mastodon.xyz is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance, open to everyone, but mainly English and French speaking.

Administered by:

Server stats:

758
active users

#infosec

486 posts168 participants60 posts today
ZeroDay Bae<p>New FileFix attack uses cache smuggling to evade security software <a href="https://www.bleepingcomputer.com/news/security/new-filefix-attack-uses-cache-smuggling-to-evade-security-software/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/new-filefix-attack-uses-cache-smuggling-to-evade-security-software/</span></a></p><p><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/bleepingcomputer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bleepingcomputer</span></a></p>
The Zeek Network Security Monitor<p>We’re excited for a few in-person events coming up: </p><p>🌟 Oct. 20, Training at NSF Cybersecurity Summit <br>🌟 Oct. 21–24, hack.lu<br>🌟 Mar. 25-26, Two day Zeek Workshop at CERN </p><p>Learn more + see all community updates in our newsletter: <a href="https://shorturl.at/NqUmr" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">shorturl.at/NqUmr</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/ZeekCommunity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ZeekCommunity</span></a> <a href="https://infosec.exchange/tags/Infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infosec</span></a></p>
Lenin alevski 🕵️💻<p>What if converting Dockerfiles was as simple as a single command? 🚀🤔 </p><p>DFC (Dockerfile Converter) transforms traditional Dockerfiles into compatible versions using Chainguard Images and APKs. It adjusts FROM lines, RUN commands, and more. Example: <br>`RUN apt-get install nano` → `RUN apk add --no-cache nano`. </p><p><a href="https://infosec.exchange/tags/Dockerfiles" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Dockerfiles</span></a> <a href="https://infosec.exchange/tags/CLItools" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CLItools</span></a> <a href="https://infosec.exchange/tags/DevOps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DevOps</span></a></p><p>🔗 Project link on <a href="https://infosec.exchange/tags/GitHub" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GitHub</span></a> 👉 <a href="https://github.com/chainguard-dev/dfc" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">github.com/chainguard-dev/dfc</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/Infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infosec</span></a> <a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/Software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Software</span></a> <a href="https://infosec.exchange/tags/Technology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Technology</span></a> <a href="https://infosec.exchange/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://infosec.exchange/tags/CTF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTF</span></a> <a href="https://infosec.exchange/tags/Cybersecuritycareer" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecuritycareer</span></a> <a href="https://infosec.exchange/tags/hacking" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hacking</span></a> <a href="https://infosec.exchange/tags/redteam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>redteam</span></a> <a href="https://infosec.exchange/tags/blueteam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>blueteam</span></a> <a href="https://infosec.exchange/tags/purpleteam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>purpleteam</span></a> <a href="https://infosec.exchange/tags/tips" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tips</span></a> <a href="https://infosec.exchange/tags/opensource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>opensource</span></a> <a href="https://infosec.exchange/tags/cloudsecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cloudsecurity</span></a></p><p>— ✨<br>🔐 P.S. Found this helpful? Tap Follow for more cybersecurity tips and insights! I share weekly content for professionals and people who want to get into cyber. Happy hacking 💻🏴‍☠️</p>
Shodan Safari<p>ASN: AS15557<br>Location: Nancy, FR<br>Added: 2025-10-07T11:15</p><p><a href="https://infosec.exchange/tags/shodansafari" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>shodansafari</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
ZeroDay Bae<p>Unplug Gemini from email and calendars, says cybersecurity firm | CSO Online <a href="https://www.csoonline.com/article/4069806/unplug-gemini-from-email-and-calendars-says-cybersecurity-firm.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">csoonline.com/article/4069806/</span><span class="invisible">unplug-gemini-from-email-and-calendars-says-cybersecurity-firm.html</span></a></p><p><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/ai" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ai</span></a> <a href="https://infosec.exchange/tags/csoonline" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>csoonline</span></a></p>
