#informationsecurity

32 posts · Last used 12d

Akamai security researchers have uncovered an interesting attack technique they call “Bring Your Own EDR.” The research demonstrates how a trusted, privileged EDR component can potentially become an attacker’s tool against the system it was designed to protect. In a SentinelOne case study, researchers found that exposed interfaces could be abused by an administrator to bypass Windows Protected Process Light protections and interact with highly protected processes. By chaining multiple techniques, they demonstrated how legitimate security software could potentially be turned into a powerful attack mechanism. The bigger lesson is important: security software itself is part of the attack surface. EDR solutions operate with extremely high privileges, which makes vulnerabilities, exposed interfaces, weak trust assumptions, and insecure management mechanisms particularly significant. Organizations should consider not only whether their security tools detect threats, but also how well those tools protect themselves from abuse. “Bring Your Own EDR” is an interesting evolution of the traditional BYOVD concept and another reminder that trusted software should never automatically be treated as inherently trustworthy. #Cybersecurity #EDR #EndpointSecurity #ThreatResearch #ZeroTrust #WindowsSecurity #SecurityResearch #InformationSecurity https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse
0
0
0
0
How average folks don't stand a chance against phishing, example #80,144,963: "Security" "Professionals" "Warning! Your account is about to be deactivated." Log in soon or terrible things will happen. Consider clicking on a link in this email. BUTTON [Click it... Click it... Click it...] Grey on grey because accessibility is for losers. Click the password manager plugin icon on a browser tab, start typing "cis...", click to open and autofill credentials and login (in one step), click the (old) password field to autofill, click to accept the suggested very long and random password suggestion which autofills both the new password field and the one to check that the autofill typed it correctly the first time then automatically submit, log out, and wait for the next email from Compliance Isn't Security inviting me to the next dance. For the historians: this is during the current wave of phishing campaigns claiming that your service is being shut down, retired, updated or otherwise changed in a way which requires you to click urgently before all that you love is lost. PS. "This email was sent with love from" PPS. NIST SP 800-63B §3.1.1.2 #6 - https://pages.nist.gov/800-63-4/sp800-63b.html#passwordver #Phishing #ComplianceVsSecurity #CIS #CenterForInternetSecurity #InfoSec #InformationSecurity #CyberSecurity
1
3
1
0
Replying to
Not only is Center for Internet Security, Inc. (CIS) still sending these, but they still have no multi-factor authentication for accounts. From https://www.cisecurity.org/about-us The CIS Vision Leading the global community to secure our ever-changing connected world. The CIS Mission Our mission is to make the connected world a safer place by developing, validating, and promoting timely best practice solutions that help people, businesses, and governments protect themselves against pervasive cyber threats. https://www.youtube.com/watch?v=51gf648nRyE&t=118s #Phishing #ComplianceVsSecurity #CIS #CenterForInternetSecurity #MFA #2FA #InfoSec #InformationSecurity #CyberSecurity
1
2
1
0
Replying to
While it may have taken them a moment, with the new CIS Portal for CIS Workbench, they have announced that, "When your account is ready, you'll be guided through a brief process to choose a primary verification method, .." Hardware tokens and/or passkeys, right? "..like SMS ..." When your account is updated, be sure to visit the Portal for "CIS-curated thought leadership and cybersecurity resources to help you put best practices into action" #Phishing #ComplianceVsSecurity #CIS #CenterForInternetSecurity #MFA #2FA #InfoSec #InformationSecurity #CyberSecurity
0
1
0
0

Coinkite advises their customers to move Bitcoin funds away from Coldcard-based wallets, after it was found that the firmware used pseudorandom number generators

https://www.cbc.ca/news/world/bitcoin-coinkite-security-hack-9.7295582


Coinkite avise sa clientèle de bouger les fonds Bitcoin loin des portefeuilles à base Coldcard, après qu’il a été trouvé que le microgiciel utilisait des générateurs de nombres pseudoaléatoires

