techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

5.3K
active users

#socialengineering

41 posts26 participants10 posts today

DATE: April 10, 2025 at 03:44PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

#BlueShield: Web Trackers Shared Member #PHI With #GoogleAds t.co/FdLGpp37bn

Here are any URLs found in the article text:

t.co/FdLGpp37bn

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: April 10, 2025 at 12:58PM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

Blue Shield of California Announces Impermissible Disclosure PHI to Google Ads -
t.co/VxofMuG0WI #healthcare #databreach

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: April 10, 2025 at 12:58PM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

Blue Shield of California Announces Impermissible Disclosure PHI to Google Ads -
t.co/VxofMuG0WI #healthcare #databreach

Here are any URLs found in the article text:

t.co/VxofMuG0WI

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: April 10, 2025 at 12:23PM
SOURCE: HIPAA Watch from JD Supra

Direct article link at end of text block below.

Data Privacy in Sports: Key Takeaways t.co/HD5rWuKSrM

Here are any URLs found in the article text:

t.co/HD5rWuKSrM

Articles can be found by scrolling down the page at jdsupra.com/ under the title "Latest Updates".

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

JD SupraData Privacy in Sports: Key Takeaways | JD SupraSports teams, leagues, agents and venues collecting personal information from athletes, fans and sponsors must comply with evolving privacy...

DATE: April 10, 2025 at 08:51AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Is #Oracle's potential involvement in #TikTok's divestiture a bad idea for #nationalsecurity and #dataprivacy? t.co/kpeu0TeFx8

Here are any URLs found in the article text:

t.co/kpeu0TeFx8

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

Wer erinnert sich noch an Kevin Mitnick? In den 1980er und 1990er-Jahren vom #FBI gesucht und als einer der Wegbereiter des "#Socialengineering" zum Mythos geworden, wird in einer ausführlichen Reportage über den 2023 verstorbenen #Computerhacker berichtet, der in seinen späteren Jahren zum #Cybersecurity Experten avancierte:

"Am Weihnachtstag 1994 hackte sich Kevin Mitnick in das Heimnetzwerk von Tsutomu Shimomura, einem bekannten Computersicherheitsexperten."

gagadget.com/de/619563-die-ges

gagadget.comDie Geschichte von Kevin Mitnick: der berühmteste Hacker der Welt"Guten Tag, Sir. Können Sie mir sagen, wo ich so einen Komposter kaufen kann? Ich brauche einen für ein Schulprojekt", sagte der Zwölfjährige mit sehr selbstbewusster Stimme, so dass der Fahrer des Stadtbusses von Los Angeles keine Ahnung hatte, was der Junge vorhatte. Tatsächlich entsprach sein Plan seinen Haupteigenschaften - seiner Neugier und seinem tadellosen Gedächtnis, das es ihm ermöglichte, sich alle Kombinationen von Perforationen auf Busfahrkarten für das Umsteigen zu merken. Und er brauchte das Werkzeug, um nie wieder für Busse bezahlen zu müssen. Und um sich kostenlos in Los Angeles bewegen zu können. Der Name des Mannes war Kevin Mitnick. Wie er sich in seiner Autobiografie erinnert, war dies das erste Mal in seinem Leben, dass er das System hackte, um freien Zugang zu seinen Ressourcen zu erhalten. Später erkannte er, dass dies als Social Engineering bezeichnet wird. Aber wir kennen ihn eher als den berüchtigtsten Hacker der Welt, der zwei Jahre lang vom FBI gejagt wurde.
Replied in thread

@EllyvA : precies. Ook ik ben mens en dus maak ook fouten en doe onverstandige/risicovolle dingen; ik ben als de dood dat ik een keer ergens intrap.

Ik hoop dat ik dan net zo dapper ben als Charlotte Cowles (thecut.com/article/amazon-scam - m.i. zeer lezenswaardig) en Troy Hunt (*) in troyhunt.com/a-sneaky-phish-ju.

In security.nl/posting/840236/Vei leg ik uit hoe je het veiligste kunt inloggen (dit helpt niet tegen foute sites waarop je nog geen account hebt).

Aanvulling verderop in die pagina (directe link: security.nl/posting/876137): zet altijd "Waarschuwen voor onveilige verbindingen" aan als jouw browser dat ondersteunt (met screenshots voor Safari op iPhone/iPad: infosec.exchange/@ErikvanStrat).

(*) Troy Hunt is beheerder van haveibeenpwned.com/About

The Cut · How I Fell for an Amazon Scam Call and Handed Over $50,000By Charlotte Cowles

Virussen en phishing

(Een late reactie op een discussie tussen @EllyvA en @ximaar eindigend met mastodon.nl/@EllyvA/1140645354).

Computervirussen, in de zin van malware (malicious software) die zichzelf verspreidt, zie ik nauwelijks nog - omdat mensen geen floppies meer gebruiken om gegevens uit te wisselen.

