CyberSecSac & DC916's Avatar

CyberSecSac & DC916

@cybersec916.com

Official Bluesky for Cybersecurity Sacramento & https://www.dc916.com a DEF CON Group Belonging is the very best thing there is. #hackthebeam

143
Followers
292
Following
229
Posts
20.10.2024
Joined
Posts Following

Latest posts by CyberSecSac & DC916 @cybersec916.com

Post image Post image

Learning about lockpicking this month thanks to our member Artefact doing a presentation on @deviantollam.bsky.social β€˜s work! πŸ₯°πŸ™ŒπŸ”’πŸ”

09.10.2025 03:00 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
β€˜Widespread’ breach let hackers steal employee data from FEMA and CBP A Citrix vulnerability β€” suspected to have led to firings of multiple FEMA technology staff β€” enabled the breach, which let hackers pilfer data from FEMA servers connected to states at the southern bo...

Another day, another reported intrusion of the US government.

www.nextgov.com/cybersecurit...

02.10.2025 01:12 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
2025 Conference Information PancakesCon 6 stream links are as follows, and ComfyCon will be cross-streamed for the 8 hours prior to the conference on Track 1: Recordings of talks are available on our YouTube, starting approxi…

Enjoy pancakescon!

pancakescon.com/2025-confere...

21.09.2025 14:37 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
China Imposes One-Hour Reporting Rule for Major Cybersecurity Incidents China is ramping up its cybersecurity enforcement with new regulations requiring network operators to report severe cybersecurity incidents within one

Incident reporting in an hour or less or the next one’s free πŸ•

thecyberexpress.com/china-cybers...

15.09.2025 15:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
CISA pledges robust support for funding, further development of CVE program A key official from the agency said the vulnerability management program will continue with additional participation and enhancements.

www.cybersecuritydive.com/news/cisa-pl...

CVE's live? πŸ™Œ

13.09.2025 00:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The slides for this month’s presentation and @zoe-j.bsky.social β€˜s book report are up on the Discord and will be up on GitHub shortly.

This months news covered NPM, AI slop, GayFemboy malware and more!

We also had a presentation on the Red Team Operations Handbook!

11.09.2025 06:14 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

That’s a wrap on the DC916 September meeting! Thank you to everyone who contributed articles, to discussions, for pizza, and for amazing community!

11.09.2025 05:59 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Plex Confirms Data Breach, Asks Users to Reset Passwords Immediately An unauthorized third-party accessed one of its customer databases, which included emails, usernames, hashed passwords, and authentication data, Plex says.

While serving media from your Plex server is cool, please update your password and try not to serve malware from it. πŸ‘Ύ

www.pcmag.com/news/plex-co...

10.09.2025 17:34 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
three hamsters are sitting at a table with the words one of us ALT: three hamsters are sitting at a table with the words one of us

πŸ’œπŸ’œπŸ’œ

10.09.2025 17:17 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
a woman is laughing and saying it 's gonna be so fun ! ALT: a woman is laughing and saying it 's gonna be so fun !

Officially official now, @blackbadgeraffle.bsky.social and I have launched DEF CON Group Orlando!
Thank you @alethe.bsky.social and DCG!!
We're on Discord welcoming new members and will have meetings starting soon! ✨
discord.gg/KyKYPBCv

10.09.2025 17:05 πŸ‘ 6 πŸ” 4 πŸ’¬ 3 πŸ“Œ 0
Preview
Oops, No Victims: The Largest Supply Chain Attack Stole 5 Cents The biggest financial impact expected to be the millions of dollars of SaaS contracts signed with security vendors

www.securityalliance.org/news/2025-09...

Thanks to @djcapy.com for this one. (also, lol at them only getting 5 cents) πŸ˜‚πŸ”₯

10.09.2025 12:56 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
npm debug and chalk packages compromised The popular packages debug and chalk on npm have been compromised with malicious code

Largest supply chain breach ever (so far?) 😭

www.aikido.dev/blog/npm-deb...

Thanks to DC916 member Slag1sh for the link! πŸ’œ

09.09.2025 00:09 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
New NIST Concept Paper Outlines AI-Specific Cybersecurity Framework Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

NIST rolling out initial AI cybersecurity papers/standards.

hackread.com/nist-concept...