ZeroDay Bae<p>RE: <a href="https://infosec.exchange/@cyberseckyle/115334541393623997" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@cyberseckyle</span><span class="invisible">/115334541393623997</span></a></p><p>With the recent news of the 1.5TB of age-verification photos being leaked from Discord in the recent breach. Thought I’d share this again. </p><p><a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/DataBreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DataBreach</span></a> <a href="https://infosec.exchange/tags/Discord" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Discord</span></a></p>
Matthias Schulze<p>Raspi-Konkurrenz: Qualcomm schluckt Arduino und stellt Einplatinencomputer vor <a href="https://www.heise.de/news/Raspi-Konkurrenz-Qualcomm-schluckt-Arduino-und-stellt-Einplatinencomputer-vor-10733137.html?wt_mc=rss.red.ho.top-news.atom.beitrag.beitrag" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">heise.de/news/Raspi-Konkurrenz</span><span class="invisible">-Qualcomm-schluckt-Arduino-und-stellt-Einplatinencomputer-vor-10733137.html?wt_mc=rss.red.ho.top-news.atom.beitrag.beitrag</span></a> <a href="https://ioc.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://ioc.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
Shodan Safari<p>ASN: AS4766<br>Location: Hwaseong-si, KR<br>Added: 2025-10-07T11:56</p><p><a href="https://infosec.exchange/tags/shodansafari" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>shodansafari</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
Tekno Fix - IT Solutions<p>Hackers are actively exploiting a critical vulnerability in the Service Finder WordPress theme that allows them to bypass authentication and log in as administrators.</p><p>WordPress plugin security firm Wordfence recorded more than 13,800 exploitation attempts since August 1st.</p><p><a href="https://mstdn.social/tags/Tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tech</span></a> <a href="https://mstdn.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://mstdn.social/tags/OpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSource</span></a> <a href="https://mstdn.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Microsoft</span></a> <a href="https://mstdn.social/tags/Computing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Computing</span></a> <a href="https://mstdn.social/tags/TechNews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechNews</span></a> <a href="https://mstdn.social/tags/Blog" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Blog</span></a> <a href="https://mstdn.social/tags/Wordpress" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Wordpress</span></a> <a href="https://mstdn.social/tags/CyberSecurityNews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurityNews</span></a> <a href="https://mstdn.social/tags/Technology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Technology</span></a> <a href="https://mstdn.social/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://mstdn.social/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mstdn.social/tags/Business" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Business</span></a> <a href="https://mstdn.social/tags/Engineering" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Engineering</span></a> <a href="https://mstdn.social/tags/Markets" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Markets</span></a> <a href="https://mstdn.social/tags/USA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>USA</span></a> <a href="https://mstdn.social/tags/EU" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EU</span></a> <a href="https://mstdn.social/tags/Asia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Asia</span></a> <a href="https://mstdn.social/tags/Africa" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Africa</span></a> <a href="https://mstdn.social/tags/SocialMedia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SocialMedia</span></a> <a href="https://mstdn.social/tags/Mastodon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mastodon</span></a></p>
rk: it’s hyphen-minus actually<p>There has been a recent spate of vulnerabilities disclosed with CVSS scores of 10.0 when they very demonstrably couldn’t possibly have that score (getting a perfect 10.0 is remarkably difficult).</p><p>You then go and look at the official CVE record and the CVSS score is something lower, sometimes much lower. </p><p>Are the authors just saying 10.0 to get clicks/fame? LLM’s writing the summaries and putting it in there because that’s what great disclosures have? Who knows. </p><p><a href="https://mastodon.well.com/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
