buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Apparently a new #wankstortion campaign in progress, preserved message https://nxdomain.no/~peter/wankstortion/20260720_wankstortion_posing_as_me%40skapet.bsdly.net_peter%40bsdly.net.txt
I almost missed it because the message is in the graphic https://nxdomain.no/~peter/wankstortion/20260720_wankstortion_posing_as_me%40skapet.bsdly.net_peter%40bsdly.net.png and with mail client in dark mode the diversion text was displayed black on dark grey.
Fun fact: last hop before reaching here was a antispamcloud.com host
Not storyworthy in itself, so linking to my 2022 piece https://nxdomain.no/~peter/despicable_no_good_blackmail.html will do (w/links)
#sextortion #scams #spam #bitcon #bitcoin #cybercrime
How We’re Keeping Reddit Real and Safe in the AI Era
https://redditinc.com/news/how-were-keeping-reddit-real-and-safe-in-the-ai-era
…
― Blocking 23 million spam views per day before they ever reach a human user.
― Catching ~25K net new spammy posts and comments a day.
― Reducing spam exposure for our users by ~20% from January to March 2026, relative to the prior three months and an additional 10–15% drop in overall spam account exposure.
― Revoking nearly 2M inauthentic votes per day over the last three months.
…
It looks like whoever is behind this has finally come for one of my sites. Manually blocking datacenter IPs has worked for a while, but it seems like the traffic is now coming either from residential IPs, or the IPs are just getting spoofed.
Real conundrum. I didn't want to have to set up Cloudflare for the site, and I have to wonder how good they are at catching this anyway, but it might just come to that.
Anyone else has been dealing with this?
Proxmox Mail Gateway 9.1 erleichtert Kampf gegen Spam und verschlüsselt Backups
Das neue Proxmox Mail Gateway will mehr Komfort beim Mail-Handling bieten und die Möglichkeit, ihre Backups zu verschlüsseln.
#Datenschutz #EMail #IT #Linux #OpenSource #PostgreSQL #Spam #Verschlüsselung #news
Cybercrime Reported in May 2026
Interisle's monthly report on cybercrime activity (phishing, malware, spam) for the month of May 2026 revealed a 27% increase in phishing reported compared to April and a 35% increase in spam. While malware reported in May decreased 17% compared to April, it still represents an 11% increase over the monthly average for the 12 -month period.
https://interisle.substack.com/p/cybercrime-reported-in-may-2026
#phishing #malware #spam #dnsabuse #cybercrime #cybersecurity
I'm so sick of it.
❗ We’ve observed a scammer clearly abusing Microsoft's 'msonlineservicesteam@microsoftonline[. ]com' for spam distribution.
The header and message body appear completely legitimate - the abuse is happening through injection into the Subject:
✉️ Here's an example:
"Your PayPal order for 0.0092 BTC ($699.99) is complete. Not you? Call +1 (803) 237-5050 account email verification code."
At this point, it appears the attacker may have simply set the malicious text as either the account name or the organization name.
This also appears to line up with what @zackwhittaker TechCrunch Security Editor identified last week:
https://mastodon.social/@zackwhittaker/116562360000833298
....although the activity we’re seeing appears to stretch back several months.
Takeaway: automated notification systems should not allow this level of customization.
Microsoft has been informed of this abusive activity.
Scammers are abusing an internal #Microsoft account to send #spam links
https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/
Dear spammer: when dealing with automated marketing campaign, AI is not just your friend, it is also my friend. And I also have another good friend: GDPR. I am taking great delight in automating GDPR requests that border legal threats against your undesired email campaign. This typically escalates quickly from "canned AI response" to "automated AI response trying to do damage mitigation" to "concerned human replying apologetically because its AI agent alerted them that someone with a lawyer is genuinely angry". Ah, the little joys of life!
Your business does not deserve to exist. What you call "your job" is parasitic. Do you think your mom would be proud of you?
#ai #gdpr #privacy #spam #marketing #capitalism #parasite #justice #shame
Sind irgendwo gerade .com-Domains im Sonderangebot? Spammer haben die grad als Wegwerf-Domains für Mailspam.
An unknown threat actor is abusing a remote management tool called #TiFLUX as an initial access vector, targeting a broad range of potential victims by email. The attacks using this Brasil-originated commercial utility began in February, but really ramped up in April and the beginning of this month.
The lures employ a variety of #spam tropes, including bogus event invitations and business invoices/bills.
TiFLUX seems uniquely vulnerable to this kind of abuse; The installer package also installs an old version of UltraVNC as well as a vulnerable #loldriver that can elevate privileges. Weirdest of all, the attackers are also using this RMM to deploy other heavily-abused RMMs, including #Splashtop and #ScreenConnect to the devices that get hit. Those RMMs are connecting to IP addresses associated with known bulletproof hosts.
