Forgot your password?
typodupeerror

Comment GoDaddy could be better... (Score 1) 20

Most domain registrars have a SLAs or OLAa suggesting turnaround time of about 24 - 72 hours when it comes to malware or phishing abuse

In contrast GoDaddy takes forever for enforcement even for trivial cases, and with proof handed over on a silver platter.
I wonder why GoDaddy are so vocal about this, perhaps because they may lose a significant chunk of their so caller customer or reseller base, because lets face it:
If Jhon Doe who always pays with cryptocurrencies has had 1280 domains revoked for confirmed fraud so far, chances are, well the 2181st one shall not be of very high quality either, wink wink.
However pivoting in such a manner is something GoDaddy seems incapable of doing, same as writing a regular expression for countless easy to predict DGA
domains following the same pattern.

In their "arsenal" of tools for efficient stalling is also requesting a subpoena or court order (?!), e.g. fighting digital crime with analog means.

Some GoDaddy staff also do not seem completely aware of their obligations as a registrar entity, specifically section 3.18 of the RAA, as they are quick to dodge responsibility in many cases with "we are just the domain registrar" excuse, which is complete nonsense.

Section 3.18 of the ICANN Registrar Accreditation Agreement (RAA) mandates that registrars maintain 24/7 monitoring for malicious activity, investigate abuse reports, and take immediate action. The 2024 amendments to the policy, part of the DNS Abuse Mitigation Program, further strengthen these obligations to actively combat malware and phishing threats.

Comment Which is more insecure - obsolete or modern (Score 1) 98

Critical vulnerabilities in July’s Patch Tuesday
There are many critical vulnerabilities, so we’ll highlight only the most urgent ones. In our list, the CVSS score never drops below 9.6.
CVE-2026-57092 (CVSS 9.9) — EoP in VMSwitch, allows escape from an isolated environment with full host compromise. A use-after-free vulnerability that allows a low-privileged attacker to cross the virtual machine boundary and gain access to the host. ZDI notes that a similar exploit was demonstrated at Pwn2Own Berlin on ESXi. Hyper-V users need to update VMSwitch today.
CVE-2026-56190 (CVSS 9.8) — RCE in RDP, unauthenticated, network-based, no user interaction required. Those with RDP servers accessible via the internet are at critical risk; such configurations are practically unsustainable in 2026.
CVE-2026-50518 (CVSS 9.8) — RCE in the DHCP server: heap overflow, unauthenticated, network-based. And this isn’t the only problem with the DHCP server. In this release, it also contains CVE-2026-50370, -56159, and -48564, while the DHCP client contains CVE-2026-54128.
CVE-2026-50522 and CVE-2026-58644 (both CVSS 9.8) — a pair of RCE vulnerabilities in SharePoint servers: deserialization of untrusted data, unauthenticated, and without user interaction. Although Microsoft describes the exploit’s reliability as “unproven”, this is, to put it mildly, untrue. For CVE-2026-50522, a working exploit was demonstrated at Pwn2Own Berlin. In the same group is CVE-2026-55040 (CVSS 9.1), an authentication bypass discovered by Rapid7 experts. Exploiting this vulnerability is the first link in the attack chain; the second is currently under embargo and will be disclosed (and patched) in August Patch Tuesday. Together, they enable RCE without authentication. Meanwhile, the July Patch Tuesday marks the end of support for SharePoint Server 2016 and 2019.
CVE-2026-56188 (CVSS 9.8) — RCE in the Windows Server network driver. The exploitation is highly complex (TOCTOU), but if successful, this vulnerability allows privileged code to be executed over the network without user interaction — in other words, it enables the creation of network worms.
CVE-2026-55008 (CVSS 9.6) — spoofing in Exchange Server (it’s unclear why this is called spoofing, as the description explicitly states “XSS”). An attacker sends a specially crafted email; the victim simply opens it in OWA — and arbitrary JavaScript is executed in their session.
Seems like malware devs know more about undocumented windows kernel features than the few folk remaining working in Microsoft yet. So using a modern OS - you still get a ton of vulns.
Using an obsolete one - threat actor may simply say "Poor guy still on windows 10" and move on to targets of higher interest - e.g. crypto bros or VCs who also use the same computer to steam play games and sign SAFE transactions on.

Submission + - SpaceXAI and Starlink X Accounts Hacked, Abused to Promote scams (spamreports.report)

D,Petkow writes: Another day, another twitter/X scam, but this time involving the official gold-verified accounts of both SPACEX and STARLINK, and another gold-verified account, which is now suspended.

An account called "Sam Catman" somehow obtained an official SpaceXAI-affiliated *gold* badge and posted promotion for a new meme coin on Robinhood Chain.
Shortly afterward, the verified @SpaceXAI and Starlink accounts reposted it, giving the scam instant credibility to millions of followers.
The token pumped hard before the expected rug pull. The original posts have since been deleted.
As of now, there has been zero official acknowledgment or statement from SpaceXAI, Starlink, or Elon Musk about how a high-profile corporate account cluster was compromised so easily — or how the "official affiliate" badge system was abused.

Full story

As a result more than 120 000 USD have been stolen and laundered (so far), how convenient.
Classic reminder that even the biggest names in tech can get owned by a cartoon cat shilling a concurrency "memecoin". The gold badge was apparently worth its weight in rug residue.

The lack of transparency also says plenty, as if never of this ever happened.

Submission + - Cloudflare, Netlify and Vercel with new toys for phishers and threat actors (cloudflare.com)

D,Petkow writes: Web Bros’ Latest Genius Move: Drop a Zip, Ship Malware

Cloudflare, Vercel, and Netlify have all launched their own “Drop” services: upload a zip, get a live site instantly on their edge networks.
Authentication and abuse protection? That’s for later. Right now it’s pure vibes.

This is peak industry brain rot. In a world already drowning in phishing, malware, and scam sites, these platforms just rolled out the easiest, fastest way for bad actors to host malicious content.
Drag-and-drop phishing kits on workers.dev, instant fake login pages on Vercel, malware droppers on Netlify — all live in seconds with zero friction.

No real verification. No serious upfront checks. Just “move fast and let the internet clean up our mess."
The hopium these web bros are smoking must be nuclear grade quality. They’ve spent years building trust in their platforms, only to turn them into free malware CDNs for anyone with a zip file.This isn’t democratizing the web.
This is handing phishers and scammers the keys with a smile.
Brilliant strategy, truly.

Nota bene — apparently real world bad actors beat red teams in abusing those new "services".

Slow clap

Apparently all the web bros are drinking the same hopium-flavored cool aid, where no phishers, c2s, implants and bad actors exist whatsoever.
https://cloudflare.com/drop/
Same concept from vercel and netlify
https://vercel.com/drop
https://app.netlify.com/drop

https://x.com/JCyberSec_/statu...

Try a DAP.LIVE or URLSCAN.IO query to see abuse and workers.dev (and pages.dev and r2.dev for that matter) — for each valid deployment, there are hundreds of confirmed fraud scams.
Nice statistics, which will only get worse now.
Good job.

Comment Macho Hamacho - the Great President (Score 5, Informative) 127

Some of macho Hamacho s achievements so far, most of which are borderline legal at best. It is a big club, but you ain’t in it:
Jan. 20, 2025 – Withdrew the U.S. from the Paris Climate Agreement (again). Criticism: Undermines U.S. climate leadership and slows emissions reductions.
2025 – Large-scale federal workforce reductions and agency restructuring. Criticism: Reduced expertise and capacity in public health, science, and environmental enforcement.
July 2025 – Exempted more than 100 industrial facilities from certain pollution-control requirements. Criticism: Could increase exposure to carcinogens and toxic pollutants for nearby communities.
Feb. 5, 2026 – EPA enforcement against polluters fell to a record low. Criticism: Environmental groups argue it weakens accountability and encourages noncompliance.
Feb. 18, 2026 – Administration moved to revoke the legal basis for major U.S. climate regulations. Criticism: Seen as an attempt to dismantle decades of environmental protections.
March 2026 – Executive actions and policy shifts favoring continued glyphosate use and limiting some pesticide liability. Criticism: Public-health advocates argue they prioritize chemical manufacturers over health concerns.
May 19, 2026 – EPA proposed rolling back drinking-water limits for several PFAS ("forever chemicals"). Criticism: Critics say it exposes millions to higher levels of persistent toxic chemicals.
May 2026 – IRS settlement reportedly shielding many of Trump's, his family's, and affiliated businesses' pre-settlement tax returns from future audits. Criticism: Tax experts called it unprecedented and argued it creates unequal treatment under tax law. (Reuters/AP reporting.)
June 2026 – Continued approvals and support for certain PFAS-related pesticide uses. Criticism: Environmental groups argue this increases long-term contamination risks despite health concerns.
July 8, 2026 – FDA rejected a petition to set enforceable PFAS limits in food. Criticism: Public-health advocates argue the decision leaves consumers inadequately protected from "forever chemicals."
This list says plenty alone.

Comment Pump Fun stories of crazy wins - all repeated (Score 2) 34

Just 0.1% of accounts on Polymarket take home 67% of the profits - this says plenty on its own.
It is genuinely laughable to see the exact same playbook being recycled for Polymarket that we saw with Pump.fun and GMGN.ai just a few months ago. The industry’s creative well is clearly dry, so they’ve returned to the most bottom-tier marketing tactic imaginable: the "Hey, printing money is easy—why are you still poor?" bait.
Just like with those previous "ecosystems," they are flooding social media with a barrage of manufactured, fake win posts to create a frantic sense of FOMO. It’s the same sleazy script: use paid puppets to LARP as financial geniuses on fake dashboards, all to lure in fresh exit liquidity that will inevitably be dumped on. They aren't building platforms; they are running standardized scams that rely on the same tired, predatory tropes to trick people into funding someone else’s exit.
At this point, if you see a post promising "easy money" on a new "prediction" or "memecoin" platform, you aren't looking at an opportunity—you’re looking at a repeat performance of the same trashy hustle.

The same applies to Polymarket, Kalshi and Opinion trade. All of which are gambling websites, pretending to be "prediction markets", which they are not.