Cybercriminelen gebruiken nu vooral social engineering om mensen te bestelen, of om aan vertrouwelijke gegevens te komen waarmee zij vervolgens mensen overtuigen dat zij een betrouwbare partij zijn.

Als zij malware maken bestaat de kwaadaardige component uit een programma (of script in het een of andere document) dat zij bij elke verspreiding wijzigen, en eerst testen op alle gangbare virusscanners (waardoor de meeste scanners aanvankelijk kansloos zijn).

In een steeds groter deel van de gevallen maakt malware misbruik van standaard onder Windows geïnstalleerde software ("lolbins" - Living Of the Land binaries) of installeert een legitieme driver waarmee verhoogde rechten (administrator privileges) worden verkregen.

Ook zeer populair zijn RAT's, Remote Access Tools zoals Teamviewer en Anydesk (steeds vaker misbruikt ook op Android en iPhones). Mensen wordt vaak voorgelogen dat zij een virusscanner zouden moeten installeren - en dat is dus zo'n RAT, zie infosec.exchange/@ErikvanStrat.

En inderdaad is phishing een gigantisch probleem - waar virusscanners nauwelijks of niet tegen helpen, omdat criminelen steeds nieuwe domeinnamen gebruiken (vb: security.nl/posting/879531) voor hun websites, en vaak captcha's inzetten waar virusscanners niet "doorheen komen".

Het komt ook voor dat automatisch door browsers verzonden gegevens, en/of IP-adressen, en/of tijdstip van de dag vaak aan specifieke criteria moeten voldoen wil de kwaadaardige versie van een website worden getoond (zie screenshot, druk Alt voor meer info).

Het beste dat je kunt doen, na het openen van een webpagina, is niet op de inhoud letten maar op de DOMEINNAAM (in de adresbalk van de browser). Voor veel te veel mensen is het echter (nagenoeg) onmogelijk om vast te stellen dat een gegeven domeinnaam *niet* van de gesuggereerde organisatie is - en hier bestaat helaas geen SIMPEL en betrouwbaar recept voor.

DATE: April 09, 2025 at 03:48PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Senate Intel Vice Chair @MarkWarner Prods #Trump Over #TikTok Plans: Says Talk of #Oracle's Involvement Worrisome Due to Recent #Data Breaches t.co/kpeu0TeFx8

Here are any URLs found in the article text:

t.co/kpeu0TeFx8

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

DATE: April 09, 2025 at 11:40AM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

Lawsuit Filed Against Teaching Hospital Over Pharmacist’s Decade-long Cyber-Spying Campaign t.co/ACnQp5JTpH #healthcare #privacy

Here are any URLs found in the article text:

t.co/ACnQp5JTpH

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: April 09, 2025 at 11:39AM
SOURCE: HIPAA JOURNAL

Direct article link at end of text block below.

Hi-School Pharmacy Agrees to Settle Data Breach Lawsuit for $600,000 t.co/t2XgtK5B63

Here are any URLs found in the article text:

t.co/t2XgtK5B63

Articles can be found by scrolling down the page at hipaajournal.com/ .

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Most healthcare security and privacy posts related to IT or infosec are at @rsstosecurity

-------------------------------------------------

DATE: April 09, 2025 at 08:25AM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Why would a #hospital #pharmacist want to #spy on coworkers? t.co/jPtQgli5rH

Here are any URLs found in the article text:

t.co/jPtQgli5rH

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

Scattered Spider: Still Hunting for Victims in 2025

Scattered Spider, a notorious hacking collective, continues to actively target victims in 2025. The group has expanded its focus to include services like Klaviyo, HubSpot, and Pure Storage, while targeting high-profile brands such as Audemars Piguet, Chick-fil-A, and Twitter/X. Silent Push researchers have identified five unique phishing kits used by Scattered Spider since 2023, with some undergoing updates. A new version of Spectre RAT has been discovered, along with the acquisition of a domain previously owned by Twitter/X. Despite arrests of several members in 2024, Scattered Spider has adapted its tactics, including the use of dynamic DNS providers and updated phishing kits. The group continues to employ sophisticated social engineering attacks to obtain credentials and multi-factor authentication tokens.

Pulse ID: 67f62708c6faf0ab4e24f6d4
Pulse Link: otx.alienvault.com/pulse/67f62
Pulse Author: AlienVault
Created: 2025-04-09 07:51:36

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

DATE: April 08, 2025 at 04:25PM
SOURCE: HEALTHCARE INFO SECURITY

Direct article link at end of text block below.

Lawsuit: #hospital #Pharmacist Spied on Coworkers for a Decade t.co/WYQAfRB2MU #UMMC

Here are any URLs found in the article text:

t.co/WYQAfRB2MU

Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

-------------------------------------------------

Private, vetted email list for mental health professionals: clinicians-exchange.org

Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

-------------------------------------------------

#security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering