#end

17 posts · Last used 3d

Back to Timeline
Reverend Elvis @reverend@social.undeadnetwork.de · Jul 31, 2026
0
0
0
サファイア・ネオ @Sapphire_neo@mastodon.com.pl · Jul 24, 2026
Poison_Raika's Philosophy Party 2 "[A conversation is not something you hear one phrase that catches your eye and think you've heard it. You should listen carefully from beginning to end.]" https://note.com/poison_raika/n/n981bfd809f5c <> #poison #philosophy #conversation #hear #catches #eye #listen #carefully #end #cool #answer #question #happen #fact #simple #understand #incorrect #perception #information #time #situation #given #different #fake #disaster
0
0
1
鳰 🍉 @n10_921@fedibird.com · Jul 24, 2026
維新・吉村氏、「同日選目指す」宣言 副首都法付帯決議に反し(毎日新聞) https://mainichi.jp/articles/20260724/k00/00m/010/397000c "来春の統一地方選と「大阪都構想」の3度目の住民投票の同日実施を目指している日本維新の会の吉村洋文代表(大阪府知事)は24日夜、参院本会議で可決、成立した副首都法の「選挙期間が重複しないよう最大限調整する」とした付帯決議に反し、改めて同日選の実施を目指すと宣言した。 副首都法の成立を受けて府庁で記者団の取材に応じ、「付帯決議の意思は尊重したいが、(野党が提出した)同日選禁止法案は否決された。これも国会の意思であり、同日選を目指すことに変わりはない」と述べた。" まじでなんなん?この人たち…好き勝手もいい加減にしろ :pndslime_angry: #END維新
0
0
0
サファイア・ネオ @Sapphire_neo@mastodon.com.pl · Jul 23, 2026
0
0
1
サファイア・ネオ @Sapphire_neo@mastodon.com.pl · Jul 21, 2026
0
0
1
サファイア・ネオ @Sapphire_neo@mastodon.com.pl · Jul 17, 2026
0
0
1
サファイア・ネオ @Sapphire_neo@mastodon.com.pl · Jul 16, 2026
0
0
1
サファイア・ネオ @Sapphire_neo@mastodon.com.pl · Jul 16, 2026
0
0
1
たすけ @tasuke005@toot.blue · Jun 21, 2026
7月7日は兵庫県告発文書問題の西播磨県民局長のご命日です。 奇しくもN国党立花にデマ文書を渡した張本人明石市選出元維新の岸口実県議の誕生日だそうです。 偶然とは思いますが、事実として岸口実は毎年自身の生誕の日に何を思うのだろう… #兵庫県斎藤知事問題 #斎藤元彦プロテスト #END維新 https://x.com/i/status/2068265873639698535
5
0
4
サファイア・ネオ @Sapphire_neo@mastodon.com.pl · Jul 03, 2026
0
0
1
サファイア・ネオ @Sapphire_neo@mastodon.com.pl · Jun 29, 2026
0
0
1
サファイア・ネオ @Sapphire_neo@mastodon.com.pl · Jun 28, 2026
0
0
1
tharien @tharien@lemmy.world · Apr 08, 2026

