social.outsourcedmath.com


ד-פּאַקס mastodon (AP)
"As a #Jewish #NewYorker, #food is always top of mind—at home, it revolves around cooking and preparing for the next #Shabbat or holiday #meal, and on the streets of #NewYorkCity, the world of Jewish food exists vastly in the form of #delicatessens, #bakeries, lox counters, and steakhouses. In a city with such strong ties to Jewish heritage—namely the Lower East Side where Jewish immigrants settled in the early 1900s, and pockets of #Brooklyn, home to one of the largest Orthodox Jewish communities in the world—it’s no secret that some of the city’s best and most nourishing bites have deep historical ties to Jewish culture, with influence from #EasternEurope, #Morocco, #Israel, and everywhere in between."

https://www.cntraveler.com/story/the-best-jewish-food-in-nyc-according-to-a-jewish-new-yorker

Snowshadow mastodon (AP)
🇨🇦 Private equity and health care: Should Canadians be concerned?
Some U.S. critics have gone so far as to describe private equity firms as vulture capitalists.

@gemelliz
#Canada #Canpoli #Healthcare

https://healthydebate.ca/2024/07/topic/private-equity-health-care/


BrianKrebs mastodon (AP)
In September 2023, I published a story about extensive research suggesting that thieves who'd obtained a copy of the encrypted LastPass vaults that were exposed in a 2022 data breach were successfully cracking access to some LastPass accounts, leading to a significant number of 7-figure+ cryptocurrency thefts.

https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/

In the past week, the talented crypto crime researcher ZachXBT walked through how thieves have stolen another $5.36M from over 40 different crypto wallet addresses recently, and why it was likely tied to the LastPass breach.

https://www.theblock.co/post/331118/lastpass-threat-actor-drains-5-4-million-in-crypto-from-over-40-victim-addresses-zachxbt

In response to media coverage of ZachXBT's research, LastPass issued a statement that basically said all of the researchers who've connected high-dollar thefts to the LastPass breach are somehow barking up the wrong tree:

"A year has passed since initial claims surfaced alleging a link between certain cryptocurrency thefts and the 2022 LastPass security incidents,” LastPass Chief Secure Technology Officer Christofer Hoff said. “In that time, LastPass has investigated these claims and to date is not aware of any conclusive evidence that directly connects these crypto thefts to LastPass. Because we take any claims regarding the security of LastPass and our customers seriously, we continue to invite any security researchers who believe they may have evidence to contact the LastPass Threat Intelligence team.”

Taylor Monahan, lead product manager at MetaMask, is one of the researchers who's been most vocal about the apparent fallout from the LastPass breach. Tay's responses over on Hellsite to the LastPass statement are scathing.

https://x.com/tayvano_/status/1869780370671226962
A statement from LastPass reads: A year has passed since initial claims surfaced alleging a link between certain cryptocurrency thefts and the 2022 LastPass security incidents,” LastPass Chief Secure Technology Officer Christofer Hoff said. “In that time, LastPass has investigated these claims and to date is not aware of any conclusive evidence that directly connects these crypto thefts to LastPass. Because we take any claims regarding the security of LastPass and our customers seriously, we continue to invite any security researchers who believe they may have evidence to contact the LastPass Threat Intelligence team.”
Tweets from @tayvano_

The last time I talked to their security team they:
Distanced themselves from their past security team who did the initial CFIR
Covered their ass
Acted like we didn’t know what we were doing
Questioned our data
Blamed victims

They didn’t know what we knew and didn’t listen when we told them what we knew.
11:22 AM · Dec 19, 2024
·

I know they know.

They know I know.

And they also know I won’t fuck over victims and the investigation by sharing the hardest intel publicly.

But they fucking know. And have known for well over 14 fucking months. I made damn fucking sure of that.
This entry was edited (1 month ago)
BrianKrebs mastodon (AP)
@troed the victims i interviewed for that story all had used LP to store their crypto seed phrase, all had low number of iterations for their pwd hash, and had relatively low-entropy passwords.
Troed Sångberg mastodon (AP)
Thanks, yeah getting people to use strong Master passwords even when you tell them how critical it is is extremely difficult :/

taz (inoffiziell) friendica (via ActivityPub)
Der Bundestag beschließt das novellierte Filmförderungsgesetz. Die Filmproduktion in Deutschland geht weiter, aber ohne geplanten Diversitätsbeirat.

