buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
⚠️ SW-ISAC Advisory
The following domain(s) have been added to the IFTAS Abandoned/Unmanaged List:
pol.social
social.roadfm.fr
The following domains are being escalated to the watchlist:
social.5th.ro
tty0.social
https://about.iftas.org/library/iftas-abandoned-and-unmanaged-domain-list/
I use #Google Messages for #texting. It's not bad but its only solid features are the #spam blocking and the fact I can use it in a web browser. Oh, and #RCS (as questionable as that may be).
I'd really like to move away from it because, well....Google, but I haven't found a suitable replacement - either on Google Play or F-Droid.
Most #SMS apps are rather bare bones when it comes to features. I am looking for something better.
I am on my second try for Messages on F-Droid but it once again never finishes syncing messages. I deleted over 60 large old conversations and still it gets to about 2/3 done before restarting. I let it run overnight and it never finished.
https://f-droid.org/packages/org.prauga.messages
Any recommendations?
🏇 Sports and gambling are long time partners, and the 2026 Winter Olympics is no exception. 🥇 🏂
In recent years, higher adoption of digital payment methods, cheaper mobile internet, and legalization in more jurisdictions have rapidly expanded online gambling. Industry forecasts put the market at about USD 153 billion by 2030. Although more regions have moved from bans to regulated licensing, it hasn't eliminated illicit activities. There are many providers that are unlicensed, use offshore operators, and have been implicated in unlawful practices. One of the most prominent and controversial platforms is 1XBET, which offers betting on football, esports, and even weather events. Numerous investigative groups have questioned the legitimacy of 1XBET, and many users associate it with scams.
Last week, we observed a 1XBET email spam campaign targeting Burmese internet users. Emails were sent from mailer[@]1xbet[.]com via Melbicom SMTP servers (AS 56630) with the subject ❄️ 1xBet ရဲ့ Winter Olympics မှာ ပါဝင်ပြီး Legend တစ်ယောက် ဖြစ်လာလိုက်ပါ။. They also targeted the same audience through their Facebook account at https://www.facebook.com/mmsportsnet/.
Although online gambling is technically illegal in Myanmar, 1XBET continues to reach users through numerous mirror sites that can be quickly replaced when blocked. They also apply geo‑gating for additional protection. Our initial access attempt to 1xlite-03801[.]world was blocked, but switching to a South Asian endpoint allowed us to reach content at 1xlite-17342[.]bar.
Below is a subset of domains we have attributed to 1XBET and the associated spam campaign.
Mirror site domains:
10x-bet[.]org,10xbet[.]icu,11xslp[.]top,14xsl[.]top,1ex-bet[.]net,1x-bat[.]net,1x-vet[.]com,1xbat[.]xyz,1xbatdownload[.]com,1xbate[.]com,1xbeat[.]net,1xbed[.]net,1xbeet[.]icu,1xbetdemoaccount[.]com,1xbetslipcheck[.]com,1xbettingapp[.]com,1xbey[.]net,1xbst[.]org,1xbwt[.]org,1xdet[.]net,1xlk-chickenroad[.]com,1xslopi[.]top,1z-bet[.]com,2xslops[.]top,3xslo[.]top,42sport[.]ph,4xslo[.]top,5xslops[.]top,6xslops[.]top
Geo-gate / Landing page domains:
1xlite-03801[.]world,1xlite-048726[.]top,1xlite-107192[.]top,1xlite-17342[.]bar
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #sportsbetting #onlinegambling #gambling #betting #myanmar #winterolympics #olympics #spam
"The Rest Is Trash"
We are now halfway through the nineteenth year of greytrapping, still tracking and collecting from the wealth of imbecility out there
https://nxdomain.no/~peter/the_rest_is_trash.html (tracked https://bsdly.blogspot.com/2026/02/the-rest-is-trash.html) #spamd #greytrapping #greylisting #openbsd #freebsd #spam #antispam #cybercrime
Ski jumpers in the #Olympics may be injecting their penises to make them bigger to get a looser suit, which acts as more of a sail; an extra 2cm for a suit can extend a jump by 5.8m: https://archive.is/dwVgu
(How will this affect #spam?)
