cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

[?]Dumb Password Rules » 🤖 🌐
@dumbpasswordrules@infosec.exchange

This dumb password rule is from CAF (French Family Allowance Fund).

You have to enter your 8-digit password using this Frenchy keypad.

dumbpasswordrules.com/sites/ca

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from NASA Earth Data.

    Username must:
    - Be a Minimum of 4 characters
    - Be a Maximum of 30 characters
    - Use letters, numbers, periods, and underscores
    - Not contain any blank spaces
    - Not begin, end or contain two consecutive special characters(._)

    Password must contain:
    - Minimum of 8 characters
    - One Uppercase letter...

    dumbpasswordrules.com/sites/na

      [?]Mike Sheward » 🌐
      @SecureOwl@infosec.exchange

      Plexfiltration update: the AI work zone compliance tool has started emailing me thousands of pictures from a (I think) Saudi industrial facility again, to my internaluser.com domain.

      some security camera still showing a group of people in a parking lot in front of a stop sign

      Alt...some security camera still showing a group of people in a parking lot in front of a stop sign

        [?]BobDaHacker 🏳️‍⚧️ [She/They] » 🌐
        @bobdahacker@infosec.exchange

        🙏 New Blog Post

        The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.

        What's exposed:

        • Email addresses
        • Names
        • Country
        • Date of birth (they call it "borned_date" lol)
        • Account role (it's "PRAYER" for everyone, obviously)

        Also found:

        • Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
        • Their verification emails fail their own domain's authentication requirements

        Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.

        Full writeup: bobdahacker.com/blog/click-to-

          [?]Thomas B. Rücker » 🌐
          @tbr@society.oftrolls.com

          Well that sure is going to be a "fun time" for the next couple of weeks/months for a lot of people…
          "Immediate kernel patching and a full reboot are the only reliable mitigations."
          bleepingcomputer.com/news/linu
          Is that Host Unknown and their smash hit "I accepted the risk" I'm starting to hear playing in the distance? 🙃

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from Sephora.

            Password must be between 6 and 12 characters. No other rules
            specified.

            dumbpasswordrules.com/sites/se

              [?]Hugo | DevOps | Cybersecurity » 🌐
              @hugovalters@mastodon.social

              CVE-2026-55973 - Buffer Overflow in NLnet Labs Unbound 1.23.0-1.25.1. EDNS Report-Channel option mishandling leads to memory corruption. CVSS 7.5. No patch yet. Disable dns-error-reporting immediately.

              valtersit.com/cve/CVE-2026-559

                Socket boosted

                [?]AA » 🌐
                @AAKL@infosec.exchange

                Socket published this yesterday, if you missed it:

                Socket: Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign socket.dev/blog/github-actions @SocketSecurity

                  [?]Dumb Password Rules » 🤖 🌐
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from KPMG Talent Community.

                  While stating otherwise, the site actually *accepts a backslash* in the password
                  and displays a forward slash as the example of the disallowed backslash
                  Password:
                  - Must be at least 8 characters long
                  - Must contain at least 1 number
                  - Must contain at least 1 letter
                  - Must contain at least 1 spec...

                  dumbpasswordrules.com/sites/kp

                    Paco Hope boosted

                    [?]Scott Wilson 🌈 [he/him/his] » 🌐
                    @scottwilson@infosec.exchange

                    Hot take:

                    I hate how all these articles talk about how OpenAI’s clanker “broke out” and attacked Hugging Face.

                    No, OpenAI’s dog slipped its chain because they don’t know what the hell they’re doing, and it bit another dog.

                    Little dog biting a person’s finger

                    Alt...Little dog biting a person’s finger

                      [?]Dumb Password Rules » 🤖 🌐
                      @dumbpasswordrules@infosec.exchange

                      This dumb password rule is from Dutch Tax Authorities (Belastingdienst).

                      At least 8 and at most 25 characters, of which at least 3 of the characters were not used in the previous password.
                      No more than 3 of the same characters.
                      At least 1 upper case and 4 lower case characters.
                      No more than 3 special characters.

                      It's not like hashing passwords is a thing or something.

                      dumbpasswordrules.com/sites/du

                        [?]k3ym𖺀 » 🌐
                        @k3ym0@infosec.exchange

                        Everyone: “nobody uses DNS tunneling in the real world, it’s a CTF meme.”

                        TrickBot 2026: hiding C2 payloads in the high 6 bits of IPv4 responses at 30 KB/s while your DNS logs sit unread in a bucket nobody has queried since 2023.

                        That’s not exfil, that’s a dial-up modem with extra steps. And it’s still faster than your change advisory board.

                        fortinet.com/blog/threat-resea

                          [?]Dumb Password Rules » 🤖 🌐
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from NetBank (Commonwealth Bank of Australia).

