infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@landelare It doesn't look fake at all, but the whole story draws a really bad picture of both model reliability and company competence. OAI+HF noticing the behavior and deciding not to intervene (or even support the actions) would be the most generous interpretation for the companies IMO.
this post | permalink
Some tracks can't be saved even by a schrantz remix

#KylieMinogue
this post | permalink
@ozu

Yes: https://infosec.place/notice/B8dh429Gf6p490VuJU

And HF also didn't notice someone is messing with their k8s in the noisiest way possible for days.
this post | permalink
This other diagram is supposed show the time distribution of events. What are considered as "events"? What is the vertical scale of this diagram? What is 461? Why do stripes contain different colors sometimes?
this post | permalink
This diagram is also bad, but at least it shows the high-level flows.

Notice that "Third party code sandbox" is marked as "Compromised", while the post text explicitly states that "Modal’s infrastructure was not compromised in any way". Also, how do you even compromise a *sandbox*? WTF is Lateralize?!
this post | permalink
[RSS] ColdFusion Under Fire: Breaking Down CVE-2026-48283 and CVE-2026-48313

https://horizon3.ai/intelligence/blogs/coldfusion-critical-cves/
this post | permalink
[RSS] The Cipher Behind QSYRUPWD: Reconstructing IBM i Password Hashes

https://blog.silentsignal.eu/2026/07/28/the-cipher-behind-qsyrupwd-reconstructing-ibm-i-password-hashes/

IBM may be overselling their local password protection: my old friends show some neat #IBMi reversing tricks to reveal how the platform hashes passwords at different security levels (QPWDLVL)
this post | permalink
HuggingFace incident report:

https://huggingface.co/blog/agent-intrusion-technical-timeline

The report itself reeks of LLM slop with gems like the "kill chain", consisting of phases like recon, exfil, c2...and k8s :) Nuances are overemphasized (like how code execution was used to execute code) while important steps are blurry (e.g. they had some kind of "allowlist" in the dataset processor, that allowed everything which didn't look like a URL?).

I feel sorry for blue teams not because they'll have to respond to more incidents but because they'll have to wade through reports like this...
this post | permalink
@TarkabarkaHolgy In case you missed the Amphora of Great Intelligence:

https://www.peppercarrot.com/en/miniFantasyTheater/018.html
this post | permalink
@ljrk @drwhax Re: 1., the usual question we got from CISO and above on our reports is "how does it look compared to similar companies?". I agree that this is in part the "you don't have to outrun the bear" logic, but also that people in position don't want to look incompetent in front of their peers.

Another thing is that you don't get fired if you didn't follow the hackers advice, but you do get fired if you don't pass compliance which is one part BS, and the other part is easy to cheat.
this post | permalink
Next Page