Sign in

CyberSecSac & DC916

@cybersec916.com
144 followers 292 following 229 posts

Official Bluesky for Cybersecurity Sacramento & www.dc916.com a DEF CON Group Belonging is the very best thing there is. #hackthebeam

PostsRepliesMedia
CyberSecSac & DC916 @cybersec916.com · 09/10/2025
Learning about lockpicking this month thanks to our member Artefact doing a presentation on @deviantollam.bsky.social ‘s work! 🥰🙌🔒🔐
030
CyberSecSac & DC916 @cybersec916.com · 02/10/2025
Another day, another reported intrusion of the US government. www.nextgov.com/cybersecurit...
nextgov.com
‘Widespread’ breach let hackers steal employee data from FEMA and CBP
A Citrix vulnerability — suspected to have led to firings of multiple FEMA technology staff — enabled the breach, which let hackers pilfer data from FEMA servers connected to states at the southern bo...
020
CyberSecSac & DC916 @cybersec916.com · 21/09/2025
Enjoy pancakescon! pancakescon.com/2025-confere...
pancakescon.com
2025 Conference Information
PancakesCon 6 stream links are as follows, and ComfyCon will be cross-streamed for the 8 hours prior to the conference on Track 1: Recordings of talks are available on our YouTube, starting approxi…
020
CyberSecSac & DC916 @cybersec916.com · 15/09/2025
Incident reporting in an hour or less or the next one’s free 🍕 thecyberexpress.com/china-cybers...
thecyberexpress.com
China Imposes One-Hour Reporting Rule for Major Cybersecurity Incidents
China is ramping up its cybersecurity enforcement with new regulations requiring network operators to report severe cybersecurity incidents within one
000
CyberSecSac & DC916 @cybersec916.com · 13/09/2025
www.cybersecuritydive.com/news/cisa-pl... CVE's live? 🙌
cybersecuritydive.com
CISA pledges robust support for funding, further development of CVE program
A key official from the agency said the vulnerability management program will continue with additional participation and enhancements.
000
CyberSecSac & DC916 @cybersec916.com · 11/09/2025
The slides for this month’s presentation and @zoe-j.bsky.social ‘s book report are up on the Discord and will be up on GitHub shortly. This months news covered NPM, AI slop, GayFemboy malware and more! We also had a presentation on the Red Team Operations Handbook!
000
CyberSecSac & DC916 @cybersec916.com · 11/09/2025
That’s a wrap on the DC916 September meeting! Thank you to everyone who contributed articles, to discussions, for pizza, and for amazing community!
100
CyberSecSac & DC916 @cybersec916.com · 10/09/2025
While serving media from your Plex server is cool, please update your password and try not to serve malware from it. 👾 www.pcmag.com/news/plex-co...
pcmag.com
Plex Confirms Data Breach, Asks Users to Reset Passwords Immediately
An unauthorized third-party accessed one of its customer databases, which included emails, usernames, hashed passwords, and authentication data, Plex says.
000
CyberSecSac & DC916 @cybersec916.com · 10/09/2025
💜💜💜
media.tenor.com
three hamsters are sitting at a table with the words one of us
ALT: three hamsters are sitting at a table with the words one of us
010
Reposted by CyberSecSac & DC916
Edna (they/them) 🅅 @ednas.bsky.social · 10/09/2025
Officially official now, @blackbadgeraffle.bsky.social and I have launched DEF CON Group Orlando! Thank you @alethe.bsky.social and DCG!! We're on Discord welcoming new members and will have meetings starting soon! ✨ discord.gg/KyKYPBCv
media.tenor.com
a woman is laughing and saying it 's gonna be so fun !
ALT: a woman is laughing and saying it 's gonna be so fun !