                          When resetting your NetBank password, the website only informs you that you can create an alphanumeric password, despite the fact that you can use special characters.
                          And also, it's password strength calculation is shit.
                          An 155 bits of entropy password is "weak."
                          Additionally, passwords are case-...

                          dumbpasswordrules.com/sites/ne

                            [?]mc.fly [he/him] » 🌐
                            @mcfly@milliways.social

                            krebsonsecurity.com/2026/07/lg

                            LG announces to ban apps that turn your tv into a proxy for third parties.

                            Like: allow everyone that paid for it to use your home internet connection (and enables people to attack your home network)

                              [?]mc.fly [he/him] » 🌐
                              @mcfly@milliways.social

                              openai.com/index/hugging-face- new OpenAI model "accidentally" hacked Hugging Face, another AI company using AI in the build pipeline.

                              they say this will become more common.

                              "Last week, Hugging Face disclosed a new kind of security incident⁠(opens in a new window) after they detected and contained an AI agent that compromised their infrastructure, something we expect to become more commonplace with the proliferation of increasingly cyber-capable models.
                              (...)
                              We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities (...)"

                                [?]Dumb Password Rules » 🤖 🌐
                                @dumbpasswordrules@infosec.exchange

                                This dumb password rule is from Arbeitnehmeronline.

                                Service for managing employment documents of the German company Datev.

                                Only the following character categories are allowed: Letters, numbers and this special
                                characters set: !#$%&()*+,-./:;<=>?@[\]^_`{|}~äöüßÄÖÜ

                                dumbpasswordrules.com/sites/ar

                                  [?]Dumb Password Rules » 🤖 🌐
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Waze.

                                  After you request a password reset and you receive an email with instructions and link to reset your password, you are presented with this password reset form. Your password length is limited between 8 and 16 characters. Additionally the form breaks with an error if you use any special characters...

                                  dumbpasswordrules.com/sites/wa

                                    [?]Dumb Password Rules » 🤖 🌐
                                    @dumbpasswordrules@infosec.exchange

                                    This dumb password rule is from BBVA.

                                    Username is your national ID (easy to find) and your password must have up to **6** alphanumeric characters only.
                                    For a bank account with all your money in one of the largest financial institutions in the world.

                                    dumbpasswordrules.com/sites/bb

                                      [?]Dream Walker » 🌐
                                      @__dreamwalker__@infosec.exchange

                                      Hello People.

                                      This is my first fediverse post, featuring my first program in . I am a who is just getting into and love contributing to , stuffs and .

                                      I love to program in , and use btw. Looking for people to connect. I installed LinkedIn a few days ago for connecting with people and figured out that it was a in jobmarket, just data feed into companies. (No offense, just in my opinion).

                                      I was suggested to start learning by a random reddit user when I asked some questions about programming and how to get better at it. Currently learning in linux, and I guess assembly programming alongside with c programming is helpful - I can understand syscalls and registers (for some extent).

                                      Looking forward for friends to connect. Follow me and I will follow you back - provided that we have same or similar interests. I am also interested in arts, languages and techs - I am not a Russian btw.

                                      I need suggestions \ on how to get started in fediverse, cybersecurity and low level stuffs. You can see my profile for more information.

                                      My First Assembly Program

                                      Alt...My First Assembly Program

                                        [?]AJ Sadauskas » 🌐
                                        @aj@gts.sadauskas.id.au

                                        Here's one for anyone curious about the technical ins and outs of why Telstra's network went down. Andrew Colley and Juha Saarinen provide as detailed an explanation as you're likely to find in any Australian media outlet:

                                        https://www.itnews.com.au/news/telstra-broke-its-network-with-undocumented-time-fix-627442

                                        #auspol #Telstra #infosec #telcos #telco

                                          [?]Geoff Simmons » 🌐
                                          @slimhazard@mastodon.world

                                          RE: chaos.social/@vogelchr/1169530

                                          You gotta be kidding me. Not only can you pwn root, you can steal, burn down buildings, and who the hell knows what else.

                                          [?]Christian Vogel » 🌐
                                          @vogelchr@chaos.social

                                          Haha. CCS2 electrical vehicle chargers communicate by running powerline commnication (yes, a full IP networking stack) over the wires plugged in your vehicle. And yes, some charging stations have a ssh listening, with default credentials (root/root).

                                          saiflow.com/blog/the-hidden-cc

                                          (thanks @faheus for pointing me to it)

                                              [?]ada » 🌐
                                              @ada@beige.party

                                              Is there an (better) alternative to privacy.sexy? It has stopped updating since last year.

                                              Meanwhile, Windows 10 is still getting updates. And from privacy.sexy GitHub, apparently there are new issues caused by windows update since 2025 remain unaddressed.

                                              Boost appreciated.