19.08.2025 01:24 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Looking forward to seeing your faces at the DC916 meeting tonight! Virtual and in person at MADE Studio!

7pm-8:30pm PST!

Dc916.com for the address/Discord!
Hack the planet!

13.08.2025 22:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Hope everyone is having a safe and happy DEF CON! πŸ’œ

09.08.2025 09:20 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Flyer for DEF CON first timers

Flyer for DEF CON first timers

Hello friends, with less than 2 weeks to go until DEF CON 33, please enjoy our β€œAttending DEF CON Guide” (great for newbies/first timers)

github.com/CyberSecSacr...

28.07.2025 11:49 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
McDonald’s AI Hiring Bot Exposed Millions of Applicants’ Data to Hackers Who Tried the Password β€˜123456’ Basic security flaws left the personal info of tens of millions of McDonald’s job-seekers vulnerable on the β€œMcHire” site built by AI software firm Paradox.ai.

When AI and fast food goes wrong. πŸ˜‘ 🍟

www.wired.com/story/mcdona...

16.07.2025 05:09 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Regular reminder to go outside and touch grass sometimes

15.07.2025 23:40 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Major railroad-signaling vulnerability could lead to train disruptions The high-severity flaw could let a hacker abruptly halt β€” and potentially derail β€” a train.

Planes, trains, and cybersecurity, oh my! 🚊

www.cybersecuritydive.com/news/railroa...

15.07.2025 03:39 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

The @summerc0n.bsky.social vibes right now:

#hackers #lucky13saloon

12.07.2025 21:14 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
youtu.be Diana Initiative 2021-Tanya Janca-Building Security Champions

πŸŽ₯ Missed one of my past conference talks? Let’s fix that.

I’m sharing my favoritesβ€”packed with real-world advice, lessons, and a few laughs.

β€œBuilding Security Champions”
πŸ“½οΈ https://twp.ai/9PTkef

#CyberSecurity #SecurityAwareness #appsec #securitychampions

12.07.2025 19:24 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

Earn up to $300k to help a cursed owl yell at people!

12.07.2025 19:28 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Cybersecurity Sacramento (DC916) A DEF CON group for hackers, makers, tinkerers and security enthusiasts in the Sacramento area.

[MEETING REMINDER]
❔What: Monthly Meeting - August

πŸ•– When: Wednesday, August 13th @ 7PM - 8:30PM+

πŸ“Where: Hybrid - Join virtually on Discord or come to the Sacramento Hacker Lab / MADE Studio!
[details in Discord]

πŸ‘ΎJoin our Discord by checking our landing page for the link: dc916.com

12.07.2025 06:11 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
NVD - CVE-2025-6514

nvd.nist.gov/vuln/detail/...

11.07.2025 19:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads A critical vulnerability in mcp-remote (CVE-2025-6514) allows remote code execution, affecting 437,000+ users.

When a 9.6 MCP exploit drops impacting hundreds of thousands 😭

thehackernews.com/2025/07/crit...

11.07.2025 19:14 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

HAPPY CULT OF THE DEAD COW DAY, SKEETR0NZ!

Be Sure to hit-up your local 7/11 to collect the free slurpeez they're handing out to celebrate the birthday of cDc!

Or, y'know, don't. We don't care. You do you, homeslice.

11.07.2025 19:08 πŸ‘ 45 πŸ” 19 πŸ’¬ 6 πŸ“Œ 4

I’m tracking 128 active CitrixBleed 2 victims in telemetry, today, from attacker infrastructure (one threat actor group).

11.07.2025 08:45 πŸ‘ 33 πŸ” 5 πŸ’¬ 2 πŸ“Œ 0
NVD - CVE-2025-6514

nvd.nist.gov/vuln/detail/...

11.07.2025 02:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads A critical vulnerability in mcp-remote (CVE-2025-6514) allows remote code execution, affecting 437,000+ users.

When a 9.6 MCP exploit drops impacting hundreds of thousands 😭

thehackernews.com/2025/07/crit...

11.07.2025 02:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

It's 8:10 PM Eastern and I'm glad you're alive.

Thanks for being here with me.

I love you.

You are worthy.

#MakeKindnessNormal

10.07.2025 00:10 πŸ‘ 43 πŸ” 5 πŸ’¬ 6 πŸ“Œ 0