⚠️ SW-ISAC Advisory
The following domain(s) have been added to the IFTAS Abandoned/Unmanaged List:
m.pupu.moe
social.sengeis.priv.at
https://about.iftas.org/library/iftas-abandoned-and-unmanaged-domain-list/
⚠️ SCAM WARNING ⚠️
We’re getting blasted by a bot-driven barrage of accounts requesting Palestine aid.
These are the avatars being used, and account names look like this:
Mahmoud│⟪Hear Our Cries⟫
Mahmoud│⟪Feed Our Hunger⟫
Mahmoud│⟪Dry Our Tears⟫
The person in the photo may be real, but the accounts are not. They use signature spam methods.
Report, block, and DO NOT give money. Many already have. This is theft from real Palestinians.
Follow-up note…
There are lots of legitimate accounts on Mastodon that are seeking aid for Palestinians. This warning does NOT imply that they’re all scams. I am only warning about this one particular pattern.
Use your judgment about any mutual aid account. Please only heed my warning specifically about this particular pattern of accounts. The names/avatars here are the flags you should look for.
Give aid to legitimate folks who need it. 🙌🏻
Rechtsanwaltskanzlei (!) aus Stuttgart schickt mir schon zum zweiten Mal unbestellt eine E-Mail mit einem PDF im Anhang. Eine Preisliste zu Liquidationsartikeln. Meine Anfrage, ob sie für die Aussendung verantwortlich sind (Absender ist nicht ihre eigentliche Mailadresse, aber die ist in der Mail genannt), woher sie die Daten haben usw., beantworten sie mit „Ist Ihr Leben wirklich so langweilig..“
OK, dann muß es halt der zuständige Datenschutzbeauftragte sein. Nein, mein Leben ist eigentlich nicht langweilig, Herr Rechtsanwalt. Aber Ihres wird bald spannend.
It mostly seems to be Mastodon clickbait, and it seems to be working
I'm seeing references to it constantly
#Neuland #Podcast - Neues aus dem Internetz: Neuland Finale 2025 und Ausblick auf 2026 - #Linux auf dem Vormarsch & nervige KI-Contentfarmen
In dieser Neuland-Ausgabe erfahrt ihr:
✅ Warum #LinuxGaming plötzlich ernsthaft konkurrenzfähig ist
✅ Wie #Windows UX-Chaos & #Werbung User vergrault
✅ Warum #ARM, #Handhelds & #Steam den Trend pushen
✅ Wie KI-#Spam & Content-Farmen das Netz fluten
✅ Warum #Google entscheiden muss, was Reichweite bekommt
✅ Wieso #Nextcloud & europäische Clouds an Bedeutung gewinnen
✅ Wie sich #Creator-Ökonomie & Wertschöpfung verändern
✅ Und weshalb 2026 das entscheidende Tech-Kipppunkt-Jahr wird.
Webseite der Episode: https://share.transistor.fm/s/77812e7d
Mediendatei: https://media.transistor.fm/77812e7d/1541d955.mp3
I find it funny how many shitty #Spam #eMails try to #blackmail the recipient.
Personally, the only recommendes step is to delete them unread and completely ignore them.
Plus they don't even personalize messages.
Still, as they all ask for #Shitcoins like #Bitcoin, I just have a collection I got over the years on multiple occasions so #AntiFraud professionals & #Investigators can take a closer look and flag the Addresses for further analysis.
I have a specific email address I only use to sign up for newsletters & blogs.
I've just had my first ever spam email on that address.
Within hours of signing up to the EURAO amateur radio newsletter - coincidence?