364
CyberSecSac & DC916 @cybersec916.com · 10/09/2025
www.securityalliance.org/news/2025-09... Thanks to @djcapy.com for this one. (also, lol at them only getting 5 cents) 😂🔥
securityalliance.org
Oops, No Victims: The Largest Supply Chain Attack Stole 5 Cents
The biggest financial impact expected to be the millions of dollars of SaaS contracts signed with security vendors
010
CyberSecSac & DC916 @cybersec916.com · 09/09/2025
Largest supply chain breach ever (so far?) 😭 www.aikido.dev/blog/npm-deb... Thanks to DC916 member Slag1sh for the link! 💜
aikido.dev
npm debug and chalk packages compromised
The popular packages debug and chalk on npm have been compromised with malicious code
010
CyberSecSac & DC916 @cybersec916.com · 19/08/2025
NIST rolling out initial AI cybersecurity papers/standards. hackread.com/nist-concept...
hackread.com
New NIST Concept Paper Outlines AI-Specific Cybersecurity Framework
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
000
CyberSecSac & DC916 @cybersec916.com · 13/08/2025
Looking forward to seeing your faces at the DC916 meeting tonight! Virtual and in person at MADE Studio! 7pm-8:30pm PST! Dc916.com for the address/Discord! Hack the planet!
000
CyberSecSac & DC916 @cybersec916.com · 09/08/2025
Hope everyone is having a safe and happy DEF CON! 💜
000
CyberSecSac & DC916 @cybersec916.com · 28/07/2025
Hello friends, with less than 2 weeks to go until DEF CON 33, please enjoy our “Attending DEF CON Guide” (great for newbies/first timers) github.com/CyberSecSacr...
Flyer for DEF CON first timers
021
CyberSecSac & DC916 @cybersec916.com · 16/07/2025
When AI and fast food goes wrong. 😑 🍟 www.wired.com/story/mcdona...
wired.com
McDonald’s AI Hiring Bot Exposed Millions of Applicants’ Data to Hackers Who Tried the Password ‘123456’
Basic security flaws left the personal info of tens of millions of McDonald’s job-seekers vulnerable on the “McHire” site built by AI software firm Paradox.ai.
020
CyberSecSac & DC916 @cybersec916.com · 16/07/2025
Regular reminder to go outside and touch grass sometimes
020
CyberSecSac & DC916 @cybersec916.com · 15/07/2025
Planes, trains, and cybersecurity, oh my! 🚊 www.cybersecuritydive.com/news/railroa...
cybersecuritydive.com
Major railroad-signaling vulnerability could lead to train disruptions
The high-severity flaw could let a hacker abruptly halt — and potentially derail — a train.
030
Reposted by CyberSecSac & DC916
DCG 201 @dcg201.bsky.social · 12/07/2025
The @summerc0n.bsky.social vibes right now: #hackers #lucky13saloon
021
Reposted by CyberSecSac & DC916
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 12/07/2025
🎥 Missed one of my past conference talks? Let’s fix that. I’m sharing my favorites—packed with real-world advice, lessons, and a few laughs. “Building Security Champions” 📽️ twp.ai/9PTkef #CyberSecurity #SecurityAwareness #appsec #securitychampions
twp.ai
youtu.be
Diana Initiative 2021-Tanya Janca-Building Security Champions
021
CyberSecSac & DC916 @cybersec916.com · 12/07/2025
Earn up to $300k to help a cursed owl yell at people!
010
CyberSecSac & DC916 @cybersec916.com · 12/07/2025
[MEETING REMINDER] ❔What: Monthly Meeting - August 🕖 When: Wednesday, August 13th @ 7PM - 8:30PM+ 📍Where: Hybrid - Join virtually on Discord or come to the Sacramento Hacker Lab / MADE Studio! [details in Discord] 👾Join our Discord by checking our landing page for the link: dc916.com
dc916.com
Cybersecurity Sacramento (DC916)
A DEF CON group for hackers, makers, tinkerers and security enthusiasts in the Sacramento area.
000
CyberSecSac & DC916 @cybersec916.com · 11/07/2025
nvd.nist.gov/vuln/detail/...
nvd.nist.gov
NVD - CVE-2025-6514
000
CyberSecSac & DC916 @cybersec916.com · 11/07/2025
When a 9.6 MCP exploit drops impacting hundreds of thousands 😭 thehackernews.com/2025/07/crit...
thehackernews.com
Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads
A critical vulnerability in mcp-remote (CVE-2025-6514) allows remote code execution, affecting 437,000+ users.
110
Reposted by CyberSecSac & DC916
The Official Pulpit of CULT OF THE DEAD COW @cultdeadcow.com · 11/07/2025
HAPPY CULT OF THE DEAD COW DAY, SKEETR0NZ! Be Sure to hit-up your local 7/11 to collect the free slurpeez they're handing out to celebrate the birthday of cDc! Or, y'know, don't. We don't care. You do you, homeslice.
