ICYMI: Microsoft Authenticator to nuke Entra creds on rooted and jailbroken phones
@hoodiepony.com
I'm a pony. Sometimes a cyber sherpa, and helping keep myself safe by helping other be cyber safe. Also sometimes breaks stuff and void warranties. π³οΈβπ (they/them/it) Also, infosec.exchange/@hoodiepony Other Endpoints @ hello.unicorncyber.space
ICYMI: Microsoft Authenticator to nuke Entra creds on rooted and jailbroken phones
Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack
CVE-2026-3315 - ASSA ABLOY Visionline Windows Unprivileged Execution
CVE ID : CVE-2026-3315
Published : March 10, 2026, 10:20 a.m. | 2Β hours, 55Β minutes ago
Description : Incorrect Default Permissions, : Execution with Unnecessary Privileges, : Incorrect Permission Assig...
"Because when we go into a bottle store or buy cigarettes, we flash our ID. The store doesn't photocopy it and keep it forever."
Can the gov guarantee that there is adequate protection from misuse of the IDs collected? Is selling access to it okay? π€π€π€
www.abc.net.au/news/2026-03...
A commit meant to "strengthen the crypto" in FreshRSS ended up removing the need for a correct password.
Why?
Longer SHA-256 nonce + bcrypt truncation at 72 bytes.
A nice example of why secure systems are about composition, not just stronger primitives.
pentesterlab.com/blog/freshrs...
Outsourced call centre sweeps Centrelink customer privacy breaches βunder the rugβ, staff allege www.theguardian.com/australia-ne...
Mmm... interesting...
I wonder how that cleared IRAP Protected and above. π€
Brit competition cops warn AI agents may not be 'faithful servants' to consumers
Now who's age to enter for the kettle/telco tower/light switch/door bell/etc running Linux? How?
How will anyone be able to comply? So, everyone that creates any software product is now by default a criminal? π€
Keep this in mind as you write policies, when you're filtering for criminal history. π«£
This is very clearly written. Kudos to Proton.
Pay extra attention to the not subtle reminder you that if you pay anonymously they wonβt have any data about your identity!
This is how you walk the line to keep your customers safe while also keeping your employees out of jail.
I'm losing the ability to contrive law school exam hypotheticals that are more absurd than the actual news
To my Canadian friends, an acquaintance started a petition to allow US transgender citizens to claim refugee status here.
www.ourcommons.ca/petitions/en...
If youβre Canadian please sign it.
If youβre not, please share β€οΈ
This feels like impersonation.
Big yikes.
If you still use Grammarly, you might want to check your legal liability for continuing using it for work.
Supply chain risks are really going to get spicy.
β³οΈ Years in the making...
The #OpenTelemetry project is delighted to announce that declarative configuration is stable!
Congratulations to everyone who contributed to this momentous accomplishment!
buff.ly/HhL8swj
this is how multiplayer games treat your data while demanding you install kernel level secureboot rootkits to βprevent cheatingβ lol
It's interesting takes in the comments π«£.
Remember that any company that wants to keep existing, or person that works there not be penalised, will need to comply with their local laws. And all their suppliers will need to comply with their respective local laws too.
Diversify & localise ur supply.
New version of OpenRelik (the #DFIR workflow engine) is out. New workflow UI, support for chords (task groups with callback), MCP server and much much more. Give it a try!
Take a look at the new page for workers showcase, both official and community contributed: openrelik.org/workers/
-Dutch parties want a digital security package for citizens (ad-blocker, VPN, password manager, antivirus)
-France wants 8y in prison for IMSI catcher gang
-Sextortionist pleads guilty
-India arrests 27 fraudsters
-New OAuth redirection abuse
-ClickFix campaign targets crypto investors
How you can tell a rare lunar event is happening in Melbourne...
The cloud coverage is 100%
#LunarEclipse
Melbourne was sadly not much better too for me :(
curl left HackerOne after being flooded with AI slop reports
They left for GitHub, but are now returning to HackerOne because it's a better platform to handle reports
daniel.haxx.se/blog/2026/02...
We quietly launched this last week. It's early days and we only have a dozen or so vendors there so far, but the plan is to have pretty decent coverage of the industry after a while
Australia and Aotearoa New Zealand are in a prime position to catch this total eclipse of the Moon; find the timing in our interactive map.
Thereβs a total #LunarEclipse coming tomorrow evening and the east coast of Australia, NZ and the Pacific Islands are in a grand position for it!
Looks like we have a bit of cloud in Sydney but it may be patchy.
Best part of the show is between 10-11pm. Max eclipse at 10:33pm.
πΈ timeanddate
π
Starting March 25, your Amazon wishlist could possibly expose your address due to new Amazon changes
www.pcmag.com/news/got-a-p...
Excellent video.
Lots of very critical lessons here.
New York Attorney General Letitia James sued video game developer and publisher Valve Corporation for using game loot boxes to facilitate illegal gambling activities among children and teenagers.