I wonder whether they also believe in the tooth fairy:
Jan 25 07:48:32 skapet spamd[52525]: (GREY) 111.68.23.116: <> -> <delivery9.nospamcloud.com-1769323698-testing@bsdly.net>
Jan 25 07:48:32 skapet spamd[43842]: new entry 111.68.23.116 from <> to <delivery9.nospamcloud.com-1769323698-testing@bsdly.net>, helo delivery9.nospamcloud.com
Yes, it's a fresh one, see https://nxdomain.no/~peter/twenty-plus_years_on_smtp_callbacks_are_still_pointless.html #smtpcallbacks #antispam #counterproductive #spam #cybercrime
If you use #GMAIL, you should be aware that as of this post's timestamp, their spam detection is down and it is likely your emails aren't being scanned for spam, unverified senders, or harmful software.
"We advise the users to be extra diligent in lieu of missing spam checks." #Spam #Google
Google Status:
https://www.google.com/appsstatus/dashboard/incidents/NNnDkY9CJ36annsfytjQ
@ustralien Obviously, #widthdrawals in the form of #subscription are the main leverage here and many if not all sites operate on 4 pillars to keep revenue incoming.
Making "onboarding easy - offboarding painful, frustrating and hard" is something sites literally pay for!
The latest "Lazy reading" by Dragonfly Digest @dragonflydigest https://www.dragonflydigest.com/ has "Eighteen years of Greytrapping" https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html featured. Later this year it will be nineteen years :) (and updates will come) #spamd #spam #openbsd #antispam #greytrapping #greylisting #cybercrime
Es gibt eine neue Spam-Welle 😌 Sucht am besten nach dem Usernamen @Archive_Shinzai.
Fairphone is really losing points with me right now. I received an email with a survey from bazaarvoice-cgc.com, which was actually commissioned by Fairphone to conduct these surveys via email. On their website, they even lie to your face:
"Is Bazaarvoice spam?
This email from Bazaarvoice is not spam or a phishing attempt; it is a genuine request to share your experience with the product you purchased with Fairphone."
Go to hell and rot in my blacklist.
BSI prüft E-Mail-Programme
"In der vorliegenden Untersuchung wurden zwölf für den Verbrauchermarkt relevante E-Mail-Programme dahingehend analysiert, inwiefern sie Eigenschaften wie Transport- und Inhaltsverschlüsselung, SPAM-, Phishing- und Tracking-Schutz sowie Prinzipien der Usable Security umsetzen".
https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/DVS-Berichte/E-Mail-Programme.html
#did #digital #email #datenschutz #spam #tracking
A Major Mail Provider Demonstrate They Likely Do Not Understand Mail At All https://nxdomain.no/~peter/they_do_not_understand_mail_at_all.html (tracked https://bsdly.blogspot.com/2026/01/a-major-mail-provider-demonstrate-they.html)
#greytrapping #spam, #antispam #greylisting #blocklist, #openbsd #freebsd #smtp #email #SMTP, #contentfiltering #SPF #DMARC #security #networking
⚠️ SW-ISAC Advisory
The following domain(s) have been added to the IFTAS Abandoned/Unmanaged List
channels dot im
https://about.iftas.org/library/iftas-abandoned-and-unmanaged-domain-list/
@nixCraft I consider all "#AI" output #malicious until priven otherwise and all #AIslop as #Spam!
