Discussion
Loading...

#Tag

  • About
  • Code of conduct
  • Privacy
  • About Bonfire
Infoblox Threat Intel
@InfobloxThreatIntel@infosec.exchange  ·  activity timestamp 2 days ago

📱Smishing Slows, Quishing Quickens 🎣

Sick of smishing and those pesky parking/toll texts? Don’t get caught by crafty, counterfeit court QR codes — it’s a scan-and-scam! 💳 🚨

North American cell phone users are being hit with yet another wave of smishing campaigns that now include quishing elements. Likely orchestrated by Chinese-speaking threat actors, this latest campaign builds on previous vehicular violations, evolving tactics while impersonating US courts. 🧑‍⚖️

We’ve recently seen a flurry of SMS messages pushing parking violations — but with a twist: face justice in court… or scan and pay instead!

Delivered as an official-looking image, the actor has begun integrating QR codes into these lures to help mask suspicious phishing URLs, baiting victims into entering personal information, credentials, and ultimately making payments.

For some, this lure may sound better than facing justice for their perceived poor parking. Victims who don't comply are warned that failure to appear or pay could have serious repercussions - a scare tactic designed to push you toward a hasty decision and scanning the QR code! 🫣

We uncovered thousands of these nefarious domains, through their use of Registered Domain Generation Algorithms (RDGAs) and local government impersonation, hosted across a diverse range of hosting providers to evade takedown.

Recent examples:
⛔ ahfgx[.]icu
⛔ euoyq[.]icu
⛔ htpze[.]icu
⛔ mwlaj[.]icu

Friendly reminder - courts don't usually communicate with you via text. That said, we suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving tradecraft used in smishing and quishing delivery. As for us, we'll take our chances on evading that bench warrant and running from the law. 🏃‍♂️‍➡️

#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #smishing #quishing

Example fake court notice with QR code
Example fake court notice with QR code
Example fake court notice with QR code
  • Copy link
  • Flag this post
  • Block
Em :official_verified: boosted
Chuck
@ChuckMcManis@chaos.social  ·  activity timestamp 3 days ago

Heads up you code maintainers who take submissions from people, delete unicode characters. See this: https://arstechnica.com/security/2026/03/supply-chain-attack-using-invisible-code-hits-github-and-other-repositories/ Yes, people put back doors in code using unicode characters that don't show up on the screen. #infosec #foss #github

Ars Technica

Supply-chain attack using invisible code hits GitHub and other repositories

Unicode that's invisible to the human eye was largely abandoned—until attackers took notice.
  • Copy link
  • Flag this post
  • Block
Chuck
@ChuckMcManis@chaos.social  ·  activity timestamp 3 days ago

Heads up you code maintainers who take submissions from people, delete unicode characters. See this: https://arstechnica.com/security/2026/03/supply-chain-attack-using-invisible-code-hits-github-and-other-repositories/ Yes, people put back doors in code using unicode characters that don't show up on the screen. #infosec #foss #github

Ars Technica

Supply-chain attack using invisible code hits GitHub and other repositories

Unicode that's invisible to the human eye was largely abandoned—until attackers took notice.
  • Copy link
  • Flag this post
  • Block
Em :official_verified: boosted
Jonathan Kamens 86 47
@jik@federate.social  ·  activity timestamp 3 days ago

Activist: "Should we put our phones in airplane mode when we're doing activist stuff?"
Me: [responds with two pages of text about threat modeling, risk assessment, levels of protection, current and future threats]
I don't think most people realize how hard it is to give people simple, straightforward cybersecurity guidance.
There's a huge risk in erring on the side of caution: people finding your recommendations burdensome and doing _nothing_ as a result.
#infosec
(1/2)

  • Copy link
  • Flag this post
  • Block
Jonathan Kamens 86 47
@jik@federate.social  ·  activity timestamp 3 days ago

Activist: "Should we put our phones in airplane mode when we're doing activist stuff?"
Me: [responds with two pages of text about threat modeling, risk assessment, levels of protection, current and future threats]
I don't think most people realize how hard it is to give people simple, straightforward cybersecurity guidance.
There's a huge risk in erring on the side of caution: people finding your recommendations burdensome and doing _nothing_ as a result.
#infosec
(1/2)

Jonathan Kamens 86 47
@jik@federate.social replied  ·  activity timestamp 3 days ago

How I ended up summarizing my pages of advice, which didn't even cover everything I wanted to cover:
"If you're doing something about which you're worried about the government coming after you or the people you're with now or in the future, it might be prudent to leave your phone home, or turn it off and not turn it back on until you're back home unless there's an emergency."
#infosec
(2/2)

  • Copy link
  • Flag this comment
  • Block
Jonathan Kamens 86 47
@jik@federate.social  ·  activity timestamp 3 days ago

Activist: "Should we put our phones in airplane mode when we're doing activist stuff?"
Me: [responds with two pages of text about threat modeling, risk assessment, levels of protection, current and future threats]
I don't think most people realize how hard it is to give people simple, straightforward cybersecurity guidance.
There's a huge risk in erring on the side of caution: people finding your recommendations burdensome and doing _nothing_ as a result.
#infosec
(1/2)

  • Copy link
  • Flag this post
  • Block
defnull
@defnull@chaos.social  ·  activity timestamp 4 days ago

The 'multipart' #python library got an independent #security audit and I only know about that because they found something -> CVE-2026-28356

This is great, actually! Someone looked into it so thoroughly that they found an obscure single-character issue in a regular expression ... and didn't find anything else! Which means I can now be really confident about the security of this library. Nice!

#cve #infosec #sansio

  • Copy link
  • Flag this post
  • Block
Flipboard Tech Desk
@TechDesk@flipboard.social  ·  activity timestamp 4 days ago

Instagram is getting rid of end-to-end encrypted messages after May 8, 2026, arguing that people barely used the feature, which is not enabled by default and only available in some areas. Here's more from @Engadget.

https://flip.it/abqNJ-

#Instagram #InfoSec #Meta #Tech

  • Copy link
  • Flag this post
  • Block
The Gibson in Sojourn boosted
c0debabe
@c0debabe@masto.hackers.town  ·  activity timestamp 4 days ago

HackerHaus is having an online mini-con tomorrow!

Live streaming via YouTube and the recording will be available after.

https://www.hackerhaus.io/con

#InfoSec #InformationSecurity

HackerHaus

HackerHausCon — HackerHaus

  • Copy link
  • Flag this post
  • Block
c0debabe
@c0debabe@masto.hackers.town  ·  activity timestamp 4 days ago

HackerHaus is having an online mini-con tomorrow!

Live streaming via YouTube and the recording will be available after.

https://www.hackerhaus.io/con

#InfoSec #InformationSecurity

HackerHaus

HackerHausCon — HackerHaus

  • Copy link
  • Flag this post
  • Block
stux⚡️ boosted
pheonix
@pheonix@hachyderm.io  ·  activity timestamp 5 days ago

Is this the first time a major service has removed end-to-end encryption instead of adding it? Why Instagram?

#instagram #socialmedia #privacy #infosec #technology #enshittification

Screenshot showing, "Instagram's end-to-end encrypted messaging is ending on 8 May"
Screenshot showing, "Instagram's end-to-end encrypted messaging is ending on 8 May"
Screenshot showing, "Instagram's end-to-end encrypted messaging is ending on 8 May"
  • Copy link
  • Flag this post
  • Block
Seth of the Fediverse boosted
Dane
@TheLastOfHisName@beige.party  ·  activity timestamp 5 days ago

