The correct way to run a headline for this story. The reg does not disappoint
#uspol #routers #surveillance #privacy #nationalsecurity #cybersecurity #infosec #cisco #theregister
The correct way to run a headline for this story. The reg does not disappoint
#uspol #routers #surveillance #privacy #nationalsecurity #cybersecurity #infosec #cisco #theregister
We are honoured to be one of the first recipients of the Nominet DNS Fund, which recognises the importance of supporting the quiet work behind the scenes.
We thank @Nominet for their forward thinking - helping public interest nonprofits, such as Quad9, who work every day to maintain internet integrity, and the security and privacy of end users around the world.
https://quad9.net/news/press/nominet-invests-in-quad9/
Congratulations to the other recipients!
Every single blueteamer in information security at the moment...
In today's episode of "Can It Run Doom": DNS fucking TXT records.
Some absolute madlad (cough Adam Rice cough) compressed the entire shareware DOOM WAD, split it into around 1,964 chunks, shoved them into Cloudflare TXT records, and wrote a PowerShell script that reassembles and runs the whole goddamn game from DNS queries alone. Nothing touches disk. The DLLs are in DNS. THE FUCKING DLLS ARE IN DNS.
RFC 1035 was written in 1987. Those engineers are spinning in their graves fast enough to generate municipal power.
Bonus: this is a fully functional globally-distributed covert data exfil channel that your NGFW will never fucking see if you're not doing deep DNS inspection. Sleep well.
blog: https://blog.rice.is/post/doom-over-dns/
repo: https://github.com/resumex/doom-over-dns
Also lmao @ every blue team that has never once looked at their DNS query volume. How's that DLP policy working out for you.
It was always DNS.
#SCOTUS Reviews Police Use of #Cell #Location #Data to Find Criminals
#Geofence searches allow law enforcement to find suspects & witnesses by sweeping up #LocationData from cellphone users near crime scenes.
Geofence searches have become increasingly popular as a tool for law enforcement, but critics say they put at risk the personal data of everyday Americans & violate the #Constitution.
#law #privacy #InfoSec
https://www.nytimes.com/2026/04/27/us/politics/supreme-court-cell-data-geofence.html?smid=nytcore-ios-share
500+ Organizations Now Participating as CVE Numbering Authorities (CNAs)!
As of March 31, 2026, there are 502 CNAs (499 CNAs and 3 CNA-LRs) from 42 countries participating in the CVE Program
Learn more:
https://www.cve.org/Media/News/item/blog/2026/03/31/502-Organizations-Participating-as-CNAs
#cve #cna #vulnerability #vulnerabilitymanagement #informationsecurity #infosec #cybersecurity
A few years ago, the infosec community was reacting with horror to the notion of doing 2FA with SMS. Apparently “SIM hacking” was child’s play and this was horribly insecure. Did things change? Because it feels like more and more organizations are doing this, including my bank and investment manager. I don’t recall seeing any things-have-changed news on infosec channels.
(Today I saw that CRA (Canada’s tax agency) switched to an authenticator app.)
#Microsoft locks account that #VeraCrypt maintainer uses to sign #Windows bootloaders with no explanation or route for appeal. If they don't fix this, in a few months every Windows computer that uses VeraCrypt whole-disk encryption will stop being able to boot and all the data on it that isn't backed up elsewhere will be lost. 🤦
If this doesn't convince you big tech has too much control, I don't know what will.
h/t @zackwhittaker
https://techcrunch.com/2026/04/08/veracrypt-encryption-software-windows-microsoft-lock-boot-issues/
#infosec #privacy #TechIsShitDispatch
attention anybody with substantial experience with Rust and networking: my team is hiring!!
one of few rust jobs I'm aware of that is not web 3.0 horseplop.
fully remote (US timezones), good culture, good trans-inclusive healthcare, good work/life balance, and a nice defensive cybersecurity mission i can get behind.
feel free to reach out for more details and the job posting.