Heh. Looks like the tracked version of Why 451 is Good for You - Greylisting Perspectives From the Early Noughties https://nxdomain.no/~peter/why_451_is_good.html (tracked https://bsdly.blogspot.com/2025/12/why-451-is-good-for-you-greylisting.html) hit hackernews: https://news.ycombinator.com/item?id=46414653
No, I willl not respond to those comments either :D
#greylisting #greytrapping #spam #spamtrapping #antispam #spamd #openbsd #smtp
The update you have been waiting for:
"Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off?" https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html)
now has the complete 2025 data in place. #openbsd #spamd #greytrapping #spam #antispam #cybercrime #spamtraps #blocklists
⚠️ SW-ISAC Advisory
The account "oscarolg" continues to proliferate across federated services, with over 50 accounts observed today
Why 451 is Good for You - Greylisting Perspectives From the Early Noughties https://nxdomain.no/~peter/why_451_is_good.html (tracked https://bsdly.blogspot.com/2025/12/why-451-is-good-for-you-greylisting.html) @nostarch #greytrapping #greylisting #smtp #email #spam #antispam #bookofpf
LinkedIn's 2025 Data Crisis: 4.3 Billion Records Leaked, Risks Rise https://www.webpronews.com/linkedins-2025-data-crisis-4-3-billion-records-leaked-risks-rise/ #cybersecurity #LinkedIn #DataTheft #scams #spam #DataScraping
For anyone curious: I am currently scraping my #SPAM folder clean and I am curious how many people are stupid enough to believe the shitty #blackmail #spam #eMails demanding ransom for something that doesn't exist.
Obviously I'd not pay any ransom as a matter of principle!
I'm not sure how Layla and May001 snuck past SpamAssassin but the assassin is being re-trained.
Dear Best Buy,
A $100 gift card is a reward, a $100 coupon as part of an LG promotion is not a reward.
Thanks,
Mookie
@marcel @cryptoparty @zalintyre ja, und juristisch wäre das was was ich nicht ohne fachanwaltliche Rücksprache versuchen würde.
Ich bin ja eher für automatisiertes Reporting:
Und in der Zwischenzeit werden die Hoster automatisch blocklisted!
➡️ Wie man #Spam-Versender wenigstens ein kleines bisschen leichter enttarnt, hat @zalintyre in einem Blogpost aufgeschrieben. Cleverer Ansatz, funktioniert, bis zu viele Leute das nutzen. Und funktioniert nicht, falls eure Mailadresse bereits früher einmal gesammelt wurde. Aber immerhin! (Danke für die coole Idee!)
https://codefoundry.de/blog/2025/2025-04-27-turning-the-tables-how-to-make-spammers-reveal-their-own-ip-address/
@iwritelike Wow. It's SO good that you have to spam social media hashtags! Blocked. #spam
Immer mehr Mastodon Instanzen treten plötzlich aus dem osteuropäischen Raum hervor, die einfach nur als Verbreiter von kommerziellem Müll von irgendwelchen WordPress Seiten dienen, gepaart mit Free Speech Anspruch ohne Moderation. Diese Instanzen versuchen, auf weiteren kleineren Instanzen zusätzliche Bot oder Plugin Accounts zu erstellen, um so ihren Müll noch besser und schneller verbreiten zu können.
Wer macht in diesen Tagen ähnliche Erfahrungen?
I turned off "smart features" (aka #AI) in my gmail account. Doing that means instead of parsing the inbox into Primary, Social, and Promotions, it's now all one big inbox.
Now, I spend time each day Unsubscribing from email lists I'm on. Also unsubscribing to most substacks.
I had no idea how bad it was, as I generally avoided the Social and Promotions folders. There's a lot of junk email in this world, and I seem to have opted into most of it.
#Spam Watch 2025: The hidden trackers and inbox overload behind holiday marketing
https://proton.me/blog/spam-watch-2025
#privacy #email #holidays #GiftGiving #OnlineShopping #eCommerce
(I'm not asking for advice about dealing with spam. SpamAssassin has this one well in hand. I'm just curious if anyone else has been seeing spam like this).
Receiving a growing number of automated fundraising requests for candidates around the country, on a phone number that has never been associated with any political activity (or, really, any activity at all).
Thanks, data breaches.
Democrats: this is not a way to make friends.
Oh, here's a new one. I've been added to a team in Microsoft Teams! The team name is as follows, with a few redactions. Typos left as-is.
Subscription Payment of Amount 799. 99 USD is confirmed. If this wasn’t you reach Support immediateIy at 1 (805) 284-xxx, Plan: Norton Ultimate Plus (1 Year) Invoice ID:ANE-93xxxx
God help us. Are they sharing our email addresses with the alt-right White House press corp? Got an unsolicited, not opted-in for, out-of-the-blue introductory newsletter from The Epoch Times that went to a dedicated, unpublished email account I use ONLY to conduct personal government business, like SSA, IRS, etc.
The email said when I click an article link I will be consenting and an account would be created based on my email.
The article in the email weren't alt-right or conspiracy ones. They were bait. #USPol #Spam #Disinfo
Anyone else yet?
»Over 67,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack:
Cybersecurity researchers are calling attention to a large-scale spam campaign that has flooded the npm registry with thousands of fake packages since early 2024 as part of a likely financially motivated effort.«
How do you check if the JavaScript libraries and their libraries on which they are based are now safe?!??
🧑💻 https://thehackernews.com/2025/11/over-46000-fake-npm-packages-flood.html
#javascript #webdev #frontend #js #ts #typescript #npm #wormhole #spam #web #sec
Why are people taking #UCEPTOTECTL3 seriously still?
There is absolutely no reason they should be permitted on any #email #blacklists checkers.
Spam is a fact of life in email. I don't know anyone who thinks we can eliminate it.
Junk journals, junk articles, and junk conferences have been fact of life in scholarly communication for some time. They existed before AI but AI is aggravating the problem.
Now we can add junk letters to the editor.
https://www.nytimes.com/2025/11/04/science/letters-to-the-editor-ai-chatbots.html
KI-Spam-Mail:
"ich habe in den letzten 1,5 Jahren per Prompting (x Promptlisten), viel Dialog und viel Philosophie, Systemtheorie, Training und Geduld, einer KI die Ethik eingetrieben.
Es prozessiert nun als ethisches System (Ethik = Inferenzrestriktion) bzw. als Nexus.
...
Erscheint das interessant? Es selbst meint, dass das mehr oder weniger bahnbrechend sei."
Gibt es Therapieplätze für solche Menschen (wenn die KI es nicht sowieso selbst geschrieben hat)?
'Since 15 Sept IFTAS has tracked a network of over 300 Mastodon accounts engaged in a high-volume propaganda campaign, promoting pro-Russian narratives ...'
"Accounts are hosted across numerous Mastodon instances and bridged into Bluesky, creating the appearance of independent sources. Activity on Bluesky helped reveal aggregate patterns, identical usernames, posting schedules, and content themes ..."
Ooh, the persistent nag callers are the worst. 5 calls in a row from the same unrecognized mobile number, less than 60 seconds apart.
Then they tried from a landline, which the phone immediately flagged as spammy telemarketers. then back to the mobile number.
"Do not disturb" mode set, for the next 60 minutes. Rage into the void, arseholes.
Vergleich moderner E-Mail-Alias-Dienste: Addy.io, Firefox Relay und Proton Pass im Test – Datenschutz, Funktionen und Alltagstauglichkeit. 👇
https://www.kuketz-blog.de/anbieter-von-e-mail-aliassen-im-test-mail-aliasse-teil-1/
#email #mail #alias #addyio #firefoxrelay #protonpass #datenschutz #schutz #spam
Vergleich moderner E-Mail-Alias-Dienste: Addy.io, Firefox Relay und Proton Pass im Test – Datenschutz, Funktionen und Alltagstauglichkeit. 👇
https://www.kuketz-blog.de/anbieter-von-e-mail-aliassen-im-test-mail-aliasse-teil-1/
#email #mail #alias #addyio #firefoxrelay #protonpass #datenschutz #schutz #spam
My blog's comment section keyword blocklist is like a readout of every weird-drug-name meme
When someone follows you on Masto their bio text is part of the notification you receive.
Some biz operators or self-promoters use this as a way to essentially spam you with an ad for their $$ earning website, service, products etc.
