flipboard.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Welcome to Flipboard on Mastodon. A place for our community of curators and enthusiasts to inform and inspire each other. If you'd like to join please request an invitation via the sign-up page.

Administered by:

Server stats:

1.2K
active users

#infosec

981 posts281 participants150 posts today

🛡️ The OVR Foundation website is live!
We were founded after the U.S. government’s 2025 threat to cut funding for the CVE program — a crucial piece of the cybersecurity landscape. Now, we’re working to create a decentralized, resilient standard for global vulnerability coordination.

🔧 Small updates will follow in the next few days.
🌍 Visit us: ovr-foundation.org
🔗 #CyberSecurity #OVR #Infosec #Decentralization #OpenStandard #CVE

ovr-foundation.orgHome - OVR FoundationThe OVR Foundation is developing a decentralized standard for global vulnerability coordination — transparent, resilient, and independent.

Craft CMS just faced a major breach—hackers exploited a subtle "return URL" trick and a framework flaw to get backdoor access. How did a tiny parameter turn into a full-blown server exploit, and what can admins do to stop it?

thedefendopsdiaries.com/craft-

#craftcms
#rce
#cybersecurity
#zeroday
#infosec

The DefendOps Diaries · Craft CMS Security Challenges: Understanding the RCE Exploit ChainBy Alex Cipher

good thing the US is gutting beneficial ownership regulations that would make it easier to understand who actually owns US trusts and corporations while simultaneously trashing both crypto enforcement at the DOJ but also more generally cyber defense

"The companies, Blocknovas LLC and Softglide LLC, were set up in the states of #NewMexico and New York using fake personas and addresses."

* Reuters: reuters.com/sustainability/boa
* Technical details from Silent Push: silentpush.com/blog/contagious

⚠️ Financial services alert: Banks are racing to build AI — but tech gaps are slowing them down 🏦⚙️

CIO Dive reports that banks are doubling down on cloud, cybersecurity, and data investments to unlock GenAI’s full potential:

🔹 72% of firms are scaling generative AI projects
🔹 4 in 5 rank cyber, analytics, and cloud as top priorities
🔹 Yet nearly half are battling data silos and quality issues
🔹 Leaders expect GenAI-driven productivity gains — but returns are uneven

The path forward?
🧠 Build resilient, secure cloud foundations
🔍 Tackle data modernization before scaling AI
🛡️ Invest in governance, access controls, and model guardrails

AI may be the future of banking — but only if the underlying tech can support it safely.

#Banking #Cloud #CyberSecurity #GenerativeAI #DataStrategy #Fintech #security #privacy #cloud #infosec

ciodive.com/news/bank-tech-clo

CIO Dive · Banks gear up to boost cybersecurity, cloud and data spendingBy Matt Ashare

New Open-Source Tool Spotlight 🚨🚨🚨

Mapping your threat-hunting workflows to the MITRE ATT&CK framework? Check out olafhartong's ThreatHunting Splunk app. With 130+ reports and dashboards, it simplifies hunting while integrating Sysmon data for deep insights. Requires tuning for best results. #ThreatHunting #MITREATTACK

🔗 Project link on #GitHub 👉 github.com/olafhartong/ThreatH

#Infosec #Cybersecurity #Software #Technology #News #CTF #Cybersecuritycareer #hacking #redteam #blueteam #purpleteam #tips #opensource #cloudsecurity

✨
🔐 P.S. Found this helpful? Tap Follow for more cybersecurity tips and insights! I share weekly content for professionals and people who want to get into cyber. Happy hacking 💻🏴‍☠️

⚠️ Mobile security risk: New Android malware "SuperCard X" enables contactless payment fraud via NFC relay attacks 📱💳

Here’s how it works:
🔹 Victims are socially engineered through fake bank alerts (smishing + calls)
🔹 Tricked into installing a rogue app posing as “security software”
🔹 NFC data is intercepted from real debit/credit cards
🔹 Attackers relay stolen credentials to PoS terminals and ATMs for fraudulent cashouts

Why it matters:
• Attackers no longer need stolen physical cards — just proximity + deception
• Banking customers, payment providers, and card issuers are all at risk
• Google is working on Android protections — but vigilance is key now

🛡️ Tip: Always scrutinize app installs, verify messages before acting, and keep Google Play Protect enabled.

#CyberSecurity #MobileSecurity #Malware #NFC #FinancialFraud #ThreatIntel #security #privacy #cloud #infosec

thehackernews.com/2025/04/supe

The Hacker NewsSuperCard X Android Malware Enables Contactless ATM and PoS Fraud via NFC Relay AttacksSuperCard X malware exploits NFC relay and social engineering to steal card data in Italy, enabling ATM fraud.

Spionii cibernetici nord-coreeni au creat firme 🇺🇸#America‎ne pentru a păcăli dezvoltatorii de criptografie.
Hackeri din grupul Lazarus au efectuat atacuri de tip „waterhole” asupra șase companii.

🔗 techrider.ro/cybersecurity/spi