

Operations Security (OPSEC)
-
[NEWS] PlushDaemon APT Targets South Korean VPN Provider in Supply Chain Attack
thehackernews.com PlushDaemon APT Targets South Korean VPN Provider in Supply Chain AttackPlushDaemon APT targets South Korean VPN with SlowStepper backdoor. Multistage DNS C&C protocol aids espionage.
-
[NEWS] Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platforms
gist.github.com Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platformUnique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform - research.md
-
[ARTICLE] Europol chief calls on tech giants to unlock encrypted messages
www.belganewsagency.eu Europol chief calls on tech giants to unlock encrypted messagesThe chief of Europol chief has urged technology companies to cooperate with law enforcement in unlocking encrypted messages. A failure to do so...
> The Europol chief said that in a digital environment, the police needed to be able to decode these messages to fight crime. “You will not be able to enforce democracy without it,” she added.
>"Anonymity is not a fundamental right,” she told the Financial Times.
-
[NEWS] PSA: RUN YOUR OWN MONERO NODE
YouTube Video
Click to view this content.
A leaked video from Chainalysis has shown they have delivered on the IRS's $1.25 million contract to trace Monero.
The good news is that their tracking heavily relies on you connecting to a compromised node.
The (debatably) bad news is that you need to run your own node to ensure privacy.
Review the linked video from Mental Outlaw (I love that guy) for more information.
-
BusKill (Dead Man Switch) Warrant Canary for 2025 H1
buskill.in BusKill Canary #9 - BusKillThis post contains the cryptographically-signed BusKill warrant canary #007 for January 2025 to June 2025.
This post contains a canary message that's cryptographically signed by the official BusKill PGP release key
| [!BusKill Canary #009](https://www.buskill.in/canary-009/) | |:--:| | The BusKill project just published their Warrant Canary #009 |
For more information about BusKill canaries, see:
- <https://buskill.in/canary>
``` -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512
Status: All good Release: 2025-01-14 Period: 2025-01-01 to 2025-06-01 Expiry: 2025-06-30
Statements ==========
The BusKill Team who have digitally signed this file [1] state the following:
-
The date of issue of this canary is January 14, 2025.
-
The current BusKill Signing Key (2020.07) is
E0AF FF57 DC00 FBE0 5635 8761 4AE2 1E19 36CE 786A
-
We positively confirm, to the best of our knowledge, that the integrity of our systems are sound: all our infrastructure is in our control, we have not been compromised or suffered a data breach, we have not disclosed any private keys, we have not introduced any backdoors, and we have not been forced to modify our system to allow access or information leakage to a third party in any way.
-
We plan to publish the next of these canary statements before the Expiry date listed above. Special note should be taken if no new canary is published by that time or if the list of statements changes without plausible explanation.
Special announcements =====================
None.
Disclaimers and notes =====================
This canary scheme is not infallible. Although signing the declaration makes it very difficult for a third party to produce arbitrary declarations, it does not prevent them from using force or other means, like blackmail or compromising the signers' laptops, to coerce us to produce false declarations.
The news feeds quoted below (Proof of freshness) serves to demonstrate that this canary could not have been created prior to the date stated. It shows that a series of canaries was not created in advance.
This declaration is merely a best effort and is provided without any guarantee or warranty. It is not legally binding in any way to anybody. None of the signers should be ever held legally responsible for any of the statements made here.
Proof of freshness ==================
14 Jan 25 01:01:33 UTC
Source: DER SPIEGEL - International (https://www.spiegel.de/international/index.rss) A Miracle? Pope Francis Helps Transsexual Prostitutes in Rome Boost for the Right Wing: Why Did a German Newspaper Help Elon Musk Interfere in German Politics?
Source: NYT > World News (https://rss.nytimes.com/services/xml/rss/nyt/World.xml) What an Upended Mideast Means for Trump and U.S. Gulf Allies Russia and Ukraine Battle Inside Kursk, With Waves of Tanks, Drones and North Koreans
Source: BBC News - World (https://feeds.bbci.co.uk/news/world/rss.xml) Gaza ceasefire deal being finalised, Palestinian official tells BBC Watch: Moment man is saved from burning LA home
Source: Bitcoin Blockchain (https://blockchain.info/q/latesthash) 0000000000000000000042db9e17f012dcd01f3425aa403e29c28c0dc1d16470
Footnotes =========
[1] https://docs.buskill.in/buskill-app/en/stable/security/pgpkeys.html
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEeY3BEB897EKK3hJNaLi8sMUCOQUFAmeFuPcACgkQaLi8sMUC OQXctQ//Zv7RZXPKMMyjMjfE2LjrL6RVESIZMT2tUO/y0wx8XTXKBpgOA7fTh2eC BHkLajpU/S3LOb+wBniuo29tpGJHG5MBWDwyNUAWXqZfJ/A9YNikNYq9lOn6nKSH oHyLB8h2nP9rfQ2wXUtN6lFJVKWU5Ef5pjMQb8flJO2kbou7QpgcOzxvRqrXOUcN UumjSlDTtwIOYOX+Ee8SamI4LyApOlwxIGMbFcbRMcJNhtioS4qCGNGw1pqhvqmF pi1kIaqd79I8y1U9ufncvC+pbCEvRdo+wb7ZsXA9ZYpYfJSQJzSkdCGgkbe0b1Tx 6CNlcgoXIVaEH6/W+C2DFlyG1u4JuH22eXIrloYnjOxlqSJCd0Dw1EeO33tg3xg3 tfeO9pGOcZPOwlBL509VlE9z6W3czyKJk7Z4RwYXCFYWWi8vlHvRQg0LNu0C4Jyw fRV2LlMSeUgBz9xyE62jh/BUNZzXsD0ntprR1eRTkeW4kOGEc6Wql4lBKE08sajT YdgTi4ojrcfTdS7Sgzh1Onh5h/nF7hoyCX0lINgyTrJFMynC6qadTZtiJ2yO8GT+ Ovk9ZJMggBMNr4Vbw6CyrU/4yYMyrEd5dzXYZLZ41lMMpjwM8OBJ/yp1pcGo9vk4 NTAjUQUvOj6nrA/r3j2ywFMDZtFR/jBjXULWE77ca3iJmc/FUdg= =xahN -----END PGP SIGNATURE----- ```
To view all past canaries, see:
- <https://www.buskill.in/category/Canary/>
What is BusKill?
BusKill is a laptop kill-cord. It's a USB cable with a magnetic breakaway that you attach to your body and connect to your computer.
| [!What is BusKill? (Explainer Video)](https://www.buskill.in/#demo) | |:--:| | Watch the BusKill Explainer Video for more info youtube.com/v/qPwyoD_cQR4 |
If the connection between you to your computer is severed, then your device will lock, shutdown, or shred its encryption keys -- thus keeping your encrypted data safe from thieves that steal your device.
-
[MEME] While it can be a hassle, reducing your attack surface is always recommended
Even though Bluetooth is designed to be secure, vulnerabilities can sneak in. We saw an example of that with the Flipper Zero being able to spam Apple devices, and while that was relatively harmless, that doesn't mean the next vulnerability will be.
-
[META] Copypastas are now allowed
Well, you guys won. Copypastas are now allowed as comments if they are related to the post or parent comment. However, they still can't be posts.
Rule 3 has been updated.
As much as I would not prefer this, we are a community and not a monarchy.
-
Good resources to monitor cybersecurity?
One site I've been following for awhile is https://notifycyber.com/
...but I'd love some more. What are your must-haves?