64219
Reposted by CyberSecSac & DC916
Kevin Beaumont @doublepulsar.com · 11/07/2025
I’m tracking 128 active CitrixBleed 2 victims in telemetry, today, from attacker infrastructure (one threat actor group).
2335
CyberSecSac & DC916 @cybersec916.com · 11/07/2025
nvd.nist.gov/vuln/detail/...
nvd.nist.gov
NVD - CVE-2025-6514
000
CyberSecSac & DC916 @cybersec916.com · 11/07/2025
When a 9.6 MCP exploit drops impacting hundreds of thousands 😭 thehackernews.com/2025/07/crit...
thehackernews.com
Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads
A critical vulnerability in mcp-remote (CVE-2025-6514) allows remote code execution, affecting 437,000+ users.
100
Reposted by CyberSecSac & DC916
Blenster 🅅 @blenster.com · 10/07/2025
It's 8:10 PM Eastern and I'm glad you're alive. Thanks for being here with me. I love you. You are worthy. #MakeKindnessNormal
6435
CyberSecSac & DC916 @cybersec916.com · 10/07/2025
Thank you so much for coming out and presenting! It was a joy having you all! @zoe-j.bsky.social presented their monthly book report and QQ presented on things to know for DEF CON first timers while Charles showed off his Geiger counter!
010
Reposted by CyberSecSac & DC916
DEF CON @defcon.bsky.social · 09/07/2025
Additional #defconworkshops information - when registration for #defcon33 workshops goes live on July 15 it will be through Humanitix, not EventBrite. 
#defcon
183
CyberSecSac & DC916 @cybersec916.com · 09/07/2025
AI PSA: Don’t make MechaH*tler. 🤖 www.rollingstone.com/culture/cult...
rollingstone.com
Elon Musk's Grok Chatbot Goes Full Nazi, Calls Itself 'MechaHitler'
Elon Musk's Grok chatbot has unleashed a slew of antisemitic commentary and praised Hitler after apparent change allowed to be 'politically incorrect'
000
Reposted by CyberSecSac & DC916
TracketPacer @tracketpacer.com · 07/07/2025
my birthright
1217414
CyberSecSac & DC916 @cybersec916.com · 07/07/2025
1 month out to DC33! Hope to see y’all there!
000
Reposted by CyberSecSac & DC916
ICEBlock Official @iceblock.app · 01/07/2025
Good morning everyone. We have some incredible news to share. ICEBlock is the #1 app in social networking on the Apple AppStore.
47125
Reposted by CyberSecSac & DC916
Ben Goggin @bengoggin.bsky.social · 01/07/2025
ICEblock, which allows users to alert others to the geographical location of ICE officers, is the top social networking app in the App Store right now after Karoline Leavitt condemned it from the podium yesterday.
618206797024
Reposted by CyberSecSac & DC916
Tanya Janca | SheHacksPurple @shehackspurple.bsky.social · 01/07/2025
#infosecgardening I grew these amazing flowers!
0161
CyberSecSac & DC916 @cybersec916.com · 30/06/2025
Ohhhh! Cox Networks v Sony Entertainment will be one to watch for piracy/ISP precedent. At issue is if ISPs should disconnect users based on alleged privacy from copyright holders. arstechnica.com/tech-policy/...
arstechnica.com
Supreme Court to decide whether ISPs must disconnect users accused of piracy
Sony victory in Cox piracy case could be overturned by Supreme Court.
031
CyberSecSac & DC916 @cybersec916.com · 30/06/2025
Who could have ever seen this coming? 🙄 www.cybersecuritydive.com/news/critica...
cybersecuritydive.com
‘Suspended animation’: US government upheaval has frayed partnerships with critical infrastructure
Recent federal cuts, reorganizations and other disruptions have alarmed industry leaders, who say the government is a less reliable partner even as cyber threats increase.
000
CyberSecSac & DC916 @cybersec916.com · 29/06/2025
Hope no one is planning on flying anytime soon. 🐦 www.nbcnews.com/tech/securit...
nbcnews.com
North American airlines targeted by cyberattacks
Westjet and Hawaii Airlines have both said in June statements that they have responded to cyberattacks.
