mamot.fr is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mamot.fr est un serveur Mastodon francophone, géré par La Quadrature du Net.

Server stats:

3.1K
active users

#cybersecurity

1.1K posts327 participants20 posts today

This dumb password rule is from CENLAR.

Your password can meet all the requirements in the list and still be invalid due to
an unspecified rule: any "special characters" that are not listed in the help text
are not allowed. Worse, it provides no useful feedback other than the "New Password"
field is red.

dumbpasswordrules.com/sites/ce

dumbpasswordrules.comCENLAR - Dumb Password RulesYour password can meet all the requirements in the list and still be invalid due to an unspecified rule: any "special characters" that are not listed in the help text are not allowed. Worse, it provides no useful feedback other than the "New Password" field is red.

Trying to find data on cybercrime case closure / conviction rates

Can you recommend a place for me to look? Or better yet, a report to read?

FBI has produced a few reports on how many criminal complaints they get, but I'm not seeing any numbers on how often anyone gets charged or convicted - proportionally (well, I have found some but they're mostly puff pieces by cybershills)

RustoBot Botnet Exploits Router Flaws

Pulse ID: 6808367b763a45db31e7f677
Pulse Link: otx.alienvault.com/pulse/68083
Pulse Author: cryptocti
Created: 2025-04-23 00:38:19

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

WBAL-TV11 started digging into the #Kairos attack on the State Attorney's Office for the City of Baltimore.

Kairos had exfiltrated 325 GB of files, and none of it appeared to have been protected with any encryption. My previous report on the incident can be found here: databreaches.net/2025/04/19/ba

The city has now confirmed they had a breach (they were notified by law enforcement as they hadn't detected it on their own, it seems). But they are not giving out any details or answering any questions. See WBAL-TV's coverage at wbaltv.com/article/baltimore-s

So, of course, I have now filed a public records request under #MPIA to try to get answers to some questions because the state ignored all of my polite email inquiries.

Did I ever mention that I hate not getting answers to questions? :)

Another reminder of the virtues of running #LLM locally e.g. via #Ollama

DeepSeek Breach Opens Floodgates to Dark Web

> [Researchers discovered] a publicly accessible .. database belonging to #DeepSeek, containing more than a million lines of log streams with highly sensitive information. This exposed data included chat history, #API keys ...

darkreading.com/cyberattacks-d