corteximplant.com is one of the many independent Mastodon servers you can use to participate in the fediverse.
CORTEX IMPLANT - an international cyberpunk'ish LGBTQIA+ friendly Fediverse instance for edgerunners, netrunners and cyberpunks and all who want to become one.

Administered by:

Server stats:

227
active users

#simswap

0 posts0 participants0 posts today
Public

📵 Your phone number is your weakest link.

Hackers use SIM swap attacks to steal your number, reset your accounts, and bypass 2FA. It happens more than you think.

💡 Protect yourself:
✔ Remove your number from important accounts (email, banking)
✔ Use app-based 2FA (Aegis, YubiKey, OTP)—NEVER SMS
✔ Ask your carrier for a port-out PIN

📌 Your phone number shouldn’t be your identity.

Public

@GossiTheDog the sheer fact that #MSPs & #CSPs can access clients' setups without proper #authorization [including #KYC / #KYB, #AuthCode|s and proper authorization via contract] is already sickening.

Such fundamental #ITsec fuckups are reasons alone not to use #Azure or any #Microsoft products & services at all...

  • I mean, it doesn't require #Mitnick-level skills to pull this off, since it doesn't necessitate #Lapsus-Style #SIMswap or other means to gain access...
CyberplaceKevin Beaumont (@GossiTheDog@cyberplace.social)Attached: 3 images This is the partner.microsoft.com portal, it allows CSPs - Cloud Solution Providers - to gain access to their customer's environments. CVE-2024-49035 was around improper privilege management, i.e. being able to access things you shouldn't. It being in CISA KEV says it was being exploited in the wild. That portal allows a huge footprint of access by design.
Public

Feds Charge Five Men in 'Scattered Spider' Roundup

Federal prosecutors in Los Angeles this week unsealed criminal charges against five men alleged to be members of a hacking group responsible for dozens of cyber intrusions at major U.S. technology companies between 2021 and 2023, including LastPass, MailChimp, Okta, T-Mobile and Twilio.

Two of the accused I've written about extensively already. Today's story looks at how several of these guys were caught. For example:

"The phishing kits used for these campaigns featured a hidden Telegram instant message bot that forwarded any submitted credentials in real-time.

In August 2022, multiple security firms gained access to the server that was receiving data from that Telegram bot, which on several occasions leaked the Telegram ID and handle of its developer, who used the nickname "Joeleoli."

krebsonsecurity.com/2024/11/fe

Public

T-Mobile Employees Across The Country Receive Cash Offers To Illegally Swap SIMs

I still stand by this: if #sms #mfa wasn’t still massively used (especially by the financial sector), sim swaps would be less attractive to sim swappers.

It’s also crazy so much trust is placed in telecoms guarding your phone number and MFA factor for your bank. 🫨

#security #cybersecurity #simswap

tmo.report/2024/04/t-mobile-em

The Mobile Report · T-Mobile Employees Across The Country Receive Cash Offers To Illegally Swap SIMsT-Mobile employees, both third-party and corporate, are receiving cash offers via text to complete SIM swaps for criminals.
Public

"The #money was from my rainy-day account, so I consider myself fortunate there, but my #DigitalIdentity has been completely trashed."

“Phone porting is a legitimate practice people use to move a phone number from one telecommunication provider to another.”

#PhonePorting / #SIMSwap / #Optus / #Australia <abc.net.au/news/2024-04-10/opt>

ABC News · Optus customer loses $10,000, digital identity in phone porting, SIM-swap scamBy Chloe Chomicki