It’s truly impressive watching these "prediction markets" work overtime to rebrand degenerate gambling as high-level financial strategy. As exposed in a reddit thread by WSJ, 0.1% of accounts are vacuuming up 67% of the profits, proving that the only thing being "predicted" here is how quickly the house can drain your wallet.

Comment Background fetch. Such a "useful" concept (Score 3, Insightful) 52

ah yes. Background fetch. Such a "useful" concept ps1 Nuke New-Item -Path 'HKLM:\Software\Policies\Google' -Name 'Chrome' -Force | Out-Null; New-ItemProperty -Path 'HKLM:\Software\Policies\Google\Chrome' -Name 'BackgroundModeEnabled' -PropertyType DWord -Value 0 -Force | Out-Null; New-Item -Path 'HKLM:\Software\Policies\Microsoft' -Name 'Edge' -Force | Out-Null; New-ItemProperty -Path 'HKLM:\Software\Policies\Microsoft\Edge' -Name 'BackgroundModeEnabled' -PropertyType DWord -Value 0 -Force | Out-Null uBlock ||*/service-worker.js$script,important ||*/sw.js$script,important Chrome/Edge Ctrl+Shift+I Network tab any request Override headers. Permissions-Policy: background-fetch=() Chrome chrome://settings/?search=background Continue running background apps when Google Chrome is closed - toggle to OFF Edge edge://settings/?search=continue

Comment misleading sensationalism article bait headline (Score 1) 132

From https://www.revisor.mn.gov/bil...
Prediction markets; hosting prohibited.
A person is guilty of a felony if the person, for consideration and as part of a business:
(1) creates a prediction market;
(2) operates, manages, or controls a platform or system intending that consumers will use the platform or system to make wagers in a prediction market; (3) intentionally facilitates the operation of a prediction market by:
(i) identifying or listing events knowing the events will be used by consumers to make
(ii) accepting, holding, or directing the disposition of money or other things of value for
(iii) determining, administering, or enforcing the terms, pricing, or settlement of wagers
made by consumers;

So does that imply that some folks recently featured in Forbes 30 under 30 are now felons? Interesting what do the "concerned legalizations" think about the about the so called "meme coins" MELANIA and TRUMP and WLFI.
I guess 3.6B embezzlement from cryptobros is fine, but ONLY if you are the POTUS haha.

Submission + - The risks of "Official" app stores hosting fraudulent cryptocurrency wallet apps (x.com)

An anonymous reader writes: If you still trust the 'rigorous manual reviews' of official app stores with your crypto, it's time to wake up.
Three years after Microsoft's store let a fake Ledger app by a developer literally named 'OFFICIAL DEV' siphon 16.8 BTC (~$588K at that time), Apple's notoriously locked-down ecosystem has suffered a similar catastrophic failure. This month, a user lost 5.9 BTC (~$417K at that time)—their entire retirement fund—to a malicious Ledger app that slipped past Apple's gatekeepers.

The vector? A basic homoglyph attack. Scammers simply swapped the 'e' in 'ledger-live' for a Cyrillic '' (URL-encoded as %D0%B5). While it looks identical to the human eye, it is baffling that a multi-trillion-dollar company's security screening missed such a well-known exploit. The harsh reality is that app store reviews seemingly prioritize protecting their 30% payment cut over catching phishing tactics.
Do not search for high-stakes software like crypto wallets in the app store(s).

Always navigate directly to the vendor's verified website (e.g., ledger . com) and click their official store link.
Don't let corporate automated screening failures cost you your life savings.

2023 Microsoft Store incident
https://x.com/zachxbt/status/1...

2026 Apple Mac store (not iOS)
https://x.com/glove/status/204...

Submission + - Singapore scammers get the canning treatment (mha.gov.sg) 1

D,Petkow writes: Singapore is often hailed as one of the world’s most ultra-modern hubs — a place of gleaming skyscrapers, cutting-edge fintech, and futuristic urban planning. Yet, beneath the polished surface, the city-state still enforces some of the strictest old-school punishments imaginable.

In a move that stunned many outside observers, Parliament recently passed a law mandating at least six strokes of the cane for scammers and money mules. With scams making up nearly 60% of reported crimes and billions lost since 2020, the government argues that harsh deterrence is necessary.

It’s a striking contrast: a nation leading in smart cities and AI governance, while simultaneously wielding rattan canes against fraudsters. This duality — hyper-modern yet deeply traditional — is part of what makes Singapore fascinating, and sometimes bewildering, to the rest of the world.

https://says.com/my/news/singa...
http://metro.co.uk/2025/11/08/...

Comment The person who did it is going down (Score 1) 55

The Finnish IT cyber security community has put a bounty on this threat actor's head. They are going down.

No matter how many crypto "tumbling" or "shape-shifting" services the threat actor is planning to use, in the moment they convert the crypto to FIAT they will get caught, even if they try to use a p2p market.

The internet is not the wild west and this sub-human garbage will soon learn it the hard way.

Slashdot Top Deals

Take care of the luxuries and the necessities will take care of themselves. -- Lazarus Long

Working...