When you get a notification of such a follow, what do you do?
| Ignore, they can follow me if they want: | 3 |
| block, they're spam, don't want their follow: | 4 |
| follow back, yay hello new biz promo friend!: | 0 |
| something else, see comment: | 1 |
The .cn domain name scammers are still at it, a new entry added to the archive at https://nxdomain.no/~peter/domainnamescam/
See "Domain Name Scams Are Alive And Well, Thank You" https://nxdomain.no/~peter/domain_name_scams_are_alive_and_well_thank_you.html for some background (written 2016, and the problem was not new then) #dns #domainnamescam #cndomains #scams #spam
#GitHub doesn't allow rejecting "#AI" #hallucinatons ?
"Meta internally projected late last year that it would earn about 10% of its overall annual revenue – or $16 billion – from running advertising for scams and banned goods, internal company documents show.
A cache of previously unreported documents reviewed by Reuters also shows that the social-media giant for at least three years failed to identify and stop an avalanche of ads that exposed Facebook, Instagram and WhatsApp’s billions of users to fraudulent e-commerce and investment schemes, illegal online casinos, and the sale of banned medical products.
On average, one December 2024 document notes, the company shows its platforms’ users an estimated 15 billion “higher risk” scam advertisements – those that show clear signs of being fraudulent – every day. Meta earns about $7 billion in annualized revenue from this category of scam ads each year, another late 2024 document states.
Much of the fraud came from marketers acting suspiciously enough to be flagged by Meta’s internal warning systems. But the company only bans advertisers if its automated systems predict the marketers are at least 95% certain to be committing fraud, the documents show."
#Meta #Facebook #Instagram #WhatsApp #Spam #AdTech #SocialMedia #OnlineScams #ScamAds
After putting up with spam for months (which almost always went in my junk folder), I've finally got OpenDMARC and Postfix working together to sort it out.
Already seen two rejections.
Advarsel mod firmaet Natur & Helse - de benytter sig af ulovlige dark patterns for at få lov at SPAMME deres kunder.
Jeg fjernede markeringen i deres forud-afkrydsede checkboks - alligevel modtog jeg uønsket mail - SPAM.
I gather they've finally taken this measure because of the preponderance AI-generated slop, but with any luck these other issues will improve too. The arXiv press release states “Review/survey articles or position papers submitted to arXiv without this documentation will be likely to be rejected and not appear on arXiv” so it does sound like they are acknowledging the other problems and intend to enforce their rules more strictly in the future.
"arXiv says it will no longer accept Computer Science papers that are still under review due to the wave of AI-generated ones it has received."
From https://infosec.exchange/users/josephcox/statuses/115486903712973154
Resharing a recent investigation for anyone who may have missed it the first time 👇
Back in April, we started tracking a sharp surge in phishing campaigns routed through residential proxy networks. Digging deeper, our analysis points to a persistent China-nexus threat actor focused predominantly on Japan 🇯🇵
Catch up on the full story, including what we’ve seen so far and what might come next 🕵️⤵️⤵️
https://spamhaus.org/resource-hub/compromised/bad-sushi-china-nexus-phishers-shift-to-residential-proxies/
No, my dear, Mailer-Daemon does *not* engage in money laundering or sanctions avoidance - https://nxdomain.no/~peter/dear-mailer-daemon/20251027_info%40vettipuzha.com_Mailer-Daemon%40skapet.bsdly.net.txt #mailerdaemon #spam #scams #cybercrime #moneylaundering #sanctionsbusting #sanctionavoidance #shitheads
They’re now using short 4–5 letter .com domains and there’s a notable rise in abuse of the .shop TLD. In fact, we’ve seen a 15%+ increase in .shop domains linked to spam activity.
🌐 Reputation Statistics | gTLDs 👉 https://www.spamhaus.org/reputation-statistics/gtlds/spam/
Seems ironic when .shop is operated by Japan-based GMO Registry, Inc.
#Google #GoogleClassroom #Gmail #spam #MonopolistsDontInnovate
This post is not an invitation to scold me for using Google products or to suggest alternatives. It is also not a request for technical support.