ruhr.social ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Eine Mastodon-Gemeinschaft rund um das Ruhrgebiet und die Menschen dort. Diese Instanz wird ehrenamtlich von Enthusiasten moderiert und technisch betreut.

Verwaltet von:

Serverstatistik:

1,5 Tsd.
aktive Profile

#security

361 Beiträge217 Beteiligte41 Beiträge heute

Heads-up from CERT-UA: they're flagging Excel phishing campaigns targeting Ukraine right now. Honestly, it's a pretty classic tactic we've seen before, right?

Still, reverse shells and data theft are absolutely no joke. This whole situation really takes me back to my pentesting days – it always hammers home that user awareness is crucial. More often than not, those sneaky macros are the exact gateway attackers use to get in.

So, how are you all keeping your users safe on your end? Are you leaning more on specific tools, or is it all about the training? Curious to hear your strategies!

#Security#Ukraine#Phishing

DATE: April 08, 2025 at 08:36AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Why do so many #healthcare sector entities still fall victim to #email #hacks? t.co/hFsFpuN6e2

Here are any URLs found in the article text:

t.co/hFsFpuN6e2

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

Fortgeführter Thread

Trump’s order also toys with innovative new abuses of power.

It directs the nonpartisan, independent Election Assistance Commission
to tighten ID measures
— a directive far beyond the scope of presidential authority.

But precedent, and the rule of law, have not often dissuaded the Trump administration.

🆘Ominous language in the order directs states to provide voter roll information to Immigration and Customs Enforcement and the Department of Homeland Security (DHS).

(The text also goes out of its way to praise the rather dystopian biometric voter ID measures in use in India.)

Later, the executive order stipulates that state voter lists must be made available for
👉review by the DHS and “the DOGE Administrator”
— this presumably referring to private citizen and public embarrassment Elon Musk.

In other words, the infamously intrusive DHS,
now with the infamously disruptive DOGE,
will be given some sort of authority over state voter rolls,
many of which are already subjected to baseless and illegal purges.

We can only imagine what sort of further mangling the flunkies of DOGE might have in mind.

After all, we’ve seen what kind of technical “upgrades” and other impending disasters they intend to carry out at the Social Security Administration (SSA).

(In fact, the executive order even contains a roundabout means of facilitating DOGE and Trump’s access to the SSA,
dictating that the SSA commissioner must provide SSA data for voting eligibility determinations.
This may be intended to circumvent legal barriers to DOGE intervention.)

Speaking of #security #threats,
the Trump administration has already hampered the "Cybersecurity and Infrastructure Security Agency" ( #CISA ),
🆘placing its 17-member election security team on administrative leave
and “under review.”

CISA is tasked with addressing election threats,
from cyberattacks to violence against poll workers.

Here, it seems likely that Trump is pursuing another petty #vendetta.

The president is evidently a bit bitter about CISA’s efforts to contradict his misinformation about COVID and the 2020 election,
as comments from DHS chief Kristi Noem
(who claimed the agency has ventured “far off mission”)
have hinted.

Yet another blow to electoral integrity arrived with the 🆘defunding of the Center for Internet Security
and the subsequent 🆘closure of its subsidiary, the "Election Infrastructure Information Sharing and Analysis Center"
( EI-ISAC ).

EI-ISAC,
alongside the "Multi-State Information Sharing and Analysis Center",
served as a technical support and advisory arm on internet security.

Shuttering it may now leave open possible avenues for cyberattacks,
foreign interference, and other uncertain threats, according to Politico.

Unfortunately, Trump’s recent executive order contains even more diktats:

💥requiring the reporting of foreign nationals to the DHS,

💥unsourced claims of illicit foreign contributions to direct-democracy ballot initiatives
(which the right generally does not like),

💥and additional stringent demands to serve up voter information to unaccountable agencies,
for purposes unknown.

🔥The most chilling section, though, might be the one titled “Prosecuting Election Crimes.”

It defines as a #criminal anyone who
“registered or voted despite being ineligible,”
“committed election fraud,”
“provided false information [on] forms,”
“threatened voters or election officials,”
or “engaged in unlawful conduct to interfere in the election process.”

Worth noting that some of these definitions are enormously subjective.

If it comes to prosecuting activists or political opponents
— which has become an acute possibility
— the listed violations will surely provide for some generously broad legal interpretations.

Lastly, the Trump administration appears keen to ensure its threats do not ring hollow.
❌The order promises to penalize recalcitrant states by conditioning their funding on obedience.

The administration reserves itself the right to
“cease providing Federal funds to States that do not comply[.]”

We’ve already been treated to the ugly sight of Trump withholding funds as a cudgel.

Perhaps he’s emboldened by his success in goading elite universities to kiss the ring,
some so eager to grovel and demonstrate fealty to escape his wrath that they folded preemptively in fear
— or just complicity.

Voting rights advocates are hoping that at least some in the judiciary will not capitulate so easily.

truthout.org/articles/trump-as

Donald Trump
Truthout · Trump Assumes Unheard-of Powers in Ordering Federal Overhaul of ElectionsHis order on voter policy could disenfranchise millions, but multiple lawsuits have already sprung up to challenge it.

Hacker hacked hackers

lemmy.ml/post/28288658

lemmy.mlHacker hacked hackers - LemmyAndi’s [https://andisearch.com/] Writeup The Everest ransomware gang’s dark web leak site was hacked and defaced on April 7, 2025, with attackers replacing the content with the message “Don’t do crime CRIME IS BAD xoxo from Prague”[^1]. The site subsequently went offline and displayed an “Onion site not found” error[^1]. Flare Senior Threat Intelligence Researcher Tammy Harper suggested the breach likely exploited vulnerabilities in the site’s WordPress template[^1]. The attack disrupted Everest’s operations, which had evolved since 2020 from data theft extortion to include ransomware deployment and selling network access to other cybercriminals[^2]. Prior to the breach, Everest had claimed over 230 victims on its leak site, including recent attacks on cannabis retailer STIIIZY and increased targeting of U.S. healthcare organizations in 2024[1][3]. The group operated as both a ransomware outfit and initial access broker, selling compromised network access to other threat actors[^4]. [^1]: BleepingComputer - Everest ransomware’s dark web leak site defaced, now offline [https://www.bleepingcomputer.com/news/security/everest-ransomwares-dark-web-leak-site-defaced-now-offline/] [^2]: CyberSecurityNews - Everest Ransomware Gang Leak Site Hacked and Defaced [https://cybersecuritynews.com/everest-ransomware-gang-leak-site-hacked/] [^3]: CyberDaily - Hackers hacking hackers: Everest ransomware leak site defaced [https://www.cyberdaily.au/security/11954-hackers-hacking-hackers-everest-ransomware-leak-site-defaced] [^4]: TheSecMaster - Everest Ransomware Group: Threat Actor Analysis 2024 [https://thesecmaster.com/blog/everest-ransomware]

#American #media ... 😄
still use words like 'maybe'

After #TRUMP policies caused massive #Job losses, dismantled the #government, damaged #social #security, damaged the #economy, accellerate #inflation and burned $ 6 trillion from the #US #market (pensions too)
they still say ...
'Maybe we are going to a period of economic depression'
Maybe ? 🤣

USA IS NOW in economic depression
Trump has forcefully dragged the USA from a healty economy
into an economic depression
to see is how bad it will be.