1
17
submitted 3 hours ago by kid to c/cybersecurity
2
11
submitted 2 hours ago by kid to c/cybersecurity
3
17
submitted 3 hours ago by kid to c/cybersecurity
4
11
submitted 3 hours ago by kid to c/cybersecurity
5
60
submitted 21 hours ago by [email protected] to c/cybersecurity
6
15
submitted 21 hours ago by [email protected] to c/cybersecurity

At least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week. Squarespace bought all assets of Google Domains a year ago, but many customers still haven’t set up their new accounts. Experts say malicious hackers learned they could commandeer any migrated Squarespace accounts that hadn’t yet been registered, merely by supplying an email address tied to an existing domain.

7
28
submitted 1 day ago by kid to c/cybersecurity
8
90
submitted 1 day ago by [email protected] to c/cybersecurity
9
87
submitted 2 days ago by [email protected] to c/cybersecurity

A smartphone’s unique Bluetooth fingerprint could be used to track the device’s user–until now. A team of researchers have developed a simple firmware update that can completely hide the Bluetooth fingerprint, eliminating the vulnerability.

10
39
submitted 2 days ago by [email protected] to c/cybersecurity

Check Point Research (CPR) has identified a critical zero-day spoofing attack exploiting Microsoft Internet Explorer on modern Windows 10/11 systems, despite the browser's retirement.

11
48
submitted 4 days ago by kid to c/cybersecurity

Morphisec, who discovered the flaw and published an advisory about it on July 9, has urged Microsoft to reclassify the vulnerability as "Critical" to reflect the higher estimated risk and ensure adequate mitigation efforts.

The security firm agreed with Microsoft that this RCE is more complex than CVE-2024-30103, making immediate exploitation less likely. However, combining it with another vulnerability could simplify attacks.

12
27
submitted 4 days ago by [email protected] to c/cybersecurity

Based on past attacks, It wouldn’t be surprising to see active targeting this time too.

13
81
submitted 5 days ago by [email protected] to c/cybersecurity
14
11
submitted 4 days ago* (last edited 4 days ago) by [email protected] to c/cybersecurity

Google Pixel phones, especially with GrapheneOS, are worlds more secure than other technologies.

Every user account is decrypted with a key generated by the secure element, and the pin is just used to unlock that key.

But the secure element is rarely used in other applications.

Here is how to unlock your KeepassDX Storage with it:

  1. Create a password storage with a very secure and long password. Length is especially important, prefer to use tons of nonsense words, over hard to remember symbols
  2. In KeepassDX Settings, under "unlock settings" enable "use system unlock"
  3. Enter the password for the password storage.
  4. Instead of pressing Enter, press on the button in the bottom left to register the password in the Android Keystore.

From now on you can unlock your password storage using all the security that your device offers.

The only weakness is the password, so make it as long as possible.

To copy-paste passwords relatively securely, you can use Florisboard's internal clipboard. Enable "sync from system clipboard", and disable "sync to system clipboard".

If you copy things using the button on Florisboard, it will only be saved in Florisboards internal app storage, not your system clipboard, which is accessible to all input devices (keyboard apps) and foreground apps.

To delete things from the system clipboard (which only holds one entry) you can use apps like this one

I recommend Obtainium to get the latest versions of these apps.

Here is a list of available app configs

15
29
submitted 5 days ago by kid to c/cybersecurity
16
27
submitted 5 days ago by kid to c/cybersecurity
17
23
submitted 5 days ago by kid to c/cybersecurity
18
17
submitted 5 days ago by kid to c/cybersecurity
19
16
submitted 5 days ago by kid to c/cybersecurity
20
12
submitted 5 days ago by kid to c/cybersecurity
21
27
submitted 6 days ago by kid to c/cybersecurity
22
9
submitted 5 days ago by kid to c/cybersecurity
23
23
submitted 6 days ago by kid to c/cybersecurity
24
13
submitted 6 days ago by kid to c/cybersecurity
25
8
submitted 6 days ago by kid to c/cybersecurity
view more: next ›

Cybersecurity

5025 readers
133 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS