Technology, Information Systems, and Security. Opinions are my own. meolikestech@infosec.exchange justlilolme@counter.social meolikestech šŸ¦‹

Joined February 2011
99 Photos and videos
MEO retweeted
The self described ā€œShodan of AWSā€ is now live! This is an amazing project from @dagrz that helps democratize cloud resource enumeration for the masses. Very excited about this! awseye.com
2
56
225
15,430
MEO retweeted
Since the beginning of September 2024, Microsoft Threat Intelligence has observed a phishing campaign using emails with ā€œeFaxā€ themed lures containing links or QR codes within PDF attachments, leading to a domain controlled by the EvilProxy phishing-as-a-service (PhaaS) platform.
6
94
330
40,686
MEO retweeted
Excited to announce the šŸš€ launch of the šŸ”„ LOLESXi project. It provides valuable insights into adversarial techniques targeting VMWARE ESXi. lolesxi-project.github.io/LO… #threatresearch #lolesxi #dfir

3
84
211
41,002
MEO retweeted
Scoring 12,565/15,400 points over 175 challenges, our 5-person Fleet Cyber Team won the prestigious SANS Netwars International Services Cup! Bravo Zulu - your capabilities in cyber warfare outperformed 35 teams from 8 countries. Learn what it takes: forces.ca/en/career/cyber-op…
7
29
105
5,994
MEO retweeted
Microsoft has uncovered a vulnerability in ESXi hypervisors, identified as CVE-2024-37085, being exploited by threat actors to obtain full administrative permissions on domain-joined ESXi hypervisors and encrypt critical servers in ransomware attacks. msft.it/6012lbTai
23
453
1,166
668,297
MEO retweeted
File Upload Checklist Mindmap.
2
199
1,054
107,917
MEO retweeted
I recommend unlinking any desktop device from your signal account. A long-known problem (that I was unaware of until today) is that Signal stores your decryption key on desktop in a plain text file, NOT your keychain, making it accessible to any app.
TL;DR: Don't install @signalapp for macOS, it is not secure. I carried out this small experiment: - I wrote a simple Python script that copies the directory of Signal's local storage to another location (to mimic a malicious script or app) - I ran the script in the Terminal and got a copy of my Signal data on my Mac - I booted a fresh macOS installation in a virtual machine - I transferred the copy of Signal's data to the VM and placed it where Signal expects it: ~/Library/Application\ Support/Signal - I installed Signal and started it - Signal started and restored my session with all the chat histories 😳 - I exchanged a couple messages with a contact from the VM and it worked 😳 - Then, I started Signal on the Mac - I got three sessions running in unison: Mac, iPhone, and VM 😳 Messages were either delivered to the Mac or to the VM. The iPhone received all messages. All of the three sessions were live and valid. Signal didn't warn me of the existence of the third session [that I cloned]. Moreover, Signal on the iPhone still shows one linked device. This is particularly dangerous because any malicious script can do the same to seize a session. Perhaps this flaw is what makes some users think that Signal has a "backdoor" as it is easy for sophisticated attackers to target a victim who's using the Mac app and see their chats. (The same may be also true for the Windows app) #privacy #security
44
156
651
269,096
2 Jul 2024
What in the Markovian Parallax Denigrate is going on here….?
1
43
2 Jul 2024
1
1
18
2 Jul 2024
Looks like they all have broken Unicode that references ā€œNamshi discountsā€ā€¦. There’s other formats … bots obviously, but for what purpose? šŸ¤·ā€ā™€ļø
1
15
MEO retweeted
1 Jul 2024
The award-winning Qualys Threat Research Unit (TRU) has discovered a critical vulnerability in OpenSSH, designated CVE-2024-6387 and aptly named "regreSSHion." This Remote Code Execution bug grants full root access, posing a significant exploitation risk. blog.qualys.com/vulnerabilit…
25
767
1,243
525,027
Today is the launch of @Semgrep Academy! Free courses on #AppSec, Secure Coding, #API Security, Functional Programming, and MORE! Please go check it out here: Academy.Semgrep.dev
18
137
342
99,712
#CyberAlert | Cyber Activity Impacting CISCO ASA Devices The Cyber Centre, along with our partners @NCSC, @GCHQ, @ASDGovAu released a joint Cyber Security Advisory. cyber.gc.ca/en/alerts-adviso…
Today, the Cyber Centre, a part of @CSE_CST, published a cyber security advisory reporting malicious cyber activity targeting VPN services used by government and critical national infrastructure networks globally. cyber.gc.ca/en/news-events/c…
2
5
7
1,541