shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

245
active users

#govsec

0 posts0 participants0 posts today
Dissent Doe :cupofcoffee:<p>York County, Pennsylvania incident: </p><p>An employee of a vendor that had been hired to develop software for York County Civil Courts was provided “with certain York County Civil Courts data to use for software development and testing purposes. The employee subsequently left the vendor’s employment without returning this data,” according to the county's press release.</p><p>So it seems they gave the vendor's employee REAL data to use for development and testing -- with "contact information, Social Security numbers, driver’s license or state ID card numbers, financial and medical information"</p><p>And of course, there's no evidence of misuse, but they have referred the matter to law enforcement.....</p><p>h/t, <a href="https://www.pennlive.com/news/2025/05/central-pa-county-alerts-residents-of-potential-data-leak.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">pennlive.com/news/2025/05/cent</span><span class="invisible">ral-pa-county-alerts-residents-of-potential-data-leak.html</span></a></p><p><a href="https://infosec.exchange/tags/infosecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosecurity</span></a> <a href="https://infosec.exchange/tags/govsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>govsec</span></a> <a href="https://infosec.exchange/tags/insiderthreat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>insiderthreat</span></a></p>
Dissent Doe :cupofcoffee:<p>WBAL-TV11 started digging into the <a href="https://infosec.exchange/tags/Kairos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Kairos</span></a> attack on the State Attorney's Office for the City of Baltimore. </p><p>Kairos had exfiltrated 325 GB of files, and none of it appeared to have been protected with any encryption. My previous report on the incident can be found here: <a href="https://databreaches.net/2025/04/19/baltimore-city-states-attorneys-office-hacked-data-leaked/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/04/19/ba</span><span class="invisible">ltimore-city-states-attorneys-office-hacked-data-leaked/</span></a> </p><p>The city has now confirmed they had a breach (they were notified by law enforcement as they hadn't detected it on their own, it seems). But they are not giving out any details or answering any questions. See WBAL-TV's coverage at <a href="https://www.wbaltv.com/article/baltimore-states-attorney-office-cybersecurity-incident/64551797" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">wbaltv.com/article/baltimore-s</span><span class="invisible">tates-attorney-office-cybersecurity-incident/64551797</span></a></p><p>So, of course, I have now filed a public records request under <a href="https://infosec.exchange/tags/MPIA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MPIA</span></a> to try to get answers to some questions because the state ignored all of my polite email inquiries. </p><p>Did I ever mention that I hate not getting answers to questions? :)</p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/govsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>govsec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a></p>
Dissent Doe :cupofcoffee:<p>NEW by me: </p><p>Baltimore City State’s Attorney’s Office hacked; Data leaked </p><p><a href="https://databreaches.net/2025/04/19/baltimore-city-states-attorneys-office-hacked-data-leaked/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">databreaches.net/2025/04/19/ba</span><span class="invisible">ltimore-city-states-attorneys-office-hacked-data-leaked/</span></a> </p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/GovSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GovSec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/Kairos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Kairos</span></a></p>
Dissent Doe :cupofcoffee:<p>The U.S. And Its Allies Are Pledging Never To Pay Hacker Ransoms: </p><p><a href="https://themessenger.com/tech/ransomware-us-international-hacking-ransom-pledge" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">themessenger.com/tech/ransomwa</span><span class="invisible">re-us-international-hacking-ransom-pledge</span></a></p><p>From the article:</p><p>"Data provided to the U.S. government by ransomware negotiators shows that companies with good backups are able to recover “far more quickly” than companies that pay a ransom, according to the senior administration official." </p><p>My questions: So when they don't have a good backup and have pledged not to pay, what exactly is going to happen next? And if this does work, does that just shift the threat actors over even more to softer targets like, say,&nbsp; healthcare and education entities?</p><p><a href="https://infosec.exchange/tags/ransomware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ransomware</span></a> <a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/extortion" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>extortion</span></a> <a href="https://infosec.exchange/tags/incidentresponse" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>incidentresponse</span></a> <a href="https://infosec.exchange/tags/govsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>govsec</span></a> <a href="https://infosec.exchange/tags/pledge" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pledge</span></a> </p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@brett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>brett</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@campuscodi" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>campuscodi</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@douglevin" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>douglevin</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@amvinfe" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>amvinfe</span></a></span></p>
Dissent Doe :cupofcoffee:<p>Does anyone know who was responsible for this attack on Maries County, Missouri that also affected their 911 system too? </p><p><a href="https://abc17news.com/news/maries/2023/09/26/maries-county-emergency-managements-says-it-was-hit-with-cyber-attack-says-one-911-call-affected/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">abc17news.com/news/maries/2023</span><span class="invisible">/09/26/maries-county-emergency-managements-says-it-was-hit-with-cyber-attack-says-one-911-call-affected/</span></a></p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@brett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>brett</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@campuscodi" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>campuscodi</span></a></span> <span class="h-card" translate="no"><a href="https://ioc.exchange/@jgreig" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jgreig</span></a></span> </p><p><a href="https://infosec.exchange/tags/cyberattack" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cyberattack</span></a> <a href="https://infosec.exchange/tags/govsec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>govsec</span></a> <a href="https://infosec.exchange/tags/infosecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosecurity</span></a></p>
Dissent Doe :cupofcoffee:<p>Cyberattack causes St. Louis County to shut down some public safety computer servers:</p><p><a href="https://www.stltoday.com/news/local/government-politics/cyberattack-causes-st-louis-county-to-shut-down-some-public-safety-computer-servers/article_bdb52ede-51c5-11ee-9ac5-23aa74956aa9.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">stltoday.com/news/local/govern</span><span class="invisible">ment-politics/cyberattack-causes-st-louis-county-to-shut-down-some-public-safety-computer-servers/article_bdb52ede-51c5-11ee-9ac5-23aa74956aa9.html</span></a></p><p>KCTV reports that three other municipalities also reported REJIS-related system issues:</p><p><a href="https://www.kctv5.com/2023/09/12/kansas-city-area-municipal-courts-suspend-services-due-security-related-incident/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">kctv5.com/2023/09/12/kansas-ci</span><span class="invisible">ty-area-municipal-courts-suspend-services-due-security-related-incident/</span></a></p><p>REJIS is a government agency that serves criminal justice departments across Missouri and in Illinois and Kansas.</p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/GovSec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GovSec</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>software</span></a> </p><p><span class="h-card" translate="no"><a href="https://infosec.exchange/@brett" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>brett</span></a></span> <span class="h-card" translate="no"><a href="https://ioc.exchange/@jgreig" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jgreig</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@BleepingComputer" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>BleepingComputer</span></a></span></p>