itquartz

287 posts

itquartz banner
itquartz

itquartz

@itquartz

#Cybersecurity | #ThreatIntelligence | #PurpleTeam | #SOC

France Katılım Temmuz 2017
902 Takip Edilen69 Takipçiler
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Anyone else seeing Microsoft #Defender flagging #DigiCert root certificate registry keys as malware? We’ve seen reports that Defender signature update from April 30 added a detection called: Trojan:Win32/Cerdigent.A!dha In some environments, Defender apparently detected DigiCert Root CA certificate registry entries and removed them from the trust store. The affected cert hashes mentioned so far: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 DDFB16CD4931C973A2037D3FC83A4D7D775D05E4 Example path: HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 There’s also a Reddit comment suggesting Microsoft has started restoring the certs and that admins can check this via Advanced Hunting in Defender: DeviceRegistryEvents | where RegistryKey contains "0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43" or RegistryKey contains "DDFB16CD4931C973A2037D3FC83A4D7D775D05E4" | where ActionType == "RegistryKeyCreated" | where Timestamp > datetime(2026-05-03T04:00:00) | project Timestamp, DeviceName, ActionType, InitiatingProcessFileName | order by Timestamp desc On an affected device, this can also be checked with: certutil -store AuthRoot | findstr -i "digicert" Could become an annoying day for admins if this spreads reddit.com/r/cybersecurit…
English
27
84
399
196.5K
itquartz
itquartz@itquartz·
@McGrewSecurity emergency for what ? What are the consequences of abolishing these certificates?
English
1
0
0
274
Dr. Wesley McGrew
Dr. Wesley McGrew@McGrewSecurity·
Re: Cerdigent, this also just flagged on a fresh ARM Windows VM I installed weeks ago, so it’s not indicative of an active attack in your environment if you’re seeing it as well. It is likely some kind of emergency “somewhere” as the normal thing to do would be to revoke and remove these certs through windows update.
kleos@dcchaser3

@McGrewSecurity It's just flagging these Root Digicerts for some reason and labeling it as Cerdigent Affected items: rootcert: 0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 rootcert: DDFB16CD4931C973A2037D3FC83A4D7D775D05E4

English
2
0
12
3.3K
itquartz
itquartz@itquartz·
@issouexe @_SaxX_ Je pense que vous n'avez pas lu mon message. Il n'y a pas le mot "bug" dedans. Vous avez fais des raccourcis comme si vous connaissiez tout.
Français
1
0
0
113
Mathias🇫🇷🇷🇴
Mathias🇫🇷🇷🇴@issouexe·
@itquartz @_SaxX_ Tu sais pas lire ou t'as juste pas lu ? C'est pas un bug, c'est un défaut de design. Donc tu peux faire ce que tu veux, ça va pas régler le souci qui est fondamental
Français
2
1
4
218
SaxX ¯\_(ツ)_/¯
SaxX ¯\_(ツ)_/¯@_SaxX_·
🚨🔴 Ça vire au pugilat cette histoire de Pass Numérique piraté avant même sa sortie ! 🤯😬 La vérification d'âge est compromise certainement pour le 1er septembre 2026... Paul Moore, expert en cybersecurité, a dans sa lancée créée une extension pour Chrome qui dit que vous avez la majorité numérique, contourne la vérification d'âge et donne accès au réseau social... Je sens que ça va bcp faire couler d'encre encore !
Paul Moore - Security Consultant @Paul_Reviews

Bypassing #EU #AgeVerification using their own infrastructure. I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly. Step 1: Install the extension Step 2: Register an identity (just once) Step 3: Continue using the web as normal The extension detects the QR code, generates a cryptographically identical payload and tells the verifier I'm over 18, which it "fully trusts". This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring. Of course, I could skip the enrolment process entirely and hard-code the credentials into the extension... and the verifier would never know.

