://dumbpasswordrules.com/sites/united-kingdom-post-office/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from LINE.
Password must:
- be between 8 to 20 characters
- not contain characters that repeat in a row
Password must contain three of the following:
- an upper-case letter
- a lower-case letter
- a number
- a symbol
https://dumbpasswordrules.com/sites/line/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Copart.
Copart: "The security of our members is extremely important to us."
Also Copart: "We're gonna need you to keep your password between 5-10 characters."
https://dumbpasswordrules.com/sites/copart/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Netflix.
[The help page](https://help.netflix.com/de/node/54078)
and the [password reset page](https://www.netflix.com/password) say:
Ihr Passwort muss zwischen 4 und 60 Zeichen lang sein und darf keine Tilde (~) enthalten.
https://dumbpasswordrules.com/sites/netflix/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Also, around the corner....
Hugging face recently posted their disclosure of Security Incident they experienced
Several key notes:
- Autonomous agentic attack are here
- The attack are through their data-processing pipeline
- Rotate your access token keys!
https://huggingface.co/blog/security-incident-july-2026
#cybersecurity #infosec #aisecurity #huggingface #securityincident
This dumb password rule is from SONY.
- between 8 and 30 characters
- at least one number or special character
- not part of email address
- avoid common passwords
- repeating characters 3 or more times should be avoided
- currency characters and 3 or more consecutive characters, also in reverse order, should be avoided
Somehow "$" i...
https://dumbpasswordrules.com/sites/sony/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Rushmore Loan Management Services.
Hmmm.. why are they afraid of double and single quotes in my passwords?
https://dumbpasswordrules.com/sites/rushmore-loan-management-services/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Fidelity National Information Services.
White label online banking provider. Typically appears as `BANK.ibanking-services.com` or `BANK.ebanking-services.com`. If your small local bank has a crappy online banking experience, these guys probably provide it.
`\<>'` and spaces prohibited, upper bound. Passwords of exactly the maximum len...
https://dumbpasswordrules.com/sites/fidelity-national-information-services/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
RE: https://mastodon.social/@zackwhittaker/116929779183940055
various plot points in #MidsomerMurders were written based on exactly this: cops having access to the victims health-tracker data. tbh that show is an #infosec #surveillance #stalkerware nightmare.
Fantastic work by @Thorin at EFF looking at the state of fitness tracker privacy.
Most wearable makers don't end-to-end encrypt your data, so police/feds (and hackers!) can get your health data — and almost none publish a transparency report, so we may never know if they do.
This dumb password rule is from Eurocircuits.
Minimum 4 and maximum 30 chars. Use only letters (a-z), numbers (0-9) and underscore (_)
https://dumbpasswordrules.com/sites/eurocircuits/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Virgin Trains.
Your password needs to be between 8 and 10 characters long. Previously
this would silently truncate the password without warning, causing
confusion when the password wouldn't work.
https://dumbpasswordrules.com/sites/virgin-trains/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This was posted yesterday. Gamers, beware.
Socket: 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload https://socket.dev/blog/11-malicious-nuget-tools-pose-as-game-cheats @SocketSecurity #malware #surveillance #Windows #infosec #Microsoft
This dumb password rule is from Sharekhan.
- At least 8 characters.
- At most 12 characters.
https://dumbpasswordrules.com/sites/sharekhan/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Green Flag.
- 8 to 10 characters
- No special characters
https://dumbpasswordrules.com/sites/green-flag/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
https://www.zerodayinitiative.com/blog/2026/7/14/the-july-2026-security-update-review
"Microsoft Patches for July 2026
Here it is. The Mother of All Releases. To call this record-breaking is an understatement. How to count this mess is anyone’s guess, but I see new Microsoft 621 CVEs for the month of July. Some of these are in online services where no user action is required. They also list about 480 bugs in Chromium and Microsoft Edge (Chromium-based) that I won’t cover here. Here’s how I put this in context. I looked at the last 20 years of Microsoft releases. The CVE count year-to-date exceeds all other years’ totals.
The products covered this month are also astonishing. There are patches for Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Ages of Empire II, and Minecraft Server (really!). That phrase “Windows components” does some pretty heavy lifting here, too, as just about everything you’ve ever heard of is getting patched. All told, there are 63 rated Critical, six rated Moderate, one rated Low, with the rest rated Important in severity. Eight of these bugs were submitted through the ZDI program (more on that later). Two CVEs are listed as under active exploit while one other is listed as publicly known."
The mother of all releases.
The Vulnerability Tsunami is on us.
This dumb password rule is from Coil.
Does not allow simple characters and sequences such as '4587' or 'efgh' in password & necessarily requires numeric values.
https://dumbpasswordrules.com/sites/coil/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Who asked for Tuesday?
New.
Socket: Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader https://socket.dev/blog/asyncapi-supply-chain-attack @SocketSecurity #infosec #threatresearch #npm #botnet #Apple #macOS #Linux #Windows #Microsoft #JavaScript
This dumb password rule is from Pole-Emploi.
Password must contain at least one letter, one number and one character from `&-_@*%=.,;:!?` only.
It rejected passwords generated by pass, while accepting `p@ssw0rd!`...
They also block pasting on the password confirmation field,
forcing you to manually type your 32-letters-long generated passwo...
https://dumbpasswordrules.com/sites/pole-emploi/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
I do love a good “comedy of errors” pen testing finding. And here is what I mean by that, very recent example (last week):
During OSINT discover target app was previously worked on by third party dev shop.
Find public repo belonging to former employee of third party dev shop on Github, contains a lot of juicy info about app, but no hardcoded creds or secrets.
Check commit history.
Commit called - “remove creds and secrets”.
There they are, in the history.
But wait, this file has a lot of commit history.
Oh cool, creds and secrets from the previous customer this dev shop worked for, and accidentally copied over into a template .env.
And scene.
The two things that remember: pepperidge farm and git commit history
This dumb password rule is from Onleihe.
Password is your birthday in format ddmmyyyy. Users are not allowed to change their passwords
https://dumbpasswordrules.com/sites/onleihe/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from EllieMae Access.
Must reset password every 6 months and password requirements are not displayed _anywhere_.
Reset uses a Security Question, and you have to choose from a list of 5.
https://dumbpasswordrules.com/sites/elliemae-access/
#password #passwords #infosec #cybersecurity #dumbpasswordrules