"We’ve been saying this for years now, and we’re going to keep saying it until the message finally sinks in: mandatory age verification creates massive, centralized honeypots of sensitive biometric data that will inevitably be breached. Every single time. And every single time it happens, the politicians who mandated these systems and the companies that built them act shocked—shocked!—that collecting enormous databases of government IDs, facial scans, and biometric data from millions of people turns out to be a security nightmare."

https://www.techdirt.com/2026/02/25/hackers-expose-the-massive-surveillance-stack-hiding-inside-your-age-verification-check/

#Discord #AgeVerification #Infosec

Techdirt

Hackers Expose The Massive Surveillance Stack Hiding Inside Your “Age Verification” Check

We’ve been saying this for years now, and we’re going to keep saying it until the message finally sinks in: mandatory age verification creates massive, centralized honeypots of sensitiv…
  • Copy link
  • Flag this post
  • Block
pheonix
@pheonix@hachyderm.io  ·  activity timestamp 5 days ago

Is this the first time a major service has removed end-to-end encryption instead of adding it? Why Instagram?

#instagram #socialmedia #privacy #infosec #technology #enshittification

Screenshot showing, "Instagram's end-to-end encrypted messaging is ending on 8 May"
Screenshot showing, "Instagram's end-to-end encrypted messaging is ending on 8 May"
Screenshot showing, "Instagram's end-to-end encrypted messaging is ending on 8 May"
  • Copy link
  • Flag this post
  • Block
Dane
@TheLastOfHisName@beige.party  ·  activity timestamp 5 days ago

"We’ve been saying this for years now, and we’re going to keep saying it until the message finally sinks in: mandatory age verification creates massive, centralized honeypots of sensitive biometric data that will inevitably be breached. Every single time. And every single time it happens, the politicians who mandated these systems and the companies that built them act shocked—shocked!—that collecting enormous databases of government IDs, facial scans, and biometric data from millions of people turns out to be a security nightmare."

https://www.techdirt.com/2026/02/25/hackers-expose-the-massive-surveillance-stack-hiding-inside-your-age-verification-check/

#Discord #AgeVerification #Infosec

Techdirt

Hackers Expose The Massive Surveillance Stack Hiding Inside Your “Age Verification” Check

We’ve been saying this for years now, and we’re going to keep saying it until the message finally sinks in: mandatory age verification creates massive, centralized honeypots of sensitiv…
  • Copy link
  • Flag this post
  • Block
Mark Wyner Won’t Comply :vm:
@markwyner@mas.to  ·  activity timestamp 5 days ago

There’s a vulnerability with Proton VPN on macOS. The kill switch leaks your real IP between connections.

https://neat.tube/w/stZcmNsKx3eH9j97UmG1jv

#VPN #Privacy #InfoSec #Proton #Vulnerability #KillSwitch

  • Copy link
  • Flag this post
  • Block
Em :official_verified:
@Em0nM4stodon@infosec.exchange  ·  activity timestamp 6 days ago

Whenever you hear "ban for kids" on the internet, read in reality "ID collection by a sketchy third-party company that will definitely use it or leak it or both for every adult."

Because that's what this truly means.
Also, it doesn't even help the kids.

#AgeVerification #Privacy #MassSurveillance #Authoritarianism

Radio_Azureus
@Radio_Azureus@ioc.exchange replied  ·  activity timestamp 6 days ago

What I find baffling, is that people on a global scale, do not go on the streets, literally march on the streets, to tell their governments that this totalitarian movement on a global level needs to stop, otherwise we will stop the governments...

@Em0nM4stodon

#InfoSec #AgeVerification #Privacy #MassSurveillance #Authoritarianism

  • Copy link
  • Flag this comment
  • Block
Log in

Bonfire Dinteg Labs

This is a bonfire demo instance for testing purposes. This is not a production site. There are no backups for now. Data, including profiles may be wiped without notice. No service or other guarantees expressed or implied.

Bonfire Dinteg Labs: About · Code of conduct · Privacy ·
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Code of Conduct
Home
Login