// Article en anglais //

#Bitcoin #Coldcard #Coinkite #InfoSec #InformationSecurity #Cybersécurité

0
1
0
0
'Objective for the We' v4.0 in Berlin, July 30th - 31st The Objective-See Foundation, Inc Foundation is pleased to present Objective for the We (#OFTW): a multi-day event aimed at empowering those interested in cybersecurity, while also working to enhance diversity in this field. The in-person event will provide free talks and trainings from some of the world's top Apple security researchers in order to provide cybersecurity students with an invaluable learning and networking opportunity. Invite-only event, to be considered for participation interested students must complete a short application form. Deadline to apply: June 26th, 2026 https://objective-see.org/oftw/v4.html #OFTW #CyberSecurity #InformationSecurity
0
0
0
0
Having just discovered Podcast Index ActivityPub support, here is a list of my current information security-related subscriptions in order of their latest release. Please add yours. • Malicious Life @460150@ap.podcastindex.org with Ran Levi at Cybereason • Random but Memorable @236393@ap.podcastindex.org with @mattdavey@social.lol, @MrRooni@mastodon.social, and Anna Eastick at @1password@1password.social • Hacking Humans @1021915@ap.podcastindex.org with @bittner@hachyderm.io, @jtcarrigan@infosec.exchange and @varmazis@mstdn.social at @N2K@infosec.exchange • Darknet Diaries @577105 with Jack Rhysider @jackrhysider@infosec.exchange • SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) @571906 with @jullrich@infosec.exchange at @sans_isc@infosec.exchange • Risky Business @548735@ap.podcastindex.org and Risky Business News @5423259@ap.podcastindex.org with @riskybusiness@infosec.exchange, @tomatospy@infosec.exchange, @campuscodi@mastodon.social, Adam Boileau, @thegrugq@infosec.exchange, and Claire Aird • Defensive Security Podcast @735955@ap.podcastindex.org with @jerry@infosec.exchange and @lerg@infosec.exchange • Open Source Security Podcast @518991@ap.podcastindex.org with @kurtseifried@infosec.exchange and @joshbressers@infosec.exchange • Troy Hunt's Weekly Update Podcast @6971@ap.podcastindex.org with @troyhunt@infosec.exchange of @haveibeenpwned@infosec.exchange fame • No Such Podcast @6991439@ap.podcastindex.org with folks at the U.S. National Security Agency • Hacker History Podcast @2169457@ap.podcastindex.org with @joshbressers@infosec.exchange • Decipher Security Podcast @615780@ap.podcastindex.org with @dennisf@infosec.exchange and @LindseyODWelch@infosec.exchange at @Deciphersec@infosec.exchange • The Cyberlaw Podcast @1089343@ap.podcastindex.org (Retired) with @stewartbaker@infosec.exchange Thanks to @dave@podcastindex.social, @adam@podcastindex.social, @alberto@podcastindex.social and all at https://podcastindex.org for the service. #InfoSec #InformationSecurity #CyberSecurity #Podcast #Podcasts #PodcastIndex
42
6
16
0
Replying to
Podcasts come and podcasts and podcasters go, then occasionally return, so here is a list of my current information security-related subscriptions in order of their latest release. • Hacker History @2169457 with @joshbressers@infosec.exchange and guests • Random but Memorable @236393 with @mattdavey@social.lol, @MrRooni@mastodon.social, Allie, and Anna Eastick at @1password@1password.social • Hacking Humans @1021915 with @bittner@hachyderm.io, @jtcarrigan@infosec.exchange and @varmazis@mstdn.social at @N2K@infosec.exchange • Risky Business Features @7716365 with James Wilson and guests • Risky Bulletin @5423259 with @riskybusiness@infosec.exchange, @tomatospy@infosec.exchange, James Wilson, @thegrugq@infosec.exchange, @campuscodi@mastodon.social, et al. featuring shows "Risky Bulletin" with Claire Aird, "Between Two Nerds", "Sponsored", and "Srsly Risky Biz" • SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) @571906 with @jullrich@infosec.exchange at @sans_isc@infosec.exchange • Open Source Security @518991 with @joshbressers@infosec.exchange and guests • Risky Business @548735 with @riskybusiness@infosec.exchange, Adam Boileau, James Wilson, • Decipher Security @615780 with @dennisf@infosec.exchange and @LindseyODWelch@infosec.exchange at @Deciphersec@infosec.exchange • Troy Hunt's Weekly Update Podcast @6971 with @troyhunt@infosec.exchange of @haveibeenpwned@infosec.exchange fame • Surveillance Report @1048322 with @hen@social.lol at @techlore@social.lol • Defensive Security Podcast @735955 with @jerry@infosec.exchange and @lerg@infosec.exchange • Darknet Diaries @577105 with Jack Rhysider @jackrhysider@infosec.exchange Thanks again to @dave@podcastindex.social, @adam@podcastindex.social, @alberto@podcastindex.social and all at https://podcastindex.org for the service. @stewartbaker@infosec.exchange died 30 April 2026 aged 78. #InfoSec #InformationSecurity #CyberSecurity #Podcast #Podcasts #PodcastIndex
23
2
7
0
"Finland, Sweden, Norway, Denmark and Estonia are rolling out offline card payment systems to provide a back-up if internet connections are lost, including due to sabotage, Bank of Finland board member Tuomas Valimaki said on Wednesday. ... Sweden's central bank told Reuters that it hoped to establish a system by July 1, 2026, that would allow Swedes to make offline card payments to buy essential goods in the event of disruptions lasting up to seven days." https://www.reuters.com/business/finance/nordics-estonia-plan-offline-card-payment-back-up-if-internet-cut-2025-05-07/ #cardpayments #businesscontinuity #offlinepayments #informationsecurity
34
7
28
0