Thousands of consumer routers hacked by Russia’s military

cross-posted from: lemmy.world/post/45350334 #Thousands of consumer routers hacked by Russia’s military ##End-of-life routers in homes and small offices hacked in 120 countries. The Russian military is once again hacking home and small office routers in widespread operations that send unwitting users to sites that harvest passwords and credential tokens for use in espionage campaigns, researchers said Tuesday. An estimated 18,000 to 40,000 consumer routers, mostly those made by MikroTik and TP-Link, located in 120 countries, were wrangled into infrastructure belonging to APT28, an advanced threat group that’s part of Russia’s military intelligence agency known as the GRU, researchers from Lumen Technologies’ Black Lotus Labs said. The threat group has operated for at least two decades and is behind dozens of high-profile hacks targeting governments worldwide. APT28 is also tracked under names including Pawn Storm, Sofacy Group, Sednit, Tsar Team, Forest Blizzard, and STRONTIUM. ###Technical sophistication, tried-and-true techniques A small number of routers were used as proxies to connect to a much larger number of other routers belonging to foreign ministries, law enforcement, and government agencies that APT28 wanted to spy on. The group then used its control of routers to change DNS lookups for select websites, including, Microsoft said, domains for the company’s 365 service. “Known for blending cutting-edge tools such as the large language model (LLM) ‘LAMEHUG’ with proven, longstanding techniques, Forest Blizzard consistently evolves its tactics to stay ahead of defenders,” Black Lotus researchers wrote. “Their previous and current campaigns highlight both their technological sophistication and their willingness to revisit classic attack methods even after public exposure, underscoring the ongoing risk posed by this actor to organizations worldwide.” To hijack the routers, the attackers exploited older models that hadn’t been patched against known security vulnerabilities. They then changed DNS settings for select domains and used the Dynamic Host Configuration Protocol to propagate them to router-connected workstations. When connected devices visited the selected domains, their connections were proxied through malicious servers before reaching their intended destination. These adversary-in-the-middle servers used self-signed certificates. When the end user clicked through browser warnings, the servers captured all traffic passing through them. Among other things, they collected OAuth tokens and other credentials set after users, unaware their connections were being tapped, completed multifactor authentication. The operation began in May 2025 on a limited number of devices. Then, in August, Britain’s National Cyber Security Center released an alert that documented a malware campaign a threat group was using to “intercept and exfiltrate Microsoft Office account credentials and tokens.” The following day, the threat group rapidly stepped up the router hijacking, an activity it continued to ramp up in the coming months. Over a four-week period starting on December 12, Black Lotus observed more than 290,000 distinct IP addresses sending at least one DNS request to the malicious APT28 DNS resolver. “This suggested that as one capability was disclosed, the actor immediately shifted to another to continue acquiring authentication material,” company researchers wrote. Black Lotus described the methodology this way: DNS changes were then propagated to the workstations on the adjacent LAN via Dynamic Host Configuration Protocol (DHCP). The actor operated a DNS server to behave like a typical recursive resolver, but when a targeted Fully Qualified Domain Name (FQDN) was queried, it was configured to provide a record back containing its own IP address instead of the correct address. The only interventions were triggered by domains associated with authentication-related services. If any other domain was requested, traffic passed directly through. The actor ran a proxy service as the AitM that the end user was directed to via DNS. The only sign of this attack would be a pop-up warning about connecting to an untrusted source because of the “break and inspect.” If warnings were present and ignored or clicked through, the actor proxied requests to the legitimate services, collecting the data at the midpoint and collecting data associated with the targeted account by passing the valid OAuth token. This allowed the actor to break and inspect traffic and access authentication material such as Oauth tokens after completing the multifactor challenge. APT28 has a history of hacking routers. In 2018, researchers discovered 500,000 of the devices, mostly located in the US, were infected with malware tracked as VPNFilter. In 2024, the US Justice Department caught the group doing it again. The easiest way for people to know if their router has been compromised in the operation is to review the current DNS settings to see if they list unrecognized servers. Users should also check event logs for any unrecognized changes to DNS server settings. People should also strongly consider replacing end-of-life routers with ones that receive regular security updates. People should never click through browser alerts warning of untrusted TLS certificates. – Dan Goodin Senior Security Editor
128
20
0
Afghanistan 🇦🇫 @afghanistan@mastodon.neometropolis.net · Mar 24, 2026
In Afghanistan, women and children are among those most affected by TB, and many cases still go undetected. Early diagnosis is critical. If you or your child have symptoms, seek care without delay. Free TB testing and treatment are available nationwide. TB is curable, and early action saves lives. #End #WorldTBDay @WHO Source: WHO Afghanistan (@WHOAfghanistan) [ https://x.com/WHOAfghanistan/status/2036387833934447092 ] #Afghanistan
0
0
0

You've seen all posts