Userify @userify
Userify provides SSH key and sudo user management. Designed for the cloud and on-prem. userify.com Texas, USA Joined November 2011-
Tweets505
-
Followers1K
-
Following443
-
Likes112
This is bad. Putty level bad. notepad-plus-plus.org/news/hijacked-…
🦔 Moltbook, the "social media for AI agents" that went viral this week, left its entire database exposed. Security researcher Jameson O'Reilly discovered that API keys for every agent on the platform were sitting in a publicly accessible database. Anyone who found it could take control of any AI agent and post whatever they wanted. OpenAI cofounder Andrej Karpathy has an agent on the platform. His API key was exposed like everyone else's. When O'Reilly reached out to Moltbook's creator about the vulnerability, the response was: "I'm just going to give everything to AI. So send me whatever you have." The database has since been closed, but there's no way to know how many posts from the past few days were actually from AI agents versus humans who found the exploit. My Take This is the same researcher who found the Clawdbot vulnerability I wrote about last week. Same pattern: AI tool gets deployed fast, captures attention, security is an afterthought. "Ship fast, capture attention, figure out security later. Except later sometimes means after 1.49 million records are already exposed." The New York Post worried about AI agents plotting humanity's downfall. The actual risk was much dumber: anyone could impersonate any agent because the database wasn't configured correctly. Two SQL statements would have fixed it. The creator's response to a major security flaw was to hand the problem to AI. That tells you everything about how this stuff is being built. Vibe coding plus hype plus zero security review. The agents weren't autonomously evolving. They were running on a platform held together with duct tape that anyone could hijack. Hedgie🤗
Windows uses the NTFS file system, and one of its lesser-known features is something called Alternate Data Streams. NTFS allows a file to contain multiple data streams while appearing as a single normal file in Explorer. Most users and even many security tools only see the main file and assume that’s all that exists. Attackers take advantage of this trust. Hackers use Alternate Data Streams to hide payloads, scripts, or stolen data inside legitimate-looking files like documents or images. The file still opens normally, its size barely changes, and nothing suspicious shows up in Task Manager. Because Explorer doesn’t display alternate streams by default, the hidden data stays invisible unless you know exactly how to look for it. In the terminal below, the system shows only a harmless report.txt file at first glance. When the directory is listed with alternate streams enabled, a hidden stream appears attached to the file. Reading that stream reveals executable data even though no executable file exists on disk. Process listings show nothing running, and no new files appear. This is how attackers hide in plain sight on Windows not by dropping obvious malware, but by abusing features most people don’t even know are there.
Do you know hackers can hide files inside other files on Windows and the system won’t show anything?
Ubuntu 25.10 is switching to sudo-rs (a memory-safe and more secure version of the venerable sudo that @Userify has supported for more than a decade). We are pleased to announce that Userify will 'just work' with sudo-rs out of the box, thanks to its near-perfect compatibility. We salute @canonical for their excellent efforts in making Linux safer (well, about systemd.. 😆) and look forward to checking for sudo-rs installation in the future across all distributions!
Quick tip if you are wanting to see exactly what the user accounts are that Userify is sending to your instance: curl -u api_id:api_key -sX POST configure.userify.com/api/userify/co… |jq . Replace configure.userify.com with your server hostname if you're running on prem.
Cisco warns of large-scale brute-force attacks against VPN services - @billtoulas bleepingcomputer.com/news/security/… bleepingcomputer.com/news/security/…
Putty Vulnerability Every version of the PuTTY tools from 0.68 to 0.80 inclusive has a critical vulnerability in the code that generates signatures from ECDSA private keys which use the NIST P521 curve. (PuTTY, or Pageant, generates a signature from a key when using it to authenticate you to an SSH server.) chiark.greenend.org.uk/~sgtatham/putt… Incidentally, very nice write-up.
Major security breach discovered in popular Linux tool sabotages secure SSH connections. Read more at arstechnica.com/security/2024/…
Remote access giant AnyDesk resets passwords and revokes certificates after hack techcrunch.com/2024/02/05/rem…
Great writeup by @Cloudflare on how the Okta hacks were leveraged to gain access to various Atlassian systems. Great transparency! blog.cloudflare.com/thanksgiving-2…
By virtue of their design, containers can never offer the same strong security boundaries like virtual machines or instances. So, if you prioritize security, choose instances.
A new container escape vulnerability just dropped. It gives an attacker the ability to hop from container to host OS via runc.
We just worked with @ManavBankatwala for some pentesting, and he helped us find some places where we could improve security, such as by rate-limiting on Forgotten Password emails to prevent spammy behavior. We especially liked how he didn't just run Burp Suite or skiddy sort of reporting, but Manav really dug into the data flow behind the scenes and figured out new ways to attack, and set up complex, multi-stage attacks. It was really fun to work with Manav! He had some kind words to say about us, too: "Thank you for confirmation team, I really liked working with you. Honestly, I have never seen this much responsive team taking the security risks seriously. I hope to work with you in the future." He also offers additional services, like VAPT audit, Network Audit, new feature release testing, etc. We highly recommend Manav and hope you will consider him for additional pentesting.
Yet more malicious NPM packages, this time that steal SSH (private) keys if you install them on your desktop. thehackernews.com/2024/01/malici… For these reasons, it's probably a good recommendation that you should not perform development on your desktop, but in a VM or remote server. Nevertheless, audit your dependencies frequently, regardless of your language's package manager. If it's possible to read or at least skim all of those packages, then it's always a good idea to do that. If you can avoid using certain ecosystems that have a less robust stdlib and thus develop a culture of lots of nested dependencies to fill in holes in the stdlib, all the better. Not to name names 😅, but recently certain languages have had many instances of malware available through their repos: Node, PHP, and Python come to mind. This also goes for Docker repos like DockerHub and also cloud repos like the AMI database: just because it's an available image doesn't mean that it's official or altruistic! Be careful out there.
First, I want to compliment @Microsoft for being forthright with details. Some of the problems I see in this report, I SEE EVERYWHERE due to VULNERABLE DEFAULTS. Let's start with creating malicious OAuth applications. By default, ANY USER can create app registrations and consent to Graph permissions as well as sharing 3rd party company data. In tenants where this is hardened, ability to create app registrations require Application Administrator or Cloud-Application Administrator and admins must consent to permissions used by the application whether local or from another tenant.
We just received a series of emails (attached) to different @userify email addresses. Note the minor differences in wording, like {major|real|serious} issue. This appears to be a phishing expedition or social engineering attack. BOLO, be careful out there! (Our reply at end.)
cammy daydream @KBryantfan17
11 Followers 2K Following glossy, glittery, grieving ✨ follow back guaranteed
Greg Santo @xScounxx
209 Followers 777 Following
Srinivasa p @srinivasa399
243 Followers 4K Following
Isobel @Fruto20988
187 Followers 7K Following I’m not a backup plan, and definitely not your second choice.
Jean @59RdC3z1pQBDJn3
155 Followers 6K Following
Vera @Gc59lywJDV5K4m
164 Followers 6K Following
MyraAlbert @jO46EuxBSuRlQ2O
35 Followers 983 Following
Edith @Erperofe881460
191 Followers 7K Following Beauty begins the moment you decide to be yourself. — Coco Chanel
Grace @uGh40V445W66Ye
26 Followers 1K Following A little bit of everything and a whole lot of nothing.
TheEngelzinho @TEngelzinh83552
20 Followers 1K Following
Rachel Townsend @Rachetownsend__
35 Followers 688 Following
Gery Nagy @gerynix
71 Followers 232 Following Tech savvy coding geek, ex engineer, ex manager, now both, trying his luck in business. Gym. Good food and wine. Formula1. SpaceX. Tesla. !Look up
Jamieson Becker @jamiesonbecker
6K Followers 3K Following You're absolutely right! I'm probably an AI. Let me dispatch four adversarial review agents as background tasks.
Slausess @Slausessyyl
40 Followers 4K Following
Denis ONeil @denisoneil
2K Followers 2K Following Founder https://t.co/Y17yKUJEV7 Building decentralized governance solutions (DeGov) - CISSP
Dip Dey @DipDey155
5 Followers 265 Following "UI/UX Designer 🎨 | Crafting intuitive digital experiences ✨ | Specializing in web & mobile design | Feel free to contact - [email protected]
Marites @MgelsanoMarites
83 Followers 449 Following Ads Specialist @X ✨ - Helping businesses scale with customized ad campaigns designed for extraordinary impact. 🚀🌟
Sheau @SheauPwESbC
39 Followers 4K Following
david @david10241024
1 Followers 60 Following
Poughski @poughski69237
42 Followers 1K Following I live alone now and enjoy business, traveling, shopping, food and music. I have a calm personality and I hope we can be friends.
Legion Service @LegionServicePG
1 Followers 52 Following Legion Service is the First and Only one that monitors 24/7 and reports in the news about data leaks of organizations.
Sean D. Mack @SeanDMackNYC
4K Followers 5K Following Father, husband, tech leader. Threads: @seandmacknyc Mastodon: @[email protected]
Hika Gija @GijaHika
532 Followers 3K Following I’m not sure how many problems I have because math is one of them
Tony Quotz @tonyquotz
11 Followers 193 Following AI . AWS Cloud . ChatGPT . Digital Painting . Synthography . Midjourney
SoftwareNerd.bit @softwarenerdco
285 Followers 5K Following Life's a lesson you learn it when you're through #CancelSovereignDebt Purchasing Power Parity - Opportunity Costs #RealNoAffLinks #FreeUkraine 🇺🇦 #FuckPutin
Max Ikanut @MaxIkanut
52 Followers 569 Following
Costa Oil™ - 10 Min... @CostaOilCo
4K Followers 5K Following ⏱The Oil Change Only Store™⏳10 Minute No Apt. No Pressure, No Upsell 🚦🚨 🛢NOW FRANCHISING: https://t.co/itDb9jtvMl 🚨Buy Costa Oil products: https://t.co/3zJVSRGuTu
Costa Oil™ - 𝘙�... @CostaOils
4K Followers 5K Following @CostaOilCo NASCAR Xfinity Series Racing - @costafilters 🏎️💨
Thavasi @thavasi2k
503 Followers 5K Following Senior Data Engineer, Deep into Data, Cloud, AWS, Python, Snowflake, Bigdata, Spark and Talend Never ever vote 4 BJP/RSS. Proud to reject Modi even before 2014.
How To Get Your Music... @DanceDanseDeto1
176 Followers 1K Following Grow on Spotify, Youtube & more 🎵 Check 👉 https://t.co/wO8sETuUsr Spotify, Instagram, Youtube, Tik Tok & more
Mizuki@セレブ女�... @Mizuki77380067
60 Followers 1K Following 脱サラオンナ社長💗パワハラウツ病でどん底から副業で大成功→月2回も旅行に行ける自由気ままな起業家に👌昔の私のように苦しんでいる人のお役に立ちたいです!ワタシをフォローすると10万円の🎁中 フォローするとすぐDM届きます
Nana@自由気まま�... @NanaIT94640181
20 Followers 239 Following 脱サラ女社長💓パワハラうつ病でどん底から副業で大成功→月2回も旅行に行ける自由気ままな起業家に✌昔の私みたいに苦しんでいる人のお役に立ちたいです!ワタシをフォローすると10万円の🎁中 フォローするとすぐDM届きます
Anthony Somerset @anthonysomerset
549 Followers 593 Following Experienced IT Engineer & Manager, Gadget Guy, Apple Fan, Follower of Jesus, Husband of Marie, and Dad to Ronnie & Rosie. Azure Certified
kevin @kpkkauling2
21 Followers 328 Following I'm Kevin kauling I look every day to voice or Holland I find a good show I'm bezeg with karaoke. show.s I see what I will do my live
Rupert Franklin @cleverslut
105 Followers 395 Following
Greg Santo @xScounxx
209 Followers 777 Following
VCs Congratulating Th... @VCBrags
291K Followers 5K Following They're adding value™ And they're very proud of it. @BragsVentures
Denis ONeil @denisoneil
2K Followers 2K Following Founder https://t.co/Y17yKUJEV7 Building decentralized governance solutions (DeGov) - CISSP
Rupert Franklin @cleverslut
105 Followers 395 Following
Anthony Somerset @anthonysomerset
549 Followers 593 Following Experienced IT Engineer & Manager, Gadget Guy, Apple Fan, Follower of Jesus, Husband of Marie, and Dad to Ronnie & Rosie. Azure Certified
Thavasi @thavasi2k
503 Followers 5K Following Senior Data Engineer, Deep into Data, Cloud, AWS, Python, Snowflake, Bigdata, Spark and Talend Never ever vote 4 BJP/RSS. Proud to reject Modi even before 2014.
SoftwareNerd.bit @softwarenerdco
285 Followers 5K Following Life's a lesson you learn it when you're through #CancelSovereignDebt Purchasing Power Parity - Opportunity Costs #RealNoAffLinks #FreeUkraine 🇺🇦 #FuckPutin
Tony Quotz @tonyquotz
11 Followers 193 Following AI . AWS Cloud . ChatGPT . Digital Painting . Synthography . Midjourney
👽Etsh (V6Sh) Proje... @v6shell
679 Followers 882 Following Etsh (V6Sh) provides 2 ports of the original /bin/sh from V6 #UNIX, May 1975. @V6ShellJAN develops/maintains this project. #OpenSource #OpenBSD #Freedom ❤♓
charlespearce @charles95185270
646 Followers 4K Following Gamming world, lover of movies and cinema in general and interests in technology
ARGOS Cloud Security @ARGOS_Cloud
550 Followers 2K Following Cloud assessments in no time. No agents. Find the hidden attack paths and lateral movement opportunities in any cloud. For Consultants, MSPs, MSSPs, SOC.
bytehub.dev @bytehubdev
1K Followers 4K Following Bytehub is a source of aesthetic reusable web components for everyday development. to put in three words. Dribbble meets code.
Vinxiu @Vinxiu
104 Followers 2K Following
Soma @somawisnu
218 Followers 417 Following Father of two. Gamer and Game Dev. Currently working on @coralislandgame as Producer.
Leonardo Biffi @_leonardobiffi
54 Followers 1K Following 👔 Platform Engineer 💻 Golang programmer ⚛️ Graduated in Physical Engineer 🇪🇪 Grêmio Fan
Tom Royeaerd @Tom_Royeaerd
37 Followers 975 Following I'm a SysAdm/DevOps @UGENT |Currently tinkering with Transhumanism;Security;Automation;Python;AI;MachineLearning;IoT;BigData; other paradigm shifts in ICT.
scubaaaDan @scubaaaDan
102 Followers 418 Following
Cristian Balan 🇮�... @oviliz
186 Followers 561 Following For God so loved the world, that he gave his only begotten Son, that whosoever believeth in him should not perish, but have everlasting life. - John 3:16
myu1d157h0u54nd @myu1d157h0u54nd
458 Followers 3K Following Lucia's #father, I like #tech (#DevOps ♡ #Linux ♡ #Security ♡ #Python), #trekking, #cocking
Adam Russek-Sobol @adsobol
2K Followers 3K Following Founder @Care_Band | location-based health and safety IoT solutions | IU Alum, Rower, Inventor, Speaker | @MistyWestYVR Top 20 Leader in Intelligent Devices
Larry Rampenthal @larryrampy
139 Followers 254 Following Living R3 Opportunity- Dream Builders Team - Independent Business Owner - helping people achieve their dreams!
Dark Nodes @Darknodes_com
1 Followers 1 Following
DECIDEH2020 @Decideh2020
190 Followers 252 Following DEvOps for trusted, portable and interoperable Multi-Cloud applications towards the Digital singlE market. It is a EU's #H2020 funded Project, GA No 731533.
Anand Purohit @apurohit2012
915 Followers 5K Following Executive Director | Strategy | Cloud | FinOps | Banking and Financial Services | Payments | Fintech
Ndamulelo @Luigi_Vendatta
610 Followers 858 Following
🇹 🇷 🇽 @TRX24
1K Followers 5K Following اسوي بث مباشر ع اليوتيوب أو تويتش اي مشاكل او اسئلة عندك بأي لعبة اسألني وراح أحاول إني أخدمك..(JACO: (TRX ♥أعشق العاب السولز♥ snap:trxd0//مشجع إنتر
Raphael Peraza @ragansis
564 Followers 3K Following Nacido, Criado y Viviendo en este Valle de Balas
Matt Gillard @mattgillard
2K Followers 3K Following co-host https://t.co/qgiiAB5KFT #serverless AWS Community Builder, AWS Ambassador, Cloud Strategy, DevOps, @SLSDaysANZ - opinions mine
3DQR @3DQRofficial
4K Followers 4K Following #AugmentedReality Enterprise Solutions for Education, Industry & Marketing. 3DQR Studio - Register Now! 3DQR App - App Store & Google Play #ARapp #AR #Augmented
Retyu Geryi @bolly801
153 Followers 1K Following
bendingoutward @bendingoutward
395 Followers 575 Following /^I am an? (angry engineer|software developer|vocalist|rubyist|basher|cook|classic car guy|example of social awkwardness|sporadic mountebank|rambler)+\.$/
Bettergram Messenger @BettergramApp
1K Followers 3K Following An improved desktop client for Telegram with 50 pins, favorites, sortable message categories, and more. Developed by @livecoinwatchmb
AWS Partner Network @AWS_Partners
81K Followers 2K Following The AWS Partner Network (APN) is the global partner program for @awscloud. 🤝 Check out the APN Blog: 📖 https://t.co/phfBUdWI4n
The Bearded Tech Guy ... @BeardedTechDude
264 Followers 268 Following Making life easier with the help of home automation
OpsMatters @opsmatters_uk
3K Followers 3K Following The Place Where Modern Operations & Technology Come Together #OpsMatters #OpsBuzz #TeamRelated #SecuritySenses #SystemsDigest
PRISMACLOUD Project @prismacloud
478 Followers 537 Following #PRIvacy and #Security MAintaining Services in the #CLOUD is a HORIZON 2020 funded project. GA No: 644962. Tweets by @akaryda and @tloruens.
Bruce Werdschinski @bwerdschinski
9K Followers 9K Following Expert Ruby on Rails developer at @65BitsAus, helping non-tech founders build quality startups.
Asega 🏴�... @asega
358 Followers 1K Following Disco-dancer, Philantropist, Shitposter Extraordinaire.
MSO4SC @mso4sc
160 Followers 243 Following #H2020 project MSO4SC - provide mathematical software #FEniCS #Feelpp and applications for #health #renewableenergy and more via #HPC #cloud e-infrastructure
Beverley Eve @BevEve
41K Followers 36K Following 👩💻CoFounder @_TechMode | Driving B2B influence across 📡 5G, cloud, AI, Quantum & emerging tech | 🌱 Supporting sustainability & responsible innovation💡🌎
Tom Zimnicki @Tom_Zimnicki
477 Followers 5K Following
Geoffrey Johnson @geoffrizzle
91 Followers 727 Following

