                                              (Anyone who mentions Linux - thank you for contributing to the gatekeeping-not-helping fedi experience)

                                                [?]Dumb Password Rules » 🤖 🌐
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from Battle.net.

                                                8 to 16 characters, at least one number and one letter and last but not least NO special characters, and can't have a password that looks like your username too. Oh, and passwords are NOT case sensitive.
                                                A real time travel adventure through the password rules of 2005!

                                                dumbpasswordrules.com/sites/ba

                                                  [?]Mitex Leo » 🌐
                                                  @ml@social.mitexleo.one

                                                  [?]Dumb Password Rules » 🤖 🌐
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from United Kingdom Post Office.

                                                  Will not allow you to copy-paste your password into the text box (e.g. from a password manager). Because allowing people to copy their passwords over will defintely not result in weak passwords :)

                                                  dumbpasswordrules.com/sites/un

                                                    [?]Dumb Password Rules » 🤖 🌐
                                                    @dumbpasswordrules@infosec.exchange

                                                    This dumb password rule is from LINE.

                                                    Password must:
                                                    - be between 8 to 20 characters
                                                    - not contain characters that repeat in a row
                                                    Password must contain three of the following:
                                                    - an upper-case letter
                                                    - a lower-case letter
                                                    - a number
                                                    - a symbol

                                                    dumbpasswordrules.com/sites/li

                                                      [?]Dumb Password Rules » 🤖 🌐
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from Copart.

                                                      Copart: "The security of our members is extremely important to us."
                                                      Also Copart: "We're gonna need you to keep your password between 5-10 characters."

                                                      dumbpasswordrules.com/sites/co

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from Netflix.

                                                        [The help page](help.netflix.com/de/node/54078)
                                                        and the [password reset page](netflix.com/password) say:

                                                        Ihr Passwort muss zwischen 4 und 60 Zeichen lang sein und darf keine Tilde (~) enthalten.

                                                        dumbpasswordrules.com/sites/ne

                                                          [?]AmmarSpaces » 🌐
                                                          @AmmarSpaces@infosec.exchange

                                                          Also, around the corner....

                                                          Hugging face recently posted their disclosure of Security Incident they experienced

                                                          Several key notes:
                                                          - Autonomous agentic attack are here
                                                          - The attack are through their data-processing pipeline
                                                          - Rotate your access token keys!

                                                          huggingface.co/blog/security-i

                                                            [?]Dumb Password Rules » 🤖 🌐
                                                            @dumbpasswordrules@infosec.exchange

                                                            This dumb password rule is from SONY.

                                                            - between 8 and 30 characters
                                                            - at least one number or special character
                                                            - not part of email address
                                                            - avoid common passwords
                                                            - repeating characters 3 or more times should be avoided
                                                            - currency characters and 3 or more consecutive characters, also in reverse order, should be avoided
                                                            Somehow "$" i...

                                                            dumbpasswordrules.com/sites/so

                                                              [?]Dumb Password Rules » 🤖 🌐
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from Rushmore Loan Management Services.

                                                              Hmmm.. why are they afraid of double and single quotes in my passwords?

                                                              dumbpasswordrules.com/sites/ru

                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                @dumbpasswordrules@infosec.exchange

                                                                This dumb password rule is from Fidelity National Information Services.

                                                                White label online banking provider. Typically appears as `BANK.ibanking-services.com` or `BANK.ebanking-services.com`. If your small local bank has a crappy online banking experience, these guys probably provide it.

                                                                `\<>'` and spaces prohibited, upper bound. Passwords of exactly the maximum len...

                                                                dumbpasswordrules.com/sites/fi

                                                                  [?]your auntifa liza 🇵🇷 🦛 🦦 » 🌐
                                                                  @blogdiva@mastodon.social

                                                                  RE: mastodon.social/@zackwhittaker

                                                                  various plot points in were written based on exactly this: cops having access to the victims health-tracker data. tbh that show is an nightmare.

                                                                  [?]Zack Whittaker » 🌐
                                                                  @zackwhittaker@mastodon.social

                                                                  Fantastic work by @Thorin at EFF looking at the state of fitness tracker privacy.

                                                                  Most wearable makers don't end-to-end encrypt your data, so police/feds (and hackers!) can get your health data — and almost none publish a transparency report, so we may never know if they do.

                                                                  eff.org/deeplinks/2026/07/most

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Eurocircuits.

                                                                      Minimum 4 and maximum 30 chars. Use only letters (a-z), numbers (0-9) and underscore (_)

                                                                      dumbpasswordrules.com/sites/eu

                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                        @dumbpasswordrules@infosec.exchange

                                                                        This dumb password rule is from Virgin Trains.

                                                                        Your password needs to be between 8 and 10 characters long. Previously
                                                                        this would silently truncate the password without warning, causing
                                                                        confusion when the password wouldn't work.

