Microsoft’s Windows Hello fingerprint authentication has been bypassed (www.theverge.com)
Windows laptop manufacturers will likely need to fix this one.

Windows laptop manufacturers will likely need to fix this one.
Hello /m/cybersecurity folks! Wanted to get a pulse check on those who use this particular community. I mod both here at Fedia as well as at infosec.pub for /cybersecurity. I run a few weekly threads (e.g. Mentorship Monday) at infosec.pub and have tried to run those same weekly threads here but they get barely any traction,...
Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.
Weekly thread to discuss industry certifications, trainings and other courses/learning. Ask questions, share your experiences and help others!
Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!
A new login technique is becoming available in 2023: the passkey. The passkey promises to solve phishing and prevent password reuse. But lots of smart and security-oriented folks are confused about what exactly a passkey is. There’s a good reason for that. A passkey is in some sense one of two (or three) different things,...
Threat actors are doubling down on brand impersonation by using lookalike domain names.
Passphrases are a great way to protect your online accounts and digital identity. But what is a passphrase?
Daniel Huigens, the head of Proton’s cryptography team, explains how the latest crypto refresh makes PGP more secure.
Fortinet patches a critical-severity vulnerability in FortiOS and FortiProxy that could lead to remote code execution.
Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.
Hey everyone! My name is Mike and I write about #infosec, #tech and other things at https://shellsharks.com. I'm currently running an event this week I refer to as >Shark Week (https://shellsharks.com/sharkweek), which is essentially just me posting some sort of "content" each day for the entire week, coinciding with actual...
Weekly thread to discuss industry certifications, trainings and other courses/learning. Ask questions, share your experiences and help others!
(article linked from m/Android)
Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.
Hey Fedia-folk of /m/cybersecurity! Wanted to get a quick pulse-check and collect some thoughts from the community here regarding their usage both current and future. I'll...
Couldn't find a poll option so I guess people can just weigh in on their thoughts here. I've been a "CISSP-holder" since 2015/2016-ish and have always had the renewal fees paid for by my employer. My renewal date has come and unfortunately I don't think I'll be getting any employer assistance paying the fee this time around. Is...
Great series on container security from Datadog.
The hackers responsible for exploiting a flaw to target users of a popular file transfer tool has begun listing victims of the mass-attacks
Where are my VM folks at? CVSS v4.0! Some takeaways reading the brief change list......
US agencies have 14 days to comply.
As someone who has spent A LOT of time getting certifications, this is a question I ask myself a lot. In the past, I was all about them, in some part because I had the time and resources to do them and less so because I thought they were the key to big career or knowledge gains. These days, I recommend to newer folks in the...