shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

267
active users

#infosec

137 posts107 participants3 posts today

New month, new goals, new family. Helping this domestic violence family with medical bills, groceries, and new devices. We're 18% to our goal so far! 😍 If you're looking for something to feel better, this is one way you can. ko-fi.com/lockdownyourlife

I do take refurbed devices. :)

Ko-fiSupport Lock Down Your Life on Ko-fi! ❤️. ko-fi.com/lockdownyourlifeSupport Lock Down Your Life On Ko-fi. Ko-fi lets you support the people and causes you love with small donations
Replied in thread

@briankrebs i've seen some IR figures get squirrely about the name. some argue Scattered Spider is a loose confederation, others an attack methodology. i don't have a strong opinion on that but i've seen the absolute bedlam these crews drop everywhere they go. #infosec #scatteredSpider

👋 Hey infosec.exchange! We’re the CHERI Alliance — excited to join the community!

🔐 We’re all about CHERI (Capability Hardware Enhanced RISC Instructions) — a powerful hardware-based approach to making memory safety and software security actually enforceable, by design.

💡 CHERI helps stop things like buffer overflows and use-after-free bugs before they cause trouble — with hardware-enforced protections built right into the architecture.

We’re here to:
- Share news about the CHERI community in general
- Talk about what our members are building with CHERI
- Connect with folks who care about deep, meaningful security improvements
Check us out 👉 cherialliance.org

Give us a follow if this sounds like your kind of thing!

You can pee every hour from 5 am to 10 pm weekdays and 8 am to 4 am on the weekends.
Every pee is fine, no problems.
Then one time, for no apparent reason, the stream is different and splashes everywhere.
So, do you wear depends as a safeguard, even though that doesn’t change the stream or splash? Do you need a funnel for the rest of your life?
#InfoSec #risk #mitigation #compensatingcontrols

#DOGE keeps gaining access to sensitive #data. Now, it can cut off billions to #farmers

A staffer from…DOGE recently got high-level access to view & change the contents of a #payments system that controls tens of billions of dollars in government payments & #loans to farmers & #ranchers across the #UnitedStates, according to internal access logs reviewed by NPR.

#Trump #law #economy #InfoSec #FederalGovernment #funding #Congress #SeparationOfPowers
npr.org/2025/07/10/nx-s1-54557

McDonald's AI hiring platform found to be vulnerable, risking 64 million job applications

Security researchers discovered vulnerabilities in McDonald's McHire hiring platform developed by Paradox.ai, including an insecure direct object reference (IDOR) flaw and trivial default credentials ("123456:123456") that potentially exposed personal data of up to 64 million job applicants across McDonald's franchises.

**Make sure to authenticate and authorize every single request to your APIs. And don't use integer auto-incrementing IDs for users, too easy to guess. Naturally, NEVER use trivial credentials for test systems.**
#cybersecurity #infosec #incident #databreach
beyondmachines.net/event_detai

BeyondMachinesMcDonald's AI hiring platform found to be vulnerable, risking 64 million job applicationsSecurity researchers discovered vulnerabilities in McDonald's McHire hiring platform developed by Paradox.ai, including an insecure direct object reference (IDOR) flaw and trivial default credentials ("123456:123456") that potentially exposed personal data of up to 64 million job applicants across McDonald's franchises.