000
Reposted by CyberSecSac & DC916
Bianca 'BiaSciLab' Lewis @biascilab.bsky.social · 28/06/2025
If you have kids bring them to DEF CON NextGen! I'm running it 👀
011
Reposted by CyberSecSac & DC916
Bianca 'BiaSciLab' Lewis @biascilab.bsky.social · 28/06/2025
A very important message to send to your non technical friends 😉 I'm on Instagram too 👀 @biascilab
042
Reposted by CyberSecSac & DC916
Phillip Wylie @phillipwylie.bsky.social · 28/06/2025
Jayson E. Street: Escaping Darkness podcasters.spotify.c...
podcasters.spotify.com
Jayson E. Street: Escaping Darkness by Phillip Wylie Show
Summary In this episode of the Phillip Wylie Show, Jayson E. Street shares his journey from a troubled childhood to becoming a prominent figure in the cybersecurity community. He discusses the importance of understanding the hacker mindset, the value of starting in blue team roles before transitioning to red team positions, and the significance of empathy and kindness in both personal and professional interactions. Through engaging stories and valuable insights, Jayson emphasizes the need for effective communication in security roles and the importance of fostering a supportive community. Takeaways Jayson E. Street emphasizes that everyone has a hacker origin story. Starting in blue team roles provides a solid foundation for cybersecurity careers. Effective communication is crucial for red teamers to convey findings to management. Success in security is measured by the impact on client awareness and behavior. Empathy and kindness are essential in navigating personal and professional relationships. The hacker mindset is about questioning and challenging the status quo. Networking and community support are vital in the cybersecurity field. Red teaming should focus on improving blue team defenses, not just breaking in. Personal growth often comes from overcoming past traumas and making conscious choices. It's important to remain humble and recognize that everyone has valuable insights to share. Sound Bites "You're one of my inspirations." "I was able to destroy them." "It's always time to be kind." Chapters 00:00 Introduction and Inspiration 03:18 The Hacker Origin Story 07:40 Starting in Cybersecurity: Blue Team First 13:03 Engaging Stories from the Field 21:58 The Importance of Communication in Security 25:26 Active Intrusions and Real-World Experiences 26:19 The Art of Social Engineering 30:56 The Hacker's Humility 36:05 From Rage to Empathy 41:02 Choosing Kindness Over Anger Resources https://www.linkedin.com/in/jstreet/ https://x.com/jaysonstreet https://jaysonestreet.com/
081
CyberSecSac & DC916 @cybersec916.com · 28/06/2025
The world could use some more joy and laughter, so let’s do a meme roundup from memes that DC916 members have posted! Thanks to members 0rphan @vxo.bsky.social Tee and echo419 for the memes! Since it’s summer stay hydrated, wear sunscreen, and happy hacking! #hacking #memes #makekindnessnormal
011
CyberSecSac & DC916 @cybersec916.com · 28/06/2025
So pretty! So sparkly!
010
Reposted by CyberSecSac & DC916
just Wes @justwes.info · 27/06/2025
If you’re a government employee…or were and no longer are the you need to check out @deviantollam.bsky.social’s new video for today. He mentions looking for the helpers while actively also being one! youtu.be/8Gno8dBMH1w?...
youtu.be
"Look for the Helpers" ... Free Training if You've Lost Your Job
YouTube video by DeviantOllam
053
Reposted by CyberSecSac & DC916
Inclusive Little Unicorn 🅅 @emmie.bsky.social · 27/06/2025
"Look for the helpers" 🫶🏻 If you're a former government worker who lost their job recently check out this amazing opportunity: youtu.be/fPppBGLnnBQ?...
youtu.be
"Look for the Helpers" ... Free Training if You've Lost Your Job
YouTube video by DeviantOllam
14021
CyberSecSac & DC916 @cybersec916.com · 28/06/2025
Even pups can't escape cyberespionage thehackernews.com/2025/06/over...
thehackernews.com
Over 1,000 SOHO Devices Hacked in China-linked LapDogs Cyber Espionage Campaign
China-linked hackers use compromised SOHO devices in espionage campaign, targeting Taiwan, the U.S., and Southeast Asia.
000
CyberSecSac & DC916 @cybersec916.com · 26/06/2025
What's old is new again, and decades on the same issues still persist. 🙄 federalnewsnetwork.com/cybersecurit...
federalnewsnetwork.com
A cybersecurity ‘awakening’ at the VA
The 2006 VA data breach shined a spotlight on cybersecurity challenges facing government. Many of those issues persist to this day.
000