Tekno Fix - IT Solutions<p>Microsoft is removing more methods that help users create local Windows accounts and bypass the Microsoft account requirement when installing Windows 11.</p><p>"We are removing known mechanisms for creating a local account in the Windows Setup experience (OOBE)," Microsoft's Amanda Langowski said.</p><p><a href="https://mstdn.social/tags/Tech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tech</span></a> <a href="https://mstdn.social/tags/InfoSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>InfoSec</span></a> <a href="https://mstdn.social/tags/Windows" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Windows</span></a> <a href="https://mstdn.social/tags/OpenSource" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OpenSource</span></a> <a href="https://mstdn.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Microsoft</span></a> <a href="https://mstdn.social/tags/Computing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Computing</span></a> <a href="https://mstdn.social/tags/TechNews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TechNews</span></a> <a href="https://mstdn.social/tags/Blog" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Blog</span></a> <a href="https://mstdn.social/tags/CyberSecurityNews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurityNews</span></a> <a href="https://mstdn.social/tags/Technology" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Technology</span></a> <a href="https://mstdn.social/tags/News" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>News</span></a> <a href="https://mstdn.social/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mstdn.social/tags/Business" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Business</span></a> <a href="https://mstdn.social/tags/Engineering" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Engineering</span></a> <a href="https://mstdn.social/tags/Markets" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Markets</span></a> <a href="https://mstdn.social/tags/USA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>USA</span></a> <a href="https://mstdn.social/tags/EU" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EU</span></a> <a href="https://mstdn.social/tags/Asia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Asia</span></a> <a href="https://mstdn.social/tags/Africa" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Africa</span></a> <a href="https://mstdn.social/tags/SocialMedia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SocialMedia</span></a> <a href="https://mstdn.social/tags/Mastodon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mastodon</span></a></p>
BeyondMachines :verified:<p>School communication platform Finalsite suspends services after security breach</p><p>Finalsite, a communication platform serving over 8,000 schools and universities across 115 countries suspended all operations on October 7, 2025, following an undisclosed security incident, leaving thousands of educational institutions without mass notification capabilities. The nature and scope of the breach is not disclosed.</p><p>****<br><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/incident" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>incident</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a><br><a href="https://beyondmachines.net/event_details/school-communication-platform-finalsite-suspends-services-after-security-breach-o-o-e-e-1/gD2P6Ple2L" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">beyondmachines.net/event_detai</span><span class="invisible">ls/school-communication-platform-finalsite-suspends-services-after-security-breach-o-o-e-e-1/gD2P6Ple2L</span></a></p>
Shodan Safari<p>ASN: AS35805<br>Location: Akhaltsikhe, GE<br>Added: 2025-10-07T11:28</p><p><a href="https://infosec.exchange/tags/shodansafari" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>shodansafari</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
BeyondMachines :verified:<p>DraftKings reports credential stuffing attack targeting customer accounts</p><p>DraftKings reports a credential stuffing attack detected on September 2, 2025, in which attackers used externally stolen or leaked login credentials from other platforms to compromise fewer than 30 customer accounts, exposing personal information and transaction history. The company has mandated password resets and multifactor authentication for affected accounts.</p><p>****<br><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/incident" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>incident</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a><br><a href="https://beyondmachines.net/event_details/draftkings-warns-users-of-credential-stuffing-attack-targeting-customer-accounts-8-4-i-q-w/gD2P6Ple2L" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">beyondmachines.net/event_detai</span><span class="invisible">ls/draftkings-warns-users-of-credential-stuffing-attack-targeting-customer-accounts-8-4-i-q-w/gD2P6Ple2L</span></a></p>
Shodan Safari<p>ASN: AS4766<br>Location: Hwaseong-si, KR<br>Added: 2025-10-07T11:30</p><p><a href="https://infosec.exchange/tags/shodansafari" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>shodansafari</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>