This is my first post at the @huntress blog: https://www.huntress.com/blog/tiflux-rmm-install
We are very close to a new OpenBSD release. "You Have Installed OpenBSD. Now For The Daily Tasks." https://nxdomain.no/~peter/openbsd_installed_now_for_the_daily_tasks.html can help you prepare for the upgrade.
If you are using exim as your MTA (or any other non-base system MTA), "OpenSMTPD Is The Mail Server For The Future" https://nxdomain.no/~peter/time_for_opensmtpd.html contains useful pointers for a better mail future.
#openbsd #newrelease #openbsd79 #opensmtpd #email #smtp #rspamd #antispam #spam
Migrating mail servers from exim to OpenSMTPD (smtpd) is fun and useful https://www.undeadly.org/cgi?action=article;sid=20260516064650 #openbsd #opensmtpd #smtpd #exim #email #smtp #mail #spam #antispam #greylisting #greytrapping #mailmigration
OpenSMTPD Is The Mail Server For The Future https://nxdomain.no/~peter/time_for_opensmtpd.html Migrating to OpenSMTPD from exim on OpenBSD was joyfully painless and smooth. #openbsd #opensmtpd #email #smtpd #rspamd #spam #antispam #greylisting #greytrapping #mailserver
Warum bekommt man Spammails in denen nichts drin steht?
Kann auch nichts anklicken.
Ich pranger das an ! 👆
„Irreführende Praxis“: Google bestraft „Back-Button-Hijacking“ als Spam
Google geht künftig gegen Webseiten vor, die den Zurück-Button des Browsers manipulieren. Ab Mitte Juni drohen Betreibern manuelle Spam-Maßnahmen.
1/4
I’m looking for a little help about dealing with the seemingly mass attack of Russian bots. What's the best way of handling this?
I report this Russian propaganda as 'Something Else' and bookmark a post, so that I can later see if the account is still running, then I block the account. I also leave the checkbox on, for the server itself to receive my report
Many accounts are not suspended
#Mastodon #Fediverse #Spam #Propaganda #ActivityPub #Russia #Putin #Ukraine #EU
@_elena Translation inside #Mastodon is a real game changer + step up.
But people who don't make #time or see the point in replying limits it all.
Using all levels of people / energy here 👍
rather than feel depth is a kind of liability or time-drag, seeing people as kind of #Spam for it.
I prefer the less defensive "show me what you got" usage instead of looking for perfection or short text.
Sincerity (people who critique) and #Spam can also look the same if not given time / care ur side ⚠️
hm. this thing seems to be popping up again and again https://news.ycombinator.com/item?id=47636937 #greytrapping #email #runyourownmailserver #spam #spamd #greylisting #antispam
My cache all email got some spam/phishing email with the link url being a github.io url.
I am wondering if something scraped my Mastodon instance and misidentified the account, which doesn't have an email account created, as an email address. How do I report this to #github? #Phishing #Spam
mail-auth-service-source dot github dot io/srf-client_id-REDACTED?emp=redacted@oldfriends.live is the link
Here's a head-shake worthy #spam from overnight if anyone wants to play with the scammer:
I'm Jeff Bezos,
The CEO of Amazon, it's on this note that I'm informing the world of my intention to give out my Fortune of $124 Billion of my wealth to the lucky ones around the country and world at large.
Congratulations, your name and details were randomly selected from some Google business contact listing as one of the beneficiaries of this
charity project. each person would be awarded $1,200,000,00
[link to a cnbc story, jeff-bezos-says-he-plans-to-give-away-most-of-his-124-billion-fortune]
DONATION CODE: G506328
Contact how to proceed.
Email: mrjeffbezos87 (at) gmail dot com
Words Commonly Found in Spam Domains
In a previous post, Interisle looked at the practice of embedding brand strings in domain names used for phishing and spam. Today, we’ll provide a summary of words that we most often find in domains used to spam.'
https://interisle.substack.com/p/words-commonly-found-in-spam-domains
I'm not sure how Layla and May001 snuck past SpamAssassin but the assassin is being re-trained.
(I'm not asking for advice about dealing with spam. SpamAssassin has this one well in hand. I'm just curious if anyone else has been seeing spam like this).
I gather they've finally taken this measure because of the preponderance AI-generated slop, but with any luck these other issues will improve too. The arXiv press release states “Review/survey articles or position papers submitted to arXiv without this documentation will be likely to be rejected and not appear on arXiv” so it does sound like they are acknowledging the other problems and intend to enforce their rules more strictly in the future.
"arXiv says it will no longer accept Computer Science papers that are still under review due to the wave of AI-generated ones it has received."
From https://infosec.exchange/users/josephcox/statuses/115486903712973154
#Google #GoogleClassroom #Gmail #spam #MonopolistsDontInnovate
This post is not an invitation to scold me for using Google products or to suggest alternatives. It is also not a request for technical support.