                                                                        dumbpasswordrules.com/sites/vi

                                                                          Socket boosted

                                                                          [?]AA » 🌐
                                                                          @AAKL@infosec.exchange

                                                                          This was posted yesterday. Gamers, beware.

                                                                          Socket: 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload socket.dev/blog/11-malicious-n @SocketSecurity

                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from Sharekhan.

                                                                            - At least 8 characters.
                                                                            - At most 12 characters.

                                                                            dumbpasswordrules.com/sites/sh

                                                                              [?]Dumb Password Rules » 🤖 🌐
                                                                              @dumbpasswordrules@infosec.exchange

                                                                              This dumb password rule is from Green Flag.

                                                                              - 8 to 10 characters
                                                                              - No special characters

                                                                              dumbpasswordrules.com/sites/gr

                                                                                mc.fly boosted

                                                                                [?]mc.fly [he/him] » 🌐
                                                                                @mcfly@milliways.social

                                                                                zerodayinitiative.com/blog/202

                                                                                "Microsoft Patches for July 2026
                                                                                Here it is. The Mother of All Releases. To call this record-breaking is an understatement. How to count this mess is anyone’s guess, but I see new Microsoft 621 CVEs for the month of July. Some of these are in online services where no user action is required. They also list about 480 bugs in Chromium and Microsoft Edge (Chromium-based) that I won’t cover here. Here’s how I put this in context. I looked at the last 20 years of Microsoft releases. The CVE count year-to-date exceeds all other years’ totals.

                                                                                The products covered this month are also astonishing. There are patches for Windows and Windows components, Office and Office Components, Microsoft Edge (Chromium-based), Azure, .NET and Visual Studio, Github Copilot, Defender, Exchange Server, Hyper-V, Ages of Empire II, and Minecraft Server (really!). That phrase “Windows components” does some pretty heavy lifting here, too, as just about everything you’ve ever heard of is getting patched. All told, there are 63 rated Critical, six rated Moderate, one rated Low, with the rest rated Important in severity. Eight of these bugs were submitted through the ZDI program (more on that later). Two CVEs are listed as under active exploit while one other is listed as publicly known."

                                                                                The mother of all releases.

                                                                                The Vulnerability Tsunami is on us.

                                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                                  @dumbpasswordrules@infosec.exchange

                                                                                  This dumb password rule is from Coil.

                                                                                  Does not allow simple characters and sequences such as '4587' or 'efgh' in password & necessarily requires numeric values.

                                                                                  dumbpasswordrules.com/sites/co

                                                                                    Socket boosted

                                                                                    [?]AA » 🌐
                                                                                    @AAKL@infosec.exchange

                                                                                    Who asked for Tuesday?

                                                                                    New.

                                                                                    Socket: Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader socket.dev/blog/asyncapi-suppl @SocketSecurity

                                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                                      @dumbpasswordrules@infosec.exchange

                                                                                      This dumb password rule is from Pole-Emploi.

                                                                                      Password must contain at least one letter, one number and one character from `&-_@*%=.,;:!?` only.
                                                                                      It rejected passwords generated by pass, while accepting `p@ssw0rd!`...
                                                                                      They also block pasting on the password confirmation field,
                                                                                      forcing you to manually type your 32-letters-long generated passwo...

                                                                                      dumbpasswordrules.com/sites/po

                                                                                        [?]Mike Sheward » 🌐
                                                                                        @SecureOwl@infosec.exchange

                                                                                        I do love a good “comedy of errors” pen testing finding. And here is what I mean by that, very recent example (last week):

                                                                                        During OSINT discover target app was previously worked on by third party dev shop.

                                                                                        Find public repo belonging to former employee of third party dev shop on Github, contains a lot of juicy info about app, but no hardcoded creds or secrets.

                                                                                        Check commit history.

                                                                                        Commit called - “remove creds and secrets”.

                                                                                        There they are, in the history.

                                                                                        But wait, this file has a lot of commit history.

                                                                                        Oh cool, creds and secrets from the previous customer this dev shop worked for, and accidentally copied over into a template .env.

                                                                                        And scene.

                                                                                        The two things that remember: pepperidge farm and git commit history

                                                                                          [?]Dumb Password Rules » 🤖 🌐
                                                                                          @dumbpasswordrules@infosec.exchange

                                                                                          This dumb password rule is from Onleihe.

                                                                                          Password is your birthday in format ddmmyyyy. Users are not allowed to change their passwords

                                                                                          dumbpasswordrules.com/sites/on

                                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                                            @dumbpasswordrules@infosec.exchange

                                                                                            This dumb password rule is from EllieMae Access.

                                                                                            Must reset password every 6 months and password requirements are not displayed _anywhere_.
                                                                                            Reset uses a Security Question, and you have to choose from a list of 5.

                                                                                            dumbpasswordrules.com/sites/el

                                                                                              Back to top - More...