Running an independent consultancy focused on resilient, accountable digital systems and the informed use of cloud and AI. Keeping infrastructure and data understandable, auditable, and under client control.
🛡️ Steele Fortress: Safeguarding your digital realm with cutting-edge cybersecurity solutions. Committed to empowering users with privacy, security, and peace of mind in an interconnected world. #CyberSecurity #Privacy #DataPrivacy #TechEthics
🛡️ Steele Fortress: Safeguarding your digital realm with cutting-edge cybersecurity solutions. Committed to empowering users with privacy, security, and peace of mind in an interconnected world. #CyberSecurity #Privacy #DataPrivacy #TechEthics
<IT-Nerd\Retro-Computing-FanBoy/ScienceGuy> <All Creature’s Welcome> <English & German> [🖇️Check my Image Description’s🖇️]
Google blocks 8.3B Policy-Violating Ads in 2025, launches Android 17 Privacy Overhaul.
The new policy updates relate to contact and location permissions in Android, allowing third-party apps to access the contact lists and a user's location in a more privacy-friendly manner. This includes a new Contact Picker, which offers a standardized, secure, and searchable interface for contact selection.
"This feature allows users to grant apps access only to the specific contacts they choose, aligning with Android's commitment to data transparency and minimized permission footprints," Google said.
https://android-developers.googleblog.com/2026/03/contact-picker-privacy-first-contact.html
⁉️To comply with this update, developers are being urged to review their apps location usage to ensure that they are requesting the minimum amount of location data necessary for them to function.⁉️
#android #security #privacy #engineer #media #infosec #developer #tech #news
IT Consultant from Germany, Linux enthusiast, BSD fanboy and firmly convinced that Ancient Domains of Mystery is the greatest video game of all time (and always will be). You'll find me here talking about Open Source, self-hosting, advanced networking (proud operator of AS201379), smart home shenanigans, and anything you can torment with a terminal. Cat pictures also welcome. Left, antifascist, vegan. The trifecta your uncle warned you about.
IT Consultant from Germany, Linux enthusiast, BSD fanboy and firmly convinced that Ancient Domains of Mystery is the greatest video game of all time (and always will be). You'll find me here talking about Open Source, self-hosting, advanced networking (proud operator of AS201379), smart home shenanigans, and anything you can torment with a terminal. Cat pictures also welcome. Left, antifascist, vegan. The trifecta your uncle warned you about.
Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice! (he/him) #infosec #DFIR #BlueTeam #Pentesting
Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice! (he/him) #infosec #DFIR #BlueTeam #Pentesting
System Architect ★ Software Developer ★ High Energy Physics PhD at Uni Oslo & CERN ★ Linux ★ Python ★ Open Source ★ Unicode Unicorn ★ ISO 8601 Enthusiast ★ Consumer of Sci-Fi ★ Hobby Writer ★ Born at 336 ppm CO₂ ★ She/They Open Source: https://novelwriter.io & https://fosstodon.org/@novelwriter Banner image from Wallpaper Access.
System Architect ★ Software Developer ★ High Energy Physics PhD at Uni Oslo & CERN ★ Linux ★ Python ★ Open Source ★ Unicode Unicorn ★ ISO 8601 Enthusiast ★ Consumer of Sci-Fi ★ Hobby Writer ★ Born at 336 ppm CO₂ ★ She/They Open Source: https://novelwriter.io & https://fosstodon.org/@novelwriter Banner image from Wallpaper Access.
Hacker, activist, free-softie ◈ techie luddite ◈ formerly information security and infrastructure at https://isnic.is/ and https://occrp.org/ ◈ my opinions are my own etc. (he/him) ⁂ profile image: drawing of a head and shoulders of a cat-person, in a space suit. banner image: long-exposure photo of a large tent, brightly illuminated from inside, looking as if it is made of lava #foss #libre #privacy #infosec #fedi22 (public toots CC By-SA 4.0 if applicable) 🇪🇺 🇵🇱 · 🇧🇦 🇮🇸 · 🇺🇦
Hacker, activist, free-softie ◈ techie luddite ◈ formerly information security and infrastructure at https://isnic.is/ and https://occrp.org/ ◈ my opinions are my own etc. (he/him) ⁂ profile image: drawing of a head and shoulders of a cat-person, in a space suit. banner image: long-exposure photo of a large tent, brightly illuminated from inside, looking as if it is made of lava #foss #libre #privacy #infosec #fedi22 (public toots CC By-SA 4.0 if applicable) 🇪🇺 🇵🇱 · 🇧🇦 🇮🇸 · 🇺🇦
Some do inspect the script, but then still run it using curl | bash anyway.
Incidentally, this very relevant blogpost about detecting curl | bash and serving different scripts based on that is almost exactly a decade old:
https://web.archive.org/web/20230318063325/https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/
#CopyFail #InfoSec
Tinkerer | Solarpunk | Hacker ☸️ Buddhist ☸️ Profile Pic: @PixelOccult
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Copy Fail: Linux Kernel Flaw Grants Root Access On All Major Distributions
A Linux kernel vulnerability called “Copy Fail” (CVE-2026-31431) allows unprivileged local users to gain root privileges with 100% reliability by corrupting the shared page cache. The flaw affects nearly all Linux distributions since 2017 and enables container escapes because the memory corruption does not modify files on disk.