Brian Greenberg :verified:<p>Tilly Norwood — the so-called “AI actress” — feels less like progress and more like propaganda. The rollout isn’t about art or tech; it’s about softening the idea that gen AI belongs in Hollywood as a replacement for people. What’s creepy is how it’s marketed: “agents are interested,” “she could be the next Scarlett Johansson.” The goal isn’t to sell a movie. It’s to sell the inevitability that AI will be the new normal. 🤖 Beneath the buzz, Tilly’s still a digital puppet needing human handlers. The only real actors here are the execs trying to convince us this is the future of storytelling.</p><p>TL;DR<br>🎭 Not an actress, a digital puppet<br>⚙️ “AI actors” = PR stunt, not progress<br>🧠 Normalization is the real goal<br>⚠️ SAG-AFTRA’s concerns are the story</p><p><a href="https://www.theverge.com/ai-artificial-intelligence/791680/tilly-norwood-particle6-xicoia-eline-van-der-velden" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">theverge.com/ai-artificial-int</span><span class="invisible">elligence/791680/tilly-norwood-particle6-xicoia-eline-van-der-velden</span></a></p><p><a href="https://infosec.exchange/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a> <a href="https://infosec.exchange/tags/Hollywood" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hollywood</span></a> <a href="https://infosec.exchange/tags/Ethics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Ethics</span></a> <a href="https://infosec.exchange/tags/FutureOfWork" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FutureOfWork</span></a> <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://infosec.exchange/tags/cloud" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cloud</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/deepfakes" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>deepfakes</span></a></p>
skry<p><a href="https://mastodon.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/@briankrebs/115339803435646384" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@briankrebs/1</span><span class="invisible">15339803435646384</span></a></p>
Brian Greenberg :verified:<p>When your AI "assistant" fabricates citations and invents court quotes, that’s not innovation, that’s negligence. Unbelievable, 🤦🏻‍♂️ Deloitte’s $290K report for the Australian government used generative AI (Azure OpenAI), and hallucinated fake sources and misattributed legal commentary. A researcher caught it and Deloitte admitted 'some' references were wrong, and now they’re refunding part of the fee. 😬</p><p>This is the growing pain of AI adoption: big firms racing ahead without the governance to match. Transparency after the fact doesn’t rebuild trust — it just highlights the gap between capability and accountability.</p><p>TL;DR<br>⚠️ AI-generated report errors<br>📚 Fake citations discovered<br>💸 Partial refund to the government<br>🤖 Big Four still chasing AI efficiency</p><p><a href="https://fortune.com/2025/10/07/deloitte-ai-australia-government-report-hallucinations-technology-290000-refund/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">fortune.com/2025/10/07/deloitt</span><span class="invisible">e-ai-australia-government-report-hallucinations-technology-290000-refund/</span></a></p><p><a href="https://infosec.exchange/tags/AIethics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AIethics</span></a> <a href="https://infosec.exchange/tags/Consulting" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Consulting</span></a> <a href="https://infosec.exchange/tags/Deloitte" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Deloitte</span></a> <a href="https://infosec.exchange/tags/Governance" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Governance</span></a> <a href="https://infosec.exchange/tags/GRC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GRC</span></a> <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> <a href="https://infosec.exchange/tags/cloud" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cloud</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
BeyondMachines :verified:<p>Critical memory corruption flaw in IBM AIX and VIOS package manager</p><p>IBM is reporting a critical vulnerability (CVE-2025-6965) in AIX and VIOS operating systems affecting the RPM package manager, where a SQLite flaw can cause memory corruption and enable arbitrary code execution on all versions of AIX 7.2/7.3 and VIOS 3.1/4.1.</p><p>**If you're running IBM AIX or VIOS systems, check if you have vulnerable RPM versions (run lslpp -L | grep -i rpm.rte). Then plan a patch to apply IBM's security patches for CVE-2025-6965.**<br><a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/advisory" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>advisory</span></a> <a href="https://infosec.exchange/tags/vulnerability" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>vulnerability</span></a><br><a href="https://beyondmachines.net/event_details/critical-memory-corruption-flaw-in-ibm-aix-and-vios-package-manager-o-r-2-p-1/gD2P6Ple2L" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">beyondmachines.net/event_detai</span><span class="invisible">ls/critical-memory-corruption-flaw-in-ibm-aix-and-vios-package-manager-o-r-2-p-1/gD2P6Ple2L</span></a></p>
Shodan Safari<p>ASN: AS266082<br>Location: Parobé, BR<br>Added: 2025-10-07T11:51</p><p><a href="https://infosec.exchange/tags/shodansafari" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>shodansafari</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a></p>