dice.camp is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon server for RPG folks to hang out and talk. Not owned by a billionaire.

Administered by:

Server stats:

1.8K
active users

#cyberattack

2 posts2 participants0 posts today

👋 Ready for a fresh day of Cyber horrors? Me neither!

Oh well, here you go: opalsec.ghost.io/daily-news-up

Here's a few of the key items to be aware of:

🚨 Palo Alto GlobalProtect Scans: Observed a significant spike in scans targeting Palo Alto Network GlobalProtect login portals, possibly prior to new exploit releases. Time to audit those logs! 🧐

🇨🇳 China as Top Cyber Threat: Gen. Paul Nakasone (former NSA/Cyber Command Head) highlights China's unprecedented cyber activities, including malicious code in critical infrastructure and rapid exploitation of vulnerabilities. It's time to rethink our defense strategies! 🛡️

🇰🇵 North Korean IT Worker Expansion: North Korean "IT warriors" are infiltrating European companies, using fake identities to secure remote work and fund their regime. Stay vigilant and double-check those remote hires! 🕵️

🔑 Identity Flaws in Breaches: A new report indicates 60% of incidents involved an identity attack, with compromised valid accounts being a top initial access vector. Focus on robust MFA, least privilege, and AD security! 🔒

Read the full post for all the details and more actionable insights, and if you want all this straight to your inbox, you're in luck! 👉 opalsec.ghost.io/daily-news-up

Opalsec · Daily News Update: Wednesday, April 2, 2025 (Australia/Melbourne)Increased scans of Palo Alto GlobalProtect devices may indicate imminent attack. Nakasone names China the biggest Cyber threat to the US. DPRK expands prolific IT Worker campaigns to Europe. Talos finds Identity a key culprit in 69% of Ransomware incidents.

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #13/2025 is out!

It includes the following and much more:

➝ DNA of 15 Million People for Sale in #23andMe Bankruptcy,

#Trump administration accidentally texted a journalist its war plans,

➝ Critical Ingress #NGINX controller vulnerability allows RCE without authentication,

#Cyberattack hits Ukraine's state railway,

➝ Troy Hunt's Mailchimp account was successfully phished,

#OpenAI Offering $100K Bounties for Critical #Vulnerabilities,

#Meta AI is now available in #WhatsApp for users in 41 European countries... and cannot be turned off

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

infosec-mashup.santolaria.net/

DNA of 15 Million People for Sale in 23andMe Bankruptcy, Trump administration accidentally texted a journalist its war plans, Critical Ingress NGINX controller vulnerability allows RCE without authentication, Cyberattack hits Ukraine's state railway, Troy Hunt's Mailchimp account was successfully phished, OpenAI Offering $100K Bounties for Critical Vulnerabilities, Meta AI is now available in WhatsApp for users in 41 European countries... and cannot be turned off
X’s InfoSec Newsletter🕵🏻‍♂️ [InfoSec MASHUP] 13/2025DNA of 15 Million People for Sale in 23andMe Bankruptcy, Trump administration accidentally texted a journalist its war plans, Critical Ingress NGINX controller vulnerability allows RCE without authentication, Cyberattack hits Ukraine's state railway, Troy Hunt's Mailchimp account was successfully phished, OpenAI Offering $100K Bounties for Critical Vulnerabilities, Meta AI is now available in WhatsApp for users in 41 European countries... and cannot be turned off

😒 What Really Happened With the DDoS Attacks That Took Down X
@WIRED

「 Kevin Beaumont and other analysts see evidence that some X origin servers, which respond to web requests, weren't properly secured behind the company's Cloudflare DDoS protection and were publicly visible. As a result, attackers could target them directly. X has since secured the servers 」

wired.com/story/x-ddos-attack-

WIRED · What Really Happened With the DDoS Attacks That Took Down XBy Lily Hay Newman

"Nym today launched NymVPN, a groundbreaking decentralized Virtual Private Network (dVPN) that protects users from government and corporate surveillance, including AI-driven tracking. NymVPN is built on the world’s first Noise Generating Mixnet (NGM), which is designed to protect metadata and patterns of communication, circumvent censorship, guard against cyberattacks, and fill security gaps in crypto transactions and VPN technology."

"Chelsea Manning, privacy advocate and security advisor at Nym, said: “Even in democratic nations, people are faced with unrestricted data collection, hyper-narrow algorithmic feeds and normalized censorship tactics. NymVPN takes an infrastructure-based privacy approach to try to combat this increasingly uncertain and splintered internet.”

#security #vpn #mixnet #cyberattack

nym.com/blog/NymVPN-launch-pre

nym.comNymVPN commercial launch press announcementNymVPN launches with Chelsea Manning with unlinkable payment system

Oh really it was Ukraine that took down X on March 10? Not so fast.

Independent security researchers found evidence that some X origin servers were not properly secured behind DDoS protection, and researchers noted they did not even see Ukraine in the breakdown of the top 20 IP address origins involved in the attacks. wired.com/story/x-ddos-attack- #X #Musk #DDoS #cyberattack #cybersecurity #security #Ukraine #BotNet #Internet

Safepay has been very active in Latin America.

🔗 security-chu.com/2025/03/Safep

Among the files exposed by these cybercriminals:

🇨🇴 Funeral Home cali.losolivos.co Among this multitude of files, we found one from customer service. An unsatisfied customer with the service expresses their dissatisfaction with the funeral home through an email sent on February 16, 2022. #databreach #PII

🇵🇪 Medical Center JockeySalud.com.pe In the samples exposed by these cybercriminals, there are image files of endoscopy reports of their patients. #databreach #PHI #Safepay

www.security-chu.comStormous Ransomware ataca a Enersol Costa Rica: Acceso no autorizado mediante correo de AdministradorCiberseguridad-Noticias- Latinoamérica: EnersolCR fue mencionada por actores maliciosos en foro de hacking.

Swiss critical sector faces new 24-hour cyberattack reporting rule

Switzerland's National Cybersecurity Centre (NCSC) has announced a new reporting obligation for critical infrastructure organizations in the country, requiring them to report cyberattacks to the agency within 24 hours of their discovery.

👮 bleepingcomputer.com/news/secu

BleepingComputer · Swiss critical sector faces new 24-hour cyberattack reporting ruleBy Bill Toulas