If you run Linux servers, especially shared environments like Kubernetes clusters, CI/CD runners, or multi-tenant hosts, patch your kernel immediately to a version that includes the fix (mainline commit a664bf3d603d) for CVE-2026-31431. If you can’t patch right away, disable the vulnerable module by running echo “install algif_aead /bin/false” > /etc/modprobe.d/disable-algif.conf followed by rmmod algif_aead, and for untrusted code environments block AF_ALG socket creation via seccomp as a long-term safeguard. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/copy-fail-linux-kernel-flaw-grants-root-access-on-all-major-distributions-w-l-v-0-c/gD2P6Ple2L
📺 https://peer.adalta.social/w/31SRjrt5uVDoD5LpdkeoAn 🔗 🇩🇪🇺🇸🇫🇷 🔗 ℹ️
OpenAI’s Cybersecurity Action Plan Presents a Critical Temporal Advantage.
#cybersecurity #security #infosec #openai #artificialintelligence
📺 https://peer.adalta.social/w/7G8R2aqWXn34FS83wmSdkc 🔗 🇩🇪🇺🇸🇫🇷 🔗 ℹ️
Die Notwendigkeit einer schnellen, verantwortungsvollen Verteidigung gegen KI-gestützte Bedrohungen
#cybersecurity #security #infosec #openai #artificialintelligence
Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice! (he/him) #infosec #DFIR #BlueTeam #Pentesting
Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice! (he/him) #infosec #DFIR #BlueTeam #Pentesting
Quad9 is a free service that replaces your default ISP or enterprise Domain Name Server (DNS) configuration. 9.9.9.9 | 149.112.112.112 2620:fe::fe | 2620:fe::9 support@quad9.net https://on.quad9.net/ https://uptime.quad9.net/#
53yo Druid, Trans, Mom, Resister @keira x17 - Life Partner #liberal #reading #author #druid #nature #meditation, #spirituality #Pagan #earth #eco #trans #queer #lgbtqia
53yo Druid, Trans, Mom, Resister @keira x17 - Life Partner #liberal #reading #author #druid #nature #meditation, #spirituality #Pagan #earth #eco #trans #queer #lgbtqia
53yo Druid, Trans, Mom, Resister @keira x17 - Life Partner #liberal #reading #author #druid #nature #meditation, #spirituality #Pagan #earth #eco #trans #queer #lgbtqia
53yo Druid, Trans, Mom, Resister @keira x17 - Life Partner #liberal #reading #author #druid #nature #meditation, #spirituality #Pagan #earth #eco #trans #queer #lgbtqia
53yo Druid, Trans, Mom, Resister @keira x17 - Life Partner #liberal #reading #author #druid #nature #meditation, #spirituality #Pagan #earth #eco #trans #queer #lgbtqia
53yo Druid, Trans, Mom, Resister @keira x17 - Life Partner #liberal #reading #author #druid #nature #meditation, #spirituality #Pagan #earth #eco #trans #queer #lgbtqia
53yo Druid, Trans, Mom, Resister @keira x17 - Life Partner #liberal #reading #author #druid #nature #meditation, #spirituality #Pagan #earth #eco #trans #queer #lgbtqia
53yo Druid, Trans, Mom, Resister @keira x17 - Life Partner #liberal #reading #author #druid #nature #meditation, #spirituality #Pagan #earth #eco #trans #queer #lgbtqia
Blog d'un technophile qui verse dans le fédiverse
Blog d'un technophile qui verse dans le fédiverse
Protéger le fédiverse contre les bots IA
Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice! (he/him) #infosec #DFIR #BlueTeam #Pentesting
Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice! (he/him) #infosec #DFIR #BlueTeam #Pentesting
Haven’t had much new stuff to report on this topic for a bit…until today!
3 new arrivals to the deleteduser dumpster:
-
a company that handles public/guest wifi access in Europe
-
An EU based sports club booking platform
and, extremely concerningly:
- a period tracking app, that emails out full PII and data
All have been contacted.
In lighter plexfiltration news, a developer who was testing something out sent a ‘hello, test’ message to a ‘deleted user’, so I was able to respond with ‘test worked - hows it going?’ which I can only assume really freaked them out.
Out of the now 60ish orgs contacted, have heard back from 2 who have fixed their use of deleteduser.com. I’d say that maybe 3 or 4 have dropped off, but the rest still continue.
Ironically, this includes all of the tech and cybersecurity companies that were contacted.
Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice! (he/him) #infosec #DFIR #BlueTeam #Pentesting
Author of Digital Forensic/Pen Test/Blue Team Diaries, Hands-on Incident Response and Digital Forensics & Security Operations in Practice! (he/him) #infosec #DFIR #BlueTeam #Pentesting