CyberSeeker

joined 1 year ago
[–] CyberSeeker@discuss.tchncs.de 82 points 2 months ago (1 children)

Shouldn’t be this hard to find out the attack vector.

Buried deep, deep in their writeup:

RocketMQ servers

  • CVE-2021-4043 (Polkit)
  • CVE-2023-33246

I’m sure if you’re running other insecure, public facing web servers with bad configs, the actor could exploit that too, but they didn’t provide any evidence of this happening in the wild (no threat group TTPs for initial access), so pure FUD to try to sell their security product.

Unfortunately, Ars mostly just restated verbatim what was provided by the security vendor Aqua Nautilus.

[–] CyberSeeker@discuss.tchncs.de 3 points 5 months ago (1 children)

Only the cyber truck. Model S and 3 refreshes are still on the legacy platform, with a lithium ion 12V.

[–] CyberSeeker@discuss.tchncs.de 67 points 6 months ago (7 children)

So the article repeats, several times, “waymo relies on remote operators”. I don’t think the author knows what “self-driving” means.

[–] CyberSeeker@discuss.tchncs.de 6 points 7 months ago* (last edited 7 months ago) (5 children)

So if ISPs are once again Title II common carriers, how can they enforce the TikTok ban? 🤔

[–] CyberSeeker@discuss.tchncs.de 3 points 7 months ago

I believe this is already the case; domain reputation is weighted pretty heavily by Gmail and others, so it will take some months before you’ve established enough rep. Following SPF/DMARC/DKIM is crucial, followed with time your domain has been registered and typical outbound volume from your domain.

[–] CyberSeeker@discuss.tchncs.de 29 points 7 months ago (11 children)

That’s the benefit of a custom domain, I suppose; you can always change he provider without changing your email.

[–] CyberSeeker@discuss.tchncs.de 5 points 8 months ago

What’s worrying about this report is that it’s coming from Google itself.

Google just bought Mandiant, one of the leading cybersecurity and threat intelligence firms. Therefore, Google is one of the leading cybersecurity and threat intelligence firms.

https://arstechnica.com/gadgets/2022/03/google-makes-second-largest-acquisition-ever-5-4-billion-for-mandiant/

It’s now expected that Google would release this kind of report, seeing as they sell this as an enterprise service.

Mandiant has previously released this type of report regularly; for instance, they were the firm that disclosed the SolarWinds hack.

[–] CyberSeeker@discuss.tchncs.de 3 points 8 months ago

Agreed, the echo chamber is real on Reddit/Lemmy. Easy to hate on Elon, but people are acting as if the old men leading most other Fortune 100 companies think any differently than he does. You can find the rare exception, but you’ll have a hard time living in modern society without your money filtering up to a bigot somewhere.

Elon just lacks the filter to keep himself from saying it.

view more: next ›