Nancy By Ernie Bushmiller
December 20,1949

Not a Goat 🦝 mastodon (AP)
Sophos security advisory 19 December 2024: Resolved Multiple Vulnerabilities in Sophos Firewall (CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)
  • CVE-2024-12727 (9.8 critical) pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall
  • CVE-2024-12728 (9.8 critical) weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall
  • CVE-2024-12729 (8.8 high) post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall

Sophos has not observed these vulnerabilities to be exploited at this time.

#sophos #firewall #vulnerability #cve #infosec #cybersecurity


taz (inoffiziell) friendica (via ActivityPub)
Kurz vor knapp haben Bundestag und Bundesrat den Weg für die Finanzierung des Deutschlandtickets 2025 freigemacht. Teurer wird das Ticket trotzdem.

taz diaspora
Eintritt in Verteidigungsbündnis

Zypern will in die Nato


Von Ferry Batzoglou

Mitglied der EU und der Eurozone ist die Republik Zypern schon, aber nicht in der Nato. Nun will sie dem Nordatlantikpakt beitreten. Die Türkei ist dagegen.

Schwerpunkt: Nato

#taz #tageszeitung #Zypern #Zypernkrise #Türkei
taz diaspora
Jetzt hab ich Netto gelesen statt Nato.
Rasmus Fuhse diaspora
Dann hast Du jetzt endlich mehr Netto vom Brutto.


taz (inoffiziell) friendica (via ActivityPub)
Eine Gasspeicherumlage war Nachbarländern ein Dorn im Auge. Sie ist nun bald Geschichte.

Ulrich Kelber mastodon (AP)
Tja, in Rekordzeit schlecht gealtert.
Menel :xmpp: mastodon (AP)
@derpostillon schrieb auch grade
"Mehr Musk wagen: Christian Lindner erklärt ebenfalls Unterstützung für die AfD"

https://www.der-postillon.com/2024/12/musk-wagen.html

#MehrMuskWagen #politics
lbarthas mastodon (AP)
Das lässt sich doch wirklich nur mit Lindners Inkompetenz erklären. Hat er sich in letzter Zeit nicht angeschaut, was von Musik so kommt? Der ist doch nicht erst seit heute in die rechtsextreme Ecke hinabgestiegen. Oder möchte man sich etwa den Rechtsextremen anbiedern?
So oder so: wie hält es ein Gerhart Baum da nur aus?

Zack Whittaker mastodon (AP)
New, by me: Hospital giant Ascension said a May ransomware attack allowed hackers to steal data on 5.6 million patients — the third-largest healthcare data breach of the year.

https://techcrunch.com/2024/12/20/ransomware-attack-on-health-giant-ascension-hits-5-6-million-patients/

Lake Michigan! Live! mastodon (AP)
Current* conditions near Chicago, IL:
View of the Chicago Harbor Lighthouse from one of the cribs located in Lake Michigan. // Image captured at: 2024-12-20 16:00:01 UTC (about 3 min. prior to this post) // Current Temp in Chicago: 34.89 F | 1.61 C // Precip: overcast clouds // Wind: NNE at 8.008 mph | 12.88 kph // Humidity: 74%

taz (inoffiziell) friendica (via ActivityPub)
Nach über 50 Jahren genießen viele Menschen in Syrien die Freiheit, zu demonstrieren. Und nutzen ihr Recht: Für einen säkularen Staat, für Pluralismus.

taz (inoffiziell) friendica (via ActivityPub)
Ob Eigenbedarf oder Wuchermiete: Vermieter brechen systematisch Gesetze. Manchmal wird der Rechtsbruch aufgehalten. Strafen erhalten sie nie.

obrhoff mastodon (AP)
What they sell in Poland as an "original" döner kebab. Bacon Cheese Döner 😭

It's actually one of the things that feels weird in Poland if you're German. Polish people love to adapt food from other countries, but compared to Berlin, it's usually Polish people running these restaurants rather than people from the food's country of origin.
#berlin #poland #döner #food
This entry was edited (1 month ago)

taz (inoffiziell) friendica (via ActivityPub)
Eine Alternative zu Cookie-Bannern soll das Surfen im Netz angenehmer machen. Doch Verbraucherschützer kritisieren die Neuregelung.

taz (inoffiziell) friendica (via ActivityPub)
Die Linke hat Michael Kretschmer ins Amt verholfen. Sie tut sich keinen Gefallen, einen Ministerpräsidenten zu wählen, nur weil von rechts die AfD droht.

taz (inoffiziell) friendica (via ActivityPub)
Über die Deutsche Bahn meckern können alle gut – der Podcast „Teurer Fahren“ liefert die Argumente.

taz (inoffiziell) friendica (via ActivityPub)
Kampfkluft oder Luxuslabel? Der Bildband „Fashion Army“ zeigt Arbeitskleidung des US-Militärs.

