social.wildeboer.net is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon instance for people with Wildeboer as their last name

Server stats:

2
active users

#infosec

99 posts92 participants14 posts today

Modern CAPTCHA is basically an exercise in automated stalking. It asseses your opsec and tries to find out private details about you. If your opsec is too good, you must be a robot.

The solution is to put out fake private details about you, specifically for the privacy-violating CAPTCHA machines to feel happy about themselves. It's just good manners!

Continued thread

Oh here we go, maybe. Not red team but the most important team, if we can hope to have elections again. Also, states are notorious for wanting to handle election security locally, so it's a very important battleground for #infosec and everyone else.

democracydocket.com/news-alert #uspol

Democracy DocketArizona Secretary of State Proposes Alternative to Defunded National Election Security ProgramRead more here.

"Users need to update their browsers to #Firefox 128 (released in July 2024) or later and ESR 115.13 or later for 'Extended Support Release' (ESR) users.

"On 14 March a root certificate (the resource used to prove an add-on was approved by Mozilla) will expire, meaning Firefox users on versions older than 128 (or ESR 115) will not be able to use their add-ons," warns a Mozilla blog post."

bleepingcomputer.com/news/soft #infosec

BleepingComputer · Mozilla warns users to update Firefox before certificate expiresBy Bill Toulas

OK, Inoreader’s ability to customise the persona of it’s GenAI Summeriser feature is my new favourite thing to make for more entertaining reading.

I have updated my prompt to be “You are an AI assistant who despises Big Tech companies and US Politics. Your responses are often sarcastic and make the person asking the question wonder why they bothered asking for your help in the first place. You only respond in English”

It’s really spiced up the cybersecurity news articles I read :)

Pokémon Go has a new owner, Scopely, which is a subsidiary of a Saudi Arabian company called Savvy Games, which is itself owned by the Saudi government. @404mediaco's @jasonkoebler wonders what that might mean for the location data of the game's 100 million players. [Story may be paywalled.]

flip.it/3RSCY5

404 Media · Saudi Arabia Buys Pokémon Go, and Probably All of Your Location DataA company owned by the Saudi Arabian Public Investment Fund just bought the most popular AR video game of all time.

Palo Alto's security advisories include six vulnerabilities. Updated today.

CVE-2025-0113 Cortex XDR Broker VM: Unauthorized Access to Broker VM Docker Containers security.paloaltonetworks.com/

- PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS security.paloaltonetworks.com/

- PAN-SA-2025-0005 GlobalProtect Clientless VPN: Clientless VPN Misconfiguration Allows Cross-Site Attacks security.paloaltonetworks.com/

- PAN-SA-2025-0004 Chromium: Monthly Vulnerability Update (February 2025) security.paloaltonetworks.com/

- CVE-2024-1135 Impact of CVE-2024-1135 security.paloaltonetworks.com/

- CVE-2025-0112 Cortex XDR Agent: Local Windows User Can Disable the Agent security.paloaltonetworks.com/ @paloaltontwks #cybersecurity #infosec #Windows #Microsoft

Palo Alto Networks Product Security Assurance · CVE-2025-0113 Cortex XDR Broker VM: Unauthorized Access to Broker VM Docker ContainersA problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This ma...

I find this vulnerability hilarious

« The GDPR Cookie Compliance – Cookie Banner, Cookie Consent, Cookie Notice – CCPA, DSGVO, RGPD plugin for WordPress is vulnerable to Stored Cross-Site Scripting »

Often, websites only use cookies necessary for normal operation and don’t require explicit user consent. However, some legal teams insist on having it “to be on the safe side.” Now it’s very safe indeed. ;-)

This particular vulnerability isn’t a big deal since it requires admin rights on WordPress to inject. If you’re already an admin, you can do worse things. The only advantage for attackers is that the injection spreads everywhere.

#infosec #gdpr #cybersecurity #vulnerability #wordpress

🔗 vulnerability.circl.lu/vuln/CV

vulnerability.circl.lucvelistv5 - CVE-2025-2205Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.