mindly.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mindly.Social is an English speaking, friendly Mastodon instance created for people who want to use their brains and their hearts to make social networking more social. 🧠💖

Administered by:

Server stats:

1.2K
active users

#security

327 posts218 participants8 posts today
Replied in thread

@tomminieminen @rejzor Oh dear, I just saw that it's not even Signal. As Heather Cox Richardson said:

"Yesterday I identified incorrectly the messaging app newly fired national security advisor Michael Waltz was using at a Cabinet meeting on Wednesday as the unsecure Signal app. Joseph Cox of 404 Media identified the app as “an obscure and unofficial version of Signal” from “a company called TeleMessage which makes clones of popular messaging apps but adds an archiving capability to each of them.” As Josh Marshall of Talking Points Memo notes, this third-party app introduces even more insecurity into those White House communications."

Hey everyone! ✌️ Sound familiar? Your AppSec tools are just *spamming* alerts left and right, right? And then you find out half of them are just noise...

It's no wonder clients get frustrated. Honestly, you've *really* got to sift through and figure out what actually matters versus what doesn't.

Sure, automated scans have their place – they're nice to have. But let's be real: a solid pentest performed by an experienced security pro? That's invaluable.

Think about it: do those scanners *really* catch the critical stuff? Most likely, nope.

What's your take on this? Let me know below! 👇

I just had a weird experience at Target—my girlfriend and I were bra shopping and this fucking sketchy crew-cut white guy in jeans and a kinda well-worn—not quite clean—white undershirt is keeping an eye on us and another woman. Then he speaks into a hidden collar mic. I couldn't quite hear him, but it sounded like he was talking about a woman.

Then, as we were checking out, he was over by the restrooms—still looking sketchy as fuck—and watching people (including us). Then I caught him following us out, but he turned around and went back in after a few feet.

We got back to the car and I told my partner my observations. I thought he might be private security...or some conservative transvestigator fucker—it really could have been either (or both) with the way he was acting.

We decided to go back in to make sure he wasn't hassling anyone. Sure enough, he was still looking sketchy AF and following people around the women's section and towards the exit. So we reported him. The lady who worked there told us he's their security, and that she'd let him know we said he should be less fucking sketchy.

China's National Computer Network Emergency Response Technical Team/Coordination Center disclosed malicious foreign websites and IP addresses.

The identified sources were mainly from the US, Sweden, and India. The attacks involved botnet creation, backdoor exploitation, and data theft.

Seven of the nine malicious IP addresses were traced to locations in the US. The cyberattacks posed a significant threat to institutions and internet users in China.

globaltimes.cn/page/202505/133

www.globaltimes.cnChina's cybersecurity center discloses malicious foreign websites and IP addresses, mainly from US, Sweden and India - Global Times

Samsung's clipboard #security flaw exposes all copied content, including passwords, as plain text indefinitely.

Users are advised to avoid using the clipboard for sensitive #information until a fix is implemented.

#Samsung moderators acknowledge the issue and are considering enhancements for future updates.

For now, consider using #passkeys for secure authentication.

Stay vigilant.

tomsguide.com/computing/online

Tom's Guide · Samsung phone security flaw leaves passwords exposed — protect yourself nowBy Amber Bouman
Continued thread

For several people who received or saw the document, the broad requests for unredacted information felt like a “witch hunt,”…one that could put the #privacy & #security of numerous individuals & organizations at risk.

Beattie, whom #Trump appointed in Feb to be the acting undersecretary for #public #diplomacy, told #State Dept ofcls that his goal…was a “#TwitterFiles” like release of internal State Dept documents “to rebuild trust with the American public”….

#Windows #RDP lets you log in using revoked passwords. #Microsoft is OK with that.

Researchers say the behavior amounts to a persistent #backdoor.

In response, Microsoft said the behavior is a “a design decision (...) As such, Microsoft said the behavior doesn’t meet the definition of a #security #vulnerability, and company engineers have no plans to change it.

arstechnica.com/security/2025/