Français
31
665
1.7K
113.3K
itquartz
itquartz@itquartz·
@UK_Daniel_Card We had needs at my company like alternative to ilovepdf. So I vibe coded a full offline alternative to iLovePDF. €20 + 2 days with Claude Code → full PDF toolkit, no data leaving the machine. People can stay mad, we’re just shipping. github.com/LeDevK/pdf-fus…
English
0
0
2
178
mRr3b00t
mRr3b00t@UK_Daniel_Card·
some people are mad at me because I intentionally vibe coded something and said I vibe coded it and they are butt hurt because their world self image is being destroyed because of LLMs...... which is insane.... also LOL. vibe coding is so fun :D
English
33
2
113
3.8K
itquartz
itquartz@itquartz·
April 1st, when a full year of corporate “creativity” finally peaks. Nothing like watching brands burn months of meetings and obscene budgets just to drop the least funny joke you’ve ever seen… with full executive approval.
English
0
0
0
21
itquartz
itquartz@itquartz·
@IntCyberDigest Google drops a “6x less RAM needed” breakthrough right when memory prices spike. I’m sure it’s 100% about innovation and 0% about timing. 👀
English
0
0
8
2.9K
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️ Google just tanked RAM and NAND stocks solving the memory shortage crisis by introducing an algorithm that requires 6x less DRAM and runs 8x faster, with zero accuracy loss. They call it TurboQuant. Hardware prices are expected to drop even further now.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
153
638
9.3K
537.6K
itquartz
itquartz@itquartz·
@kaspersky Which LLM do you use? I look forward to your reply.
English
0
0
0
9
Kaspersky
Kaspersky@kaspersky·
AI in cybersecurity should make life of your skilled security experts easier. Security professionals capable of operating complex tools are hard to find, and even harder to replace. Their time should be spent on advanced investigations, not repetitive tasks. With Kaspersky Next Expert, AI handles the routine work, reducing cognitive load and accelerating detection and investigation.* KIRA is here to support your SOC. >> kas.pr/my3h #KasperskyNextExpert #AI #SOC #ThreatDetection #CyberSecurity *To access this feature, an additional license and integration with an LLM provider is needed
Kaspersky tweet mediaKaspersky tweet mediaKaspersky tweet mediaKaspersky tweet media
English
1
1
9
955
itquartz
itquartz@itquartz·
@0x0SojalSec How do you interact with it for chart analysis or code debugging? Do you use Open WebUI?
English
0
0
0
331
Md Ismail Šojal 🕷️
Md Ismail Šojal 🕷️@0x0SojalSec·
Qwen 3.5 9b Runs on 8GB RAM. Less than Chrome 256K token context, frontier-level reasoning, Native OCR + multimodal, chain-of-thought, image understanding, and multilingual support across 100+ languages, Beats many 70B+120B models in reasoning.
Md Ismail Šojal 🕷️ tweet media
English
18
22
241
15.1K
itquartz
itquartz@itquartz·
@Frandroid Vous faites bouillir de l'eau à 50° ?
Français
2
0
6
252
itquartz
itquartz@itquartz·
@Fabien_qKwad Mec, c'est quoi la marque des pinces à linge !?
Français
0
0
54
1.7K
Fabien
Fabien@Fabien_qKwad·
Cyclone le plus dévastateur de ma vie… #Garance
Français
57
102
613
1.3M
itquartz
itquartz@itquartz·
@_SaxX_ Pourquoi lier désinformation et IA ? La désinformation existait bien avant l'existence de l'IA. L'IA rend certaines choses bien plus facile/accessible, il est vrai, mais elle ne les à pas inventés pour autant.
Français
0
0
0
148
SaxX ¯\_(ツ)_/¯
SaxX ¯\_(ツ)_/¯@_SaxX_·
On ne parle pas assez de la facilité monstre d'utilisation de l'intelligence artificielle pour le côté désinformation en Afrique... Ces dernières semaines je suis à la fois tellement surpris mais aussi apeuré de voir que sur de nombreuses pages, sur fb et tiktok, sont partagés des images et vidéos totalement générées par l'IA, et que les populations africaines prennent pour argent comptant ! Les prochaines élections présidentielles sur le continent sans compter les grands événements sportifs risquent d'être très compliqués ! En attendant rien côté gouvernements africains pour anticiper ces campagnes de désinformation... pire encore aucune éducation à détecter les fausses images/vidéos pour les populations... Ça va être folklo ! Lors de mes prochaines conférences et prises de parole en Afrique, l'accent sera mis là-dessus !
SaxX ¯\_(ツ)_/¯ tweet media
Français
6
9
33
6.5K
itquartz
itquartz@itquartz·
@ValeryMarchive @hopitaldecannes Bonjour, je n'ai pas saisi l'objectif du thread. Pointez-vous du doigt la communication du CH ? Que cherchez-vous à mettre en évidence ? Qu'elle aurait été la version parfaite de l'histoire si tant est qu'il en existe une ? Vraies questions par de sarcasmes ici.
Français
1
0
0
36
itquartz retweetledi
Hervé Schauer
Hervé Schauer@Herve_Schauer·
Je souhaite sincèrement et sympathiquement bienvenue 🙂aux milliers des personnes qui chaque jour, en 🇫🇷, rejoignent la cybersécurité. 🙏🏻 de rejoindre un secteur éclatant 😉. Cependant, ayez l'humilité de penser à apprendre la cybersécurité avant de faire des conférences 😱
Neuilly-sur-Seine, France 🇫🇷 Français
5
22
130
19.9K
itquartz
itquartz@itquartz·
Hey @vxunderground Do you plan to make your vx-underground Collection HDD available again? And when? Thank you guys !
English
0
0
0
60
itquartz
itquartz@itquartz·
@SOSIntel It's pure coincidence, I'm learning logical fallacies, cognitive biases and analysis of competing hypotheses right now. Very interesting, more information on this case?
English
1
0
0
32
SOS Intelligence
SOS Intelligence@SOSIntel·
A horrific and tragic story, but this can serve as a good example of ACH (analysis of competing hypothesis) with a mix of temporal analysis to remove bias from Intelligence investigations.
SOS Intelligence tweet media
English
3
1
12
2.9K