Oh boy…
https://edition.cnn.com/2026/04/08/china/china-supercomputer-hackers-hnk-intl
> A [cyberthreat actor] has allegedly stolen a massive trove of sensitive data – including highly classified defense documents and missile schematics – from a state-run Chinese supercomputer
> The dataset, which allegedly contains more than 10 petabytes of sensitive information, is believed by experts to have been obtained from the National Supercomputing Center (NSCC) in Tianjin
🧵
RE: https://flipboard.com/@404media/404-media-qvt3vv94z/-/a-qoIXNx-4Q-i9Qb4-DwsX5A%3Aa%3A4082434389-%2F0
If you think there's any chance that law enforcement might ever be interested in the content of your Signal chats, and you don't want them to have access to them, then setting up disappearing messages is necessary but not sufficient. You also need to go into the Signal settings and either disable notifications completely or set them to show "No name or message" so the content won't be capture and preserved in the phone's notification database.
#infosec #privacy #OpSec "#antifa"
This is still my favourite personal hackery/security story, and the only one I have ever written about where I am on the naughty-side of the desk.
Different times!
https://artofsecurity.com/2011/humble
#Security #InfoSec #Hacking #DEC #VAX #VMS #Teletype #Blog #History #UniversityofLeicester #FoiledAgain
Once again, my professional recommendation in response to the latest Linux kernel vulnerability in the news is that you should gather up all your electronic devices, cast them into the sea, and retreat to the woods.
Each night, gather your children and tell them tales of the Before Times when the hubris of humanity grew so large that we made idols of sand and spoke to them as equals. Remind them that the sand, of course, did not speak or think, but we imagined it could, and let it guide us to folly.
Should a stranger ever come to your village with a glowing rectangle, encourage the youth to beat them with sticks.
Hello, Mastodon! 👋 We help people take back control of their personal data online, and we're here to connect with others who care about digital privacy.
Help us out: What feeds or accounts should we be following?
#privacy #cybersecurity #infosec #dataprivacy #dataprotection
ISO an Infrastructure Provisioning Manager to join our amazing Quad9 team. 🌠
Interested? You can find all the details right here: https://quad9.net/about/jobs/
Remember, sharing is caring 🫶
#DNS #privacy #internetfreedom #infosec #getfedihired #jobs #hiring
Edit: issue seems fixed.
Looks like DE ccTLD is unresolvable due to DNSSEC issue:
https://dnsviz.net/d/nic.de/afpsNg/dnssec/
😬
🧵👇
I am looking for a few more US-based early adopters to provide feedback on a protective DNS service offering aligned with NIST SP 800-81 Rev. 3 (March 2026).
https://csrc.nist.gov/pubs/sp/800/81/r3/final
This service merges Zero Trust and DNS without requiring client-side agents. Supports mobile devices, browsers, server hardware & IoT.
If you're interested in providing feedback on this service as a free beta tester, email me at:
securednsbeta@techliterate.co
Everybody hates #robocalls. But, despite tech reporting being willing to give the #FCC leeway, this new measure is not to stop robocalls, it won’t do a damn thing to stop robocalls. What it does is make burner phones illegal.
Burners are an integral part of many social justice actions. Protestors use them to record #ICE and other #cops. We include them in “Go Bags” to let abused women and children escape. They allow for anonymity.
They are a thorn in the side of the panopticon, and they are moving to eliminate them.
Stock up kids.
https://mashable.com/article/fcc-proposes-to-battle-spam-calls-at-the-expense-of-privacy-protections
This dumb password rule is from Getin Bank.
The new password should contain at least 10 and a maximum of 20 characters.
The password must contain at least one upper case letter, one lower case
letter and one number. The password cannot contain non-ASCII Polish alphabet
characters, special characters `&<'"` or spaces.
https://dumbpasswordrules.com/sites/getin-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
RE: https://eigenmagic.net/@arichtman/116583583697455397
cue Admiral Akbar’s IT’S A TRAP dot jiff