CyberMedics

98 posts

CyberMedics banner
CyberMedics

CyberMedics

@CyberMedicsOrg

Tracking the Heartbeat of technology- Vitalizing & Defending Your Digital Life!

Katılım Şubat 2016
120 Takip Edilen36 Takipçiler
k9io
k9io@key9identity·
We are proud to be FIDO Alliance "Passkey Pledge" signers. Unlike legacy Identity Providers, we are "all in" on #Passkeys and #Passwordless technologies. Our mission is to drive adoption, make companies secure, and make Identity easy. fidoalliance.org/passkeypledge/
English
1
2
3
65
CyberMedics
CyberMedics@CyberMedicsOrg·
@vtslkshk In general, never click on an email link. Especially from an unknown source. Remove SMS second factor from your accounts, were possible at hardware security keys for account authentication.
CyberMedics tweet media
English
0
0
0
1
Vatsal
Vatsal@vtslkshk·
🚨X phishing alert: just got a legit looking email saying that there was a suspicious log in to my account. I have TOTP 2FA enabled but still decided to change my password and clicked on the link. Turns out it takes you to a third-party app "X Support Department" seeking access to your account. A clear scam/phishing attempt. NEVER authorize any such app ever and always double-check the FROM email ID before taking any action. @nikitabier @elonmusk
Vatsal tweet mediaVatsal tweet media
English
1
1
4
2.2K
CyberMedics
CyberMedics@CyberMedicsOrg·
@scredcpt @TeamYouTube What 2 FA was on your account security? You may want to review all of your account to make sure you have a strong second factor authentication other than SMS messaging. It is the least secure method for securing account access.
English
0
0
0
12
Scred
Scred@scredcpt·
@TeamYouTube My YouTube channel got hacked. The hacker managed to remove my 2FA, recovery mail and phone number, they even added a physicall key of their own. I lost years of work and dedication on the platform, I had +11k subs.
English
9
0
2
232
Dr. Steve Keen
Dr. Steve Keen@ProfSteveKeen·
. @Google my debunking account now appears compromised. The password was changed yesterday--and not by me--and ow I'm getting "verify" messages from you that I expect are the scammer trying to crack my security. What can I do?
Dr. Steve Keen tweet media
English
5
2
15
3.4K
CyberMedics
CyberMedics@CyberMedicsOrg·
@ProfSteveKeen @Google Reset the password. Regenerate backup codes. Add an authentication app independent of Google. Remove SMS 2 FA. Add two Hardware security keys.
English
0
0
0
9
CyberMedics
CyberMedics@CyberMedicsOrg·
@imfastasfsckboi Spot on! Financial institutions in general…security is minimal. SMS F-
English
0
0
1
4
Lee 🇺🇸
Lee 🇺🇸@imfastasfsckboi·
Dear financial companies, If you're using SMS to authenticate my account in any way, you don't have the security moral high ground to send me lecture-spam about fraud tactics scammers might use. Get your shit together. XOXO HTH
English
1
0
3
57
CyberMedics
CyberMedics@CyberMedicsOrg·
@morrisfrance @Meta @facebook Would you mind sharing what type of second factor authentication you had on the account? We’ve been trying to help protect people from this exact sort of thing of losing account access.
English
0
0
0
4
Anton Stetner
Anton Stetner@AntonStetner·
Urgent Request: Account Recovery and Review of Meta Verification Failure @Meta @facebook @instagram. As a Meta Verified user with two-factor authentication (2FA) enabled, I expect a high standard of security and support, especially as someone who runs a business and creates content on your platforms. Unfortunately, your system has failed me on both fronts. Despite having 2FA in place, a third party was able to access my accounts without my authorization. I even actively denied the 2FA prompt, yet access was still granted. The result? My accounts were compromised, spam content was posted, and the accounts were ultimately disabled. To make matters worse: No meaningful communication has been provided to help resolve this situation. Support channels are nearly impossible to access, despite my verified status. Now, your system is introducing new hurdles—such as requiring an authenticator app for Facebook login, even though it was only ever enabled on Instagram. This inconsistency is further complicating recovery efforts. This is not just a security oversight; it is a systemic failure; one that puts creators and business owners at risk. We rely on your platforms to engage audiences, run ads, and generate income. The inability to restore service promptly and communicate clearly is unacceptable. Please escalate this issue immediately and take action to: 1. Review the 2FA breach and authentication logs. 2. Reinstate the affected accounts. 3. Provide direct support and communication to resolve any remaining recovery issues. Meta must do better. Verified users deserve systems that work and support that responds.
Mount Vernon, WA 🇺🇸 English
45
2
3
2K
CyberMedics
CyberMedics@CyberMedicsOrg·
@AntonStetner @Meta @facebook @instagram Have you secured your email with a strong second factor authentication like authentication app or HW security key? Would remove text notifications from all second factor authentication. It is the least secure method for validating account authentication.
English
1
0
1
27
BleepingComputer
BleepingComputer@BleepinComputer·
A new "EUCLEAK" attack on FIDO devices, such as the YubiKey 5, can extract secret keys and clone the FIDO device. However, the attacks require physical access to the device and specialized equipment, mitigating the risk for the majority of users. bleepingcomputer.com/news/security/…
English
1
21
59
8.4K
The Hacker News
The Hacker News@TheHackersNews·
Titan Security Keys — Google launches its own USB-based FIDO U2F physical security keys. thehackernews.com/2018/07/google… It includes a firmware developed by Google that verifies the integrity of security keys at the hardware level for stronger two-factor authentications.
The Hacker News tweet media
English
7
136
178
0
KeePassXC
KeePassXC@KeePassXC·
We loved your article on Password Manager extension clickjacking attacks. We would love it if you evaluated KeePassXC as well and included it as an addendum to your blog. @marektoth marektoth.com/blog/dom-based…
English
4
24
280
18.5K
Vittorio
Vittorio@vibronet·
Tricky things about #passkeys: even identity experts don't always have a clear idea of what the term indicates. I find myself having to explain it all the time, so I put together a visual to help me do that. 🧵 If you consider the space of all @FIDOAlliance credentials:
Vittorio tweet media
English
6
13
52
7.6K