Hannu Ikonen, MD mastodon (AP)
fuck i gotta shower, cant alt text it for a spell, but i fuckin laughed
Hannu Ikonen, MD mastodon (AP)
2024 is seeing a staged photo up of police geared out in more expensive garb than all 32 NHL & MLB teams fucking *combined* tryna recreate some religious Renaissance era painting of Jesus being prosecuted with police fully unaware that *they are the baddies*
Hannu Ikonen, MD mastodon (AP)
And since both MLB & NHL cheaped out with Fanatics, you 100% know this is accurate
Hannu Ikonen, MD mastodon (AP)
First motherfucker to actually defund the NYPD should win the Nobel Peace prize.
JustAFrog mastodon (AP)
Oh noes, that rampant racism against ... uh ... italians?

Never mind that Nintendo consoles do well in Italy and people play the Mario games on them.

Not a Goat 🦝 mastodon (AP)
JPCERT/CC: Recent Cases of Watering Hole Attacks, Part 1
Japan's Computer Emergency Response Center shows a graphic about APT attacks, but talks generally about watering hole attacks targeting Japan. They describe multiple watering hole attacks by the same threat actor group (unknown). Indicators of compromise are shared.

#wateringhole #IOC #threatintel #infosec #cybersecurity #cyberthreatintelligence #cti

Tengrain mastodon (AP)
Speaker Johnson Books Trip On The Kobayashi Maru

At the moment, Speaker Jeebus Johnson is trying to pass the legislation under a suspension of the normal rules. The upside to doing it this way is that it stops the usual vandals from throwing cinder blocks onto the highway by demanding procedural votes or trying to add amendments. The downside to doing it this way is that it requires a two-thirds vote…

http://mockpaperscissors.com/2024/12/20/speaker-johnson-books-trip-on-the-kobayashi-maru/

Not a Goat 🦝 mastodon (AP)
Kaspersky: BellaCPP: Discovering a new BellaCiao variant written in C++
Kaspersky discovered an older version of BellaCiao written in C++, while investigating an intrusion on a computer in Asia. They provide a technical analysis of this version, dubbed BellaCPP, which they assess with medium to high confidence to the Iranian state-actor Charming Kitten (publicly attributed to Islamic Revolutionary Guard Corps (IRGC) by the U.S. Government). Kaspersky believes they continue to work on and update BellaCiao, and warns incident responders to be thorough in investigations for finding unknown samples, not just the known ones. Indicators of compromise provided.

#charmingkitten #mintsandstorm #apt42 #apt35 #iran #irgc #cyberespionage #IOC #threatintel #infosec #cybersecurity #cyberthreatintelligence #cti


Rightardia mastodon (AP)
Here's what happens if the government shuts down right before the holidays

"During a shutdown, the federal government would be unable to pay its millions of employees, including members of the military and reservists, just before the holidays . . .

'Hundreds of thousands of government workers could be furloughed, meaning they would temporarily stop going to work. During a shutdown in 2013, about 850,000 workers were furloughed."

https://news.yahoo.com/heres-happens-government-shuts-down-035938988.html

unusual_whales mastodon (AP)
The multi-billionaire owner of luxury jewellery company Cartie, Johann Rupert, has said his greatest fear is robots replacing workers and the poor rising up to bring down the rich, per the Independent.

#news #finance #economics #stocks #options

Tony Pennino mastodon (AP)
Oh FFS. I just received a grade grubbing email written using ChatGPT. This is like any moment in a superhero franchise when the villains join forces. #academia #academicchatter #academiclife
Taysia mastodon (AP)
😂😂😂🤭

fediverseobserver friendica (via ActivityPub)
Found 8 new servers and 21 servers died off since 7 hours ago.

22,914 servers checked. 14,756,970 Total Users with 1,069,805 Active Users today. Check out the stats!

New #fediverse servers found:

stream.neotheta.fi a #owncast server from Germany
keepupwthetempo.com a #wordpress server from United States
janerationx.rocks a #mastodon server from Portugal
pixel.starbuckstech.com a #pixelfed server from United States
content.haacksnetworking.org a #peertube server from United States
social.moekyun.me a #sharkey server from United States
thedailyid.com a #wordpress server from United States
m.drifting.boats a #mastodon server from Private

Help others find a home, send them to fediverse.observer

Sue Stone mastodon (AP)
'Making this dude look cool as hell': NYPD's Luigi Mangione photo op instantly backfires - Raw Story

https://www.rawstory.com/luigi-mangione-backfire-nypd/

Not a Goat 🦝 mastodon (AP)
Unit 42: Now You See Me, Now You Don’t: Using LLMs to Obfuscate Malicious JavaScript
Unit 42 describes how large language models (LLMs) can generate malicious JavaScript code (or at least rewrite/obfuscate existing malware). Attackers can prompt LLMs to perform "transformations" that are much more natural-looking (read:benign) which make malware harder to detect by security vendor tools and malware classifiers. Unit 42 provides real-world examples of detections from LLM-obfuscated malicious JavaScript. Indicators of compromise are provided.

#llm #JavaScript #malware #obfuscation #IOC #infosec #cybersecurity #cyberthreatintelligence #cti

Tony Pennino mastodon (AP)
Last night, I graded an AI-generated paper so poor that even I was like, “Oh, ChatGPT, I know you can do better.” #academia #academicchatter #chatgpt #professor

GaslitNation mastodon (AP)
In the United States, the principle of "innocent until proven guilty" is a cornerstone of justice. Yet, the NYPD's promotion of fascist pageantry, exemplified by this stunt, only undermines that ideal. It should be central to the defense’s case that Luigi Mangione, the alleged Claims Adjuster Assassin, cannot receive a fair trial given the NYPD's exploitation of his image for a grotesque PR campaign.

#luigimangione #nyc

Follow me for more recipes.

#FunnyRecipes
Left: A mandarin on a plate.
Right: A peeled mandarin on a plate.
Crowjane mastodon (AP)
What a lovely holiday dessert! I’m going to do my best to replicate it.
Jess ex machina mastodon (AP)
You are so talented and creative. 😍

Not a Goat 🦝 mastodon (AP)
Krebs on Security: Web Hacking Service ‘Araneida’ Tied to Turkish IT Firm
A cracked version of Acunetix, a commercial web app vulnerability scanner, is being resold as a cloud-based service to cybercriminals. @briankrebs traced the identity of the advertiser to an individual named Altuğ Şara from Ankara, Turkey, who worked the past two years as a senior software developer for a Turkish IT firm called Bilitro Yazilim.

#Araneida #acunetix #altugsara #turkey #BilitroYazilim #cybercrime #threatintel #infosec #cybersecurity #cyberthreatintelligence #cti

Covidiocracy mastodon (AP)
“A man in California had been messaging [school shooter] about attacking a government building with a gun and explosives, according to a restraining order issued against him under California’s gun red flag law. The order didn’t detail his interactions with Rupnow except to state that the man was plotting a mass shooting with her.”

https://apnews.com/article/wisconsin-school-shooting-abundant-life-rupnow-32ef21b182db91a097dfffa317dfec53
#California #Wisconsin #schoolshooting #DomesticTerrorism

nd.Aktuell mastodon (AP)
»Die Scham muss die Seite wechseln«, dieser Satz ging um die Welt, wo Gisèle Pelicot seither für ihren Mut und ihre Entschlossenheit bewundert wird. Dank des Avignon-Prozesses ermutigt Pelicot Opfer dazu, laut zu werden, schreibt Livia Lergenmüller.

👉 https://www.nd-aktuell.de/artikel/1187700.avignon-prozess-schande-gehoert-nur-den-taetern.html

Hol dir jetzt dein Last-Minute-Geschenk: Linken Journalismus im Abo. 🎁 https://dasnd.de/verschenken 🎁
“All jenen von sexualisierter Gewalt betroffenen Frauen, die bisher geschwiegen haben, zeigt Gisèle Pelicot, dass es sich lohnt, zu sprechen.”

Livia Lergenmüller, nd-Autorin

newer older

This website uses cookies to recognize revisiting and logged in users. You accept the usage of these cookies by continue browsing this website.