The lack of common sense among the people, it should be called "uncommon sense".
The lack of common sense among the people, it should be called "uncommon sense".
Which companies are forcing staff into the office during the tube strike? #London
How do you get this info?
(Some 3rd party IP is reaching out to some xyz IP)
Help a noob
Don't forget our Call for Papers (also Rookies and Workshops) is still open!
Have you got something original and interesting to share, but need somewhere to do it?
β‘οΈ #BSidesLDN2025
More information and to submit your proposal: cfp.bsides.london/bsides-londo...
#Security #BSides #London
Now I know why my teeth glow at night .
A web malware campaign tracked as ZuizhongJS has now hijacked over 150,000 websitesβand countingβto insert ads and redirect users to Chinese gambling sites: cside.dev/blog/over-15...
This campaign started last month: cside.dev/blog/over-35...
I thiywe need more people to acknowledged it.
It seems most of the time people and companies try to hush it down. π€·ββοΈ
Never realised there is a visa requirement for delivery training as well. Is this something new?
Browsers only read the CSP when a page initially loads. This means that adding or modifying a <meta> tag afterward wonβt affect or weaken the policy. Additionally, secure sites typically define the CSP in the HTTP header, which browsers enforce immediately and ignore any attempts to override.
I had an stupid thought: since a CSP (Content Security Policy) can be implemented using a <meta> tag, whatβs stopping JavaScript from rewriting these meta tags to bypass the CSP?
I knew it was not possible but why not?
Poor handwriting.
π₯²
Hey cybersecurity folks! As a direct or indirect consequence of the US (and others) cutting foreign aid, there are many who have done cybersecurity for NGOs and at-risk groups who are or will be looking for a job. They often have broad experience, from research to incident response to education 1/2
Hey Brian
I was the one who found this. Feel free to let me know if I can be of any help.
Cheers
Hackers are hijacking WordPress sites to push Windows and Mac malware
Honored to be quoted in @techcrunch.com 's latest article on the hijacking of WordPress sites to distribute Windows and Mac malware. It's crucial for website owners to stay vigilant and implement robust security measures. Read more: techcrunch.com/2025/01/29/h...
We found 2 more domains associated with the same attack:
iogamesl[.]xyz
wp-cdn[.]top
In today we have identified a little over 500 websites that were impacted.
I was expecting a crash, but I guess the system's a bit rustyβ¦
WP infected website infecting windows users with SocGholish and Mac Users with AMOS.
cside.dev/blog/10-000-...
Black hat SEO, compromised gov and university websites.
cside.dev/blog/governm...
Over 5,000 WordPress sites caught in WP3.XYZ malware attack
cside.dev/blog/over-5k...
This is crazy, everything I say BOTS 1 new bot follows me. π π€£
Post about BOTS get more BOTS. π₯²
I got more bots followers than real people. π€·ββοΈ
When to expect next Ivanti 0day?
> My prediction 1 more this quarter.
New year/quarter is incomplete without Ivanti 0day.
French authorities are asking for the proof.
Can I show them this screenshot?
Waiting for the list!!
Happy CVE-2025-0001
A bit old but I was quoted :D
Bluesky BOTS: bluebots